Migration playbook

Vanta to Drata, without losing the audit trail.

A vendor-neutral runbook for moving controls, owners, evidence sources and auditor context. Product-specific steps are added only when verified against current documentation.

01

Freeze the baseline

Export the active control set, owners, tests, exceptions, policy versions and open auditor requests before configuration changes.

02

Map, do not blindly copy

Create a control-by-control crosswalk. Record where naming, test cadence or evidence requirements differ.

03

Reconnect evidence sources

Inventory cloud, identity, HR, ticketing, code and device-management integrations. Validate permissions with least privilege.

04

Run in parallel

Keep the old workspace readable until scheduled tests pass and evidence gaps are reconciled in the destination.

05

Protect audit continuity

Tell the auditor what changed, when it changed, and how control operation remained continuous through the transition.

06

Close with an export

Retain final exports, access logs, exceptions and sign-offs under your evidence-retention policy.

Before signing the new contract

Request a complete data-export example, integration permission list, historical evidence behavior, offboarding terms and confirmation of how auditor access works.

SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement