Drata Release Notes

Follow

102 release notes curated from 66 sources by the Releasebot Team. Last updated: Oct 5, 2026

Get this feed:
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 5, 2026
    Drata logo

    Drata

    AIUC-1 Version Update: July 2026

    Drata ships the July 2026 AIUC-1 update, keeping the framework aligned with AIUC's quarterly cycle while preserving customer certification work.

    The July 2026 version of AIUC-1 is now live in Drata, keeping the framework aligned with AIUC's quarterly update cycle while preserving each customer's existing certification work and evidence.

    Original source
  • Sep 29, 2026
    • Date parsed from source:
      Sep 29, 2026
    • First seen by Releasebot:
      Oct 5, 2026
    Drata logo

    Drata

    New Framework Support: EU Cyber Resilience Act (CRA)

    Drata now supports the EU Cyber Resilience Act with a focused framework, cross-mapped controls, templates, and continuous evidence.

    Drata now supports the EU Cyber Resilience Act (CRA) with a focused framework covering the 22 Essential Cybersecurity Requirements in Annex I, purpose-built requirements, cross-mapped controls, policy templates, and continuous evidence.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Drata and hundreds of other software products.

    Create account
  • Sep 29, 2026
    • Date parsed from source:
      Sep 29, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Drata logo

    Drata

    Get Ahead of the EU Cyber Resilience Act

    Drata now supports the EU Cyber Resilience Act with a purpose-built CRA framework, cross-mapped controls, continuous evidence, and centralized readiness tools to help security teams manage secure-by-design, reporting, and supplier risk workflows.

    Drata supports the EU Cyber Resilience Act (CRA) with purpose-built requirements, cross-mapped controls, and continuous evidence for security teams.

    The CRA or Cyber Resilience Act (Regulation (EU) 2024/2847) gives manufacturers of hardware and software products a clear, EU-wide standard for building security best practices into products from the start and maintaining them effectively. As a Regulation, it applies automatically across every EU country, with no country-by-country rollout to track. Its reporting obligations took effect September 11, 2026, and its broader requirements — covering secure-by-design development, vulnerability handling, documentation, and conformity assessment — become fully applicable December 11, 2027.

    That timeline still leaves a real runway. Reporting obligations already live, so the work ahead is the bigger lift:secure-by-design development, documentation, and conformity assessment before the December deadline.Teams that start now can build that foundation properly instead of assembling it under pressure. The challenge is knowing where the work tends to stall.

    Where Most Teams Get Stuck

    If your company sells hardware, software, IoT devices, or anything else with a chip or code in it into the EU, there's a good chance the CRA applies to you — with narrow carve-outs for pure SaaS, medical devices, vehicles, aviation and marine equipment, and a handful of other sector-specific exclusions. For most teams, the hard part isn't understanding applicability — it's finding one place to manage it well.

    Knowing which products are in scope, whether they're built securely, and whether documentation would satisfy a regulator's review is work that often lives across spreadsheets, legal memos, and disconnected tools. The CRA also introduces a staged reporting rhythm: manufacturers have 24 hours from becoming aware of an actively exploited vulnerability or a severe incident to file an early warning, 72 hours to follow up with more detail, and then a final report — due within 14 days of a fix for vulnerabilities, or within one month of the initial notification for incidents. Having that workflow in place before an incident happens is what makes the timelines manageable.

    Manufacturers also need visibility into the security of the components they integrate. That makes CRA readiness a natural reason to extend product-security practices to suppliers and open-source dependencies teams already rely on. That's the gap a purpose-built CRA framework is meant to close.

    Turning CRA Into a Repeatable System

    Drata now supports a focused CRA framework covering the 22 Essential Cybersecurity Requirements in Annex I. A Requirements Library breaks the regulation into practical requirements for self-assessment and third-party review, so teams can start from a clear structure instead of reverse-engineering the law themselves. Those requirements map to Drata Common Framework (DCF) controls for secure-by-design, vulnerability-handling, and lifecycle-security obligations — controls that are cross-mapped across frameworks, so evidence gathered once for CRA can also count toward overlapping requirements elsewhere.

