Skip to main content
Skip to main content

Okta Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about Okta before Okta sends a questionnaire or a security document.

Okta's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Okta — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Okta's own trust page.

FedRAMP Certified — Class D (High) Checked August 2026.

Okta IDaaS Government High Cloud is FedRAMP Certified at Class D (High) via the Agency path (package FR2131856836). Okta's commercial identity cloud is a separate offering.

Risk
Tier 3Moderate Risk
Evidence confidence
100%
26 of 27 sources returned data
Questionnaire
93 / 133 answered
70% from public evidence
Last assessed
Aug 28, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 22.2 years🟢Infrastructure: 2 open ports, 0 CVEs
FedRAMP Status
Okta is listed on the FedRAMP Marketplace — Independently verified (checked August 2026).
SOC 2 Status
Okta — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
Okta returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Okta a Moderate Risk tier across 27 intelligence sources, 26 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 26 returning usable evidence. The Okta assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest Okta Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

93 questions answered before Okta responds.

ThirdProof used public evidence to pre-fill 70% of a 133-question vendor security questionnaire — without waiting for Okta. The remaining 40 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

Okta announced in 2018 a commitment to support PCI DSS compliance and released SAQ-D attestation, and is considered a supporting system for PCI-DSS compliance, but specific level not stated in snippets.

Public evidencemedium confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

Okta has published an updated Data Processing Addendum (DPA) available at okta.com/sites/default/files/2025-01/DATA_PROCESSING_ADDENDUM.pdf and maintains GDPR compliance page at okta.com/legal/gdpr/.

Public evidencehigh confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

Okta requires customers to sign a Business Associate Agreement (BAA) prior to storing HIPAA-related information and has developed a solution to execute BAAs with customers.

Public evidencehigh confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

Okta encrypts data at rest using AES-256 encryption, an industry-standard encryption algorithm, as stated in their 2025 cybersecurity executive order blog post.

Public evidencehigh confidence

+ 88 additional evidence-backed answers

Get the Complete Okta Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before Okta sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • FedRAMP — independently verified
  • FedRAMP Authorization Independently Verified
  • FedRAMP Authorization Confirmed via Registry
  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered
  • Clean domain reputation

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Data Security — 6 of 14 questions need vendor input
  • Access Control — 5 of 12 questions need vendor input
  • Incident Response — 4 of 10 questions need vendor input
  • Governance & Risk — 3 of 10 questions need vendor input

Reviewing Okta for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for Okta

Okta is a large, established identity and access management (IAM) platform serving enterprise and government customers worldwide.

Area Requiring Attention

The vendor demonstrates significant security maturity with FedRAMP High authorization, strong cryptographic practices (AES-256 encryption at rest, TLSv1.3 in transit), and a published compliance posture including ISO 27001 certification and SOC 2 Type II claims. Positive signals include: a 22-year-old domain with stable ownership, FedRAMP authorization independently verified through the FedRAMP Marketplace, multi-factor authentication enforcement as a default policy, comprehensive data residency options, a published Data Processing Addendum (DPA) for GDPR compliance, documented incident response procedures, and a responsible disclosure and bug bounty program.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence in this assessment was independently sourced from external data sources, registries, and public disclosures without vendor participation or input.

Investigation Findings

4 findings identified for Okta

1 high1 medium2 low
high

Customer environment compromises reported on the vendor's platform

Multiple security incidents were publicly reported between January and April 2026 in which threat actors gained unauthorized access to Okta customer environments through compromised credentials and vishing (voice phishing) attacks. The incidents affected at least nine organizations including Hims & Hers, ReliaQuest, CrunchBase, SoundCloud, and Betterment, with attackers using stolen Okta SSO credentials to breach downstream systems. …

medium

Security header deficiencies detected

A HTTP security scanner scan of okta.com (the marketing website) returned a failing grade (F, 20/100) due to missing or misconfigured HTTP security headers. Specifically, the domain lacks Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), and X-Frame-Options headers. …

low

Security incident reported involving the vendor (historical)

A historical security incident was confirmed in October 2023, in which Okta's customer support systems were breached, resulting in unauthorized access to data for all customer support users. This incident was publicly disclosed by Reuters and confirmed by Okta and has since been resolved. …

low

Subprocessor page contains placeholder content

Okta's published [subprocessor page](https://okta.com/trust/subprocessors) was identified during the assessment but contains placeholder content with zero subprocessors listed. For a vendor with medium data access, a complete and current subprocessor list is a material due diligence requirement under GDPR Article 28 and industry best practices. …

Showing the 4 most severe of 5 findings.

Security Strengths

Evidence that positively supports Okta's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

FedRAMP Authorization Independently Verified

Trust & Compliance Page Scan

FedRAMP Authorization Confirmed via Registry

Certification Registry Verification

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Clean Website Security Scan

Website Security Scan

Okta complete vendor assessment

Tier 3
Moderate Risk
93 / 133
questionnaire answers
27
sources checked
Aug 28, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 28, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Okta Compliance and Certification Status

Okta claims SOC 2 Type II, ISO 27001, FedRAMP, HIPAA, and CSA STAR certifications. Okta IDaaS Government High Cloud is FedRAMP Certified at Class D (High), independently verifiable on the FedRAMP Marketplace. ThirdProof's assessment cross-references these claims with public registries and flags certifications that cannot be independently verified. As an identity provider, Okta is a critical vendor for most organizations — request the full SOC 2 Type II report and any bridge letters before finalizing vendor approval.

Okta Security Posture and Historical Incidents

ThirdProof investigated Okta across 27 intelligence sources. Historical media search identified the 2022 LAPSUS$ breach and the 2023 support case/HAR file compromise. Okta's current threat intelligence profile is clean — no active sanctions, no current adverse media, no malware indicators. The assessed risk rating is driven by incident history, not current controls, and should be weighed alongside Okta's post-incident remediation disclosures.

Frequently asked about Okta

Does Okta have SOC 2 Type II?+
Okta states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is Okta on the OFAC sanctions list?+
Okta returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is Okta's vendor risk tier?+
ThirdProof assigned Okta a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning Okta.
Has Okta had any data breaches or security incidents?+
ThirdProof's assessment as of August 2026 records 2 incident-related findings for Okta, of which 1 is rated high severity or above. The most severe concerns customer environment compromises reported on the vendor's platform. Each finding states whether the incident affected Okta's own systems, a customer's environment, or a third party — a distinction that changes what you should ask about — and links to the source it was drawn from. The complete assessment carries all of them with their evidence.
Is Okta PCI DSS compliant?+
Okta announced in 2018 a commitment to support PCI DSS compliance and released SAQ-D attestation, and is considered a supporting system for PCI-DSS compliance, but specific level not stated in snippets. ThirdProof records this from Okta's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does Okta support HIPAA and sign BAAs?+
Okta requires customers to sign a Business Associate Agreement (BAA) prior to storing HIPAA-related information and has developed a solution to execute BAAs with customers. If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a Okta security questionnaire?+
Yes. ThirdProof answered 93 of 133 questions (70%) about Okta from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 40 are listed as open, so the follow-up you send Okta is short and specific.
What evidence should I request from Okta?+
Public evidence settles a large part of the review, so the request you send should be short. Ask Okta for the current SOC 2 report and, where applicable, a bridge letter covering the period since the report date; the audit scope — which systems and services the report actually covers; written answers on data security, access control, incident response; contractual commitments, cyber insurance, and the current subprocessor list. Everything ThirdProof could already establish is recorded with its source, so you are not asking Okta to re-confirm what is already documented.

If Okta is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Okta assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required