Okta

Cybersecurity United States Website Reviewed Aug. 6, 2026

Independent identity provider (Okta Workforce Identity Cloud and Auth0 Customer Identity) for SSO, MFA, IGA and PAM.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
SOC 1 Type 2 Independent third-party auditor Okta Workforce Identity Cloud, Customer Identity and Auth0 platforms. Report available under NDA via the Okta Security Trust Center. Current
SOC 2 Type 2 Independent third-party auditor Okta Workforce Identity Cloud, Customer Identity Solution and Auth0 platforms. Covers security, availability and confidentiality. Report under NDA. Current
SOC 3 Independent third-party auditor Public-facing summary report for the Okta and Auth0 platforms. Current
ISO/IEC 27001:2022 Accredited certification body Okta information security management system covering the Okta and Auth0 services. Current
ISO/IEC 27017:2015 Accredited certification body Cloud-specific information security controls for the Okta services. Current
ISO/IEC 27018:2019 Accredited certification body Protection of personally identifiable information in public cloud acting as a PII processor. Current
CSA STAR Level 1 (CAIQ Self-Assessment) Cloud Security Alliance Self-assessment published to the CSA STAR registry; CAIQ also available from the trust centre. Current
CSA STAR Level 2 (Certification) Cloud Security Alliance / accredited auditor Third-party audited CSA STAR Level 2 certification for the Okta cloud services. Current
CSA Trusted Cloud Provider Cloud Security Alliance Trust mark recognising CSA membership and demonstrated cloud security practice. Current
FedRAMP High FedRAMP PMO / JAB Okta for Government High and Okta US Military subscriptions only. Not the commercial Okta cell. Current
FedRAMP Moderate FedRAMP PMO Okta for Government Moderate subscriptions only. Current
DoD Impact Level 5 (IL5) US Department of Defense / DISA Okta US Military offering. Not applicable to commercial subscriptions. Current
GovRAMP (formerly StateRAMP) GovRAMP US state and local government offering. Current
IRAP Assessment (PROTECTED) ASD-endorsed IRAP assessor Australian Government IRAP assessment; IRAP Protected documentation available via the trust centre. Current
BSI C5 Independent third-party auditor German Cloud Computing Compliance Criteria Catalogue attestation for the Okta cloud services. Current
PCI DSS v4.0.0 Qualified Security Assessor (QSA) Okta as a service provider; Attestation of Compliance available under NDA. Current
FIPS 140-2 NIST/CSE Cryptographic Module Validation Program Validated cryptographic modules used within the Okta service. Current
TISAX ENX Association / accredited audit provider Automotive industry information security assessment exchange label. Current
EU Cloud Code of Conduct SCOPE Europe (monitoring body) GDPR Article 40 code of conduct adherence; public report of adherence published by Okta. Current
ST4S (Safer Technologies 4 Schools) Education Services Australia Australian schools sector safety, privacy and security assessment badge. Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
Certified to ISO/IEC 27001:2022 for the Okta and Auth0 services; certificate available via the Okta Security Trust Center.
SOC 2 Type 2
Full
SOC 2 Type 2 audited annually across Workforce Identity Cloud, Customer Identity Solution and Auth0. SOC 3 public summary also issued.
PCI DSS v4.0
Full
PCI DSS v4.0.0 compliant as a service provider; AoC available under NDA.
BSI C5
Full
BSI C5 attestation held for the Okta cloud services.
NIST Cybersecurity Framework
Partial
Okta maintains an internal Control Library mapped across NIST, PCI DSS, ISO 27001 and FedRAMP. NIST 800-53 Rev. 5 alignment is claimed via FedRAMP authorisation rather than a standalone CSF attestation.
GDPR 2016/679
Full
Global DPA incorporating the 2021 EU SCCs (controller-to-processor and processor-to-processor), EU-US / Swiss-US Data Privacy Framework and UK Extension certification, EU Cloud Code of Conduct adherence and Global PRP certification.
DORA
Full
Okta is listed as DORA-ready on its trust centre and publishes a DORA compliance factsheet for financial-sector customers.
HIPAA Security
Full
HIPAA support with an Okta Business Associate Agreement published on the trust and compliance documentation page.
ISO 27002
Partial
Annex A / ISO 27002 control alignment is inherited from the ISO/IEC 27001:2022 certification rather than separately attested.

