How I would run APAC enterprise implementations from kickoff to audit, and a working kickoff kit built from Drata's public API spec, its docs and live public data.
A Sydney region and office since October 2025, about 550 APAC customers, mostly ANZ. Vanta arrived a year earlier and has CPS 234 in product.
Most APAC requirements outside Australia are a custom framework today. How fast an SA maps them onto existing controls decides time-to-audit in the region.
A kickoff kit: a live scan of a customer's public posture and stack, a plan generator for APAC stacks and frameworks, and a read-only API console.
| Takeaway | Why it matters for implementations |
|---|---|
| HR data is the first APAC blocker | Employment Hero connects through Merge and needs broad read scope. KeyPay and Xero Payroll have no HRIS connection. Onboarding and offboarding evidence depends on this. |
| Custom frameworks carry the region | CPS 234, MAS TRM, NZISM, ISMAP, DPDP and the CSA marks all need mapping onto ISO 27001 controls. A reusable template library pays back on every account. |
| Essential Eight is changing | ASD consulted in mid 2026 on an "Essentials series" to replace it. Evidence built on the underlying controls carries over. |
| Trust Center is the expansion path | Many APAC companies already run SafeBase portals. Linking them to live control status is a natural second conversation. |
An early regional book on a platform that has widened from compliance automation into trust management.
| Area | What is public | Implementation read |
|---|---|---|
| APAC footprint | Sydney office and data centre announced October 2025; 550+ APAC customers, majority AU and NZ. Channel through MSSPs, auditors and AWS. | Region choice is a kickoff decision; partners often co-deliver. |
| API regions | Separate US, EU and APAC API hosts (public-api.apac.drata.com) and an APAC MCP host. | Scripts and integrations must target the tenant's region. |
| Platform | Compliance automation, Trust Center (SafeBase, acquired 2025 for $250M), TPRM sold standalone from September 2026, AI Agent Governance in limited availability. | Implementations start with compliance and expand into trust and vendor risk. |
| Frameworks | 33 listed, plus unlimited custom frameworks with an AI mapping agent. APAC-native: Essential Eight (October 2025) and APRA CPS 230 (July 2026). | Anything else in the region runs through custom frameworks. |
| Customer Success org | SAs sit post-sale with CSMs, Professional Services, Support and Education. An Associate SA tier serves the commercial segment 1:many. | The APAC SA owns enterprise accounts one to one. |
| Company | Founded 2020; 8,500+ customers (June 2026); $100M+ ARR (February 2025); last priced round $200M at $2B (December 2022). | Enterprise growth is the stated priority in 2026. |
Deals are decided on regional frameworks, hosting and price. Implementations are where the choice gets proven.
| Vendor | AU hosting | APAC frameworks in product | Gap vs Drata, and the SA angle |
|---|---|---|---|
| Drata | Sydney, 2025 | Essential Eight, CPS 230 | Benchmark. Strength in Trust Center, TPRM and the API; everything else in APAC is a custom framework. |
| Vanta | Sydney, October 2024 | Essential Eight, CPS 234 | A year ahead in ANZ and has CPS 234. A fast, documented CPS 234 custom framework closes most of that gap in an implementation. |
| Sprinto | Australia, April 2026 | Essential Eight content; list not verifiable | Price-led, strong in India. Competes on time-to-audit for smaller accounts. |
| Scrut | Not found | Essential Eight L1 and L2, ISM, MAS TRM, Singapore PDPA, DPDP, RBI, SEBI | Widest APAC catalogue of the pure-plays, smaller company. Wins framework checklists in SG and India. |
| 6clicks | Sovereign, IRAP-assessed to PROTECTED | Essential Eight with maturity scoring, ISM and IRAP | Default for Australian government and defence work. Drata competes on commercial accounts. |
| OneTrust | AU and NZ since 2018 | Privacy-first | Enterprise privacy suite; heavier to implement. |
| Secureframe, Thoropass, Hyperproof | Not found | Limited | US-centric; rarely the APAC shortlist. |
| Consultancies and MSSPs | Local | Deliver E8, CPS 234 and IRAP assessments | Mostly partners. Clear SA-to-partner handoffs keep them selling Drata. |
What customers will ask about, country by country, and how each lands in Drata today.
