Table of Contents

Reach SOC 2 Compliance in 6 Weeks or Less.

  / SOC 2 to ISO 27001 Mapping: A Crosswalk Guide

SOC 2 to ISO 27001 Mapping: A Crosswalk Guide

A company that already holds a SOC 2 report has, by most industry estimates, already built somewhere between 60 and 80 percent of what ISO 27001 certification requires. Yet only a small fraction of organizations actually capture that overlap. Teams run the second framework as a fresh project, rewrite policies that already exist, and re-collect evidence they already have on file. The result is paying twice for the same security program.

SOC 2 to ISO 27001 mapping is the discipline that stops this. It is a control crosswalk: a structured comparison that shows which SOC 2 controls already satisfy which ISO 27001 requirements, where the genuine gaps sit, and what new work the second framework actually demands. Done well, it turns the second audit from a rebuild into a mapping exercise.

SOC 2 to ISO 27001 Mapping

What Is SOC 2 to ISO 27001 Mapping?

SOC 2 to ISO 27001 mapping links each SOC 2 Trust Services Criterion to its corresponding ISO 27001 clause or Annex A control. The output is a single control library: each control is defined once, tagged to both frameworks, and backed by evidence that both auditors will accept.

Worth being clear about upfront: a crosswalk does not make you compliant with anything. It shows where coverage already exists and where it does not. The real work still sits in control design, evidence discipline, and keeping the mapping current as systems and vendors change.

A spreadsheet built once and never touched again becomes an audit liability, not an asset. For a structured starting point, a thorough SOC 2 to ISO 27001 gap analysis will surface those liabilities before an auditor does.

 

SOC 2 Trust Services Criteria: An Overview

SOC 2 is an attestation framework from the American Institute of Certified Public Accountants (AICPA). It is built on five Trust Services Categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the only mandatory category, and every SOC 2 report includes it.

The Security category is evaluated through the Common Criteria, written as CC1 through CC9, containing 32 individual criteria in total. CC1 through CC5 cover the control environment, communication, risk assessment, monitoring, and control activities, and they align directly with the COSO internal control framework. CC6 through CC9 are more technology-specific, covering logical and physical access, system operations, change management, and risk mitigation.

A SOC 2 audit produces one of two report types. A Type 1 report assesses control design at a single point in time. A Type 2 report assesses both design and operating effectiveness across an observation window, usually 3 to 12 months. A licensed CPA firm issues the report. SOC 2 is an attestation, not a certification, and there is no such thing as a SOC 2 certificate.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

ISO 27001 Annex A Controls: An Overview

ISO/IEC 27001 is the international standard for an information security management system, or ISMS. The current version, ISO 27001:2022, has two distinct layers, and the distinction matters for any mapping effort.

Clauses 4 through 10 define the management system itself: organizational context, leadership, planning, risk treatment, support, operations, performance evaluation, and improvement. These clauses are mandatory. Annex A is the second layer, a reference catalogue of 93 controls grouped into four themes: Organizational (37 controls), People (8), Physical (14), and Technological (34). The 2022 revision consolidated the previous 114 controls and 14 domains and added 11 new controls covering areas such as threat intelligence and cloud security.

Annex A controls are not all mandatory. Organizations select controls based on a risk assessment and record their choices, including any exclusions and the reasoning behind them, in a Statement of Applicability. Certification is granted by an accredited body, lasts three years, and requires annual surveillance audits. Learn more about what the full certification process involves.

 

Key Structural Differences That Affect Mapping

The two frameworks share a large security foundation, but they are built differently, and a mapping that ignores the structural gaps will fail. Understanding ISO 27001 vs SOC 2 at a structural level is the prerequisite for any mapping work worth doing. Four differences matter most.

ISO 27001 certifies a management system, while SOC 2 attests to a set of controls. ISO Clauses 4 through 10 have no direct SOC 2 equivalent, because SOC 2 never asks you to prove you run a continuous, governed program; it asks only whether specific controls met specific criteria during the review period.

