---
title: "Drata: Compliance Accelerator Program"
description: "Drata: Compliance Accelerator Program"
---

[Skip to content](https://knowledge.sensiba.com/the-drata-playbook#main-content)

English

Show submenu for translations

- Sensiba

Open main navigation

Close main navigation

- Sensiba
- English
  
  Show submenu for translations
- [Go to sensiba.com](https://sensiba.com/)

[Go to sensiba.com](https://sensiba.com/)

 Hi There! How can we help you?

- There are no suggestions because the search field is empty.

1. [Sensiba Knowledge Base](https://knowledge.sensiba.com/?hsLang=en)
2. [Platform](https://knowledge.sensiba.com/platform?hsLang=en)
3. [Drata](https://knowledge.sensiba.com/platform?hsLang=en#drata)

# Drata: Compliance Accelerator Program

## Fast-track your compliance with 6 easy steps with Sensiba

#### 1. Connecting your Key Systems

Start with the **Quick Start** button in the top left corner of Drata - this walks you through your first connections.

**Systems to connect:**

- Cloud Providers
- Identity Providers (IDP)
- Version Control (GitHub, GitLab, Bitbucket, etc.)
- HRIS (Human Resource Information Systems)
- Datastores
- Mobile Device Management (MDM)

*In-scope = production systems, sensitive information, or user data*  
*Out-of-scope = test, sandbox, or non-production systems*

Connections use the **principle of least privilege.** Drata only pulls configuration data needed for evidence.

*Tip - You'll need admin credentials for each system. Loop in IT, app owners, or stakeholders as needed.*  
*For step-by-step instructions, view more about the Quick Start in Drata [here.](https://help.drata.com/en/articles/12004296-quick-start-guide#h_08ea70e77c)*

#### 2. Get Your Drata Instance Audit-Ready

Beyond your initial connections and system description, there are a few key areas in Drata that help ensure you're truly audit ready. Taking the time to configure these properly now will save time later.

**Focus areas to review in Drata:**

- **Personnel in scope:** Confirm all employees who should be part of the audit are added and that only relevant people are included. (For example, contractors are generally excluded unless they have access to critical systems.)
- **Policy management:** Upload your required policies, assign them to the right staff, and track acknowledgements.
  
    - Leverage our free **Policy Generator (PolicyTree)** that creates robust, tailor-fit policies aligned with your controls. This is optional, you can use Drata's policies instead but if you choose PolicyTree, you'll need to upload those policies into Drata. You can create them [here.](https://knowledge.assurancelab.cpa/policy-tree)

*For a detailed step-by-step walkthrough, check out [Drata's SOC 2 Checklist](https://help.drata.com/en/articles/8168169-soc-2-checklist).*

*Tip: Think of these areas as the 'readiness foundation'. The stronger they are, the smoother your audit will go.*

#### 3. Scoping your Controls

Drata comes with a broad set of default controls, but you don't need all of them for your audit.

- Your audit with us only requires a **subset of controls**.
- There are approximately 50 controls relevant for **Security, Availability, and Confidentiality Trust Service Criteria**. We've included Processing Integrity & Privacy, however these are not tested by default.
- You can safely **descope/exclude** any controls that aren't relevant to your audit, as per our control listing provided below.
- Depending on the date your organization was signed up to Drata, you may see either the previous or the updated version of the framework within your instance. For more context, you can view the article [here](https://help.drata.com/en/articles/9265872-soc-2-updates-as-of-5-7-2024).

📖 [Download Sensiba's SOC 2 Control Framework Guide here (](https://knowledge.sensiba.com/hubfs/Drata%20Sensiba%20Control%20Listing%20V4%20(SOC%202%20-%203%20TSC%20Control%20list).xls?hsLang=en)[updated June 1st, 2026)](https://knowledge.sensiba.com/hubfs/Drata%20Sensiba%20Control%20Listing%20V3.xlsx?hsLang=en)

💡 *Please note, the auditors will assess the requirements within the context of the audit scope and may request additional evidence if appropriate.*

 

#### 4. Create Audit Package

Set up your audit so we can join you in Drata, we will need access to be able to perform the AI review.