| Country | Requirement | What customers ask | In Drata |
|---|---|---|---|
| AU | ASD Essential Eight | Target maturity level; ML2 for Commonwealth entities and often their suppliers. Replacement "Essentials series" under consultation. | native |
| AU | APRA CPS 230 | Operational risk and material service providers; contracts by renewal or 1 July 2026. | native |
| AU | APRA CPS 234 | 72-hour incident notice; 10 business days for material control weaknesses. | custom or partner pack |
| AU | ISM and IRAP | Government and PROTECTED workloads. | partner pack |
| AU | Privacy Act amendments 2024 | Statutory tort from June 2025; automated-decision transparency by December 2026. | policies, custom |
| NZ | NZISM | NZ government buyers. | custom or partner pack |
| SG | MAS TRM, Cyber Hygiene | Drives questionnaires from MAS-regulated customers. | custom |
| SG | PDPA | Notify PDPC within 3 calendar days of assessing a notifiable breach. | policies |
| SG | CSA Cyber Essentials, Cyber Trust | Local certification marks. The Cyber Essentials framework in Drata is the UK scheme; the names collide. | custom |
| MY | PDPA amendments 2024 | DPO and 72-hour breach notice from 1 June 2025. | policies |
| MY | Cyber Security Act 2024 | NCII entities and their suppliers. | custom |
| IN | DPDP Act and 2025 Rules | Duties phase in through about May 2027. | custom |
| IN | CERT-In directions | 6-hour incident reporting; 180 days of logs kept in India. | runbook, custom |
| JP | ISMAP, APPI | Government cloud list; APPI amendment promulgated July 2026. | custom |
| HK | Cap. 653 critical infrastructure | In force 1 January 2026. | custom |
Encoding the docs and spec into rules forced precise reading. Each finding saves time in an APAC implementation.
| Finding | Evidence | What it changes |
|---|---|---|
| Essential Eight help article uses retired identifiers | The mapping cites ISO 27001:2013 numbers (A.9.2, A.17.1), NIST CSF 1.1 subcategories and the old strategy name "Configure Microsoft Office Macros". ASD's current text and ISO 27001:2022 use different references. | Auditors working from 2022 Annex A will query it. The kit carries a 2022 mapping. |
| Two "Cyber Essentials" | Drata's Cyber Essentials framework is the UK NCSC scheme. Singapore's CSA Cyber Essentials mark is unrelated. | A Singapore customer could enable the wrong framework. One line in kickoff notes prevents it. |
| APAC payroll gap | The API's connection enum includes Employment Hero (via Merge) but no KeyPay; Xero appears only among SaaS connections, with no HRIS source. | Plan IdP inference or a custom HRIS push in week one for payroll-only customers. |
| Employment Hero needs broad scope | Its OAuth has no granular scopes, so the connection needs broad read. | Brief the customer's HR and privacy owner before kickoff so consent does not stall week one. |
| The API accepts browser calls | API hosts return access-control-allow-origin: * with the authorization header allowed. | Customer scripts should still keep keys server-side; IP-allowlisted keys need a fixed egress. |
| Trust centers are visible in DNS | SafeBase portals resolve to *.portals.safebase.io; competitor portals have their own CNAME patterns. Canva and Airwallex resolve to SafeBase. | The scan tells the account team which customers can link a trust center to live controls. |
Checked 20 September 2026 against developers.drata.com (v1 and v2 OpenAPI), help.drata.com, ASD's Essential Eight Maturity Model (November 2023) and public DNS. The demo reproduces each one.
