EN
Back to the archive

The archive · Developer & Business Tools · Strategic decision · 2018–2026

Vanta's bet that EU DORA/NIS2 make compliance software a must-buy; $150M at $2.45B

Founded 2018 to automate SOC 2, Vanta rode EU DORA/NIS2/CRA deadlines to 8,000+ customers, $100M ARR and a $2.45B valuation.

Vanta

The betThat security compliance becomes a continuous, software-defined trust layer every company buys — and EU rules like DORA and NIS2 make the category a must-have market.Scaling

What the business is

Automated compliance platform that turns security frameworks (SOC 2, ISO 27001, DORA) into continuously monitored, verifiable evidence.

Starting capital$353M total raised through the July 2024 Series C (per SiliconANGLE)

How it started

Christina Cacioppo founded Vanta in 2018 in San Francisco, betting that security reviews would become the bottleneck in B2B sales; automating SOC 2 evidence collection was the wedge, with Y Combinator among early backers.

What happened

Vanta passed $10M ARR before its Series A, then $100M ARR by January 2024 with roughly 8,000 customers. In July 2024 it raised a $150M Series C led by Sequoia at a $2.45B valuation, and shipped AI questionnaire automation, Trust Centers, and DORA/NIS2/CRA products as EU deadlines hit: NIS2 applied from October 2024, the Cyber Resilience Act entered into force in December 2024, and DORA from January 2025.

How it ended up

Still scaling: category leader in trust management, growing fastest outside North America (UK, Germany, Australia), with a dedicated DORA product and 375+ integrations as of early 2025.

Background

In 2018 Christina Cacioppo founded Vanta in San Francisco to automate SOC 2. Instead of weeks of spreadsheets and point-in-time audits, software collected evidence continuously and produced the security report — the wedge for a bet that trust, not technology, would become the bottleneck in B2B sales, and that compliance would evolve from an annual chore into a continuous product.

The EU turned that bet into a bigger market. NIS2 applied from October 2024, the Cyber Resilience Act entered into force in December 2024, and the Digital Operational Resilience Act made compliance mandatory for 22,000+ EU financial entities and their ICT providers from 17 January 2025 (a PwC estimate Vanta cites). Vanta shipped dedicated DORA/NIS2/CRA offerings and positioned itself as the way to get audit-ready in six to ten weeks.

By July 2024 Vanta had crossed $100M ARR, counted more than 8,000 customers including Atlassian, Quora and ZoomInfo, and raised a $150M Series C led by Sequoia at a $2.45B valuation — with growth outside North America faster than at home, funding expansion in the UK, Germany and Australia.

What has to be true

  • A dated regulatory deadline converts vague anxiety into a budgeted, must-buy purchase.
  • SOC 2 automation maps onto DORA's five pillars, so each new EU rule expands the same product's market.
  • Selling 'audit-ready before the deadline' to non-security buyers beats selling security theory.
  • Banks, ICT providers and crypto services all face the same evidence problem, so the TAM grows by rule, not by niche.

What can be applied

When regulation sets a deadline, sell the deadline: promise 'ready in weeks', and each new framework (NIS2, CRA, DORA) compounds the same wedge instead of starting over.

Aftermath

As of February 2025 Vanta sells DORA, NIS2 and Cyber Resilience Act automation alongside SOC 2 and ISO 27001, claiming 375+ integrations, 8,000+ customers and DORA compliance in six to ten weeks; the Series C funds upmarket GRC displacement and expansion in the UK, Germany and Australia. No exit; still private.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases