a program for existing drata customers

Drata Compliance Accelerator Program (CAP)

Rapidly facilitate Drata implementation and reduce the time to achieve audit-readiness by up to 40 hours


WHAT'S INCLUDED

GOALS

The Compliance Accelerator Program has been engineered to rapidly facilitate Drata implementation and reduce the time to achieve audit-readiness by up to 40 hours. The program has a 5-star rating on PartnerPage.

 
The Compliance Accelerator Program does not include support on the following:
  • Full audit-readiness for any compliance standard
  • Support on completing security assessment questionnaires
  • Representation as security or compliance team
 

Upon completion of the program, Riveron will offer both DIY guidance and retained offerings for achieving audit-readiness.

GAP ANALYSIS

‍Time saved: 3 hours
‍‍Riveron:
  • Conduct a Drata gap analysis leveraging integrations based on the selected compliance frameworks to identify improvement points across the platform and establish a baseline of progress towards audit readiness.
  • Review and confirm scoped SOC 2 and other relevant framework(s) based on customer needs.
Customer:
  • No action required

 

INTEGRATIONS

‍Time saved: 4 hours
‍‍Riveron:
  • Verify that all connected systems are showing as connected and pulling the required compliance-related data into Drata to populate control evidence and monitoring.
  • Perform a review of data points to ensure key information is flowing:
  • Background Check
  • Infrastructure (e.g., AWS, GCP, Azure)
  • Human Resources Information System (e.g., HRIS)
  • Identity (e.g., Google Workspace, Microsoft 365)
  • Version Control (e.g., GitHub, GitLab)
Customer:
  • Debug or reverse-engineer API issues.
  • Confirm appropriate access provisioning.
  • Manual mapping of individual data points.
  • Validate 3rd-party tool accuracy (e.g., confirming whether GitHub data itself is correct).

 

POLICY CREATION & REVIEW

‍Time saved: 12 hours
‍‍Riveron:
  • Customize information security policies using best practices from thousands of successful infosec reviews and audits, rather than boilerplate one-size-fits-all policies.
  • Establish a core set of 7 policies that are categorically outlined and assigned to controls and frameworks in Drata, and provide one iteration on clarifying questions and comments
  • Review customer’s existing policies as they relate to the partner materials shared during the program and offer recommendations in response to specific questions or areas of concern.
Customer:
  • Review and confirm accuracy of policy statements to current business practices.
  • Build procedural documents and policies for frameworks not covered by CAP.
  • Project management to ensure every policy is approved and acknowledged by all personnel.

 

OWNERSHIP AND ROLES

‍Time saved: 3 hours
‍‍Riveron:
  • Guidance on the process of identifying appropriate owners based on job function and existing responsibilities.
  • Assistance in assigning clear ownership for Vendors, Policies, and Controls to ensure accountability within the Drata platform.
  • Guidance on setting proper access levels in Drata to reflect ownership and responsibility for managing compliance tasks and evidence collection.
Customer:
  • Assignment of specific users in the Drata platform.
  • Restructuring internal team roles or functions to accommodate ownership assignments.
  • Ongoing monitoring of role effectiveness or reassignment of roles after implementation.

 

VENDOR MANAGEMENT

‍Time saved: 10 hours
‍‍Riveron:
  • Add up to 15 vendors to the vendor module, including Drata itself.
  • Conduct an example security review for the customer’s Identity Provider (IdP) to illustrate how vendor risk is assessed and documented.
  • Provide guidance on maintaining vendor records and aligning them with control requirements in Drata.
Customer:
  • Perform comprehensive security reviews for all vendors beyond the initial example.
  • Build custom vendor intake, risk scoring, or tracking workflows.
  • Validate the accuracy or completeness of vendor-provided documentation.
  • Ongoing management or reassessment of vendor profiles post-implementation.

 

PERSONNEL SET UP

‍‍Time saved: 4 hours
‍Riveron:
  • Verify that personnel are properly synced and mapped in Drata.
  • Identify gaps in setup related to:
  • MFA enforcement
  • Background check completion
  • Multi-domain requirements (e.g. if multiple email domains are in use)
  • Guidance on how to resolve identified gaps so personnel-related controls can pass during monitoring and audit.
Customer:
  • Manually updating user records.
  • Technical configuration of identity provider or HRIS integrations.
  • Ongoing personnel monitoring after implementation is complete.

 

COMPANY SECURITY PRACTICES

‍‍Time saved: 2 hours
‍Riveron:
  • Verify current endpoint management practices (e.g. use of MDM, Drata Agent, or manual evidence uploading) and provide guidance on best practices and set up.
  • Confirm security awareness training practices are in place.
Customer:
  • Deploying or configuring endpoint management tools or training platforms.
  • Create or customize security awareness content.
  • Manually enroll users in training programs or adjusting their completion statuses.

