Automated Compliance: What Vanta and Drata Do and Don’t Cover

Compliance-automation platforms like Vanta and Drata have transformed how firms approach certifications such as SOC 2 and ISO 27001, and they are genuinely useful — they automate the evidence collection and continuous monitoring that used to consume months of manual effort. They have also created a dangerous misconception: that the tool makes you compliant. It does not. Understanding precisely what these platforms do and do not cover is the difference between using them to accelerate a real compliance programme and relying on them to substitute for one — which is how firms end up with a green dashboard and a certification that does not survive scrutiny.

What they genuinely do well

The core value of these platforms is automating the evidence and monitoring that certifications require. They connect to your systems and continuously check that controls are configured as they should be — that encryption is on, access is restricted, logging is enabled — and they collect the evidence of this automatically, so that when the auditor comes, the proof is already gathered rather than assembled by hand in a panic. They map your controls to the framework’s requirements, flag gaps, and monitor continuously rather than at a point in time. For the mechanical, evidence-heavy part of compliance, this is a real and substantial saving, and it makes continuous compliance far more achievable than the old annual scramble.

What they don’t cover

  • The controls themselves. The platform checks and evidences that controls exist and operate; it does not create them. You still have to actually have the security practices, the policies, the processes — the tool monitors reality, it does not manufacture it.
  • Judgement and scope. Deciding what is in scope, what the risks are, how the framework applies to your specific business — this requires human judgement the platform does not provide. A misjudged scope produces a certification that misses what matters.
  • The things that cannot be automated. Many controls are about people and process — training, incident response, governance — that a platform can track but not perform. The green checkmark says the evidence exists, not that the practice is sound.
  • Real security. Passing SOC 2 is not the same as being secure; the framework is a floor, and a firm can automate its way to a certificate while leaving real risks unaddressed. The tool optimises for the certification, which is not identical to optimising for safety.

Using them well

  • Treat the platform as an accelerator, not a substitute. Use it to automate evidence and monitoring on top of a real compliance programme, not to replace the work of actually having good controls.
  • Bring judgement to scope and risk. Decide what matters and how the framework applies to your business; the tool executes, it does not strategise.
  • Do not confuse the certificate with security. Use the certification as a floor and keep addressing the real risks that the framework may not reach.
  • Own the non-automatable controls. The people-and-process controls need genuine attention regardless of how neatly the platform tracks them.

Vanta, Drata and their peers are excellent at what they do, and for a firm pursuing SOC 2 or ISO 27001 they turn a painful manual slog into a manageable, continuous process. The mistake is letting the automation create the illusion that compliance is handled because the dashboard is green. The platforms cover the evidence and the monitoring; they do not cover the controls, the judgement, or the security those certifications are meant to signal. Used as an accelerator on top of a genuine programme, they are a real asset — relied on as a substitute for one, they produce a certificate that means less than everyone assumes.

Free · 4 minutes

Do you actually know what you are running — and what it is about to cost you?

Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.

Who this is for

This reading is for:

  • Founders and CTOs pursuing SOC 2 or ISO 27001 efficiently
  • Compliance leads weighing an automation platform
  • Firms that think a tool will “get them compliant”
  • Boards funding a compliance-automation platform and expecting certainty

Sixteen Pillars helps firms use compliance-automation platforms as accelerators on top of a real programme – bringing the judgement, scope and controls the tools do not provide. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming