Try our new research platform with insights from 80,000+ expert users
Vanta Logo

Vanta pros and cons

Vendor: Vanta
4.3 out of 5
Badge Ranked 1

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Vanta's automation provides significant time savings and continuous compliance monitoring.
It helps in tracking compliance with components and various security policies.
Vanta automates security controls and checks for cloud providers and aids in ISO 27001 compliance.
Its prebuilt control frameworks and integrations streamline processes like SOC 2 compliance.
This tool positively impacts organizations by improving compliance scores and processes like HITRUST R2 assessment.

CONS

Vanta's user access review module is still in development, with ongoing feedback for improvement.
There is a delay with Vanta's customer support, and they are often unsure of needed answers.
Automated tests sometimes do not function as expected within Vanta.
Permissions issues require admin access for additional team members to view all items in Vanta.
Connection problems occur about 50% of the time due to automated evidence collection in Vanta.
 

Vanta Pros review quotes

reviewer2297691 - PeerSpot reviewer
Security GRC Program Manager at a computer software company with 201-500 employees
Oct 20, 2023
The most valuable feature of Vanta would be the time savings from the automation and the continuous compliance monitoring once set up.
Anupam Dutta - PeerSpot reviewer
Team Lead- Sr. Linux administrator-Kubernetes-DevOps at ExpressRCM
Oct 25, 2023
It helps us track the compliance of the components listed in our partner's directory. We can also check if the password manager, XML, and three log policies have been properly implemented on the desktop.
Stefan Rusu - PeerSpot reviewer
Information Security and Compliance Manager at a tech vendor with 11-50 employees
Nov 1, 2023
The product has provided automated security controls for our cloud provider. It helps to automate security checks. Vanta offers a list of things that can be done to achieve ISO 27001 compliance.
Learn what your peers think about Vanta. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
reviewer2356296 - PeerSpot reviewer
Security Compliance Manager at a tech services company with 11-50 employees
Mar 12, 2024
The most valuable feature of Vanta is its prebuilt control frameworks.
LindaBrown - PeerSpot reviewer
Founder at Viridis Security
Jul 3, 2024
Task management and vendor assurance are the most valuable features. It is also an easy tool to use.
reviewer2585640 - PeerSpot reviewer
Consultant at a consultancy with 11-50 employees
Oct 17, 2024
They integrate into New Relic as a performance monitoring tool.
Anas Rifai - PeerSpot reviewer
DevOps Engineer / SRE at a outsourcing company with 201-500 employees
Oct 15, 2025
After implementing those changes with Vanta, we tracked specific outcomes and metrics and improved compliance scores, which we can see in Vanta.
reviewer2585640 - PeerSpot reviewer
Consultant at a consultancy with 11-50 employees
Dec 5, 2025
Vanta provides a necessary repository that any compliance expert will look at and recognize right away.
reviewer2788602 - PeerSpot reviewer
Vice President of Technology at a tech services company with 1-10 employees
Dec 17, 2025
Vanta's integrations and automated tests have streamlined our SOC 2 compliance and provided a single entry point for addressing risks and failed tests.
Kevin_Thompson - PeerSpot reviewer
HITRUST and GRC Consultant at Privaxi
Jan 2, 2026
Vanta has positively impacted my organization by streamlining the whole HITRUST R2 assessment process.
 

Vanta Cons review quotes

reviewer2297691 - PeerSpot reviewer
Security GRC Program Manager at a computer software company with 201-500 employees
Oct 20, 2023
Currently, Vanta's user access review module is still in development, and we've been giving them continuous feedback to help them improve that.
Anupam Dutta - PeerSpot reviewer
Team Lead- Sr. Linux administrator-Kubernetes-DevOps at ExpressRCM
Oct 25, 2023
There is a delay with customer support and they are unsure of the answers we need.
Stefan Rusu - PeerSpot reviewer
Information Security and Compliance Manager at a tech vendor with 11-50 employees
Nov 1, 2023
Some of the tool's automated tests do not work the way it should.
Learn what your peers think about Vanta. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
reviewer2356296 - PeerSpot reviewer
Security Compliance Manager at a tech services company with 11-50 employees
Mar 12, 2024
The main area for improvement in Vanta is the user interface's refresh rate.
LindaBrown - PeerSpot reviewer
Founder at Viridis Security
Jul 3, 2024
Scalability could be improved.
reviewer2585640 - PeerSpot reviewer
Consultant at a consultancy with 11-50 employees
Oct 17, 2024
They have an AI generator for the system description for SOC 2, however, the outline is a little sketchy.
Anas Rifai - PeerSpot reviewer
DevOps Engineer / SRE at a outsourcing company with 201-500 employees
Oct 15, 2025
Permissions for platform users have been an issue. We've had to give admin access to Vanta for another team member to view all items.
reviewer2585640 - PeerSpot reviewer
Consultant at a consultancy with 11-50 employees
Dec 5, 2025
There are connection problems about 50% of the time because of the automated evidence collection.
reviewer2788602 - PeerSpot reviewer
Vice President of Technology at a tech services company with 1-10 employees
Dec 17, 2025
Failed tests for device CVEs seem to be cumulative, meaning I have to clear all CVEs before the test will pass, which makes it difficult to resolve the test before the next round of CVEs are published.
Kevin_Thompson - PeerSpot reviewer
HITRUST and GRC Consultant at Privaxi
Jan 2, 2026
I would tell others looking into using Vanta to use it for HITRUST E1 and I1 assessments, as the R2 assessments are still a work in progress.