One Okta finding can support multiple compliance lenses.
Map Okta evidence to HIPAA, SOX ITGC, SOC 2, GLBA/FFIEC, ISO 27001, PCI DSS, CIS Controls v8, NIST 800-53, or customer controls without changing the underlying evidence model.

Choose the compliance view without changing the evidence trail.
HIPAA Okta Assessment Review
For healthcare and healthcare-adjacent teams that need practical identity evidence around access control, workforce access, activity review, and secure operations.
Open framework pageSOX ITGCSOX ITGC Okta Access Review
For finance, SaaS, and public-company teams that need stronger evidence around access governance, privileged access, change risk, and sensitive business apps.
Open framework pageSOC 2SOC 2 Okta Trust Services Review
For SaaS and service organizations that need identity evidence around logical access, privileged access, change control, monitoring, and user lifecycle governance.
Open framework pageGLBA / FFIECGLBA and FFIEC Okta Assessment
For financial services and advisory teams that need clear identity evidence for safeguarding customer information and managing privileged access risk.
Open framework pageISO 27001ISO 27001 Okta Identity Control Review
For teams that want Okta identity evidence aligned to an information security management system and repeatable access-control review process.
Open framework pagePCI DSSPCI DSS Okta Access Control Review
For merchants, processors, and SaaS teams in PCI scope that need identity evidence around access restriction, unique user identification, MFA, and administrative accountability.
Open framework pageCIS Controls v8CIS Controls v8 Okta Identity Review
For teams that benchmark against CIS Controls v8 and want Okta evidence organized around account, access, MFA, and log management safeguards.
Open framework pageNIST 800-53NIST 800-53 Okta Control Evidence Review
For security programs built on NIST 800-53 that need Okta evidence tied to AC, IA, and AU family controls without reworking raw exports.
Open framework pageControls stay attached to findings as review metadata.
Same Okta evidence. Different audit language.
Evidence first
The technical finding stays grounded in Okta data and captured evidence.
Framework lens
Report metadata adds HIPAA, SOX ITGC, SOC 2, GLBA/FFIEC, ISO 27001, PCI DSS, CIS Controls v8, NIST 800-53, or customer control language.
Scoped output
Control mapping depth is chosen before report generation.
Report output
Used in scoped report output.
Need Okta evidence organized around a specific framework?
Scope the framework lens before report generation.
Request an Okta assessment