SAP Cloud Infrastructure SOC 1 Audit Report 2024 H2

SAP Cloud Infrastructure (SCI) spearheads SAP’s 4+1 strategy and supports the adoption and governance of all services deployed as part of SAP’s Cloud Infrastructure Strategy. Specifically, this refers to the management of public cloud hyperscalers and SAP’s internal IaaS known as SAP Converged Cloud.

 

SAP Converged Cloud

Converged Cloud is SAP’s standardized Infrastructure as a Service (IaaS) offering to support all of SAP’s cloud business on a global scale. SAP Converged Cloud provides access to a vendor-agnostic hardware infrastructure architecture as well as infrastructure orchestration and automation services in all SAP. With SAP Converged Cloud, it is possible to deploy applications into data centers without needing to deploy a solution-specific infrastructure stack (the application infrastructure) beforehand.

The SAP Converged Cloud infrastructure landscape is hosted either in SAP SE owned data centers or co-location data centers, as detailed below:

DC LocationsDC Providers
USA: Ashburn, VACo-Location Provider
Netherlands: AmsterdamCo-Location Provider
USA: Colorado Springs, COSAP
Australia: SydneyCo-Location Provider
Canada: TorontoCo-Location Provider
United Arab Emirates: DubaiCo-Location Provider
USA: Chandler, AZCo-Location Provider
Saudi Arabia: DammamCo-Location Provider
Germany: FrankfurtCo-Location Provider
USA: Newtown Square, PASAP
Japan: OsakaCo-Location Provider
Saudi Arabia: RiyadhCo-Location Provider
Germany: St. Leon-RotSAP
China: ShanghaiCo-Location Provider
Brazil: São PauloCo-Location Provider
USA: Sterling, VACo-Location Provider
Japan: TokyoCo-Location Provider
Germany: WalldorfSAP

SAP Multi Cloud

 

The SAP Multi Cloud organization provides a ‘platform of enablement’ for Lines of Business (LoB) in the public cloud, providing costing services such as billing and cost optimization, architecture consultation and application design and security safeguards, tool engineering to automate and expand services offerings and hyperscaler operational support.

 

The SAP Multi Cloud infrastructure landscape is hosted either in SAP SE owned data centers or co-location data centers, as detailed below:

 

