JULY 18, 2026

Platform Sunset Forces a Compliance Reckoning

When the compliance platform a 630-person investment firm had relied on for years announced it was shutting down, the security team had 18 months to find a replacement that could handle custom frameworks, automate evidence collection, and bring order to a vendor risk process running entirely on spreadsheets. After an independent market survey confirmed Drata as the leading option, the firm's Deputy CISO drove a focused technical evaluation that ended with a signed contract and a clear path to replacing every workflow the old platform had supported.

[ The Problem ]

Their compliance platform was sunsetting. Their vendor risk process was a spreadsheet. The clock was running.

The firm's compliance program depended on a platform that would reach end-of-life within 18 months, covering custom framework management, recurring compliance tasks, and policy tracking. Losing it without a replacement meant losing automated support for every one of those workflows at once.

At the same time, vendor risk management was entirely manual — security reviews, questionnaires, and third-party posture tracked across spreadsheets, consuming operational bandwidth the team could not afford to keep spending. Neither problem could wait indefinitely, and the convergence of platform loss, manual process burden, and regulatory alignment requirements created pressure that eventually forced a decision.

[ What they needed ]

The security team needed to accomplish several things simultaneously:

  • Replace a sunsetting compliance platform before its end-of-life deadline
  • Preserve custom framework support for internal and regulatory frameworks
  • Automate evidence collection across a hybrid cloud and on-premises infrastructure
  • Consolidate vendor risk management out of spreadsheets and into a structured workflow
  • Validate the right platform choice through independent third-party research before committing
  • Secure internal budget approval and close before year-end fiscal window closed

[ Why Drata won ]

Selected over Vanta, Drata won because a hands-on proof of concept demonstrated capabilities Vanta could not match on custom frameworks and vendor risk management.

  1. POC depth created real switching costs: the solution engineer worked through live technical problems alongside the buyer's team, including custom framework creation and multi-account AWS troubleshooting. By the time the evaluation concluded, the team had already built working solutions inside Drata's platform.

  2. Custom framework flexibility was a hard requirement Vanta could not meet: the firm needed to manage an internal framework alongside NIST CSF, and Drata's ability to create and maintain custom frameworks was a direct functional gap in the competing platform.

  3. Vendor risk management depth tipped the decision: Drata's TPRM module offered a structured replacement for the firm's manual spreadsheet process. Vanta's bundled offering did not provide equivalent capability for this use case.

  4. Commercial structure removed procurement friction: by routing through a managed service partner's order form, removing auto-renewal and logo rights clauses, and offering deferred billing with a January start, the team eliminated the legal sticking points that could have pushed the close into the following quarter.

[ How Drata solved it ]

Drata's GRC platform gave the team a direct replacement for the custom framework management and compliance task workflows they were losing, with the ability to build and maintain internal frameworks alongside NIST CSF alignment in a single environment. Drata's TPRM module replaced the spreadsheet-based vendor risk process, centralizing security reviews, questionnaire tracking, and third-party posture management in a way the old platform never supported.

A hands-on proof of concept let the team build custom frameworks, configure integrations across AWS, Microsoft Intune, Bamboo HR, and GitHub, and validate the control-evidence-policy model against their actual environment. Drata's Trust Center addressed the firm's inbound security questionnaire volume, reducing the manual effort required to respond to routine diligence requests. The depth of technical engagement during the evaluation, including live troubleshooting of a complex multi-account AWS environment, gave the team confidence that the platform could handle infrastructure complexity that out-of-the-box cloud tooling could not.

[ Before and after Drata ]

Before Drata, the firm's compliance program depended on a platform with a known expiration date and a vendor risk process that ran entirely on manual spreadsheet tracking. After, both gaps are addressed under a single contract: compliance workflows continue without interruption and third-party risk management moves into a structured, automated environment for the first time.

Before Drata
After Drata
Before DrataCompliance platform approaching end-of-life with no replacement in place. All custom framework management and task tracking at risk of disappearing.
After DrataCompliance workflows migrated to Drata before end-of-life. Custom framework support preserved with no operational gap.
Before DrataVendor risk management tracked manually across spreadsheets. Security reviews and third-party posture monitoring consumed direct team time with no automation.
After DrataTPRM module centralizes vendor security reviews, questionnaire tracking, and third-party posture management. Spreadsheet dependency eliminated.
Before DrataNIST CSF alignment and internal framework management handled in a tool that would not exist beyond December 2026.
After DrataNIST CSF and internal frameworks managed in a single GRC environment with automated evidence collection and control mapping.
Before Drata117 AWS accounts and hybrid on-premises infrastructure with no unified evidence collection. Each integration required manual effort.
After DrataAWS integration configured across multi-account organizational structure. Hybrid infrastructure covered through custom connections built during the POC.
Before DrataInbound security questionnaires handled manually with no shared content layer to deflect repeat requests.
After DrataTrust Center handles routine inbound security questionnaire requests. Manual response effort reserved for novel or high-priority diligence only.

[ Business outcome ]

The firm entered 2026 with a compliance platform under contract, a structured onboarding timeline in motion, and a vendor risk process no longer dependent on manual spreadsheet management. Custom framework support for both internal and regulatory requirements is preserved without interruption as the old platform winds down.

The 24-month contract creates a defined window to mature the firm's risk management practices and build toward expanded platform adoption as those processes develop. The Deputy CISO now has a single GRC environment covering compliance automation, third-party risk, and evidence collection across a hybrid infrastructure that no single prior tool had addressed.

More Wins to Explore