SAP Enterprise Cloud Services SOC 2 Audit Report 2024 H1

The scope of this SOC report includes:

  • RISE with SAP S/4HANA Cloud, Private Edition

  • RISE with SAP S/4HANA Cloud, Private Cloud, Tailored Option

  • SAP HANA Enterprise Cloud Credit & Overage, Advanced Edition (BYOL)

as well as passive, renewals only options:

  • SAP S/4 HANA Cloud, Extended Edition

This offering has the following predecessors:

  • STE (Single Tenant Edition)  

  • CPO (Cloud Private Option) 

  • CPE (Cloud Private Edition) 

  • SAP Credit & Overage HANA Enterprise Cloud Advanced Edition (Subscription) 

  • SAP HANA Enterprise Cloud Advanced Edition (Subscription) 

  • SAP HANA Enterprise Cloud Classic (Subscription and BYOL)

Services are offered on SAP infrastructure, Amazon Web Services, Microsoft Azure or Google Cloud Platform.  A detailed list of locations of the data centers are available within the report. RISE with SAP S/4 HANA Cloud, Private Edition, Private Cloud, Tailored Option, as well as the predecessors, SAP S/4 HANA Cloud Extended Edition, SAP HANA Enterprise Cloud Advanced Edition, SAP HANA Enterprise Classic and SAP Credit & Overage HANA Enterprise Cloud Advanced Edition are fully scalable and secure private managed cloud solutions available only from SAP. It empowers organizations to unlock the full value of SAP Enterprise Cloud Services in the cloud — accelerating growth and innovation, driving IT and business transformation, quickly delivering business outcomes, and reducing risk. SAP S/4 HANA Cloud, Extended Edition Service is using the SAP Enterprise Cloud Services architecture and processes but includes also specific SAP products, use rights and services.

 

The SAP Enterprise Cloud Services reference architecture helps the customer to use flexible services for modular and rapid deployment.  SAP ECS is offered in the primary data center locations:

DC Locations

DC Providers

Rot, Germany

SAP

Amsterdam, Netherlands

Co-Location Provider

Sterling, USA

Co-Location Provider

Santa Clara, USA

Co-Locatin Provider

Tokyo, Japan

Co-Location Provider

Osaka, Japan

Co-Location Provider

Sydney, Australia

Co-Location Provider

Waldorf, Germany

SAP

Toronto, Canada

Co-Location Provider

Frankfurt, Germany

Co-Location

Ashburn, USA

Co-Location

Colorado, USA

SAP

US East (N. Virginia)

AWS

EU (Ireland)

AWS

Canada (Montreal)

AWS

Asia Pacific (Singapore)

AWS

Asia Pacific (Seoul)

AWS

Asia Pacific (Osaka)

AWS

EU (Paris)

AWS

EU (Stockholm)

AWS

Beijing

AWS

Middle East (Bahrain)

AWS

Middle East (UAE)

AWS

EU (Frankfurt)

AWS

EU (Spain)

AWS

Asia Pacific (Hong Kong)

AWS

EU (Milan)

AWS

Asia Pacific (Jakarta)

AWS

EU (London)

AWS

Asia Pacific (Mumbai)

AWS

Ningxia

AWS

US East (Ohio)

AWS

South America (Sao Paulo)

AWS

Africa (Cape Town)

AWS

Asia Pacific (Sydney)

AWS

Asia Pacific (Tokyo)

AWS

Asia Pacific (Hyderabad)

AWS

US West (Oregon)

AWS

Asia Pacific (Melbourne)

AWS

AWS Zurich

AWS

China East 2 (Shanghai)

Azure

China East 3 (Jiangsu)

Azure

China North 3 (Hebei)

Azure

Japan East (Tokyo)

Azure

East Asia (Hong Kong)

Azure

Korea South (Busan)

Azure

South India (Chennai)

Azure

Australia East (Sydney)

Azure

Australia Central (Canberra)

Azure

Southeast Asia (Singapore)

Azure

Japan West (Osaka)

Azure

Central India (Pune)

Azure

Korea Central (Seoul)

Azure

Australia SouthEast (Victoria)

Azure

Brazil South (Sao Paulo)

Azure

West US 2 (Washington)

Azure

Canada Central (Toronto)

Azure

NA West US 3 (Arizona)

Azure

East US (Virginia)

Azure

East US2 (Virginia)

Azure

South Central US (Texas)

Azure

Canada East (Quebec City)

Azure

West Europe (Amsterdam)

Azure

UK South (London)

Azure

Switzerland North (Zurich)

Azure

Germany Central (Frankfurt)

Azure

South Africa North (Johannesburg)

Azure

AE Central (Abu Dhabi)

Azure

Norway East (Oslo)

Azure

Qatar Central (Doha)

Azure

Sweden Central (Gävle)

Azure

North Europe (Dublin)

Azure

UK West (Cardiff)

Azure

Switzerland West (Geneva)

Azure

South Africa West (Cape Town)

Azure

Germany North (Berlin)