Scope differs too. An ISO 27001 ISMS is expected to cover the organization broadly, while SOC 2 scope is set at the level of a system or service. The outputs differ as well: ISO produces a pass or fail certificate, whereas a SOC 2 report can carry noted exceptions or a qualified opinion and still be a valid, useful report. And because SOC 2 Type 2 tests evidence across a defined window, a control that worked only on audit day will not pass.

The most common mapping mistake is treating ISO 27001 as SOC 2 plus a few extra controls. It is not.

The Annex A controls map cleanly, but the ISMS management clauses, including internal audit, management review, and continual improvement, are a separate body of work with no SOC 2 starting point. Budget for them as net-new.

 

SOC 2 Common Criteria to ISO 27001 Control Mapping

The Common Criteria map to ISO 27001 with a high degree of overlap. The table below is a practical starting crosswalk for the CC series. It lists the primary ISO 27001 references rather than every possible match, and your auditor’s judgment will shape the final mapping.

SOC 2 Common Criteria

Topic

Primary ISO 27001:2022 References

CC1

Control Environment

Clauses 5 (Leadership), 6 (Planning), A.5.1, A.5.2, A.6.1–A.6.4

CC2

Communication and Information

Clause 7.4 (Communication), A.5.1, A.6.3, A.8.2

CC3

Risk Assessment

Clause 6.1 (Risk Assessment), A.5.7, A.8.8

CC4

Monitoring Activities

Clause 9 (Performance Evaluation), A.5.35, A.5.36, A.8.16

CC5

Control Activities

Clause 6.1.3 (Risk Treatment), A.5.37, A.8.9

CC6

Logical and Physical Access

A.5.15–A.5.18, A.5.31, A.7.1–A.7.4, A.8.2–A.8.5, A.8.18

CC7

System Operations and Incident Response

A.5.24–A.5.28, A.8.15, A.8.16

CC8

Change Management

A.8.32

CC9

Risk Mitigation and Vendor Management

A.5.19–A.5.23, A.6.7, A.8.30

The AICPA publishes an official mapping of the Trust Services Criteria to ISO 27001, and it is a reasonable reference point. Treat any published crosswalk as a draft, though. No mapping survives contact with a real environment unchanged, because how a control is tested depends on how your organization actually operates it.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

SOC 2 Additional Categories Mapped to ISO 27001

If your SOC 2 scope includes categories beyond Security, those map to Annex A as well, though less tidily than the Common Criteria do.

Availability lines up with the ISO controls for backup (A.8.13), redundancy (A.8.14), capacity management (A.8.6), and ICT readiness for business continuity (A.5.30).

Confidentiality maps to information classification (A.5.12), labelling (A.5.13), cryptography (A.8.24), and information deletion (A.8.10).

Processing Integrity is the weakest fit. It relates loosely to the secure development controls A.8.25 through A.8.29, but ISO 27001 has no control dedicated to transaction completeness and accuracy, as SOC 2 does.

Privacy maps partially to A.5.34, which covers privacy and protection of personally identifiable information, but the genuine counterpart is ISO/IEC 27701, the privacy extension to ISO 27001. Organizations serious about privacy assurance usually pursue 27701 alongside the base certification rather than leaning on a single Annex A control.

 

Control Areas With Strong Overlap Between SOC 2 and ISO 27001

Several domains map so cleanly that one well-designed control satisfies both frameworks at once, and these are the areas where a dual-framework program pays for itself fastest.

Access control is the clearest case.

SOC 2’s CC6 and ISO’s A.5.15 through A.8.5 cover the same ground: least privilege, multi-factor authentication, access reviews, and credential management. A single access control policy and one quarterly review process will serve both audits. Incident response overlaps just as well, with CC7 aligning to ISO’s A.5.24 through A.5.28, so one incident response plan with defined roles and tested playbooks covers both frameworks simultaneously.

Change management maps CC8 to A.8.32.

Vendor and third-party risk maps CC9 to the supplier controls in A.5.19 through A.5.23. Data backup and recovery maps the Availability criteria to A.8.13 and A.8.14. Physical security maps the physical elements of CC6 to the A.7 control family. In each of these areas, the work is to design the control once and produce evidence that both auditors will accept.

