specification: API Commons Plans specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/Plans provider: Drata providerId: drata created: '2026-05-08' method: searched modified: '2026-08-27' tags: - GRC - Compliance - SOC 2 - ISO 27001 - Security - Plans description: Drata publishes no pricing tiers. https://drata.com/pricing is a product/benefits page whose only calls to action are "Get Started", "Contact Sales" and "Get a Demo" — no named plan, no price, no included quota, no overage schedule. Pricing is quote-based and scoped by framework selection, headcount and integration count. plan_count is 0 because zero plans are published, not because none were looked for. notes: API access is included with a paid Drata subscription; there is no separate API plan, no metered API pricing and no self-serve tier. The Drata MCP server is a gated beta requiring a request form, and some API operations return HTTP 402 "You must upgrade your plan to use this feature" (37 operations) or "The required account entitlement is not enabled" — so entitlement IS enforced at the contract level even though the plan matrix behind it is not published. sources: - https://drata.com/pricing - https://drata.com/products/api - https://developers.drata.com/openapi/reference/v2/overview/ plans: - id: drata-quote-based name: Quote-Based Subscription type: enterprise description: Annual subscription priced by selected frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR and others), employee headcount and integration count. Contact Drata sales. No published price. entries: - label: Subscription name: subscription type: flat metric: annual subscription limit: -1 timeFrame: yearly geo: global unit: 1 price: contact sales userMultiplied: false elements: - name: API Access (included) - name: Custom Connections - name: Continuous Monitoring - name: MCP Server (beta, request form) maintainers: - FN: Kin Lane email: kin@apievangelist.com generated: '2026-08-27' source: https://drata.com/pricing plan_count: 0 evidence: - url: https://drata.com/pricing status: 200 note: Live page; contains no pricing tiers. - url: https://drata.com/products/api status: 200 reconciled: true