1. Go to the **Audit Hub** tab ? select **Create Audit**
   
   **[![](https://knowledge.sensiba.com/hs-fs/hubfs/Knowledge%20Base%20Import/image-1.png?width=670&height=292&name=image-1.png)](https://knowledge.sensiba.com/hubfs/Knowledge%20Base%20Import/image-1.png?hsLang=en)**
2. Enter your audit details:
   
     - Audit type (e.g. SOC 2)
     - Audit period ? use past dates up to the current date. 
       
           - If you're unsure, don't worry! we can always adjust the dates for you at a later stage.
3. Add your auditors from the dropdown or by inviting new ones.

[Learn more about audit periods here](https://help.drata.com/en/articles/10361639-understanding-evidence-sampling-in-drata)

#### 5. Provide Sensiba Auditor Access

Once your audit is created, give our team access:

1. Go to **Audit Hub** ? **Open Audit**

   [![](https://knowledge.sensiba.com/hs-fs/hubfs/Knowledge%20Base%20Import/AD_4nXc811CHsTCrHqK4ZQ2Hyo26xbeEEqHHK_beA6xxTnNGs4UHZondq1F_1HD6wEsAzYi-CRDBwSebp9SR6CjixP3VFISZyHiUKxS6iKmEB96MycgUDA-xjFMLXaFbjOL2nZhurqOVF_E5ULk93-1.png?width=670&height=361&name=AD_4nXc811CHsTCrHqK4ZQ2Hyo26xbeEEqHHK_beA6xxTnNGs4UHZondq1F_1HD6wEsAzYi-CRDBwSebp9SR6CjixP3VFISZyHiUKxS6iKmEB96MycgUDA-xjFMLXaFbjOL2nZhurqOVF_E5ULk93-1.png)](https://downloads.intercomcdn.com/i/o/am69aeco/1324880624/e3f6bfe0e645c5581b6f6a3c0429/AD_4nXc811CHsTCrHqK4ZQ2Hyo26xbeEEqHHK_beA6xxTnNGs4UHZondq1F_1HD6wEsAzYi-CRDBwSebp9SR6CjixP3VFISZyHiUKxS6iKmEB96MycgUDA-xjFMLXaFbjOL2nZhurqOVF_E5ULk93dHR3H0RhiE?expires=1756349100&signature=d70973c46d06ae11881bb637eaeb81af6912f98c0fa0b0350f1c9363ea2169b2&req=dSMlEsF2nYddXfMW1HO4zblEMbH09BbdfLHRChw%2Fzq46ShcZhUsOIPq1escZ%0AlqxD%0A)
2. Select the edit icon under **Assigned auditors**.

   [![](https://knowledge.sensiba.com/hs-fs/hubfs/Knowledge%20Base%20Import/AD_4nXea5rIFMNNbUmwRlbCvuA2_Ri0K3rBVWIPPaQEq4OKjYq45vhyRnSGrZ_p7s3RYZf2UqqJmdfJMx8J-UZnPyrUG4LqpeOtNCgGLD4mMZCOfb1Fa0io8sYyVylo_Ms10BqMfYDcWQkoSc81bu-1.png?width=670&height=359&name=AD_4nXea5rIFMNNbUmwRlbCvuA2_Ri0K3rBVWIPPaQEq4OKjYq45vhyRnSGrZ_p7s3RYZf2UqqJmdfJMx8J-UZnPyrUG4LqpeOtNCgGLD4mMZCOfb1Fa0io8sYyVylo_Ms10BqMfYDcWQkoSc81bu-1.png)](https://downloads.intercomcdn.com/i/o/am69aeco/1324880737/b77f32ca05951058e10674d1fcc9/AD_4nXea5rIFMNNbUmwRlbCvuA2_Ri0K3rBVWIPPaQEq4OKjYq45vhyRnSGrZ_p7s3RYZf2UqqJmdfJMx8J-UZnPyrUG4LqpeOtNCgGLD4mMZCOfb1Fa0io8sYyVylo_Ms10BqMfYDcWQkoSc81buz7UQ2X1dK1s?expires=1756349100&signature=57d74c0d8b4ef1f6cab6ff60e9f5fb30b60aedc9a967270b52f9f2ae8d467d72&req=dSMlEsF2nYZcXvMW1HO4zUn8ThftuNNDzVHmVS%2FzVuM60PDnz5whKpZLpyu4%0AKU8G%0A)

3. Add our audit team address:

- **grc@drata.sensiba.com**
- **csplatform@sensiba.com**

 This ensures we can start supporting you right away!