Pro Tip: Two frameworks with Different Frequencies

Where the two frameworks set different frequencies for the same control, default to the stricter one. If ISO 27001 expects quarterly access reviews and your SOC 2 controls only specified annual reviews, run them quarterly. One piece of evidence then satisfies both auditors, and you never have to explain a mismatch in a control narrative.

Control Gaps: Where SOC 2 and ISO 27001 Diverge

Controls Unique to ISO 27001 Not Covered by SOC 2

The biggest gap is the management system itself. ISO 27001 Clauses 4 through 10 require a documented ISMS scope, a formal risk treatment plan, an internal audit program, a management review process, and a continual improvement cycle based on Plan-Do-Check-Act. SOC 2 touches none of this directly.

The Statement of Applicability has no SOC 2 equivalent, and neither does the formal tracking of nonconformities. For a team arriving from SOC 2, this management layer is where most of the genuine new effort goes.

SOC 2 Requirements Not Addressed by ISO 27001

The gap runs in the other direction, too. SOC 2 evaluates controls against the system commitments described in the report, and a Type 2 engagement tests evidence across a continuous observation window. ISO 27001 has no comparable concept of a multi-month evidence period or a detailed, customer-facing report that describes your system.

SOC 2’s point-of-focus testing is also more granular in places, and its Processing Integrity category has no clean ISO home. An ISO certificate, on its own, does not produce the detailed control narrative that US enterprise buyers often expect to review.

 

Why Map SOC 2 Controls to ISO 27001?

The case for mapping comes down to three concrete returns, and they compound over time.

It reduces audit fatigue and overhead. Teams that build a unified control set and map it to both frameworks consistently spend far less on the second framework than teams running two separate projects. One policy library, one evidence cadence, and one remediation backlog replace two of everything.

A well-maintained SOC 2 compliance checklist that is also cross-referenced against ISO requirements is a practical way to keep that single-source discipline in place day to day.

It strengthens your security posture. Mapping forces you to reconcile two views of the same risks. SOC 2 frames controls around service commitments, while ISO 27001 frames them around information assets and a formal risk assessment. Reconciling the two surfaces gaps that either framework alone would miss, and gaps that auditors and attackers both find.

It meets multiple market requirements at once. US enterprise buyers generally expect SOC 2. European and international customers, along with a growing number of large procurement teams, expect ISO 27001. Microsoft, for one, stopped accepting SOC 2 security reports as sufficient evidence for its supplier program after 2021. Holding both removes the framework question from your sales cycle entirely.

SOC 2 to ISO 27001 Gap Analysis

How to Conduct a SOC 2 to ISO 27001 Gap Analysis

Step 1: Inventory Existing SOC 2 Controls

Start with a complete list of the controls already operating under your SOC 2 program, each recorded with its owner, its frequency, and the evidence it produces. This inventory is the raw material for everything that follows, so it needs to reflect reality rather than the control descriptions in last year’s report. Controls that exist on paper but are not actually being operated will fail ISO testing just as quickly as they would fail a SOC 2 Type 2 review.

Step 2: Align Risk Assessment Processes Across Both Frameworks

SOC 2 expects risks to be assessed and mitigated. ISO 27001 goes further, requiring a documented, repeatable risk assessment methodology and a risk treatment plan tied to the Statement of Applicability. The practical answer is to run one unified risk assessment in a single register that addresses both threats to information assets and risks to your service criteria, rather than maintaining two registers that inevitably drift out of sync.

Step 3: Identify Overlapping and Conflicting Documentation

Compare policies side by side. Where two documents cover the same ground, consolidate them into one. Where they conflict, whether on review frequencies, definitions, or scope, resolve the conflict before an auditor finds it. Conflicting documentation is one of the fastest ways to draw a finding, because it raises the obvious question of which version staff are actually following.

Step 4: Address Scoping Misalignments

SOC 2 scope is set at the system level, while an ISO 27001 ISMS is expected to be broader. Decide deliberately what the ISMS covers and confirm it is consistent with what your SOC 2 report describes. Mismatched scope is one of the most heavily scrutinized issues in an ISO certification audit, and it is also one of the common pitfalls that derails otherwise well-prepared teams.

