How to export your data from Vanta

Vanta has no single 'export everything' button — data is exported section by section as CSV, PDF, ZIP, or XLSX from the Documents, Policies, Frameworks, Tests, People, and Access pages inside the app.

Formats: CSV, PDF, ZIP, XLSXPlan: Not specified in Vanta's export documentation — the exports described are standard app features, not called out as plan-gatedRole: Not specified in the docs; export buttons appear for users with access to the relevant page (e.g. Documents, Policies, Frameworks, Tests, People, Access)

✓ Verified against Vanta's official documentation, October 2026

Step by step

  1. 1Documents: go to the Documents page, click '...' (more options), then click Export All — downloads a ZIP of all stored documents.
  2. 2Policies: go to the Policies page, click '...' and select Download Policy Packet for a single compiled PDF with acceptance history, or open an individual policy and click Download for a single PDF.
  3. 3Framework evidence: go to Frameworks, open a framework, click More, then Export all framework evidence — downloads a ZIP with policies, documents, and automated test files organized by folder.
  4. 4Controls: in the same framework, click More, select Export controls, optionally check 'Include evidence status', then click Download CSV.
  5. 5Gap assessment: in the framework, click More and select the gap assessment export option to download it as a PDF.
  6. 6Automated test evidence: go to Tests, open an automated test, click the Evidence tab, scroll to Exports, then click Workpaper (audit-ready PDF) or CSV (raw data).
  7. 7People: go to People, click '...' and select Export — downloads a CSV of your employee list.
  8. 8Access: go to Access and click Export — downloads an Excel file with access/account data.

What the export includes

  • ✓All documents stored on the Documents page (ZIP)
  • ✓Policies as a compiled PDF packet including acceptance history, or individual policy PDFs
  • ✓Framework evidence (policies, documents, automated test files) organized by folder
  • ✓Controls list as CSV, optionally with pass/fail evidence status
  • ✓Gap assessment as PDF
  • ✓Automated test evidence via Workpaper (audit-ready PDF) or CSV (raw data)
  • ✓Security awareness training completion records (dates, user emails, status)
  • ✓Personnel list as CSV
  • ✓Access/account data as an Excel file

What it doesn't include

  • ✗There is no single 'export everything' option covering the whole workspace at once
  • ✗All policies as separate PDFs bundled in one ZIP is not supported — only the combined Policy Packet or one-by-one individual downloads
  • ✗Manual test evidence has no bulk 'Exports' section — only the uploaded file/screenshot and version history can be downloaded
  • ✗People-page training export excludes completion records from third-party integrations (e.g. KnowBe4) — use the Test export for those
  • ✗For very large datasets, the Workpaper PDF may omit raw JSON data (use the CSV export instead)

Before you start

  • ⚠Exports are done page-by-page and framework-by-framework; there's no master export job
  • ⚠The Workpaper export is locked/immutable by design to preserve audit integrity
  • ⚠Accounts still in an active audit may see the older 'Source Data' tab instead of the new Evidence tab, and won't have the Workpaper option until migrated
  • ⚠Automated vs. manual tests behave differently for exports — only automated tests show the Workpaper/CSV Exports section

Where to take your data

Free and cheaper tools that can take a Vanta export. See all Vanta alternatives →

Secureframe

Secureframe has no native Vanta importer; use your exported Vanta policy PDFs, control CSVs, and evidence files as the starting documents you upload into Secureframe's policy library and control mappings, then reconnect your cloud/HR/identity integrations directly in Secureframe.

Sprinto

Upload the exported policy PDFs and framework evidence ZIP as reference documents in Sprinto, map Vanta's exported controls CSV to Sprinto's equivalent framework controls, and re-authorize your integrations in Sprinto since connections aren't migrated automatically.

Scrut Automation

Use the exported controls/evidence CSVs and policy PDFs as source material when setting up Scrut's framework, and re-connect cloud, HR, and device integrations natively in Scrut rather than transferring Vanta's integration config.

Exporting from Vanta: common questions

Can I export all my Vanta data in one click?+

No. Vanta does not have a single 'export everything' button — you export documents, policies, framework evidence, controls, test evidence, people, and access data separately from their respective pages.

What file formats does Vanta use for exports?+

Depending on the section, Vanta exports as CSV (controls, people, test evidence), PDF (policy packet, gap assessment, Workpaper), ZIP (documents, framework evidence), or XLSX (access data).

What's the difference between the Workpaper and CSV export on a test?+

Workpaper is a locked, immutable, audit-ready PDF export designed to meet auditor standards; CSV gives you the raw underlying data, which is recommended for very large datasets where the Workpaper PDF may not include raw JSON.

Can I download all my policies as separate PDF files?+

Bundling all policies as separate PDFs in a single ZIP isn't supported. You can download the combined Policy Packet (one PDF with acceptance history) or download individual policies one at a time.

Why don't I see a Workpaper option on one of my tests?+

Accounts still in an active audit may show the older Source Data tab instead of the new Evidence tab and won't have Workpaper access until migrated; use the download button under 'Full test results' on that tab instead.

Does the People page export include security awareness training completion from tools like KnowBe4?+

No. The People page export does not include third-party integration training records — use the dedicated training test's Workpaper or CSV export under Tests for audit-ready completion records.

Sources

This guide was written from Vanta's own documentation and checked against it in October 2026. If a step has changed, the official page wins.