    From there, Continuous Control Monitoring keeps those controls checked on an ongoing basis rather than documented once and set aside, which fits the CRA's post-market model. Audit Hub centralizes the resulting supporting evidence, and Task Management tracks recurring work such as vulnerability remediation and evidence updates. Vulnerability Monitoring, tailored policy templates, and Drata's agentic Third-Party Risk Management (TPRM) for supplier and component risk round out the picture.

    Taken collectively, Drata supports everyone the CRA touches.

    What This Looks Like Day-to-Day

    Directors of Compliance and GRC Managers get a single source of truth for which CRA obligations apply, mapped controls, and readiness activities.

    CISOs and VPs of Security clearly define operations around the CRA's reporting clock: identifying, triaging, documenting, and escalating vulnerabilities and severe incidents on the regulation's staged timelines.

    Product and Engineering Leads get practical support for secure product development, vulnerability handling, and coordinating software bill of materials (SBOM) and related evidence with compliance and security teams.

    Individually, that's less to track for each team. Together, it adds up to something bigger: fewer handoffs, one shared source of truth, faster response when an incident hits.

    The Difference It Makes

    With Drata, teams get a documented approach to the 22 Essential Cybersecurity Requirements in Annex I, centralized and continuously maintained supporting evidence including SBOM-related information, and cross-mapped controls that cut down on duplicate work across overlapping frameworks — all inside the platform teams already use for the rest of their compliance program.

    That foundation is worth building well: The point is to show, clearly and continuously, that your products are secure by design.It’s a natural extension of good product security practice.

    Why Now Is the Right Time

    Most teams evaluating CRA readiness today are asking a simple question: when should I start? The answer is now. Because the CRA touches product security, documentation, and supply-chain risk all at once, a single system that connects those pieces is a better fit than a checklist bolted onto an existing program. That's the approach Drata's CRA framework is built around — and getting started with it is the easy part.

    Get Ahead of the Deadline

    The EU Cyber Resilience Act sets a clear bar for product security — and now there's one place to help you meet it.

    Get a demo to see how your team can move from scattered tracking to a single, continuously ready system.

    Original source
  • Sep 28, 2026
    • Date parsed from source:
      Sep 28, 2026
    • First seen by Releasebot:
      Oct 5, 2026
    Drata logo

    Drata

    SafeBase Accounts Can Now Disconnect Their Slack & Teams Users

    Drata adds self-serve management for linked Slack and Teams accounts in Profile & Preferences, including a Disconnect option.

    Users can now see and manage their own linked Slack and Teams accounts: a new Integrations section on the Profile & Preferences page lists each linked account, with a self-serve Disconnect option — no admin or support help needed.

    Original source
  • Sep 28, 2026
    • Date parsed from source:
      Sep 28, 2026
    • First seen by Releasebot:
      Oct 5, 2026
    Drata logo

    Drata

    Rich Text Editor for SafeBase Trust Centers

    Drata adds a Rich Text Editor for Trust Center, letting users switch between rich text and Markdown without losing content.

    Rich Text Editor for Trust Center is now available. A toggle sits above every Trust Center text editor — updates, item cards, and your custom footer — that lets you switch between rich text and Markdown without losing content, so you can write bold text, headings, lists, and links with no Markdown skills necessary.

    Original source
  • Similar to Drata with recent updates:

  • Sep 28, 2026
    • Date parsed from source:
      Sep 28, 2026
    • First seen by Releasebot:
      Oct 5, 2026
    Drata logo

    Drata

    Notification Settings for SafeBase

    Drata adds new SafeBase notification settings to control organization alerts across email, Slack, and Teams.

    New Notification Settings for SafeBase let you control which notifications go out to your organization, and on which channels — email, Slack, or Teams.

    Go to your organization settings, then click the new "Notifications" tab to manage organization-wide notification settings.

    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 26, 2026
    Drata logo

    Drata

    SafeBase for Salesforce v1.28: Portal Link Submissions & Due Dates

    Drata adds SafeBase for Salesforce v1.28, letting reps submit portal questionnaires from Salesforce and set due dates.

    SafeBase for Salesforce v1.28 lets reps submit portal-based questionnaires straight from Salesforce and add a due date to any submission.

    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 26, 2026
    Drata logo

    Drata

    View Available Test Before You Connect AWS, GCP, Azure

    Drata now shows all available tests, controls, and impact areas in AWS, GCP, and Azure connection panels before setup.

