💡 Still using the classic Drata experience? Refer to Marking Controls In and Out of Scope for the original UI.
Overview
Not all controls are required for every audit. Drata allows you to mark controls as In Scope or Out of Scope so your audit reflects only the controls your organization plans to use.
Marking controls out of scope helps you:
Focus on relevant audit requirements
Reduce noise during audit preparation
Clearly document which controls are intentionally excluded
Prerequisites
Only the following roles can mark controls in or out of scope:
Administrators
Information Security Leads
Mark controls out of scope
To mark one or more controls as out of scope:
Go to the Controls page.
Select one or more controls from the list.
Mark the selected controls as Out of Scope.
The selected controls are excluded from audit scope and readiness calculations where applicable.
Mark controls in scope
To mark controls back in scope:
Go to the Controls page.
Select one or more controls.
Mark the selected controls as In Scope.
Once marked in scope, controls are included again in audit preparation and readiness tracking.
What to expect after changing scope
Out-of-scope controls remain visible but are excluded from audit scope
In-scope controls contribute to readiness and audit workflows
Scope changes are tracked for audit transparency
Key takeaways
Scope settings help tailor controls to your specific audit
Only authorized roles can change control scope
Controls can be marked in or out of scope at any time
Scope changes improve audit focus without deleting controls