Step 5: Build a Unified Control Set

Produce a single control catalogue in which each control is defined once, mapped to both frameworks, assigned an owner, and written at a level that stays stable as systems change. This catalogue, not the original mapping spreadsheet, is the durable output of the whole exercise. Everything else feeds into it and is governed by it going forward.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

Best Practices for Successful SOC 2 to ISO 27001 Mapping

Use a Unified Control Framework as Your Foundation

Define each control once, map it to both frameworks, and treat that catalogue as the single source of truth. Separate per-framework spreadsheets drift apart within a quarter, and reconciling them later costs more in time and rework than building the unified version correctly from the start. Reference frameworks like NIST CSF can serve as a neutral backbone that maps to both SOC 2 and ISO 27001, which is particularly useful for organizations that anticipate adding more frameworks in the future.

Automate Compliance Audits Where Possible

Manually collecting and tagging the same evidence for two audits is where both time and accuracy leak. Tag each piece of evidence with every control it supports, across both frameworks, so it is collected once and reused. Automated, time-stamped evidence is also more convincing to an auditor than a manually assembled folder.

Automate compliance audits using purpose-built tools and you eliminate a category of error that manual processes cannot reliably prevent. Pair automation with continuous monitoring and your evidence library stays current between audits rather than being assembled in a panic the week before fieldwork begins.

Regularly Update Your Mapping as Standards Evolve

Frameworks change, as the 2022 ISO revision demonstrated, and so do your systems and vendors. Review the crosswalk on a schedule and whenever you add a system, adopt a new cloud service, or change a core process.

A mapping left static between audits tends to be quietly wrong by the time anyone needs it, and the auditor will find the discrepancies before you do.

Involve Cross-Functional Stakeholders in the Mapping Process

Mapping is not a job for one compliance manager working alone. Control owners in engineering, IT, human resources, and legal need to confirm that the mapped controls reflect how work actually happens. A crosswalk owned by one person and never seen by the people who run the controls is the version auditors quietly take apart. The people closest to the systems know where the documentation does not match the practice, and that knowledge needs to be in the crosswalk before the audit, not discovered during it.

Common Pitfalls When Mapping SOC 2 to ISO 27001

Scoping misalignment is the most frequent failure. A narrow SOC 2 system boundary quietly becomes the assumed ISMS scope, and the ISO auditor pushes back hard.

Duplicate and conflicting documentation is close behind: two access policies, two incident response plans, slightly different in wording and both technically in force, with no clear authority on which one governs.

Overlooking third-party risk catches teams that treated vendor management lightly under SOC 2, since ISO’s supplier controls in A.5.19 through A.5.23 expect a more structured and documented program. And many teams fail to account for the continual improvement obligation, mapping the Annex A controls cleanly while forgetting that ISO’s internal audit and management review requirements are ongoing rather than one-time tasks.

Reviewing the full list of common pitfalls before you start the mapping effort is time well spent.

Auditors test evidence, not intent. A flawless crosswalk spreadsheet proves nothing on its own. What an ISO 27001 auditor wants to see is the management review minutes, the internal audit reports, and the nonconformity log, artifacts that only exist if the ISMS has actually been running for a few months. Start those processes early, well before you feel ready, so the evidence trail exists when the audit arrives.

Frequently Asked Questions

Does SOC 2 to ISO 27001 mapping guarantee compliance with both frameworks?

No. Mapping shows where control coverage overlaps and where gaps remain. Compliance still depends on designing the controls properly, operating them consistently, and producing evidence that satisfies each auditor. A crosswalk is a planning tool, not a substitute for the work itself.

Industry estimates generally place the control overlap between 60 and 80 percent, concentrated in access control, risk management, incident response, and change management.

The overlap is high enough that the second framework should never be a full rebuild, but it is not complete, because the ISO management system clauses have no SOC 2 equivalent and must be built from scratch regardless of where you are starting from.

