Oracle Database@Azure Compliance Information
Learn about the compliance certifications and service management responsibilities of Oracle Database@Azure.
Shared responsibility between Oracle and Microsoft
Oracle Database@Azure is an Oracle Cloud Infrastructure (OCI) database service that runs Oracle Database workloads in a customer's Azure environment. When the customer implements this solution, they deploy resources in two cloud environments: database resources are in Azure, while the database administration control plane is in OCI. This lets the customer deploy Oracle Database products in their Azure environment while OCI maintains administration capabilities.
Azure-based applications access Oracle Databases directly from within the customer's Azure environment. The customer performs most database administration operations in the Azure console as well. Maintaining the database control plane in OCI lets Oracle Database@Azure be easily managed and upgraded with the latest operational and administrative capabilities.
All hardware for Oracle Database@Azure uses Azure networking. Oracle’s responsibility for monitoring the data center control environments is included within the scope of the System. Oracle Database@Azure uses Azure's Identity and Access Management integration to manage user and group access for the customer's Oracle database resources. Azure networking and Identity and Access Management are not within the scope of the System.
While an OCI tenancy is required, day-to-day operations and visibility are centralized within the Azure environment, reflecting a shared responsibility model between Oracle and Azure.
Oracle Database@Azure Compliance Certifications
As of August 2025, following compliance certifications have been completed for Oracle Database@Azure:
Audit Program | Location Scope | Status |
---|---|---|
SOC1 (System and Organization Controls) | Global | Supported |
SOC2 (System and Organization Controls) | Global | Supported |
SOC3 (System and Organization Controls) | Global | Supported |
HIPAA (Health Insurance Portability and Accountability Act) | Global | Supported |
C5 (Cloud Computing Compliance Controls Catalogue – Germany) | Global | Supported |
CSA STAR Attestation | Global | Supported |
CSA STAR Certification | Global | Supported |
HDS (Hébergement de Données de Santé – France) | Global | Supported |
ISO/IEC 9001 (Quality Management) | Global | Supported |
ISO/IEC 20000-1 (Service Management) | Global | Supported |
ISO/IEC 27001 (Information Security Management) | Global | Supported |
ISO/IEC 27017 (Information Security for Cloud Services) | Global | Supported |
ISO/IEC 27018 (Personally Identifiable Information in Public Clouds) | Global | Supported |
ISO/IEC 27701 (Privacy Information Management) | Global | Supported |
ISO/IEC 22301 (Business Continuity Management) | Global | Supported |
PCI DSS (Payment Card Industry Data Security Standard) | Global | Supported |
HITRUST (Health Information Trust Alliance) | Global | Supported |
MTCS (Multi-Tier Cloud Security -Singapore) | Singapore | Supported |
GSMA (GSM Association) | Global | Supported |
IRAP (Infosec Registered Assessors Program - Australia) | Australia | Supported |
ISMAP (Information system Security Management and Assessment Program - Japan) | Japan | Supported |
FISC (Center for Financial Industry Information Systems - Japan) | Japan | Supported |
For detailed information on the compliance certifications visit Microsoft service trust portal and Oracle compliance website. If you have further questions about Oracle Database@Azure compliance, contact your account team, or get information through Oracle and Microsoft support for Oracle Database@Azure.