Azure

UAE North (Dubai)

Azure

France Central (Paris)

Azure

Belgium, West Europe-1

GCP

London, West Europe-2

GCP

Zürich, Switzerland - West Europe-6

GCP

Paris, Europe-west9

GCP

Madrid, Europe-southwest1

GCP

Frankfurt, West Europe-3

GCP

Netherlands, West Europe-4

GCP

Finland, North Europe-1

GCP

Warsaw, Poland, Europe-Central-2

GCP

Milan, Europe-west8

GCP

Israel, Tel Aviv

GCP

Iowa, US Central-1

GCP

Northern Virginia, US East-4

GCP

Salt Lake City, US-west3

GCP

Montréal, Northamerica-northeast1

GCP

Santiago, Southamerica-west1

GCP

Columbus, US-east5

GCP

Oregon, US West-1

GCP

South Carolina, US East-1

GCP

Los Angeles, US West-2

GCP

Las Vegas, US west-4

GCP

Toronto, Northamerica-northeast2

GCP

Dallas, US-south1

GCP

Sao Paulo, Southamerica East-1

GCP

Singapore, Southeast Asia

GCP

Osaka, Asia-northeast2

GCP

Finland, North Europe-1

GCP

Israel, Tel Aviv

GCP

Iowa, US Central-1

GCP

Northern Virginia, US East-4

GCP

Montréal, Northamerica-northeast1

GCP

Oregon, US West-1

GCP

South Carolina, US East-1

GCP

Los Angeles, US West-2

GCP

Singapore, Southeast Asia

GCP

Osaka, Asia-northeast2

GCP

Mumbai, Asia-South1

GCP

Delhi, Asia-south2

GCP

Sydney, Australia-Southeast-1

GCP

Melbourne, Australia-southeast2

GCP

Jakarta, Indonesia, Asia-southeast2

GCP

Tokyo, Asia-Northeast-1

GCP

Hong Kong, Asia-East2

GCP

Taiwan, Asia-East-1

GCP

Seoul, South Korea, Asia-northeast3

GCP

Turni, West Europe -12

GCP

Doha -ME Central - 1

GCP

SOC 2 reports are prepared in accordance with AT-C Section 205, Examination Engagements under Statement on Standards for Attestation Engagements (SSAE) No. 18, Attestation Standards: Clarification and Recodification.  SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria).  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  Please note that this examination's scope does not include the controls of any subservice organizations.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.

 

SAP Enterprise Cloud Services has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2023 to 31. March 2024, and the trust principles Security, Availability, Confidentiality, and Privacy.

The scope of this SOC report includes:

  • RISE with SAP S/4HANA Cloud, Private Edition

  • RISE with SAP S/4HANA Cloud, Private Cloud, Tailored Option

  • SAP HANA Enterprise Cloud Credit & Overage, Advanced Edition (BYOL)

as well as passive, renewals only options:

  • SAP S/4 HANA Cloud, Extended Edition

This offering has the following predecessors:

  • STE (Single Tenant Edition)  

  • CPO (Cloud Private Option) 

  • CPE (Cloud Private Edition) 

  • SAP Credit & Overage HANA Enterprise Cloud Advanced Edition (Subscription) 

  • SAP HANA Enterprise Cloud Advanced Edition (Subscription) 

  • SAP HANA Enterprise Cloud Classic (Subscription and BYOL)

Services are offered on SAP infrastructure, Amazon Web Services, Microsoft Azure or Google Cloud Platform.  A detailed list of locations of the data centers are available within the report. RISE with SAP S/4 HANA Cloud, Private Edition, Private Cloud, Tailored Option, as well as the predecessors, SAP S/4 HANA Cloud Extended Edition, SAP HANA Enterprise Cloud Advanced Edition, SAP HANA Enterprise Classic and SAP Credit & Overage HANA Enterprise Cloud Advanced Edition are fully scalable and secure private managed cloud solutions available only from SAP. It empowers organizations to unlock the full value of SAP Enterprise Cloud Services in the cloud — accelerating growth and innovation, driving IT and business transformation, quickly delivering business outcomes, and reducing risk. SAP S/4 HANA Cloud, Extended Edition Service is using the SAP Enterprise Cloud Services architecture and processes but includes also specific SAP products, use rights and services.

 

The SAP Enterprise Cloud Services reference architecture helps the customer to use flexible services for modular and rapid deployment.  SAP ECS is offered in the primary data center locations:

DC Locations

DC Providers

Rot, Germany

SAP

Amsterdam, Netherlands

Co-Location Provider

Sterling, USA

Co-Location Provider

Santa Clara, USA

Co-Locatin Provider

Tokyo, Japan

Co-Location Provider

Osaka, Japan

Co-Location Provider

Sydney, Australia

Co-Location Provider

Waldorf, Germany

SAP

Toronto, Canada

Co-Location Provider

Frankfurt, Germany

Co-Location

Ashburn, USA

Co-Location

Colorado, USA

SAP

US East (N. Virginia)

AWS

EU (Ireland)

