Skip to main content

Mark Controls In or Out of Scope (New Experience)

Updated this week

💡 Still using the classic Drata experience? Refer to Marking Controls In and Out of Scope for the original UI.

Overview

Not all controls are required for every audit. Drata allows you to mark controls as In Scope or Out of Scope so your audit reflects only the controls your organization plans to use.

Marking controls out of scope helps you:

  • Focus on relevant audit requirements

  • Reduce noise during audit preparation

  • Clearly document which controls are intentionally excluded

Prerequisites

Only the following roles can mark controls in or out of scope:

  • Administrators

  • Information Security Leads

Mark controls out of scope

To mark one or more controls as out of scope:

  1. Go to the Controls page.

  2. Select one or more controls from the list.

  3. Mark the selected controls as Out of Scope.

The selected controls are excluded from audit scope and readiness calculations where applicable.


Mark controls in scope

To mark controls back in scope:

  1. Go to the Controls page.

  2. Select one or more controls.

  3. Mark the selected controls as In Scope.

Once marked in scope, controls are included again in audit preparation and readiness tracking.

What to expect after changing scope

  • Out-of-scope controls remain visible but are excluded from audit scope

  • In-scope controls contribute to readiness and audit workflows

  • Scope changes are tracked for audit transparency

Key takeaways

  • Scope settings help tailor controls to your specific audit

  • Only authorized roles can change control scope

  • Controls can be marked in or out of scope at any time

  • Scope changes improve audit focus without deleting controls

Did this answer your question?