Skip to main content
Okta logo

Okta

Security and trust center evidence

okta.comIdentity and accessLast verified 17 Sep 2026

Summary

Okta has 2 registry-verified rows and 14 vendor-stated rows, and 1 expired in the CertReports index, last verified 17 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.

Reviewer brief

As of 17 Sep 2026, Okta is listed in the FedRAMP registry as FedRAMP Authorized (issued 26 Apr 2017, audited by Coalfire Systems, Inc.). As of 17 Sep 2026, Okta is listed in the CSA STAR registry at STAR Level 2, Trusted Cloud Provider (issued 28 Mar 2013). As of 17 Sep 2026, Okta states on its trust centre that it holds SOC 2, SOC 1, SOC 3, GDPR, PCI DSS, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, GovRAMP, TISAX, BSI C5, ENS, and IRAP, and displays a HIPAA badge, though BAA availability is not yet captured. As of 17 Sep 2026, Okta's EU-US Data Privacy Framework status is listed as expired, with the record dated 23 Sep 2025 and marked inactive. As of 17 Sep 2026, no public evidence found regarding subprocessor disclosures for Okta.

  • FedRAMP: listed in FedRAMP registry as Authorized, issued 26 Apr 2017, auditor Coalfire Systems, Inc. (as of 17 Sep 2026).
  • CSA STAR: listed in CSA STAR registry at Level 2, Trusted Cloud Provider, issued 28 Mar 2013 (as of 17 Sep 2026).
  • EU-US Data Privacy Framework: expired/inactive, dated 23 Sep 2025 (as of 17 Sep 2026).

Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.

Among identity and access vendors

2verified rows

Category median 1, across 47 indexed identity and access vendors. Okta has more verified rows than 96 percent of them.

access-controlauthenticationidentity-managementsso

Compliance grid

No public evidence yet for Cyber Essentials, ISO 27701, ISO 42001. This does not mean the vendor lacks them; it means nothing public was found at the last check.

Subprocessors

No subprocessor list captured yet.

Change history

  1. 17 Sep 2026BSI C5 evidence addedA BSI C5 row entered the index with state Vendor-stated.
  2. 17 Sep 2026ENS evidence addedA ENS row entered the index with state Vendor-stated.
  3. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  4. 17 Sep 2026GovRAMP evidence addedA GovRAMP row entered the index with state Vendor-stated.
  5. 17 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
  6. 17 Sep 2026IRAP evidence addedA IRAP row entered the index with state Vendor-stated.
  7. 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
  8. 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
  9. 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
  10. 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.

Similar vendors with evidence

Related by product tags and the Identity and access category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.