New in Vanta
Keep up with the latest releases and improvements.
July 2026
Vanta, now directly inside ChatGPT

Customers want Vanta's intelligence wherever they already work, and increasingly that's ChatGPT. The Vanta App for ChatGPT, powered by our remote MCP server, brings Vanta's tools for getting Trust done into that conversation with a click; no need to switch tabs or context.
Your Trust Center, live on AWS Marketplace

Buyers on AWS Marketplace ask for compliance information during purchasing, but vendors previously had no way to surface it there. Now, Vanta integrates with AWS Marketplace in both directions: feature your Trust Center on your Marketplace listing so buyers see your security posture up front, and link your Marketplace listing from your Trust Center to turn credibility into a purchase path. One source of truth surfaced everywhere it matters, and any customer can set it up today.
Track the commitments your business actually cares about

Customer Commitments extracts 16 out-of-the-box commitment types from your contracts automatically, but every business tracks a different set. Custom Commitment Types let you define your own: give it a name, a definition, and example clauses, and Vanta extracts it from every future contract, plus retroactively across everything you've already uploaded—no re-uploading required. An agent-driven version, where you build types by working with the Vanta agent directly, is coming in a few weeks.
Looking for more? Check out the Vanta changelog on our Help Center.
June 2026
Register Scoring Customization

A single global scoring setup stops serving every team as risk programs mature. A security team running a 5x5 matrix and a finance team managing fraud and insider risk often need different scales, risk levels, and definitions.
Now you can configure scoring per register. A new domain-level Scoring tab in Risk Settings lets you set a default rubric that all registers inherit, then customize scales, risk levels, and descriptions per register. Everything happens on one editing page with a live heatmap that updates as you edit, so you can see exactly how each score maps to a risk level before saving.
You stay in control as things evolve, too: choose which registers pick up default changes, reset any customized register back to default in one click, and get prompted to select the right configuration on reports, widgets, and bulk import or update whenever registers diverge.
The Vanta Agent can read and configure this for you, and more flexible scoring capabilities are on the way.
Duplicate Audits
For customers running the same audit year over year, most of the work carries forward — the auditor, frameworks, and scope typically stay the same, with only incremental updates needed each cycle.
Now you can duplicate a past audit in a few clicks and start the new cycle already most of the way to ready. Vanta carries over your request list, control mappings, request owners, and the latest version of any evidence previously submitted through Vanta.
You can update year-to-year details like audit name, firm, observation window, and early access date, and auditors can add or remove requests so the list matches this year's scope. Each duplicated audit is its own engagement, so changes in one never affect the other, and Vanta flags anything needing a fresh look, like evidence sourced from outside Vanta.
Manage risk registers with the Vanta Agent and MCP
As risk programs evolve, you need to create, rename, and retire registers, whether you're spinning up a new business unit, restructuring after a reorg, or sunsetting a product. The Vanta Agent and MCP can now support your register management by creating, updating, and deleting risk registers through natural conversation.
You can ask the Vanta Agent to create a new register with a name and optional description, for example "Create an Operational Risk Register for our infrastructure team." You can also have it update an existing register by renaming it, changing its description, or managing which custom fields apply, or delete registers that are no longer needed.
Look out for more agentic tools to help you manage your risk program soon.
External and internal commenting in TPRM


