We're bootstrapping our way through SOC 2 with Drata (mostly happy with the core platform!). As we get deeper into the compliance weeds, the vendor management module keeps popping up as a "recommended" feature.
Honestly, my team glanced at it and our first thought was: "Is this just fluff to make the feature list longer, or do companies actually run their third-party risk through here?"
We're managing about 40-50 vendors right now in a gnarly spreadsheet, and it's painful. The promise of automating evidence collection and having a central register is appealing, but I'm skeptical about the real-world utility.
I'd love to hear from other founders or ops folks who have tried using it:
* **Did you actually migrate your vendor risk process into Drata?** Was it worth the setup time?
* **How does it handle the practical stuff?** Like chasing a small SaaS vendor for their SOC 2 report, or tracking questionnaire responses?
* **Does it meaningfully connect to your other controls in Drata,** or does it feel like a separate, siloed list?
* **For the price point,** would you recommend just sticking with a dedicated vendor risk platform instead?
Trying to decide if we should invest the hours to set it up properly, or if we're better off just keeping our spreadsheet updated quarterly. 🧐
Build with what you have