Often, yes. A large share of SOC 2 evidence, including access reviews, change tickets, vulnerability scans, and training records, directly supports ISO 27001 Annex A controls.

The catch is that ISO also requires evidence SOC 2 never asks for, such as internal audit reports and management review records, which must be generated separately and cannot be substituted.

Treat it as a living document. Review it at least once a year, and also whenever you add a major system, adopt a new cloud service, change a core process, or when either framework is revised. A mapping that sits untouched between audits is almost certainly inaccurate by the time it is needed.

It depends on your customers. If your buyers are mostly US-based, starting with SOC 2 is common practice. If you sell internationally or need a recognized certificate, starting with ISO 27001 builds the broader management system foundation and tends to make the subsequent SOC 2 faster. Either order works.

What matters is building one security program rather than two. A good SOC 2 guide can help you assess which starting point makes the most sense for your current market and customer base.

For most organizations, ISO 27001 takes more time and effort on the first attempt, mainly because of the management system requirements. SOC 2 has no equivalent to the ISMS clauses, the Statement of Applicability, or the internal audit and management review cycle.

The controls themselves are comparable in difficulty. It is the surrounding management system that makes ISO 27001 the heavier lift, and the reason why arriving from SOC 2, with your control library already built, gives you a meaningful head start.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

Vanta does not publish a single price on its website. Every quote is custom, generated after a sales call, and shaped by four variables: your headcount, the number of frameworks you need, the add-ons you select, and how long you commit. The median Vanta contract sits around $20,000 per year based on aggregated procurement-platform data, with the full range running from about $10,000 for a lean startup to $80,000 and beyond for a multi-framework enterprise. There is also one cost that most analyses miss: the actual audit fee, which is not included in the Vanta subscription price. This breakdown covers every tier, every hidden line item, and the levers that actually move the number down. Vanta Pricing at a Glance Vanta sells five named tiers, each aligned to a company stage or GRC maturity level. The figures below come from customer-reported benchmarks aggregated by procurement and price-intelligence platforms such as Vendr and PriceLevel, since no list prices exist publicly. Treat them as ranges, not quotes. The audit, paid to an independent firm, sits on top of all of these and typically adds $10,000 to $50,000 depending on framework and scope. Plan Typical Annual Cost Best For Core ~$10,000 Startups, single framework Plus $15,000–$30,000 Growing teams needing access reviews and questionnaire automation Growth $25,000–$50,000 Scaling companies running multiple frameworks Scale $50,000–$80,000 Formalised GRC or security teams Enterprise $80,000+ Multi-entity, IPO-level, or highly complex environments Vanta Pricing Plans Explained Core Plan: Entry-Level Compliance for Startups Core is the entry point, generally landing around $10,000 per year, with reported deals clustering between roughly $7,500 and $14,000. It covers one framework, usually SOC 2 or ISO 27001, with automated evidence collection, ready-made policy templates, basic integrations, a public-facing Trust Center, and access to Vanta’s network of approved audit firms. Smaller teams pursuing a single framework land at the low end of that range. It is built for the first-time compliance journey, not for running compliance as an ongoing operational function. Plus Plan: Advanced Features for Growing Teams Plus typically runs $15,000 to $30,000 per year. It adds the capabilities Core leaves out: automated access reviews, approval workflows, and a capped allowance of automated security-questionnaire responses, commonly cited at 25 