| JD duty | How I would do it | Detailed in |
|---|---|---|
| Own a portfolio of APAC enterprise customers | One page per account: frameworks, audit dates, owners, connection health, open risks. Reviewed weekly with the CSM. | §05 |
| Lead end-to-end implementations | Pre-kickoff scan, scoped plan with milestones, named owners, weekly working session on failing tests, readiness review before the auditor. | §05, demo |
| Senior stakeholder relationships | Separate cadences: weekly for the working team, monthly for the sponsor with status against the audit date. | §05 |
| Monitor health, renewal risk, expansion | Signals from the API: framework readiness, failing tests by age, Agent coverage, personnel failures. Expansion notes on Trust Center and second frameworks. | §06 |
| Configure, integrate, migrate, troubleshoot | Connections in week one, custom connections for unsupported tools, scripted bulk work through the API. | §05, demo |
| Advise on integrations, cloud, identity, HR systems, AI workflows | Stack-specific advice from the plan generator, including the APAC HRIS gaps and AI tool policy questions. | ★, demo |
| Training, workshops, QBR insights | Role-based sessions for control owners; QBR slide built from readiness and test trends. | §07 |
| Reduce engineering escalations | Reproduce first, document the platform behaviour, file with request IDs and payloads. | §06 |
| UAT, bugs, feature requests, regional requirements | Regional requests logged with account count and ARR attached, so APAC frameworks get prioritised on evidence. | §03, §06 |
| Share APAC trends | Monthly note: top blockers, custom frameworks built, partner handoffs. | §07 |
The demo generates this per customer. Durations stretch with headcount, frameworks and workarounds.
| Phase | Work | What usually runs late |
|---|---|---|
| Before kickoff | Public posture scan, stack inference, tenant region, framework scope, audit firm and window. | Region: moving a tenant later is a migration. |
| Kickoff | Owners for IT, HR, engineering and policy approval; target maturity level for Essential Eight in writing. | An unnamed HR owner. |
| Connections and people | IdP, HRIS, cloud, version control, ticketing; reconcile contractors and service accounts; Agent or MDM rollout. | Agent coverage on the last 10% of laptops. |
| Policies and risk | Tailor and publish policies, collect acceptance, risk register, Statement of Applicability, custom framework mapping. | Policy acceptance from executives. |
| Remediation | Weekly session on failing tests by owner; tickets in the customer's tracker; manual evidence for non-automatable controls. | Application control, macro settings and restore tests for Essential Eight. |
| Readiness and handoff | Readiness review per framework, auditor access, handover to CS with health baseline and expansion notes. | Access reviews left to the last month. |
Grounded in the gaps above. Each one shortens time-to-audit or opens expansion across many accounts.
| Move | How | Measure |
|---|---|---|
| APAC custom framework library | Reviewed templates for CPS 234, MAS TRM, NZISM and the CSA marks, mapped onto ISO 27001:2022 controls, shared with the team and partners. | Days from kickoff to framework live. |
| HR data pre-brief | Short guide per APAC HRIS (Employment Hero scope, KeyPay and Xero fallbacks) sent before kickoff. | Personnel reconciled by end of week one. |
| Essentials series readiness | Map Essential Eight evidence to the underlying controls now; brief AU customers on the consultation as it lands. | No rework when ASD publishes. |
| Trust Center linkage | Scan the book for SafeBase portals not yet linked to live controls; offer the setup at the first QBR. | Trust Center attach rate. |
| Partner handoffs | Clear split with MSSPs and auditors: who scopes, who remediates, who attests. | Partner-sourced implementations on time. |
| Mandarin coverage | Workshops and working sessions in Mandarin for Singapore, Malaysia, Hong Kong and Taiwan teams. | Adoption in those accounts. |
| Escalation packets | Every product issue filed with tenant region, request IDs, payloads and a reproduction. | Escalations resolved without a second round trip. |
Built from the public job posting (2026), Drata's public OpenAPI spec and help centre, press releases, regulator publications and public DNS, read on 2026-09-20. Company figures are labelled as company figures. The demo is my own tool and calls the Drata API only with a key the user supplies. Unsolicited interview homework; happy to walk through any section.
APAC launch: press release, Oct 2025 · CRN
API: v2 reference · keys and limits
HRIS: connect your HRIS · how Drata uses HRIS data
Essential Eight: Drata overview · ASD maturity model · Essentials series consultation
APRA: CPS 230 · Drata CPS 230 · CPS 234
Frameworks: drata.com/frameworks · AU/NZ partner packs
Competitors: Vanta ANZ · Scrut frameworks · 6clicks IRAP
Singapore: MAS TRM · PDPC · India: CERT-In directions
SafeBase: TechCrunch · TPRM: Sept 2026
Independent homework for the Drata Solutions Architect (APAC) role · 2026 · edwardtay.com