The archive · Developer & Business Tools · Strategic decision · 2018–2026
Vanta's bet that EU DORA/NIS2 make compliance software a must-buy; $150M at $2.45B
Founded 2018 to automate SOC 2, Vanta rode EU DORA/NIS2/CRA deadlines to 8,000+ customers, $100M ARR and a $2.45B valuation.
Vanta
What the business is
Automated compliance platform that turns security frameworks (SOC 2, ISO 27001, DORA) into continuously monitored, verifiable evidence.
Starting capital:$353M total raised through the July 2024 Series C (per SiliconANGLE)
How it started
Christina Cacioppo founded Vanta in 2018 in San Francisco, betting that security reviews would become the bottleneck in B2B sales; automating SOC 2 evidence collection was the wedge, with Y Combinator among early backers.
What happened
Vanta passed $10M ARR before its Series A, then $100M ARR by January 2024 with roughly 8,000 customers. In July 2024 it raised a $150M Series C led by Sequoia at a $2.45B valuation, and shipped AI questionnaire automation, Trust Centers, and DORA/NIS2/CRA products as EU deadlines hit: NIS2 applied from October 2024, the Cyber Resilience Act entered into force in December 2024, and DORA from January 2025.
How it ended up
Still scaling: category leader in trust management, growing fastest outside North America (UK, Germany, Australia), with a dedicated DORA product and 375+ integrations as of early 2025.
Background
In 2018 Christina Cacioppo founded Vanta in San Francisco to automate SOC 2. Instead of weeks of spreadsheets and point-in-time audits, software collected evidence continuously and produced the security report — the wedge for a bet that trust, not technology, would become the bottleneck in B2B sales, and that compliance would evolve from an annual chore into a continuous product.
The EU turned that bet into a bigger market. NIS2 applied from October 2024, the Cyber Resilience Act entered into force in December 2024, and the Digital Operational Resilience Act made compliance mandatory for 22,000+ EU financial entities and their ICT providers from 17 January 2025 (a PwC estimate Vanta cites). Vanta shipped dedicated DORA/NIS2/CRA offerings and positioned itself as the way to get audit-ready in six to ten weeks.
By July 2024 Vanta had crossed $100M ARR, counted more than 8,000 customers including Atlassian, Quora and ZoomInfo, and raised a $150M Series C led by Sequoia at a $2.45B valuation — with growth outside North America faster than at home, funding expansion in the UK, Germany and Australia.
What has to be true
- A dated regulatory deadline converts vague anxiety into a budgeted, must-buy purchase.
- SOC 2 automation maps onto DORA's five pillars, so each new EU rule expands the same product's market.
- Selling 'audit-ready before the deadline' to non-security buyers beats selling security theory.
- Banks, ICT providers and crypto services all face the same evidence problem, so the TAM grows by rule, not by niche.
What can be applied
When regulation sets a deadline, sell the deadline: promise 'ready in weeks', and each new framework (NIS2, CRA, DORA) compounds the same wedge instead of starting over.
Aftermath
As of February 2025 Vanta sells DORA, NIS2 and Cyber Resilience Act automation alongside SOC 2 and ISO 27001, claiming 375+ integrations, 8,000+ customers and DORA compliance in six to ten weeks; the Series C funds upmarket GRC displacement and expansion in the UK, Germany and Australia. No exit; still private.
Sources
- Announcing Vanta's $150 million Series C funding
- Compliance automation and trust management startup Vanta raises $150M
- What is the Digital Operational Resilience Act (DORA)?
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card