WIN WITH TRUST

Take Advantage of 30+ Pre-Built Frameworks

Get compliant fast and manage multiple frameworks more easily with Drata. Whether you’re just getting started with SOC 2, expanding to ISO 27001, or managing hundreds of requirements, Drata has you covered.

Image

Choose from dozens of pre-built frameworks.

Reduce repeat audit and assessment effort.

Monitor controls continuously across requirements.

Show your compliance externally via Trust Center.

SUPPORTED FRAMEWORKS

Designed to Support Your Compliance Needs.


Image
SOC 2
Demonstrate audited controls that protect customer data and build trust.
Image
ISO 27001
Certify an ISMS to manage security risk and improve governance.
Image
GDPR
Comply with EU privacy requirements for lawful processing and data rights.
Image
HIPAA
Safeguard PHI with HIPAA-aligned privacy and security controls.
Image
CMMC
Meet DoD maturity requirements to protect CUI across the supply chain.
Image
PCI DSS
Protect cardholder data with PCI DSS security requirements.
Image
FedRAMP
Authorize your cloud for U.S. federal use with continuous monitoring.
Image
HITRUST
Unify security and privacy controls under the HITRUST CSF.
Image
TISAX
Satisfy automotive security requirements for suppliers and partners.
Image
NIST AI RMF
Manage AI risk with NIST guidance for oversight.
Image
NIS 2
Strengthen EU cyber resilience with required governance and incident readiness.
Image
CCM
Map cloud controls to CSA CCM for assurance and risk visibility.
Image
CIS
Harden your environment with CIS Controls to reduce common attack paths.
Image
CCPA
Honor California privacy rights with access, deletion, and opt-out workflows.
Image
Cyber Essentials
Validate core cyber hygiene against common internet threats.
Image
DORA
Improve ICT resilience to meet EU financial-sector operational requirements.
Image
Essential Eight
Reduce ransomware risk with Australia’s preferred mitigations.
Image
ISO 27701
Extend ISO 27001 with a privacy information management system.
Image
ISO 27017
Clarify cloud shared-responsibility security guidance.
Image
ISO 27018
Protect PII in the public cloud with privacy controls.
Image
ISO 42001
Govern responsible AI with a standardized management system.
Image
Microsoft SSPA
Demonstrate supplier security alignment with Microsoft expectations.
Image
NIST 800-171
Protect controlled unclassified information in non-federal systems.
Image
NIST 800-53
Apply controls for comprehensive security and privacy coverage.
Image
NIST CSF 2.0
Align governance to NIST CSF 2.0 risk management outcomes.
Image
NYDFS
Meet New York’s cybersecurity regulation with required controls.
Image
FFIEC
Prepare for financial services exams with aligned cyber maturity.
Image
COBIT
Govern enterprise IT with COBIT 2019 objectives.
Image
SOX ITGC
Demonstrate IT controls for reliable financial reporting.
Image
FedRAMP 20x
Support Low and Moderate authorization under FedRAMP 20x
Image
Custom Framework
Tailor to your unique customer, auditor, or internal needs.

Request a New Framework

Not seeing what you need? Let us know!
FEATURED PRODUCTS & RELATED FRAMEWORKS

Get Compliant with Drata

Enterprise GRC

Centralize governance, controls, risks, policies, and evidence across the enterprise to stay continuously audit-ready.

Discover Enterprise GRC

Compliance Automation

Automate evidence collection and control monitoring across frameworks so you're always prepared for your next audit.

Discover Compliance Automation

Unlock the Power of Automation

Integrate Drata with your tech stack to power continuous trust. 

See All Integrations
RELATED RESOURCES

The Compliance Resources You Need

CISO Guide Continuous Compliance
Guide

CISO Guide Continuous Compliance

Read More

Launch Your Compliance Program with Confidence