How to export your data from Drata
Drata has no single one-click "export all data" tool; you pull data out through several separate places (Evidence Library, Controls, Events, Audit Hub, Frameworks, Personnel) in CSV, PDF, TXT, JSON and ZIP formats, or use the Drata Public API for bulk/programmatic JSON export of controls and events.
✓ Verified against Drata's official documentation, October 2026
Step by step
- 1Evidence files: go to Compliance > Evidence (Evidence Library), select an item, open the Current artifact section, click the ellipsis, and download — files must be downloaded one at a time
- 2Evidence linked to a specific control: go to Controls, select a control, open the Evidence tab (requires Early Access), and click Download near the top-right of the evidence table
- 3Raw/system-generated evidence from monitoring tests: go to Events, select an event, then download Raw Evidence and Event Details (PDF) or Raw result (TXT)
- 4Consolidated evidence for an audit period: go to Compliance > Audit, select an audit, choose the ellipsis > Pre-Audit package > Request package; Drata builds a ZIP in the background and emails a download link when ready
- 5Control-to-framework mappings: go to Frameworks, select a framework, click Downloads, and choose a CSV mapping export (out-of-scope controls are excluded automatically)
- 6Personnel/compliance data: go to Governance > Personnel and export the Compliance Overview or Policy Acknowledgement report as CSV
- 7Test results: from the Monitoring page, select tests and use Export tests to CSV, or use Download Findings on the Findings tab to get a ZIP with a remediation PDF and findings CSV
- 8For a full/bulk pull of raw records, use the Drata Public API (GET endpoints for controls and events) to page through and write all records to a JSON file
What the export includes
- ✓Individual evidence artifacts from the Evidence Library
- ✓Evidence attached to specific controls
- ✓Raw event/test evidence (JSON, PDF, TXT) from monitored tests
- ✓Pre-audit evidence packages scoped to a date range (PDF + CSV + evidence files in a ZIP)
- ✓Control-to-requirement/framework mapping data (CSV)
- ✓Personnel compliance status and policy acknowledgement records (CSV)
- ✓Monitoring test results and findings (CSV/ZIP)
- ✓Bulk controls and events data via the Public API (JSON)
What it doesn't include
- ✗A single bulk "export everything" workflow — the docs state there is no one workflow that exports all evidence in bulk without using the API
- ✗Full historical event log in one download (API pulls are paginated and must be scripted/filtered by date)
- ✗Evidence Library bulk download — items must be downloaded individually in the UI
- ✗Controls > Evidence tab is only available to accounts opted into Early Access
Before you start
- ⚠No native bulk evidence export in the UI; large evidence sets require either many individual downloads or API scripting
- ⚠Pre-Audit package generation happens in the background and can take time for large audits; you're notified by email when it's ready
- ⚠The Controls > Evidence tab requires Early Access opt-in — it's not available to every account by default
- ⚠Public API GET requests return data in pages of 50 items by default, so bulk pulls need pagination logic
- ⚠Steps differ between Drata's "New Experience" and "Classic Experience" interfaces; accounts created on/after Feb 24, 2026 are automatically on the New Experience
Where to take your data
Free and cheaper tools that can take a Drata export. See all Drata alternatives →
Vanta
Upload exported evidence files and CSV mappings as manual evidence/documents against the equivalent controls in Vanta's control library; there's no automated Drata-to-Vanta migration tool, so mapping is done control-by-control.
Secureframe
Import personnel CSVs and control mapping CSVs manually, and attach downloaded evidence files/PDFs as supporting documents on the matching Secureframe controls.
OpenGRC
Since OpenGRC is self-hosted and open source, you can bulk-upload exported evidence files and use the control mapping CSVs to recreate your control set manually, or build an import script against OpenGRC's data model using the JSON pulled from Drata's Public API.
Exporting from Drata: common questions
Can I export all my Drata data in one click before canceling?+
No. Drata's own help docs say there is no single workflow that exports all evidence in bulk without using the API — you have to pull data from the Evidence Library, Controls, Events, Audit Hub, Frameworks, and Personnel pages separately, or script a bulk pull with the Public API.
What format does Drata evidence export in?+
Depending on where it comes from: individual evidence artifacts download as their original file type, event-based evidence as PDF or TXT, audit packages as ZIP, and control/personnel reports as CSV. Bulk API pulls of controls or events come back as JSON.
Do I need a special role to export data from Drata?+
Personnel exports require an Admin, Information Security Lead, Workspace Manager, or Personnel Compliance Manager role. Other exports (Evidence, Controls, Events, Frameworks, Audit Hub) are generally available to users with access to those sections of the app.
How do I get a full evidence package for my auditor instead of individual files?+
Use the Audit Hub: create or open an audit, set a date range, and request the Pre-Audit package. Drata builds a ZIP of evidence tied to that audit and date range and emails you a link when it's ready — note this is a date-scoped package, not a full export of every evidence item ever collected.
Can I automate exporting all my controls and events out of Drata?+
Yes, via the Drata Public API. There are GET endpoints to page through all controls or events and write the results to a JSON file, which is the closest thing Drata offers to a bulk/full export.
Will I lose my control-to-framework mappings if I leave Drata?+
Not if you export them first. From a framework's page, use Downloads to get a CSV of control-to-requirement or requirement-to-control mappings before you cancel.
Sources
This guide was written from Drata's own documentation and checked against it in October 2026. If a step has changed, the official page wins.