Logo Menu

OneTrust Certification Automation SOC 2 compliance software

SOC 2 / ISO 27001 certification automation module within OneTrust's Tech Risk & Compliance suite Last updated

Certification Automation is the current name for what OneTrust acquired as Tugboat Logic in September 2021; OneTrust renamed the product effective December 13, 2022 and relaunched it under the new name in March 2023 with 29 frameworks and over 100 integrations.

By , Lead Editor · independently researched · Methodology

Pricing
Published, from 36K GBP/yr
Source-checked frameworks
2
Integrations
100+
What the evidence says

It is sold and reviewed as part of OneTrust's broader Tech Risk & Compliance / GRC and Security Assurance Cloud solution area rather than as a standalone SOC 2 point product, which is also why we could not find a G2 listing scoped to it alone.

Company context

OneTrust's last confirmed round was $150 million led by Generation Investment Management in July 2023, valuing the company at $4.5 billion (down from a $5.1 billion valuation in 2021). As of mid-2026, Reuters and other outlets report OneTrust in exploratory private-equity buyout talks (Thoma Bravo and Vista Equity Partners named as possible bidders), but no deal has closed or been confirmed.

Pricing

OneTrust Certification Automation publishes a price.

You can read the numbers without a sales call, which is uncommon in this category and worth weighing on its own.

Disclosure model
Published, from 36K GBP/yr
Sourced annual price
GBP 36,180 / year
Basis
Confirmed, 2026-07-24

Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.

Read the OneTrust Certification Automation pricing guide for the current source table and quote checklist.

Capabilities

What OneTrust Certification Automation does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes G-Cloud feature list: 'Automated evidence collection'; the March 2023 launch press release claims up to 50% of evidence collection automated. Source
Auditor workspace Yes G-Cloud feature list: 'Audits and auditor collaboration.' Source
Trust center Partial G-Cloud lists a 'customer portal to share security reports,' which is trust-page-like but we could not confirm it is a full public-facing trust center product under this module. Source
Security questionnaire answering Not established The original Tugboat Logic product answered security questionnaires; we could not confirm this feature is still marketed under the current Certification Automation name.
Enterprise admin (SSO, SCIM, RBAC) Not established OneTrust is enterprise software and likely supports SSO/SCIM/RBAC platform-wide, but we found no source confirming this scoped to Certification Automation specifically.
SCIM 2.0 provisioning Not established OneTrust documents SCIM 2.0 provisioning for the OneTrust platform login generally, via Okta. Nothing scopes it to the SOC 2 compliance product or names a tier. OneTrust sells SOC 2 as a solution layered on a shared compliance-automation product with no SOC 2 specific SKU, so a platform-wide fact cannot be reported as a fact about the thing a SOC 2 buyer would purchase.
Continuous control testing Not established Marketing describes 'security posture management' and ongoing evidence collection but does not confirm a scheduled, recurring automated control-test cadence.
Native multi-framework support Partial Vendor describes a 'proprietary shared evidence framework' that lets teams 'test once, comply many' across more than 29 frameworks, i.e. a shared/crosswalked control model rather than fully separate native control sets per framework. Source
Source-checked frameworks

2 frameworks checked individually, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed UK G-Cloud listing: 'prepare for security audits like SOC 2, ISO 27001 and more.' Source
ISO 27001 Vendor-claimed Independent trade press coverage of the March 2023 product launch citing 29 supported frameworks including ISO 27001. Source
Auditor handoff

Who actually issues the report.

Certification Automation is a self-service compliance-management tool; OneTrust does not issue the buyer's SOC 2 report. The buyer's own licensed CPA firm performs the actual audit and uses the product's auditor-collaboration workspace to request and review evidence.

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who OneTrust Certification Automation is for, and who it is not.

Good fit

A company already standardized on OneTrust for privacy or vendor risk management that wants one vendor relationship covering SOC 2 and ISO 27001 as well.

Poor fit

A first-time SOC 2 buyer with no existing OneTrust relationship and no near-term need for the broader GRC suite. The licence price we found (£36,180/year on the UK G-Cloud marketplace) sits well above the roughly $7,500-$15,000 entry tier that dedicated SOC 2 point-solutions charge, and G2 does not track Certification Automation as its own product, so buyers cannot compare it head-to-head against tools like Vanta or Drata the way review platforms let them do for other vendors.

Typical buyer: Mid-market to enterprise companies already using OneTrust for privacy or third-party risk that want to add SOC 2/ISO 27001 certification management on the same platform..

Related profiles

Compare OneTrust Certification Automation with three alternatives.

  • Comp AI

    An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.

  • A pre-Series-B SaaS company that wants a hands-on advisory team bundled into the subscription rather than a pure self-serve automation tool.

  • A small SaaS startup that wants one flat-fee vendor to own evidence collection, policy setup, and hands-on audit coordination through a first SOC 2 (optionally plus one more framework) without hiring a compliance person.

Source ledger

Where every figure on this page came from.

7 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.

← All SOC 2 compliance software · OneTrust Certification Automation review · How we verify

For OneTrust Certification Automation

4 facts on this page we could not establish.

Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at OneTrust Certification Automation, send us the sources and we will fill them.

Verification is free and always will be. It does not change where OneTrust Certification Automation appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.

Correct this record