Penetration Testing

Scope Conducted By Date Frequency Report
Annual third-party penetration testing of the Okta and Auth0 production services, plus continuous internal penetration testing of source code and production security controls including OWASP-specific flaws. Customers may also run their own penetration tests against their tenant with prior approval. (date shown is the profile capture date) Independent third-party testing firms plus Okta internal penetration testing team Aug. 6, 2026 Annual On NDA

Data Handling

Data Residency Regions
Okta operates regional "cells". Workforce/Customer Identity: USA (standard), Canada, India, EU (Germany, Ireland), Australia, Japan. Auth0 public cloud: USA, Canada, UK, EU, Japan, Australia. Auth0 private cloud adds Brazil, Germany, Hong Kong, Indonesia, Ireland, Italy, UAE, France, Sweden, South Africa, Bahrain, India, South Korea, Singapore, Mexico, Thailand and Switzerland/Norway/Netherlands via Azure. Okta for Government and US Military are USA-only.
Encryption at Rest
Yes — Stored data is encrypted using an encryption key created specifically for each customer, with each tenant assigned its own key (per the Okta Security Trust Center Data Security section).
Encryption in Transit
Yes — All communication between Okta and the customer is protected by TLS with Perfect Forward Secrecy (PFS). HTTP Strict Transport Security (HSTS) is enforced to prevent downgrade to clear-text HTTP.
Backup Frequency
Backups of customer data are maintained as required to meet the published Recovery Point Objective; backup restoration is tested as part of quarterly Disaster Recovery testing.
Retention Policy
Data Deletion
Separate published Okta Data Retention Policy and Auth0 Data Retention Policy are linked from the Data Security section of the Okta Security Trust Center. Retention periods vary by product and data type (e.g. System Log retention differs by SKU) - confirm the specific figures for your subscription against the current policy documents before relying on them. Okta also revised Help Center data retention following the October 2023 support-system incident.

Sub-processors

Sub-processor Purpose Data Location Trust Portal
Amazon Web Services (AWS) Primary hosting and cloud infrastructure for Workforce/Customer Identity, Auth0, Identity Security Posture Management and Okta for Government USA, Canada, India, Germany, Ireland, Australia, Japan (plus extensive Auth0 private-cloud regions) View ↗
Google, Inc. Cyber defence (threat detection, investigation and response); hosting for Access Governance and Okta Privileged Access; non-training generative AI for Log Investigator USA, Canada, India, Germany, Belgium, Australia, Japan, EMEA View ↗
Microsoft Hosting and cloud infrastructure - Azure regional failover for Auth0 public cloud (Canada, Japan, Australia) and Auth0 private cloud regions USA, Canada, Brazil, Ireland, Netherlands, France, Switzerland, Norway, Germany, Sweden, South Africa, UAE, UK, India, South Korea, Australia, Japan View ↗
Splunk, Inc. Business analytics and log analysis USA, Germany, Ireland, United Kingdom
Salesforce, Inc. (salesforce.com, inc.) Support and maintenance ticketing process (Okta Help Center) USA View ↗
Twilio, Inc. SMS authenticator delivery USA
SendGrid, Inc. Email notifications and email access request inbox USA
TeleSign Corporation SMS authenticator delivery USA, Netherlands
Snowflake Computing, Inc. / Snowflake Computing Netherlands B.V. Data warehouse services USA, Canada, India, Germany, Australia, Japan
MongoDB, Inc. Managed database services for Access Governance, Okta Privileged Access, ISPM and Auth0 USA, Canada, India, Germany, Belgium, Netherlands, Australia, Japan
Datadog, Inc. Business analytics for Access Governance, Advanced Server Access, Okta Privileged Access and Auth0 USA, Germany
Cloudflare, Inc. Content delivery network and DDoS prevention for the Auth0 platform (may process data in any country by design) Global View ↗
Aiven Ltd Managed database services for Auth0 Corresponds to the customer-selected AWS or Azure region
S.C. Computer Generated Solutions Romania S.R.L. (subsidiary of Computer Generated Solutions, Inc., USA) 24x7 outsourced customer support team; may access AWS and Salesforce data centres Okta uses while providing support No data centres; support team located in Romania (USA for Government Moderate)
Sentry Security event analysis and incident response for Identity Security Posture Management USA, Germany
Slack Technologies, LLC Messaging and collaboration for Identity Security Posture Management USA