per year. That questionnaire cap is the detail that catches growing teams off guard, and it is covered in the hidden-fees section below. Growth Plan: Built for Scaling GRC Programs Growth, sometimes sold as the Professional tier, ranges from roughly $25,000 to $50,000 per year and is Vanta’s most commonly sold plan for scaling companies. It supports multiple frameworks, advanced integrations, customisable risk-management workflows, custom monitoring tests for non-standard controls, automated access reviews, advanced reporting, and a far larger questionnaire allotment, often cited at 144 per year. This is the tier for organisations treating compliance as a service and a real business function, rather than a one-time checkbox. Scale Plan: Expanded Compliance Coverage Scale pricing starts where Growth tops out and can reach up to $80,000 per year. It is aimed at companies with formalised GRC or security teams, many connected assets, and several frameworks running in parallel. SCIM-based user provisioning and deeper automation across onboarding and offboarding tend to appear at this level. Enterprise Plan: Fully Custom Pricing Enterprise is entirely bespoke, starting above $80,000 and quoted case by case. It bundles a dedicated customer success manager, priority support, custom integrations, and tailored implementation. It becomes relevant for organisations managing multiple legal entities, thousands of assets, strict SLA requirements, or IPO-level scrutiny. Insider note: Vanta’s plan names shift over time and between sales reps. You will see Core called Essentials, and Growth called Professional, in different quotes and on different comparison sites. Anchor your evaluation to what the plan actually includes, frameworks supported, questionnaire allowance, access review automation, rather than the label on the proposal, because the label is the least stable thing about it. How Much Does Vanta Cost Per Year? Annual Cost by Company Size and Stage For a startup under 50 employees chasing a single framework, expect roughly $10,000 to $12,000 per year. Most growing companies pay between $25,000 and $55,000. Larger organisations running multiple frameworks commonly land between $50,000 and $110,000 or more once add-ons and headcount are factored in. The median across all reported deals stays near $20,000, which tells you most buyers sit in the Core-to-Growth band rather than at the extremes. How Pricing Scales With Company Size and Complexity Vanta prices primarily on employee count and framework count. Add an employee bracket, and the per-seat-driven base creeps up. Add a framework, and you pay again for the incremental coverage. Complexity compounds this: more cloud accounts, more vendors to assess, and more integrations all push you toward higher tiers and more add-ons. Two companies of identical headcount can pay very different amounts purely on framework count and the modules they bolt on. How to Negotiate Vanta Pricing Buy Through a Certified Partner Certified partners can frequently pass through discounts of 20 to 40 percent off list on multi-year contracts, alongside faster onboarding and implementation support. As a certified Vanta partner, Axipro secures clients 25% off Vanta pricing, and that discount applies on top of the platform’s standard multi-year terms rather than instead of them. The saving is only part of the value. Axipro folds the licence into a consultant-led compliance program, so you get the negotiated rate plus hands-on implementation, framework scoping, and audit preparation, rather than a cheaper login and a blank dashboard. For a team weighing a $25,000 quote, a quarter off the platform cost covers a meaningful slice of the audit fee that Vanta’s subscription never includes. Negotiate Multi-Year Discounts A two or three-year commitment is the most reliable discount lever. Vanta will trade a lower annual rate for a longer term and committed future growth. If you expect to add headcount or frameworks, name that expansion in the negotiation and use it to pull the rate down now. Bundle Frameworks You’ll Need Later If ISO 27001 or HIPAA is on your roadmap, negotiate