4\. Toggle on:

- Read only access

- Download for Controls, Tests and Requirements

?? *Note: Your dedicated audit team member will be assigned to complete the remainder of your audit, once you have signed up to complete your audit with us. They�ll let you know when to add their individual account.*

#### 6. Complete your System Description

This is a key step for your audit:

- It forms the **basis of your final SOC 2 report.**
- Avoids any delays in the process when it comes time to prepare your report!
- It tells your auditor exactly which systems are in scope

You can complete it by following the instructions linked [here.](https://knowledge.assurancelab.cpa/system-description)

*Tip: Do this early to give your auditor full context from the start.*

#### What Next?

Once you've completed the above steps, please reach out and book a meeting with our Customer Success team to get your AI review underway!

You can book [here](https://scheduler.zoom.us/d/wi_mljlh/sensiba-grc-global-core-kick-off).

#### Need Help?

We're here for you! If you have questions or something feels unclear, reach out anytime at **GRCAccelerator@sensiba.com**

- [Platform](https://knowledge.sensiba.com/platform?hsLang=en#main-content)

    - [Vanta](https://knowledge.sensiba.com/platform?hsLang=en#vanta)
    - [Drata](https://knowledge.sensiba.com/platform?hsLang=en#drata)
    - [Scrut](https://knowledge.sensiba.com/platform?hsLang=en#scrut)
    - [Sprinto](https://knowledge.sensiba.com/platform?hsLang=en#sprinto)
- [Best Practices Series](https://knowledge.sensiba.com/best-practices-series?hsLang=en#main-content)

    - [Risk management & internal controls](https://knowledge.sensiba.com/best-practices-series?hsLang=en#risk-management-internal-controls)
    - [Information & communication](https://knowledge.sensiba.com/best-practices-series?hsLang=en#information-communication)
    - [Data protection](https://knowledge.sensiba.com/best-practices-series?hsLang=en#data-protection)
    - [System security](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-security)
    - [Change management](https://knowledge.sensiba.com/best-practices-series?hsLang=en#change-management)
    - [System operations](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-operations)
    - [Control environment](https://knowledge.sensiba.com/best-practices-series?hsLang=en#control-environment)
- [Consumer Data Right Guides](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#main-content)

    - [Network Security](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#network-security)
    - [Vulnerability Management](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#vulnerability-management)
    - [Security Awareness](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#security-awareness)
    - [Anti-malware](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#anti-malware)
    - [Information Asset Lifecycle](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#information-asset-lifecycle)
    - [Access Control](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#access-control)
    - [Governance Requirements](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#governance-requirements)
- [ISO 27001](https://knowledge.sensiba.com/iso-27001?hsLang=en)
- [Control Environment](https://knowledge.sensiba.com/control-environment?hsLang=en)
- [Information and Communication](https://knowledge.sensiba.com/information-and-communication?hsLang=en)
- [Risk Management](https://knowledge.sensiba.com/risk-management?hsLang=en)
- [Vendor Management](https://knowledge.sensiba.com/vendor-management?hsLang=en)
- [System Security](https://knowledge.sensiba.com/system-security?hsLang=en)
- [System Operations](https://knowledge.sensiba.com/system-operations?hsLang=en)
- [Change Management](https://knowledge.sensiba.com/change-management?hsLang=en)
- [Confidentiality](https://knowledge.sensiba.com/confidentiality?hsLang=en)
- [Privacy](https://knowledge.sensiba.com/privacy?hsLang=en)
- [CDR Reps](https://knowledge.sensiba.com/cdr-reps?hsLang=en)
- [Access reviews](https://knowledge.sensiba.com/access-reviews?hsLang=en)
- [Governance](https://knowledge.sensiba.com/governance?hsLang=en)
- [Employee management](https://knowledge.sensiba.com/employee-management?hsLang=en)
- [FAQs](https://knowledge.sensiba.com/faqs?hsLang=en)
- [Sensiba Audit Tools](https://knowledge.sensiba.com/sensiba-audit-tools?hsLang=en)

- Sensiba

[![Sensiba Logo](https://knowledge.sensiba.com/hs-fs/hubfs/Sensiba_Logo_Hubspot-01.png?width=247&height=48&name=Sensiba_Logo_Hubspot-01.png "Sensiba Logo")](https://sensiba.com/)

Copyright © 2026, Sensiba LLP