Incident & Breach History

Date Summary Impact Resolution Report
Oct. 20, 2023 Unauthorised access to the Okta Help Center (support case management system). A threat actor used stolen credentials to access the support case management system and viewed HTTP Archive (HAR) files uploaded by customers during troubleshooting, which could contain session tokens. Okta stated its production identity service was not impacted. A subset of support customers were affected and received a customised impact report; indicators of compromise were published and regulators and law enforcement were notified. RCA published 3 Nov 2023; recommended actions 29 Nov 2023. Independent forensic firm Stroz Friedberg confirmed no malicious activity beyond Okta’s own findings; investigation closed 8 Feb 2024. Okta hardened the Help Center, changed admin access provisioning and that system’s retention policy, and shipped Zero Standing Privileges for admins, MFA for protected admin actions, anonymiser blocking, IP binding and API network zone allowlisting. Report ↗

Security Policies

Policy Availability Link
Information Security Policy On Request View ↗
Access Control Policy On Request View ↗
Acceptable Use Policy On Request View ↗
AI Governance Public View ↗
Business Continuity Plan + DR Attestation On Request View ↗
Cyber Security Incident Response Plan On Request View ↗
Data Classification and Handling Standard On Request View ↗
Endpoint Security Standard On Request View ↗
Engineering Release Management Procedure On Request View ↗
Okta Control Library On Request View ↗
Physical Security Policy On Request View ↗
Risk Assessment / Management Policy On Request View ↗
Vulnerability Reporting Policy Public View ↗

Contact & Responsible Disclosure

Trust Portal & Audit Evidence

**Primary trust portal:** https://security.okta.com (SafeBase) - reached from https://trust.okta.com. Public status and availability: https://status.okta.com (trust page reports 12-month availability of 99.99%, averaged across incidents affecting at least 10% of customers).

**Publicly available without NDA**
- Full compliance badge list, control descriptions and policy summaries on the trust centre landing page
- SOC 3 report (public summary)
- Sub-processor list: https://www.okta.com/en-gb/legal/trustandcompliance/subprocessors/
- Data Processing Addendum, SCCs, Information Security Addendum, Business Associate Agreement, Government Request Transparency Report, Modern Slavery statement, EU Cloud Code of Conduct public report of adherence and AI Model Cards: https://www.okta.com/trustandcompliance/
- Vulnerability Reporting Policy and Bugcrowd programmes
- Security advisories and RSS: https://trust.okta.com/security-advisories/
- Security blog: https://sec.okta.com

**Gated behind trust-centre access request / NDA**
- SOC 1 and SOC 2 Type 2 reports
- ISO 27001 / 27017 / 27018 certificates
- CSA STAR Level 2 certification, CAIQ, HECVAT, MVSP
- IRAP Protected documentation, ENS (Royal Decree 311/2022) report, PCI DSS AoC
- Penetration test reports and the Okta FastPass Assessor’s Report
- Information Security Policy, Okta Control Library, BCP/DR attestation, incident response plan, endpoint security standard, release management procedure

**Additional trust-centre claims recorded here but not held as separate certificates:** CISA Secure-by-Design Pledge signatory, NIST 800-53 Rev. 5 (via FedRAMP), EU-US / Swiss-US DPF and UK Extension, GDPR, HIPAA, DORA, ENS, APEC/Global CBPR and PRP, ProcessUnity and TruSight questionnaire participation, VPAT accessibility conformance.

**Other notes**
- Okta runs a "Pooled Security Audits" programme allowing customers to share audit effort - see https://sec.okta.com/articles/pooledauditretro/
- Customers should set a Primary Security Contact and CIO/CISO contact in the Okta Help Center so Okta can alert them to organisation-specific threats.
- Sub-processor change notifications are opt-in by emailing [email protected] with an executed DPA; customers have 10 business days to object.