 

AUDITOR AND VENDOR RECOMMENDATIONS

‍‍Time saved: 2 hours
‍Riveron:
  • Recommendations and introductions to auditors, pentesting firms, and any other necessary vendors for compliance
Customer:
  • Take introductory calls and procure vendors

TIMELINE

 
Phase 1
Phase 2
 
Phase 3
After CAP
Foundational Work & Technical Setup
Documentation & Review
 
 
 
 
Touchpoint call
Finalize deliverables from the CAP SOW
OPTION 1
 
Auditor & Penetration Testing Selection Consultation (if needed): Discuss requirements & make vendor recommendations
Integration Completion
Verification: Verify that all connections are not only showing successful, but that they are pulling the necessary data.
Company Information: Collect information about your product directly from your website and other accurate public resources
‍Policy Development: Begin formulating compliance-aligned policies for your core policies and upload them to Drata
Roles and ownership: Discuss importance of Vendor, Policy and Control ownership as we define next steps to assign proper access for ownership in Drata
Personnel Management: We will update Drata with any HR page documentation provided to our team as well as confirm Key Stakeholders are appropriately documented.
Trust Service Criteria Scoping (for SOC 2): Review which TSCs are in scope of the business needs for SOC 2.
Vendor Support: We will upload up to 15 vendors to your repository as well as provide an example of a vendor security review to understand what a successful vendor management program looks like.
‍Personnel Page: Assist in verifying that personnel has been accurately scoped in Drata to their job type.
Internal Security: Verify current endpoint management practices (e.g. use of MDM, Drata Agent, or manual evidence uploading) and provide guidance on best practices and set up and confirm/set up compliance training best practices.
If not completed in the first two phases, we will extend the timeline until the included scope is completed, at which point we will offer the project review and closure.
Continue independently: Follow the steps in Drata to navigate the 100+ steps to achieve audit-readiness with the help of some of our provided templates.
OPTION 2
Graduate to Sprint: Our team will handle all the heavy lifting to get audit-ready, involving you only when absolutely required.
 
Contact our team to learn more about our Sprint offering.

Frequently asked questions

Why is the Compliance Accelerator Program complimentary?

Riveron is Drata’s #1 Implementation Partner, and our close partnership with Drata includes offering the Compliance Accelerator Program exclusively to Drata’s customers. Riveron values the opportunity to meet prospective clients, but your interest or lack thereof in becoming a long-term client of Riveron is not in any way a requirement to participate and get the full value of the program.

If we decide to move forward with Riveron after CAP, how much will it cost and how long will it take to get audit-ready?

Our Sprint offering includes a US-based cybersecurity expert who will do all the heavy lifting to get you audit-ready, interface directly with your auditor, and involve you only when absolutely required. Our advisory team consists of ex-Big 4 auditors, ex-military cybersecurity professionals, and industry veterans. Monthly pricing varies typically between $4,500 to $5,500 with a 4-6 month commitment with various levels of support available thereafter depending on your compliance goals.

If we decide not to move forward with Riveron after CAP, how long will it take to get audit-ready?

Drata provides detailed instructions for the 100+ steps to achieve audit-readiness, and we’ll provide proven templates for tabletop exercises, onboarding and offboarding operating procedures, and other deliverables. Depending on your level of expertise and time commitment, it takes about 6-12 months to complete.

Who will I be working with at Riveron during CAP?

You will have multiple points of contact, including both US and international team resources. Experienced US-based cybersecurity professionals oversee all aspects of the program.

Success Stories

We’ve helped more than 1,000 organizations – from venture-backed startups to family-owned local businesses – get real traction on compliance during their CAP engagement. Here are a few recent examples:
A 30-person, venture-backed AI prospecting platform that chose to DIY after CAP
With just two internal champions and limited compliance experience, Sailes leveraged Riveron’s policy creation, tabletop scenarios, and vendor guidance to achieve SOC 2 Type I in 60 days with A-Lign as their auditor. They followed Drata’s tasks and our documented guidance independently, dedicating 25 hours per week to get Type I compliant by a key customer’s deadline.
PureWay Compliance chose DIY after CAP but then retained Riveron to accelerate their journey
Starting from zero and with just one internal point of contact, PureWay, a medical and waste equipment manufacturer, made quick progress during their 30-day CAP and reached 17% progress spending approximately 5 hours per week. After CAP, progress stalled for competing priorities. Realizing they’d prefer to invest their time in other initiatives, they retained Riveron’s subscription services to accelerate their journey and free up their team, and are now on the verge of achieving their SOC 2 Type 2 ahead of schedule.
Experiad Motivity, a venture-backed healthcare platform, retained Riveron immediately during CAP
Motivity completed their policies during CAP and used Riveron’s complementary guidance to chart a course for SOC 2 Type II and HIPAA. In week 3 of CAP they subscribed to Sprint so that their internal resources could stay focused on growing the business while we handled their security and compliance. In under 8 months, they’ve achieved compliance with both frameworks, plus a pentest.

Additional Capabilties

Riveron offers comprehensive risk advisory solutions and services including IT compliance advisory, GRC technology implementation, penetration testing, and more.

let’s get started

Connect with us to schedule a call

Our cybersecurity and compliance experts are here to help. Contact us to discuss next steps.

Add Your Heading Text Here

Riveron’s operational expertise helps you design and implement practical solutions that improve processes, strengthen controls, and position accounting and finance functions for growth.

Program change management

With industry focus, speed, and agility, our interim executives help both private equity and corporate clients maintain their momentum to drive transformational change. Our professionals deliver lasting, bespoke results to achieve our clients’ goals.