The Vanta agent checks four things on a laptop: whether the disk is encrypted, whether a password manager is installed, whether antivirus is running, and whether the screen locks on its own. That is the entire job. It is a lightweight background program that reports those signals back to Vanta so your compliance evidence stays current without anyone emailing screenshots to an auditor. Most of the confusion around it comes from one of two directions: people expect it to manage their fleet like a full device-management platform, or they worry it reads far more than it does. Neither is true, and the gap between those two assumptions is where this guide lives. What follows covers what the agent collects, what it deliberately ignores, how it talks to the Vanta platform, how it stacks up against a full MDM, and which compliance frameworks the evidence ends up supporting. What Is the Vanta Agent? The Vanta agent is a small program installed on employee computers to continuously confirm that each device meets a short list of security requirements. If you have seen it referred to as the Vanta Device Monitor, that is the same product under an earlier name. The two terms are interchangeable. Under the hood, it runs a hardened build of osquery, an open-source framework that exposes operating system state as a queryable SQL database. Vanta ships a modified version that strips out the tables it considers risky, which is why the agent can read a disk-encryption flag but cannot pull your browser history or SSH keys. It is read-only by design. It inspects configuration and reports back; it never changes a setting on the machine. Vanta positions it primarily for smaller fleets, generally companies running fewer than about 75 devices, where standing up a full management platform would be overkill. What Does the Vanta Agent Do? The agent exists to turn a recurring manual chore — proving that every laptop is configured securely — into something that happens quietly in the background. Continuous Device Monitoring Once installed, the agent keeps tabs on the device’s security posture on an ongoing basis rather than at a single point in time. This matters because audits care about whether a control held throughout the period, not whether it happened to be true the morning someone took a screenshot. Continuous checks caught the laptop with encryption switched off last Tuesday. Automated Compliance Checks Each signal the agent gathers maps to a control your auditor wants evidence for. Instead of chasing employees for proof that their disk is encrypted, the check runs automatically, and the result flows into Vanta as evidence. The work that used to eat days of an onboarding cycle collapses into a background process. Real-Time Security Posture Tracking The findings appear in Vanta as pass or fail states against each requirement, so a security lead can see fleet-wide compliance at a glance. A device that drifts out of compliance surfaces quickly, which shortens the window between a problem appearing and someone noticing it. What Information Does the Vanta Agent Collect? This is the question employees actually care about, and the honest answer is reassuring: the agent collects security configuration, not content. It does not transmit passwords, environment variables, SSH keys, emails, or browsing history. It reads whether protections are switched on, not what you are doing with the machine. Insider Note: The reason the agent cannot snoop even if someone wanted it to is architectural, not a policy promise. Vanta deploys a modified osquery build that removes the tables capable of reading sensitive content. The dangerous queries are not blocked at the dashboard; they are absent from the binary. That distinction is worth raising directly when an employee pushes back on installation. Operating System and Version Details The agent records the OS and version so Vanta can confirm the device runs a supported, patchable platform. An end-of-life operating system is a control failure in its own right, and this is how it gets flagged. Disk Encryption Status It checks whether full-disk encryption is active — FileVault on macOS and BitLocker on Windows. This is the single most universally required device control across every major framework, which is also why it is the one Linux check the agent does support. Screen Lock and Password Policies The agent verifies that the screen locks automatically after a period of inactivity and that a password or equivalent is required to get back in. An unlocked laptop left on a train is a textbook breach, and this control is the cheapest defense against it. Antivirus and Firewall Status It confirms that antivirus or endpoint protection software is installed and running. The point is not to endorse a particular product but to prove that some recognized protection is active and has not been quietly disabled. Installed Software and Auto-Update Settings To detect the controls above, the agent reads the list of installed applications — for example, to confirm a password manager is present — along with update-related settings. It is reading the inventory to verify protections exist, not building a behavioral profile of the user. How Does the Vanta Agent Work? How the Agent Communicates with the Vanta Platform After installation, the employee registers the device against your Vanta account, which links that machine to its owner. From then on the agent runs its checks locally and sends only the results — the pass or fail signals — up to Vanta over an encrypted connection. The raw system queries stay on the device. What travels is the verdict, not the underlying data. How Often the Vanta Agent Runs Checks The agent uses osquery’s scheduled-query model, meaning each check runs on a recurring interval in the background rather than continuously hammering the system. Results sync to Vanta periodically through the day, and the platform’s tests re-evaluate on a regular cadence so a freshly remediated device clears its failing check without anyone forcing a manual refresh. In practice, a fixed laptop usually shows green within hours, not at the

