Q39
Are you PCI DSS compliant? At what level?
Okta announced in 2018 a commitment to support PCI DSS compliance and released SAQ-D attestation, and is considered a supporting system for PCI-DSS compliance, but specific level not stated in snippets.
ThirdProof independently checks public intelligence sources to show what your team can verify about Okta before Okta sends a questionnaire or a security document.
Okta's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Okta — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Okta's own trust page.
✓ FedRAMP Certified — Class D (High) Checked August 2026.
Okta IDaaS Government High Cloud is FedRAMP Certified at Class D (High) via the Agency path (package FR2131856836). Okta's commercial identity cloud is a separate offering.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The Okta assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Okta Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 70% of a 133-question vendor security questionnaire — without waiting for Okta. The remaining 40 are listed as open, so the follow-up you send is short and specific.
Q39
Okta announced in 2018 a commitment to support PCI DSS compliance and released SAQ-D attestation, and is considered a supporting system for PCI-DSS compliance, but specific level not stated in snippets.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
Okta has published an updated Data Processing Addendum (DPA) available at okta.com/sites/default/files/2025-01/DATA_PROCESSING_ADDENDUM.pdf and maintains GDPR compliance page at okta.com/legal/gdpr/.
Q40
Okta requires customers to sign a Business Associate Agreement (BAA) prior to storing HIPAA-related information and has developed a solution to execute BAAs with customers.
Q23
Okta encrypts data at rest using AES-256 encryption, an industry-standard encryption algorithm, as stated in their 2025 cybersecurity executive order blog post.
+ 88 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Okta for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Okta
Okta is a large, established identity and access management (IAM) platform serving enterprise and government customers worldwide.
The vendor demonstrates significant security maturity with FedRAMP High authorization, strong cryptographic practices (AES-256 encryption at rest, TLSv1.3 in transit), and a published compliance posture including ISO 27001 certification and SOC 2 Type II claims. Positive signals include: a 22-year-old domain with stable ownership, FedRAMP authorization independently verified through the FedRAMP Marketplace, multi-factor authentication enforcement as a default policy, comprehensive data residency options, a published Data Processing Addendum (DPA) for GDPR compliance, documented incident response procedures, and a responsible disclosure and bug bounty program.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from external data sources, registries, and public disclosures without vendor participation or input.
4 findings identified for Okta
Multiple security incidents were publicly reported between January and April 2026 in which threat actors gained unauthorized access to Okta customer environments through compromised credentials and vishing (voice phishing) attacks. The incidents affected at least nine organizations including Hims & Hers, ReliaQuest, CrunchBase, SoundCloud, and Betterment, with attackers using stolen Okta SSO credentials to breach downstream systems. …
A HTTP security scanner scan of okta.com (the marketing website) returned a failing grade (F, 20/100) due to missing or misconfigured HTTP security headers. Specifically, the domain lacks Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), and X-Frame-Options headers. …
A historical security incident was confirmed in October 2023, in which Okta's customer support systems were breached, resulting in unauthorized access to data for all customer support users. This incident was publicly disclosed by Reuters and confirmed by Okta and has since been resolved. …
Okta's published [subprocessor page](https://okta.com/trust/subprocessors) was identified during the assessment but contains placeholder content with zero subprocessors listed. For a vendor with medium data access, a complete and current subprocessor list is a material due diligence requirement under GDPR Article 28 and industry best practices. …
Showing the 4 most severe of 5 findings.
Evidence that positively supports Okta's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Okta complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Okta claims SOC 2 Type II, ISO 27001, FedRAMP, HIPAA, and CSA STAR certifications. Okta IDaaS Government High Cloud is FedRAMP Certified at Class D (High), independently verifiable on the FedRAMP Marketplace. ThirdProof's assessment cross-references these claims with public registries and flags certifications that cannot be independently verified. As an identity provider, Okta is a critical vendor for most organizations — request the full SOC 2 Type II report and any bridge letters before finalizing vendor approval.
ThirdProof investigated Okta across 27 intelligence sources. Historical media search identified the 2022 LAPSUS$ breach and the 2023 support case/HAR file compromise. Okta's current threat intelligence profile is clean — no active sanctions, no current adverse media, no malware indicators. The assessed risk rating is driven by incident history, not current controls, and should be weighed alongside Okta's post-incident remediation disclosures.
Represent Okta? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Okta assessment above is already written; ask for it and it lands in your inbox.