    The AWS, GCP, and Azure connection panels now show every available test, control, and impact area before you connect — not just what's already enabled.

    Original source
  • Sep 24, 2026
    • Date parsed from source:
      Sep 24, 2026
    • First seen by Releasebot:
      Sep 26, 2026
    Drata logo

    Drata

    SafeBase Self-Service SAML SSO

    Drata adds self-serve SAML single sign-on setup for SafeBase, removing the need for a support ticket.

    Org admins can now set up SAML single sign-on for SafeBase entirely on their own — no support ticket required.

    Original source
  • Sep 18, 2026
    • Date parsed from source:
      Sep 18, 2026
    • First seen by Releasebot:
      Sep 26, 2026
    Drata logo

    Drata

    Question Classification and Subject Matter Expert Assignment is now in Early Access

    Drata adds AI Questionnaire Assistance that automatically routes security questions to the right SME, reducing manual coordination.

    AI Questionnaire Assistance now routes security questionnaire questions to the right Subject Matter Expert automatically, cutting down on manual coordination.

    Original source
  • Sep 18, 2026
    • Date parsed from source:
      Sep 18, 2026
    • First seen by Releasebot:
      Sep 20, 2026
    Drata logo

    Drata

    September 18, 2026 Feature Enhancement AI Questionnaire Assistance

    Drata adds Early Access AI Questionnaire Assistance to route security questionnaire questions to the right Subject Matter Expert automatically.

    Question Classification and Subject Matter Expert Assignment is now in Early Access

    AI Questionnaire Assistance now routes security questionnaire questions to the right Subject Matter Expert automatically, cutting down on manual coordination.

    Original source
  • Sep 16, 2026
    • Date parsed from source:
      Sep 16, 2026
    • First seen by Releasebot:
      Sep 20, 2026
    • Modified by Releasebot:
      Sep 26, 2026
    Drata logo

    Drata

    Add Notes to Questionnaires

    Drata adds questionnaire context notes so submitters, owners, and collaborators can share key details inline.

    Questionnaire submitters, owners, and collaborators can now add a short context note directly to a questionnaire, so anyone answering or managing it has the details they need.

    Original source
  • Sep 16, 2026
    • Date parsed from source:
      Sep 16, 2026
    • First seen by Releasebot:
      Sep 17, 2026
    Drata logo

    Drata

    Introducing Drata Third-Party Risk Management: Defensible Vendor Decisions at Agentic Speed

    Drata launches Third-Party Risk Management, bringing agentic, evidence-backed vendor reviews into one platform. It helps teams make defensible decisions, keep vendor risk current, and cover the full portfolio with less manual work.

    Drata launches Third-Party Risk Management for defensible, evidence-backed vendor decisions across your whole portfolio.

    Today we're launching Third-Party Risk Management, a newly standalone agentic approach to vendor risk that replaces fragmented, questionnaire-heavy reviews with criteria-based, evidence-driven decisions in a single platform. It's built for how third-party risk actually works now: a vendor list that keeps growing, questionnaires that keep piling up, and an onboarding review that says very little about whether a vendor is still safe six months later.

    Third-party risk has become one of the hardest — and busiest — jobs in security. The pressure shows up in the data too. In our upcoming 2026 State of TPRM research report, nearly 85% of IT and security teams reported at least one third-party incident in the past 12 months. Having a TPRM tool was rarely the problem. Keeping up with the volume, depth, and pace of vendor review is.

    We built the Third-Party Risk Management to close that gap, so teams can raise the bar on every assessment, surface risk gaps, and stand behind every vendor decision with full traceability.

    Why We Built It

    We kept hearing the same thing from security teams: most third-party risk programs are stretched thin across three problems at once.

    The first is defensibility. Vendor decisions still come down to inconsistent, subjective judgment calls that are hard to explain after the fact, and growing regulatory pressure makes that gap harder to ignore.

    The second is fragmentation. Third-party risk tends to spread across multiple disconnected tools, accumulated through separate purchases or inherited through mergers and acquisitions. Answering one question about a vendor means checking five places.

    The third is capacity. Third-party counts keep growing faster than headcount ever does, so teams triage: real scrutiny for a handful of critical vendors, while the rest go unchecked or under-assessed. In our new research, staffing was the number one obstacle teams named (59%) — and only 11% plan to hire to fix it. The answer they're reaching for is automation.