Risk Assessment Notes

**Inherent risk drivers**
- Okta is an identity provider and therefore a single point of authentication for every downstream application it fronts. Compromise of the Okta tenant is effectively compromise of the whole estate, so inherent risk should be treated as **critical** regardless of the data volume held.
- Holds authentication credentials, MFA factors, session tokens, directory attributes and detailed sign-in telemetry.
- Highly attractive target: Okta has been the subject of two widely reported supply-chain style incidents (the January 2022 Lapsus$/Sitel third-party support compromise and the October 2023 Help Center incident recorded above).
- Long fourth-party chain. Okta depends on AWS, Google and Microsoft Azure for hosting, plus Twilio, TeleSign and SendGrid for out-of-band authentication delivery - meaning MFA availability depends on third-party telecom providers.
- Outsourced 24x7 support in Romania (CGS) with potential access to production support data. This was the risk pattern behind the 2022 incident.

**Mitigating factors**
- Very broad and independently audited assurance set: SOC 1/2/3, ISO 27001/27017/27018, CSA STAR Level 2, BSI C5, PCI DSS v4.0.0, IRAP, FedRAMP High and Moderate, DoD IL5, GovRAMP, TISAX, EU Cloud Code of Conduct and FIPS 140-2 validated crypto.
- Per-tenant encryption keys at rest and TLS with PFS and HSTS in transit.
- Public, dated and product-segmented sub-processor list with an opt-in notification and objection process - materially better transparency than most vendors in this library.
- Annual third-party penetration testing plus a continuous internal penetration testing team and two public Bugcrowd programmes.
- Quarterly DR testing with regional and geographic DR capacity; BCP/DR and incident response attested within SOC 2 Type II.
- Demonstrated incident transparency: root cause analysis, recommended actions, independent forensic review by Stroz Friedberg and published closure.
- Concrete product hardening delivered after 2023 (Zero Standing Privileges for admins, MFA for protected admin actions, IP binding, API network zone allowlisting, anonymiser blocking) and the ongoing Okta Secure Identity Commitment.

**Concerns to track**
- Verify which cell your tenant is in. Data residency, and which sub-processors apply, differ per cell and per SKU - EU cell data can still flow to US-hosted Splunk, Datadog or Google depending on the service.
- FedRAMP High, FedRAMP Moderate, DoD IL5 and GovRAMP apply **only** to Okta for Government / US Military subscriptions. Do not credit these to a commercial tenant.
- Retention periods are in separate Okta and Auth0 Data Retention Policy documents and vary by product and log type; confirm actual figures rather than assuming.
- CDN processing for Auth0 via Cloudflare is explicitly global and cannot be pinned to a region.
- MFA delivered by SMS depends on Twilio/TeleSign; prefer phishing-resistant factors (Okta FastPass, WebAuthn) to reduce both security and third-party availability risk.
- Most substantive evidence (SOC 2, ISO certificates, pen test reports, ISMS policies) requires an NDA and a trust-centre access request - budget time for this in the assessment.

**Residual customer responsibilities**
- Configure and enforce phishing-resistant MFA, admin role scoping, Zero Standing Privileges, session and IP binding, Dynamic Zones and API network zone allowlisting. Okta ships these controls but does not enable them for you.
- Restrict who can upload HAR files or other troubleshooting artefacts to Okta support, and sanitise them first.
- Set the Primary Security Contact and CIO/CISO contact in the Help Center.
- Subscribe to sub-processor change notifications and to the security advisory RSS feed.
- Execute a DPA (and a BAA where PHI is in scope) and confirm the applicable SCC module.
- Monitor and retain Okta System Log events in your own SIEM - do not rely on Okta-side log retention.

**Suggested review cadence:** annual full reassessment, with quarterly review of security advisories, sub-processor changes and tenant configuration drift. Given the criticality of the identity layer, treat any Okta security advisory as an out-of-cycle trigger for review.

Assess Okta in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.