Traditional third-party risk workflows lean on static, one-directional communication. Buyers issue long questionnaires, vendors respond in isolation, and clarifying an answer or requesting more evidence often means restarting the review or juggling email threads. At scale, that creates operational drag and erodes confidence in the review.
With this release, you can now add comments to individual questions on an assessment questionnaire and filter for all questions with comments when reviewing. Comments run on two separate tracks for visibility control: internal among your team, or external between your team and vendor contacts through the Vanta Exchange. Any vendor who has accessed the Exchange receives an email when you comment.
The result: buyers get answers faster, vendors add context where it's asked for, and assessments turn around more quickly.
May 2026
New framework: ISO 22301
.webp)
Vanta now supports ISO 22301, the international standard for Business Continuity Management Systems (BCMS). ISO 22301 helps organizations prepare for, respond to, and recover from disruptive incidents (from cyberattacks to natural disasters) with a structured, auditable framework.
With Vanta's support for ISO 22301, customers can map existing controls, track compliance against the standard's requirements, and streamline evidence collection, all within the same platform they use for their other frameworks.
AI recommendations for access reviews
.webp)
Access reviews are supposed to surface risk, but when reviewers are staring at thousands of accounts, fatigue sets in fast and the accounts that actually need attention get lost in the noise.
Vanta now generates an AI recommendation for every account at the start of a review: Approve, Deny, or Needs Review. Each recommendation surfaces the signals behind it (employment status, last login, access control policy, previous decisions, prior access requests) so reviewers understand why an account was flagged, not just what the verdict is.
The result: Low-risk accounts can be bulk-approved in seconds, freeing reviewers to spend their time on the accounts that actually matter. This is the first release in a broader AI-powered access review experience. More coming soon!
Automatic deprovisioning for Zoom and Figma
.webp)
When someone leaves your organization, their accounts need to be shut down immediately. Vanta has long helped teams see what access terminated employees had and track remediation through tasks and admin notifications. Now Vanta can pull the trigger automatically.
Zoom and Figma now support automatic deprovisioning through Vanta's offboarding workflow, joining existing integrations like Calendly and OpenAI. When a team member is offboarded in Vanta in Zoom,the user is deactivated immediately. They can no longer sign in, their license is freed, and their data (meetings, recordings, chats) stays intact. When a team member is offboarded in Figma, the user is deactivated via Figma's SCIM API, removing org access while preserving their data.
SPRS score tracking for CMMC Level 2
For organizations pursuing CMMC Level 2 certification, the Supplier Performance Risk System (SPRS) Score is a fundamental requirement: a self-assessed score submitted to the DoD that reflects your current compliance posture against all 110 NIST SP 800-171 security requirements.
CMMC Level 2 customers can now track their SPRS Score automatically, directly inside Vanta. The score is calculated at the requirement level and updates in real time as you mark controls as Implemented or Not Applicable. When you hit 110 points, Vanta surfaces the guidance you need to complete your self-assessment and submit to the SPRS portal.
Defense contractors using Vanta to manage their CMMC programs can now handle SPRS Score tracking end-to-end without leaving the platform — further strengthening Vanta's position as the leading compliance automation solution for government and defense-adjacent companies.
SharePoint integration for Customer Commitments
.webp)
Keeping your Customer Commitments inventory complete requires that contracts actually make it into the system. Manual uploads work, but they don't scale. Every missed upload is a commitment that goes untracked.
Customers can now use SharePoint as a contract source for Customer Commitments. Connect your existing SharePoint environment directly from the Commitments settings page, and Vanta will continuously and automatically sync your contracts. Because this builds on Vanta's existing SharePoint connection, there's no additional OAuth setup required.
The result: A scalable, low-maintenance way to keep your commitments inventory up to date, without the operational overhead of manual uploads or custom API workflows.
April 2026
Connect Vanta to your AI tools of choice with the remote MCP server
AI tools are rapidly changing the way we work, and more users are shifting to tools like Claude Code, Cursor, and more for their day-to-day tasks. These tools offer a simple, no-code method to orchestrate work across their tech stack. With Vanta’s remote MCP server, your trust program can now easily plug into these tools as well.
As of April 15, 2026, the Vanta remote MCP server is available to all customers in Public Preview. The MCP server connects directly to your compliance program in Vanta, including tests, controls, vendors, and more, so AI tools can query your program in real time.
For teams using Claude, there's an additional layer: the Vanta Plugin for Claude bundles the MCP connection with purpose-built remediation skills and slash commands (/vanta:list-tests, /vanta:fix-test). It enables users to discover failing tests, generate infrastructure-as-code fixes grounded in their actual repository, and open pull requests without leaving their editor. This covers 500+ cloud tests across AWS, GCP, and Azure.
Evaluate vendors across every risk domain with Multiple Assessments