DC LocationsDC Providers
USA: N. VirginiaAWS
IrelandAWS
Canada: CentralAWS
SingaporeAWS
South Korea: SeoulAWS
Japan: OsakaAWS
France: ParisAWS
Sweden: StockholmAWS
China: BeijingAWS
USA: N. CaliforniaAWS
BahrainAWS
United Arab EmiratesAWS
Germany: FrankfurtAWS
SpainAWS
China: Hong KongAWS
Italy: MilanAWS
Indonesia: JakartaAWS
Israel: Tel AvivAWS
UK: LondonAWS
India: MumbaiAWS
China: NingxiaAWS
USA: OhioAWS
Brazil: São PauloAWS
South Africa: Cape TownAWS
Australia: SydneyAWS
Japan: TokyoAWS
India: HyderabadAWS
USA : CalgaryAWS
USA: OregonAWS
Australia: MelbourneAWS
Switzerland: ZurichAWS
Poland: WarsawAzure
USA: CaliforniaAzure
USA: VirginiaAzure
USA: VirginiaAzure
USA: IowaAzure
USA: IllinoisAzure
USA: TexasAzure
USA: West CentralAzure
USA: Quincy, WAAzure
USA: VirginiaAzure
USA: IowaAzure
USA: DoD EastAzure
USA: DoD CentralAzure
Canada: Quebec CityAzure
Canada: TorontoAzure
Brazil: São PauloAzure
USA: ArizonaAzure
USA: TexasAzure
Ireland: DublinAzure
Netherlands: AmsterdamAzure
Spain: MadridAzure
Germany: MagdeburgAzure
UK: CardiffAzure
UK: LondonAzure
France: ParisAzure
France: MarseilleAzure
SingaporeAzure
China: Hong KongAzure
Australia: New South WalesAzure
Australia: VictoriaAzure
China: ShanghaiAzure
China: BeijingAzure
India: PuneAzure
India: MumbaiAzure
India: ChennaiAzure
Japan: TokyoAzure
Mexico: QueretaroAzure
Japan: OsakaAzure
South Korea: SeoulAzure
South Korea: BusanAzure
South Africa: Cape TownAzure
South Africa: JohannesburgAzure
Australia: CanberraAzure
Australia: CanberraAzure
China: ShanghaiAzure
China: BeijingAzure
United Arab Emirates: Abu DhabiAzure
United Arab Emirates: DubaiAzure
Germany: NorthAzure
Germany: FrankfurtAzure
Switzerland: ZürichAzure
Switzerland: GenevaAzure
Norway: OsloAzure
Norway: StavangerAzure
Sweden: StaffanstorpAzure
Sweden: GävleAzure
Brazil: Rio de JaneiroAzure
Qatar: DohaAzure
USA: ArizonaAzure
China: HebeiAzure
China: JiangsuAzure
IsraelAzure
Italy: MilanAzure
Israel: Tel AvivGCP
USA: Council Bluffs, IAGCP
USA: The Dalles, ORGCP
USA: Ashburn, VAGCP
USA: Moncks Corner, SCGCP
Belgium: St. GhislainGCP
UK: LondonGCP
Singapore: Jurong WestGCP
Taiwan: Changhua CountyGCP
Japan: TokyoGCP
Australia: SydneyGCP
Germany: FrankfurtGCP
USA: Los Angeles, CAGCP
Canada: MontrealGCP
China: Hong KongGCP
India: MumbaiGCP
Finland: HaminaGCP
Netherlands: EemshavenGCP
Brazil: São PauloGCP
Japan: OsakaGCP
Switzerland: ZürichGCP
South Korea: SeoulGCP
Indonesia: JakartaGCP
USA: Salt Lake City, UTGCP
USA: Las Vegas, NVGCP
Poland: WarsawGCP
Australia: MelbourneGCP
India: DelhiGCP
Canada: TorontoGCP
Chile: SantiagoGCP
France: ParisGCP
Italy: MilanGCP
Spain: MadridGCP
USA: Columbus, OHGCP
USA: Dallas, TXGCP
Germany: BerlinGCP
Qatar: DohaGCP
South Africa: JohannesburgGCP
Italy: Turin  GCP

Other Data Center Services

 

SAP uses additional co-location data centers for physical security of SAP Cloud Services other than SAP Converged Cloud.

DC Locations

DC Providers

USA: Ashburn, VA

Raging Wire (NTT)

Ireland: Dublin 

Digital Realty

Germany: Frankfurt

Nippon Telegraph and Telephone Corporation

Malaysia: Selangor

Nippon Telegraph and Telephone Corporation

Malaysia: Kuala Lumpur

Nippon Telegraph and Telephone Corporation

Japan: Osaka

Nippon Telegraph and Telephone Corporation

USA: Sacramento, CA

Raging Wire (NTT)

USA: Santa Clara

Cologix 

Singapore

Nippon Telegraph and Telephone Corporation

SOC 1 reports are prepared pursuant to AT-C Section 320 and International Standard on Assurance Engagements No. 3402. SOC 1 reports are specifically intended to meet the needs of the entities that use service organizations (user entities) and the CPAs that audit the user entities’ financial statements (user auditors).  Please note that this examination's scope does not include the controls and related control objectives of any subservice organizations. SOC 1 Type 1 report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design of controls to achieve the related control objectives as of a specified date, whereas a SOC 1 Type 2 also includes the operating effectiveness of controls to achieve the related control objectives throughout a specified period.

 

SAP Cloud Infrastructure has regularly prepared SOC 1 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period 1. April 2024 to 30. September 2024.

 

The use of these reports is restricted to the management of the service organization, user entities, and user auditors. A copy of this report is available for all SAP Cloud Infrastructure customers who had productive and had financially-relevant systems during the audit period covered by the report.