Roughly 60% of data breaches still trace back to a person rather than a system, according to Verizon’s 2025 Data Breach Investigations Report. Earlier editions of the same report put the figure as high as 74%. That single statistic is why every framework Drata supports — from SOC 2 to HIPAA — treats Drata security awareness training as a required control rather than a nice-to-have. Drata gives you three ways to run that training: automatic tracking across your personnel and recurring resets that keep evidence current for auditors. This guide covers how each piece works, how to configure it, and the quiet mistakes that break compliance. What Is Security Awareness Training in Drata? Security awareness training in Drata is the annual cybersecurity education your workforce completes to satisfy personnel-related controls across frameworks. The control language is consistent across audits: security awareness training is provided to all employees on an annual basis. Drata’s job is to deliver or track that training, then hold the completion evidence in one place so you can show an auditor that every current employee and contractor met the requirement for the current cycle. The discipline itself is well established. The broad concept of security awareness maps to the Protect function (PR.AT) of the NIST Cybersecurity Framework, which treats workforce education as a foundational layer of organizational defense. Inside Drata, training settings live on the Internal Security page, and completion surfaces on the Personnel page and in each person’s My Drata onboarding. Training Methods Available in Drata Drata supports three approaches, and you choose one on the Internal Security page. They differ mainly in who delivers the content and who supplies the completion evidence. Drata Embedded Security Awareness Training (Default) Drata built its own training course that personnel complete directly inside the platform. During onboarding, the employee opens the Complete Security Awareness Training task, clicks Begin Training, and works through the module. On completion, the task flips to completed automatically, and the Personnel page reflects it. No file uploads, no chasing screenshots. This is the simplest route to compliance and the default for most accounts. Connected Training Provider If you already run a training platform, you can connect it so completion data flows into Drata automatically. Drata integrates with providers including KnowBe4, Huntress, and Curricula. Once connected, Drata recognizes that provider as your default training source and pulls completion status for the campaigns you select. For each person, Drata combines campaign selection, enrollment, and completion status to decide whether they are compliant. Insider Note: Drata only syncs training for individuals who are not yet compliant. Once someone is marked compliant, Drata stops pulling their status from the connected provider, so a later change in that tool won’t accidentally overwrite a green check. The practical consequence: if you need to re-run someone, reset them in Drata first, then let the sync pick them back up. External Training (Evidence Upload) The third option covers training done entirely outside Drata. Here, evidence is uploaded manually — either by the employee through My Drata, or by an admin on their behalf, depending on configuration. Compliance is determined by the presence of valid evidence — a certificate, screenshot, or other file — for each current person. How to Configure Security Awareness Training in Drata Where to Find Security Awareness Training Settings All training configuration lives in one place. Select your account from the bottom-left navigation, open Settings, then Internal Security. Only account administrators can access this section. The Security Awareness Training section is where you choose your method. If HIPAA or an AI-related framework is enabled on your account, additional training sections appear below it. Setting Up Security Awareness Training for All Personnel Under the Security Awareness Training section, select the radio button for your chosen method — embedded, a connected provider, or external upload — then save. That setting applies to all personnel going forward, and new hires see the corresponding task in their onboarding automatically. Assigning Training to Individual Personnel Most configuration is account-wide, but you manage individuals from the Personnel page. Select a person to open their detail drawer, where you can view their training status and, for the external method, view or upload evidence on their behalf. This is also where you handle one-off resets, covered further below. HIPAA Training in Drata (If Enabled) What Is Annual HIPAA Training in Drata? The HIPAA Security Rule requires covered entities to implement a security awareness and training program for their entire workforce — a standard codified at 45 CFR 164.308(a)(5). If you have purchased the HIPAA framework in Drata, a dedicated HIPAA Training section appears on the Internal Security page so you can track this separately from general security awareness. Personnel complete it annually to address the associated control. How to Configure HIPAA Training With HIPAA enabled, the HIPAA Training section offers four options: Drata’s embedded HIPAA training, a connected provider, external training with manual evidence upload by an admin or information security lead, or opting out if HIPAA training is not required for your personnel. Select one and save. If you opt out, Drata removes all references to HIPAA training from the interface. Compliance is based on valid evidence existing for each current employee or contractor.   AI Awareness Training in Drata What Is AI Awareness Training? AI awareness training covers responsible and secure use of AI tools, and it maps to newer governance frameworks. Personnel should complete it annually to satisfy requirements in frameworks such as the NIST AI Risk Management Framework and ISO 42001. The setting only appears on your Internal Security page when a related framework is enabled on your account. How to Configure AI Awareness Training The AI Awareness Training section offers four options that mirror the others: Drata’s embedded AI training, a connected provider, external training with manual upload, or a URL that links personnel straight to an external course from My Drata. With the embedded option, Drata generates a certificate of completion as a PDF and uploads it automatically, viewable from the