ALL RESOURCES
Company news
Vanta Named G2’s 2022 Leader in Cloud Compliance Software
BlogsCompany news
March 28, 2022

Vanta Named G2’s 2022 Leader in Cloud Compliance Software

Vanta has been named G2’s top provider for cloud compliance software and services for Spring 2022. Vanta continues to receive the most customer reviews (291) among competitors, resulting in a rating of 4.7 out of 5 stars. 

Vanta also claimed the number one position for G2’s Momentum Grid® Report which helps potential customers compare companies and conduct market analysis. The report uses an algorithm that considers two main variables of each company—Satisfaction and Momentum. 

Vanta’s Satisfaction score of 95% consists of authentic feedback and reviews from real Vanta customers. The Momentum score, 83%, is calculated by looking at Vanta’s social, web, employee, and review data. Included below are a few examples of what customers are saying about Vanta.

Personalized support and consultation 

The head of quality assurance from a mid-market company needed to get SOC 2 compliant as fast as possible. They referenced Vanta’s customer success team as a vital part of the process.

“[Vanta’s] customer success team is exemplary, keeping a regular health check of your compliance program with frequent updates and weekly action items to make sure you are up to speed with your compliance activities.”

Oftentimes small to medium-sized businesses are not able to hire an in-house compliance specialist. It’s not uncommon for owners or CEOs to spearhead these responsibilities. One such owner depended on Vanta’s proactive support during a SOC 2 audit.

“Vanta guided us through the process of getting compliant. Great customer success team. Loved the list of issues to correct in our environment—gave us a working to-do list and we always knew how much more we had to go.”

Intuitive out-of-the-box functionality

Small teams usually don’t have the time to manually integrate new tools or learn complicated software. An infrastructure systems manager noted Vanta’s easy-to-use platform.

“We would not have the bandwidth to get SOC 2 ready without a tool like Vanta. The ability to take this process at our own pace and integrate it into our current tech stack…is invaluable to a small team…”

Seasoned IT professionals especially appreciate Vanta’s quick setup and installation. This feedback was submitted by a computer software administrator.

“So easy to use! Out-of-the-box setup was plug-and-play. It integrated with our stack and the vendors that they recommended for us have been really easy to work with.”

Automated compliance security at all times

Continuous automation provides the most security for small businesses. Having one central place to assess a compliance environment is invaluable. An events services administrator agrees.

“The automated tests provided by Vanta help us have an easy bird’s eye view over all our resources which concentrates all evidence in one place…[this] provides peace of mind that everything is under control and enables us to act when something is falling off the plate.” 

Automation is essential when a company needs to ensure compliance across a large tech stack. When asked what they liked best about Vanta, a founder and COO commented on how easy it was to scan their system.

“Vanta's integrations with AWS, Google, and all our other providers meant that performing control checks was automated and easy. We were anticipating many months of work to get our SOC 2, and Vanta cut down our expected effort by an order of magnitude.”

Making the internet a safer place 

At Vanta, our mission has always been to restore trust and security in internet businesses. By putting our customers and their challenges first, we continue to discover new ways to provide as much value as possible. These marks of achievement reflect our ongoing goal to help our customers grow their businesses with confidence.

Written by
No items found.
Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail

PCI Compliance Selection Guide

Determine Your PCI Compliance Level

If your organization processes, stores, or transmits cardholder data, you must comply with the Payment Card Industry Data Security Standard (PCI DSS), a global mandate created by major credit card companies. Compliance is mandatory for any business that accepts credit card payments.

When establishing strategies for implementing and maintaining PCI compliance, your organization needs to understand what constitutes a Merchant or Service Provider, and whether a Self Assessment Questionnaire (SAQ) or Report on Compliance (ROC) is most applicable to your business.

Answer a few short questions and we’ll help identify your compliance level.

1
2
3
4
!
👍

Does your business offer services to customers who are interested in your level of PCI compliance?

Yes
No

Identify your PCI SAQ or ROC level

The PCI Security Standards Council has established the below criteria for Merchant and Service Provider validation. Use these descriptions to help determine the SAQ or ROC that best applies to your organization.

Good news! Vanta supports all of the following compliance levels:

SAQ A

A SAQ A is required for Merchants that do not require the physical presence of a credit card (like an eCommerce, mail, or telephone purchase). This means that the Merchant’s business has fully outsourced all cardholder data processing to PCI DSS compliant third party Service Providers, with no electronic storage, processing, or transmission of any cardholder data on the Merchant’s system or premises.

Get PCI DSS certified

SAQ A-EP

A SAQ A-EP is similar to a SAQ A, but is a requirement for Merchants that don't receive cardholder data, but control how cardholder data is redirected to a PCI DSS validated third-party payment processor.

Learn more about eCommerce PCI

SAQ D
for service providers

A SAQ D includes over 200 requirements and covers the entirety of PCI DSS compliance. If you are a Service Provider, a SAQ D is the only SAQ you’re eligible to complete.

Use our PCI checklist

ROC
Level 1 for service providers

A Report on Compliance (ROC) is an annual assessment that determines your organization’s ability to protect cardholder data. If you’re a Merchant that processes over six million transactions annually or a Service Provider that processes more than 300,000 transactions annually, your organization is responsible for both a ROC and an Attestation of Compliance (AOC).

Automate your ROC and AOC

Download this checklist for easy reference

Questions?

Learn more about how Vanta can help. You can also find information on PCI compliance levels at the PCI Security Standards Council website or by contacting your payment processing partner.

The compliance news you need. Delivered securely to your inbox.