SAP Cloud Infrastructure (SCI) spearheads SAP’s 4+1 strategy and supports the adoption and governance of all services deployed as part of SAP’s Cloud Infrastructure Strategy. Specifically, this refers to the management of public cloud hyperscalers and SAP’s internal IaaS known as SAP Converged Cloud.

 

SAP Converged Cloud

Converged Cloud is SAP’s standardized Infrastructure as a Service (IaaS) offering to support all of SAP’s cloud business on a global scale. SAP Converged Cloud provides access to a vendor-agnostic hardware infrastructure architecture as well as infrastructure orchestration and automation services in all SAP. With SAP Converged Cloud, it is possible to deploy applications into data centers without needing to deploy a solution-specific infrastructure stack (the application infrastructure) beforehand.

The SAP Converged Cloud infrastructure landscape is hosted either in SAP SE owned data centers or co-location data centers, as detailed below:

DC LocationsDC Providers
USA: Ashburn, VACo-Location Provider
Netherlands: AmsterdamCo-Location Provider
USA: Colorado Springs, COSAP
Australia: SydneyCo-Location Provider
Canada: TorontoCo-Location Provider
United Arab Emirates: DubaiCo-Location Provider
USA: Chandler, AZCo-Location Provider
Saudi Arabia: DammamCo-Location Provider
Germany: FrankfurtCo-Location Provider
USA: Newtown Square, PASAP
Japan: OsakaCo-Location Provider
Saudi Arabia: RiyadhCo-Location Provider
Germany: St. Leon-RotSAP
China: ShanghaiCo-Location Provider
Brazil: São PauloCo-Location Provider
USA: Sterling, VACo-Location Provider
Japan: TokyoCo-Location Provider
Germany: WalldorfSAP

SAP Multi Cloud

 

The SAP Multi Cloud organization provides a ‘platform of enablement’ for Lines of Business (LoB) in the public cloud, providing costing services such as billing and cost optimization, architecture consultation and application design and security safeguards, tool engineering to automate and expand services offerings and hyperscaler operational support.

 

The SAP Multi Cloud infrastructure landscape is hosted either in SAP SE owned data centers or co-location data centers, as detailed below:

 

