💡 Still using the classic Drata experience? Refer to Start and manage security reviews for your vendors for the original UI.
Security reviews allow you to evaluate, document, and track a vendor’s security posture over time. Reviews live on the vendor profile and can include questionnaires, SOC reports, uploaded evidence, and a final security decision.
Use security reviews to:
Assess vendors during onboarding
Perform recurring security reviews
Track review status and deadlines
Maintain audit-ready review documentation
Security review statuses
On the Current vendors page, the table includes two key columns that help you track review health across vendors:
Security review status
Next review deadline
You can filter vendors using either column.
Security review status definitions
Status | Description | Recurring reviews |
Up to date | The vendor completed a review within 90 days of the most recent deadline | Enabled |
Needs review | The review window has started and no review is in progress | Enabled |
In progress | A security review is currently underway | Enabled or disabled |
Completed | A review is complete and recurring reviews are not enabled | Disabled |
No past reviews | The vendor has never completed a review | Enabled or disabled |
Next review deadline indicators
Indicator | Description |
Due soon | The review deadline is within 7 days |
Overdue | The review deadline has passed |
Deadline not set | Recurring reviews are not enabled |
Where security reviews live
To manage security reviews:
Select Vendors.
Open Current vendors or Prospective vendors.
Select a vendor.
Open the Security reviews tab.
Each vendor profile contains a full history of completed and in-progress reviews.
Step 1: Start a security review
To begin a new review:
Select Vendors.
Open Current vendors or Prospective vendors.
Select a vendor.
Open the Security reviews tab.
Select Create review.
Choose one of the following:
Security review
SOC report review
Upload review report
Option 1: Create a security review
A security review allows you to collect evidence and document your assessment.
During a security review, you can:
Upload files (such as SOC 2 reports)
Send questionnaires through Drata
Upload questionnaire responses received outside Drata
View AI summaries (if enabled)
After reviewing the vendor’s documentation and questionnaire responses, select a final decision based on your organization’s risk and onboarding requirements:
Pending: Select this if the review is still in progress or you are waiting on additional information, documentation, or responses from the vendor.
Approved: Select this if the vendor meets your security and compliance requirements and no further action is needed before onboarding.
Approved with conditions: Select this if the vendor is acceptable to move forward, but requires follow-up actions (such as remediation, contract clauses, or additional controls) before full approval.
Rejected: Select this if the vendor does not meet your organization’s security requirements or presents an unacceptable level of risk.
Add notes to document the reason for your decision, including any required follow-up actions or conditions.
After completion, you can:
View the review summary
Download the review package
Re-open the review if updates are required
Option 2: SOC report reviews
SOC report reviews are used to formally review and document SOC reports. To start a SOC report review:
Select Create review → SOC report review.
Complete each section using the SOC report as reference.
Save and close if needed.
Select Finish review when complete.
Note:
You cannot start a new SOC report review until the current one is completed or deleted.
Option 3: Upload a completed review report
If a review was completed outside Drata:
Select Create review → SOC report review.
Select Upload review report.
Upload the completed document.
The uploaded report is stored with the vendor’s review history for audit purposes.
Schedule recurring reviews
Recurring reviews help ensure vendors are reviewed on a regular cadence.
Configure global recurring review settings
Go to Vendors → Vendor settings.
Scroll down to the Recurring reviews section.
Set how many days before the deadline the review window should open.
Default: 30 days
Scheduled questionnaires are sent automatically on the review window start date.
Enable recurring reviews for a vendor
Open Vendors → Current vendors.
Select a vendor.
Select Manage recurring reviews.
Enable Schedule recurring reviews to get reminders to conduct a security review of this vendor on a recurring basis.
Set the review frequency.
Enable Scheduled questionnaires (optional).
Select the questionnaires to send and the vendor contact email.
Review the start date and deadline.
Automatic deadline adjustment
To maintain a consistent review schedule, Drata may automatically adjust the next review deadline when a review is completed close to its existing due date.
If a review is completed within 90 days of the current deadline, Drata calculates the next deadline based on the original schedule, not the date the review was completed. This prevents deadline drift and keeps recurring reviews aligned to their intended cadence.
For example,
Original deadline: June 25
Review completed: June 10
Review frequency: Every 6 months
Next deadline: December 25
Because the review was completed within 90 days of the deadline, Drata sets the next deadline to December 25 (six months from the original deadline), not December 10. This ensures your review cycle remains consistent over time.
Automated reminder emails
You can automatically remind vendors to complete questionnaires.
To configure reminders:
Go to Vendors → Vendor settings.
Scroll to Questionnaire reminders.
Select Edit to enable Follow-up reminders.
Customize when and how often reminders are sent.
Key distinctions to remember
Security reviews are the container for decisions and evidence
Questionnaires are sent within security reviews
SOC reviews and uploaded reports are review types, not questionnaires






