Third Party Security Annex FAQ
This document should be available on the supplier portal to help suppliers navigate through the Third Party Security Annex (TPSA). Скачать документ
PUBLIC
SAP Third-Party Security Annex
FAQs
SAP Third-Party Security Annex
FAQs
© 2024 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2 / 2
What is the TPSA?
The TPSA (Third Party Security Annex), formerly known as the SSSA, is a contract which sets the security
measures to be implemented by third parties who will, during their association with SAP, have access to
internal or confidential information from SAP and/or SAP customers, develop software to be used by SAP or
SAP Customers or, be relevant from a Business Continuity perspective.
What is the scope of the TPSA?
The TPSA has in scope IT assets and security processes used by a Third Party to provide services/products
to SAP or SAP Customers.
Should a Third Party sign a TPSA per service?
No. The TPSA is not service/product specific, there is just one TPSA per supplier which covers all
services/products that a Third Party provides to SAP or SAP Customers.
What is there any cadence to sign the TPSA?
The TPSA is signed just once.
Some sections of the TPSA are not relevant to the service provided, now what?
Some sections could not be applicable to the current service(s) that a Third Party provides to SAP or SAP
Customers however, they could be in the future, and this is the reason why the document is non-negotiable
and non-adjustable, with rare outstanding exceptions.
Should the Third Party implement all security measures listed in the TPSA?
No, just those security measures relevant/applicable to the service/product provided. SAP won’t ask for
evidence of security measures that are not applicable.
What is the TPSA?
The TPSA (Third Party Security Annex), formerly known as the SSSA, is a contract which sets the security
measures to be implemented by third parties who will, during their association with SAP, have access to
internal or confidential information from SAP and/or SAP customers, develop software to be used by SAP or
SAP Customers or, be relevant from a Business Continuity perspective.
What is the scope of the TPSA?
The TPSA has in scope IT assets and security processes used by a Third Party to provide services/products
to SAP or SAP Customers.
Should a Third Party sign a TPSA per service?
No. The TPSA is not service/product specific, there is just one TPSA per supplier which covers all
services/products that a Third Party provides to SAP or SAP Customers.
What is there any cadence to sign the TPSA?
The TPSA is signed just once.
Some sections of the TPSA are not relevant to the service provided, now what?
Some sections could not be applicable to the current service(s) that a Third Party provides to SAP or SAP
Customers however, they could be in the future, and this is the reason why the document is non-negotiable
and non-adjustable, with rare outstanding exceptions.
Should the Third Party implement all security measures listed in the TPSA?
No, just those security measures relevant/applicable to the service/product provided. SAP won’t ask for
evidence of security measures that are not applicable.