DC LocationsDC Providers
USA: N. VirginiaAWS
IrelandAWS
Canada: CentralAWS
SingaporeAWS
South Korea: SeoulAWS
Japan: OsakaAWS
France: ParisAWS
Sweden: StockholmAWS
China: BeijingAWS
USA: N. CaliforniaAWS
BahrainAWS
United Arab EmiratesAWS
Germany: FrankfurtAWS
SpainAWS
China: Hong KongAWS
Italy: MilanAWS
Indonesia: JakartaAWS
Israel: Tel AvivAWS
UK: LondonAWS
India: MumbaiAWS
China: NingxiaAWS
USA: OhioAWS
Brazil: São PauloAWS
South Africa: Cape TownAWS
Australia: SydneyAWS
Japan: TokyoAWS
India: HyderabadAWS
USA : CalgaryAWS
USA: OregonAWS
Australia: MelbourneAWS
Switzerland: ZurichAWS
Poland: WarsawAzure
USA: CaliforniaAzure
USA: VirginiaAzure
USA: VirginiaAzure
USA: IowaAzure
USA: IllinoisAzure
USA: TexasAzure
USA: West CentralAzure
USA: Quincy, WAAzure
USA: VirginiaAzure
USA: IowaAzure
USA: DoD EastAzure
USA: DoD CentralAzure
Canada: Quebec CityAzure
Canada: TorontoAzure
Brazil: São PauloAzure
USA: ArizonaAzure
USA: TexasAzure
Ireland: DublinAzure
Netherlands: AmsterdamAzure
Spain: MadridAzure
Germany: MagdeburgAzure
UK: CardiffAzure
UK: LondonAzure
France: ParisAzure
France: MarseilleAzure
SingaporeAzure
China: Hong KongAzure
Australia: New South WalesAzure
Australia: VictoriaAzure
China: ShanghaiAzure
China: BeijingAzure
India: PuneAzure
India: MumbaiAzure
India: ChennaiAzure
Japan: TokyoAzure
Mexico: QueretaroAzure
Japan: OsakaAzure
South Korea: SeoulAzure
South Korea: BusanAzure
South Africa: Cape TownAzure
South Africa: JohannesburgAzure
Australia: CanberraAzure
Australia: CanberraAzure
China: ShanghaiAzure
China: BeijingAzure
United Arab Emirates: Abu DhabiAzure
United Arab Emirates: DubaiAzure
Germany: NorthAzure
Germany: FrankfurtAzure
Switzerland: ZürichAzure
Switzerland: GenevaAzure
Norway: OsloAzure
Norway: StavangerAzure
Sweden: StaffanstorpAzure
Sweden: GävleAzure
Brazil: Rio de JaneiroAzure
Qatar: DohaAzure
USA: ArizonaAzure
China: HebeiAzure
China: JiangsuAzure
IsraelAzure
Italy: MilanAzure
Israel: Tel AvivGCP
USA: Council Bluffs, IAGCP
USA: The Dalles, ORGCP
USA: Ashburn, VAGCP
USA: Moncks Corner, SCGCP
Belgium: St. GhislainGCP
UK: LondonGCP
Singapore: Jurong WestGCP
Taiwan: Changhua CountyGCP
Japan: TokyoGCP
Australia: SydneyGCP
Germany: FrankfurtGCP
USA: Los Angeles, CAGCP
Canada: MontrealGCP
China: Hong KongGCP
India: MumbaiGCP
Finland: HaminaGCP
Netherlands: EemshavenGCP
Brazil: São PauloGCP
Japan: OsakaGCP
Switzerland: ZürichGCP
South Korea: SeoulGCP
Indonesia: JakartaGCP
USA: Salt Lake City, UTGCP
USA: Las Vegas, NVGCP
Poland: WarsawGCP
Australia: MelbourneGCP
India: DelhiGCP
Canada: TorontoGCP
Chile: SantiagoGCP
France: ParisGCP
Italy: MilanGCP
Spain: MadridGCP
USA: Columbus, OHGCP
USA: Dallas, TXGCP
Germany: BerlinGCP
Qatar: DohaGCP
South Africa: JohannesburgGCP
Italy: Turin  GCP

Other Data Center Services

 

SAP uses additional co-location data centers for physical security of SAP Cloud Services other than SAP Converged Cloud.

DC Locations

DC Providers

USA: Ashburn, VA

Raging Wire (NTT)

Ireland: Dublin 

Digital Realty

Germany: Frankfurt

Nippon Telegraph and Telephone Corporation

Malaysia: Selangor

Nippon Telegraph and Telephone Corporation

Malaysia: Kuala Lumpur

Nippon Telegraph and Telephone Corporation

Japan: Osaka

Nippon Telegraph and Telephone Corporation

USA: Sacramento, CA

Raging Wire (NTT)

USA: Santa Clara

Cologix 

Singapore

Nippon Telegraph and Telephone Corporation

SOC 1 reports are prepared pursuant to AT-C Section 320 and International Standard on Assurance Engagements No. 3402. SOC 1 reports are specifically intended to meet the needs of the entities that use service organizations (user entities) and the CPAs that audit the user entities’ financial statements (user auditors).  Please note that this examination's scope does not include the controls and related control objectives of any subservice organizations. SOC 1 Type 1 report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design of controls to achieve the related control objectives as of a specified date, whereas a SOC 1 Type 2 also includes the operating effectiveness of controls to achieve the related control objectives throughout a specified period.

 

SAP Cloud Infrastructure has regularly prepared SOC 1 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period 1. April 2024 to 30. September 2024.

 

The use of these reports is restricted to the management of the service organization, user entities, and user auditors. A copy of this report is available for all SAP Cloud Infrastructure customers who had productive and had financially-relevant systems during the audit period covered by the report.