Third-party risk is not just about security. Today, teams are responsible for evaluating vendors across privacy, legal, financial, AI, ESG domains, and more, often during a single procurement or renewal event.
With TPRM Multiple Assessments now fully rolled out, teams can run and manage multiple assessments concurrently within a single vendor lifecycle event. Rather than forcing every evaluation into a one-size-fits-all security review, teams can create domain-specific assessments in parallel, assign each to the right owner with tailored evidence collection, and bring everything into a single unified vendor view. AI-powered automation runs across all assessment types simultaneously.
More what's new this month
Expanded Vanta Agent coverage: Privacy (data processors, DPIAs, processing activities), Personnel (task completion, policy acceptance, device compliance at scale), and Questionnaire Automation (search knowledge base and questionnaire library) context now embedded in the Vanta Agent.
Outbound Webhooks: Real-time notifications when specific events occur like vendor creation, Trust Center access requests, questionnaire status changes, and more. No more polling the API.
Auto-tracking and auto-account assignment with Customer Commitments: Commitments are now automatically added to your inventory and automatically assigned to the right account. The full path from contract ingestion to tracked commitments runs end-to-end without manual intervention.
March 2026
Generate SSP packages for federal frameworks

Preparing for federal audits often involves creating a time-consuming System Security Plan (SSP). These documents can span hundreds of pages, requiring teams to manually write, format, and compile detailed descriptions of their system and controls. With SSP generation, Vanta removes that manual burden.
Vanta now enables teams to generate SSP packages that meet FedRAMP and CMMC requirements directly within the platform. Using a structured template and guided workflow, you can input required information, and produce a complete SSP without starting from scratch. The SSP is generated in a standardized template with all necessary attachments and appendices and is stored in Vanta for easy management.
Unlock more automation with our integrations
Vanta has introduced several new integrations and key enhancements to existing ones, all in an effort to deliver greater visibility and deeper automation for our customers.
Microsoft Entra and Microsoft Intune (GCC High): Enabling users of Microsoft’s GCC High environments to securely connect to Vanta to automate evidence collection and unlock continuous controls monitoring. These integrations enable device management and monitoring via Microsoft Intune (GCC High), and continuous synchronization of users, groups, and vendor applications between Entra ID (GCC High) and Vanta.
Miradore: Enabling users to continuously monitor device posture and security policy adherence, verify that only compliant devices have access to organizational resources, and validate device compliance status as reported by Miradore.
Splunk (Cloud): Enabling users to monitor and manage personnel access to Splunk (Cloud), ensure that only active employees retain access to company systems, and simplify access reviews to support compliance requirements.
We’ve also released a key enhancement to Vanta’s Linear integration, allowing users to link existing Linear tickets to Vanta Documents, enabling attachments uploaded to Linear tickets to automatically appear in Vanta as recommended evidence. This change ensures Vanta users can see ticket status and synced attachments in the platform, while stakeholders can contribute their work in Linear.
Turn customer obligations into actionable, trackable commitments

Customer Commitments helps you centralize, track, and act on every obligation your team has made, without digging through contracts when it matters most. Contracts are automatically ingested from your contract management system like Ironclad, key obligations are extracted and then structured into searchable, actionable data via the Vanta AI Agent.
Quickly understand who needs to be notified, by when, and why, whether you’re responding to an incident, preparing for an audit, or heading into a renewal. With real-time visibility and alerts, teams can move from reactive contract reviews to proactive trust management, ensuring every promise is delivered, every time.
Evaluate vendors across every risk domain

Third-party risk isn’t just about security. Today, teams are responsible for evaluating vendors across multiple risk domains like privacy, legal, AI, and ESG.
With Vanta’s Multiple Assessments, teams can run and manage assessments concurrently within a single vendor lifecycle event, like procurement or renewal. Instead of forcing every evaluation into a one-size-fits-all security review, teams can assign domain-specific assessments to the right owners, collect tailored evidence and questionnaires, and bring everything together into a single, unified view enabling faster decisions.
The result? Faster assessments, clearer ownership, and a more complete picture of vendor risk, without slowing down the business.