AWS

Canada (Montreal)

AWS

Asia Pacific (Singapore)

AWS

Asia Pacific (Seoul)

AWS

Asia Pacific (Osaka)

AWS

EU (Paris)

AWS

EU (Stockholm)

AWS

Beijing

AWS

Middle East (Bahrain)

AWS

Middle East (UAE)

AWS

EU (Frankfurt)

AWS

EU (Spain)

AWS

Asia Pacific (Hong Kong)

AWS

EU (Milan)

AWS

Asia Pacific (Jakarta)

AWS

EU (London)

AWS

Asia Pacific (Mumbai)

AWS

Ningxia

AWS

US East (Ohio)

AWS

South America (Sao Paulo)

AWS

Africa (Cape Town)

AWS

Asia Pacific (Sydney)

AWS

Asia Pacific (Tokyo)

AWS

Asia Pacific (Hyderabad)

AWS

US West (Oregon)

AWS

Asia Pacific (Melbourne)

AWS

AWS Zurich

AWS

China East 2 (Shanghai)

Azure

China East 3 (Jiangsu)

Azure

China North 3 (Hebei)

Azure

Japan East (Tokyo)

Azure

East Asia (Hong Kong)

Azure

Korea South (Busan)

Azure

South India (Chennai)

Azure

Australia East (Sydney)

Azure

Australia Central (Canberra)

Azure

Southeast Asia (Singapore)

Azure

Japan West (Osaka)

Azure

Central India (Pune)

Azure

Korea Central (Seoul)

Azure

Australia SouthEast (Victoria)

Azure

Brazil South (Sao Paulo)

Azure

West US 2 (Washington)

Azure

Canada Central (Toronto)

Azure

NA West US 3 (Arizona)

Azure

East US (Virginia)

Azure

East US2 (Virginia)

Azure

South Central US (Texas)

Azure

Canada East (Quebec City)

Azure

West Europe (Amsterdam)

Azure

UK South (London)

Azure

Switzerland North (Zurich)

Azure

Germany Central (Frankfurt)

Azure

South Africa North (Johannesburg)

Azure

AE Central (Abu Dhabi)

Azure

Norway East (Oslo)

Azure

Qatar Central (Doha)

Azure

Sweden Central (Gävle)

Azure

North Europe (Dublin)

Azure

UK West (Cardiff)

Azure

Switzerland West (Geneva)

Azure

South Africa West (Cape Town)

Azure

Germany North (Berlin)

Azure

UAE North (Dubai)

Azure

France Central (Paris)

Azure

Belgium, West Europe-1

GCP

London, West Europe-2

GCP

Zürich, Switzerland - West Europe-6

GCP

Paris, Europe-west9

GCP

Madrid, Europe-southwest1

GCP

Frankfurt, West Europe-3

GCP

Netherlands, West Europe-4

GCP

Finland, North Europe-1

GCP

Warsaw, Poland, Europe-Central-2

GCP

Milan, Europe-west8

GCP

Israel, Tel Aviv

GCP

Iowa, US Central-1

GCP

Northern Virginia, US East-4

GCP

Salt Lake City, US-west3

GCP

Montréal, Northamerica-northeast1

GCP

Santiago, Southamerica-west1

GCP

Columbus, US-east5

GCP

Oregon, US West-1

GCP

South Carolina, US East-1

GCP

Los Angeles, US West-2

GCP

Las Vegas, US west-4

GCP

Toronto, Northamerica-northeast2

GCP

Dallas, US-south1

GCP

Sao Paulo, Southamerica East-1

GCP

Singapore, Southeast Asia

GCP

Osaka, Asia-northeast2

GCP

Finland, North Europe-1

GCP

Israel, Tel Aviv

GCP

Iowa, US Central-1

GCP

Northern Virginia, US East-4

GCP

Montréal, Northamerica-northeast1

GCP

Oregon, US West-1

GCP

South Carolina, US East-1

GCP

Los Angeles, US West-2

GCP

Singapore, Southeast Asia

GCP

Osaka, Asia-northeast2

GCP

Mumbai, Asia-South1

GCP

Delhi, Asia-south2

GCP

Sydney, Australia-Southeast-1

GCP

Melbourne, Australia-southeast2

GCP

Jakarta, Indonesia, Asia-southeast2

GCP

Tokyo, Asia-Northeast-1

GCP

Hong Kong, Asia-East2

GCP

Taiwan, Asia-East-1

GCP

Seoul, South Korea, Asia-northeast3

GCP

Turni, West Europe -12

GCP

Doha -ME Central - 1

GCP

SOC 2 reports are prepared in accordance with AT-C Section 205, Examination Engagements under Statement on Standards for Attestation Engagements (SSAE) No. 18, Attestation Standards: Clarification and Recodification.  SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria).  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  Please note that this examination's scope does not include the controls of any subservice organizations.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.

 

SAP Enterprise Cloud Services has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2023 to 31. March 2024, and the trust principles Security, Availability, Confidentiality, and Privacy.