Okta vs 1Password: Security & Compliance Comparison
Summary
- Okta holds 21 certifications. 1Password holds 9 certifications.
- Both are certified for: SOC 2, ISO 27001, ISO 27017, ISO 27018, CSA STAR, GDPR, CCPA, PCI DSS.
- Okta has but 1Password doesn't: SOC 3, SOC 1, BSI C5, UK GDPR, EU-US DPF, Swiss-US DPF, Global PRP, HIPAA, FedRAMP, StateRAMP, DORA, IRAP, NIST CSF.
- 1Password has but Okta doesn't: ISO 27701.
Side-by-side: all 32 frameworks
| Framework | Okta | 1Password |
|---|---|---|
| Security & General Standards | ||
| SOC 2 | ✓ | ✓ |
| SOC 3 | ✓ | ?Not documented in trust center |
| SOC 1 | ✓ | ?Not documented in trust center |
| ISO 27001 | ✓ISO/IEC 27001:2022 | ✓ISO/IEC 27001:2022 |
| ISO 27017 | ✓ISO/IEC 27017:2015 | ✓ISO/IEC 27017:2015 |
| ISO 27018 | ✓ISO/IEC 27018:2019 | ✓ISO/IEC 27018:2019 |
| ISO 27701 | ?Not documented in trust center | ✓ISO/IEC 27701 |
| ISO 42001 | ?Not documented in trust center | ?Not documented in trust center |
| ISO 9001 | ?Not documented in trust center | ?Not documented in trust center |
| CSA STAR | ✓CSA STAR Level 1 and Level 2 | ✓CSA STAR Level 1 |
| HITRUST | ?Not documented in trust center | ?Not documented in trust center |
| BSI C5 | ✓BSI Cloud Computing Compliance Controls Catalog | ?Not documented in trust center |
| Privacy & Data Transfer | ||
| GDPR | ✓ | ✓ |
| CCPA | ✓ | ✓ |
| UK GDPR | ✓ | ?Not documented in trust center |
| LGPD | ?Not documented in trust center | ?Not documented in trust center |
| PIPEDA | ?Not documented in trust center | ?Not documented in trust center |
| DPDP Act | ?Not documented in trust center | ?Not documented in trust center |
| PIPL | ?Not documented in trust center | ?Not documented in trust center |
| EU-US DPF | ✓ | ?Not documented in trust center |
| Swiss-US DPF | ✓ | ?Not documented in trust center |
| Global CBPR | ?Not documented in trust center | ?Not documented in trust center |
| Global PRP | ✓Not documented in trust center | ?Not documented in trust center |
| Industry & Government | ||
| HIPAA | ✓ | ~AgileBits is not defined as a Business Associate pursuant to HIPAA nor subject to a BAA |
| PCI DSS | ✓PCI DSS v4.0.0 | ✓PCI DSS materials available in trust center |
| FedRAMP | ✓FedRAMP High and Moderate authorized | —Not FedRAMP authorized |
| StateRAMP | ✓Not documented in trust center | —Not StateRAMP authorized; TX-RAMP is Texas state authorization only |
| DORA | ✓ | ?Not documented in trust center |
| CJIS | ?Not documented in trust center | ?Not documented in trust center |
| FINRA | ?Not documented in trust center | ?Not documented in trust center |
| IRAP | ✓IRAP Protected | ?Not documented in trust center |
| Emerging & Strategic | ||
| NIST CSF | ✓NIST 800-53 Rev. 5 | ?Not documented in trust center |
✓ Certified~ Partial / conditional— Not certified? Not publicly documented
Need help choosing?
Join our waitlist for compliance alerts and expert comparisons.
Join the waitlist →