    What Drata Third-Party Risk Management Does

    We put an agent to work on the most time-consuming parts of vendor review, while keeping a human in control of every decision. It runs the review end to end — syncing your vendors, tiering inherent risk, gathering and scoring evidence against your residual risk standards, and recording the decision — with a reviewer signing off on every result.. Here's how that holds up against the three problems above.

    Make Decisions You Can Defend

    When a regulator, auditor, or customer security team asks why a vendor was approved, subjective judgment calls don't hold up, and regulators keep expecting more documented oversight. It's the capability teams value most: in our latest research, defensible assessments — ones that stand up to customers, regulators, and auditors — rated the single most important capability, at 4.38 out of 5, just ahead of speed.

    Drata evaluates every third party against standards you set in plain language, not limited to a rigid checklist, and every result carries the specific logic and evidence behind it. Ask the agent to explain any decision, or generate an automated report, and you get an audit-ready record every time — with criteria outcomes, evidence references, and residual risk.

    Design partners are already seeing it. "Drata's TPRM Agent allows us to level up our security risk management program across the board by reducing manual work and letting us focus on the risks that matter," says Priyanka Chaudhary, Head of GRC at Brex. Allan Silva, Senior GRC Lead at Brex, adds that it's made the team "a lot more productive while also improving the quality of our reviews."

    Bring Third-Party Risk Into One System of Record

    Vendor inventory, risk tiers, assessments, and evidence live together in a single system of record. Sync your full vendor population from procurement, CLM, and other systems, let Drata AI enrich each profile with firmographic and risk context, and write decisions back to those same tools to keep everything current. Every third party's risk profile, assessment history, and decisions sit in one place, so teams work from one consistent view instead of reconciling five tools.

    Keep Every Vendor Current, Not Just at Onboarding

    A questionnaire completed at onboarding tells you nothing about whether a vendor is still safe today. We keep every vendor's risk profile current with recurring reviews, tailored follow-up questionnaires, and automated reassessment cadences so a vendor's status reflects its most recent evidence, not just what it looked like on day one.

    Cover the Whole Portfolio

    Our agent tiers each third-party's inherent risk based on how it's actually used. Then it collects vendor security information, maps it to your criteria, and scores residual risk automatically. What used to take days per vendor now takes minutes. Reviewers drive the entire process in natural language: kicking off an assessment, surfacing vendor context, or submitting the final decision right in the app. The same team ends up covering far more of the portfolio while aligning to the same standards.

    Manage Third-Party Risk with Drata

    Your vendor list keeps growing, and so does the pressure to prove your program holds up. Drata Third-Party Risk Management gives your team defensible, evidence-backed vendor decisions across the entire portfolio, ready to hand over the moment a regulator or customer asks.

    Get a Demo to see agentic third-party risk management in action.

    Original source
  • Sep 14, 2026
    • Date parsed from source:
      Sep 14, 2026
    • First seen by Releasebot:
      Sep 20, 2026
    • Modified by Releasebot:
      Sep 26, 2026
    Drata logo

    Drata

    Multi-Product Questionnaires in AIQA (Early Access)

    Drata adds Multi-product Questionnaires in AIQA to answer one security questionnaire across products with less repetitive work.

    Answer one security questionnaire for multiple products in a single AIQA run, instead of duplicating the work or merging separate answers by hand. Multi-product Questionnaires reduces repetitive work while preserving human review. AIQA helps security teams produce clearer, more consistent responses for complex customer due diligence requests without manually merging separate answer sets.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    Drata logo

    Drata

    SEPTEMBER 09, 2026 MAJOR RELEASE THIRD-PARTY RISK MANAGEMENT

    Drata adds Agentic TPRM to automate vendor reviews, from intake and evidence collection to risk evaluation and decision tracking.

    Agentic TPRM

    Drata Third-Party Risk Management (TPRM) automates the vendor review lifecycle—from intake and inherent-risk tiering to evidence collection, criteria-based assessment, residual-risk evaluation, and decision tracking—in one workflow. It helps teams expand review coverage, apply consistent standards, and make evidence-backed vendor decisions with less manual work.

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.