Skip to main content
Okta logo

Okta

SOC 2 evidence

okta.comIdentity and accessLast verified 17 Sep 2026
SOC 2 mark, CertReports state Vendor-stated as of 17 Sep 2026Vendor-stated

Okta and SOC 2

Okta states it holds a SOC 2 Type II report. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Okta trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026SOC 2
Live page Snapshotsha256 9fa130beaf
VerifiedSTAR Level 2 certification, Trusted Cloud Provider
as of 17 Sep 2026 · confidence 100%
Kind
level2
Issued or listed
28 Mar 2013
Products in scope
okta inc.
SourceCapturedQuoteLinks
CSA STAR registry
Official registry · HTTP 200
17 Sep 2026okta inc.: STAR Level 2 certification, Trusted Cloud Provider
Live pagesha256 e7f124247f
Vendor-statedVendor states CSA STAR on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Okta trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026CSA STAR
Live page Snapshotsha256 9fa130beaf
Vendor-statedVendor states SOC 1 on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Okta trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026SOC 1
Live page Snapshotsha256 9fa130beaf
Vendor-statedVendor states SOC 3 on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Okta trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026SOC 3
Live page Snapshotsha256 9fa130beaf

What is not public

  • The report period is not public, so CertReports cannot say whether the Okta SOC 2 report covers the last 12 months.
  • The audit firm is not stated in any public source CertReports has captured.
  • Trust services criteria in scope, carve-outs and bridge-letter status are only in the restricted-use report, which CertReports never hosts.
What SOC 2 means, and what it does not

SOC 2 reports are restricted-use and are never "certifications". A Type II report covers a period; freshness is the period end plus a bridge letter of at most three months. "SOC 2 ready" and "in progress" are not reports. No public SOC 2 registry exists; the strongest registry-grade signal is a CSA STAR Level 2 attestation, then a public SOC 3.

Read the SOC 2 guide and browse all vendors with evidence

Questions buyers ask

Is Okta SOC 2 certified?

No organisation is "SOC 2 certified": SOC 2 is an attestation report issued by a CPA firm, not a certification. Okta states it holds a SOC 2 Type II report as of 17 Sep 2026.

How do I get the Okta SOC 2 report?

SOC 2 reports are restricted-use documents shared under NDA. Request it through the Okta trust centre or security page; CertReports links to it and never hosts the report.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with SOC 2 evidence

Similar vendors (shared product tags or the Identity and access category) whose SOC 2 row is verified or vendor-stated, ranked by similarity.

No Identity and access vendor has SOC 2 evidence in the index yet.