SAP Fieldglass Cloud Computing Compliance Criteria Catalog (C5:2020) Audit Report 2025

​Please Note: Starting from 2025 H1, SAP will release new SOC 1, SOC 2 and C5 audit reports called “SAP Central Cloud Services” comprising of SAP Cloud Services (IaaS, PaaS, SaaS) and SAP central services. Customers will automatically receive a copy of this audit report in addition to the requested report(s) to assess relevant controls of the internal subservice organization “SAP Central Cloud Services” as outlined in Section III.

​Learn More: Digital Resources & Enablement

SAP Fieldglass provides a cloud-based Vendor Management System (VMS) to manage services procurement and external workforce programs. Hundreds of global businesses leverage our industry-leading technology to gain visibility into their external labor, project-based services including Statements of Work (SOWs), independent contractors, and additional flexible talent pools.

 

The scope of this report covers the following data center locations:

  • Germany: St. Leon-Rot

  • Netherlands: Amsterdam

  • Saudi Arabia: Dammam

  • Saudi Arabia: Riyadh

  • USA: Colorado Springs, CO

  • USA: Sterling, VA

Google Cloud Platform

  • USA: Iowa

  • USA: South Carolina

Microsoft Azure

  • Australia: New South Wales

  • Australia: Victoria

  • Ireland: Dublin

  • Netherlands: Amsterdam

  • United Arab Emirates: Abu Dhabi

  • United Arab Emirates: Dubai

  • USA: Iowa

  • USA: Virginia

Cloud Computing Compliance Controls Catalogue (C5) reports are prepared in accordance with attestation standards established by the American Institute of Certified Public Accountants (“AICPA”) and in accordance with the International Standard on Assurance Engagements (“ISAE”) 3000 Revised, Assurance Engamenets Other than Audits or Reviews of Historical Financial Information, issued by the International Auditing and Assurance Board (IAASB). C5 outlines minimum security for cloud computing, aimed at cloud providers, auditors, and clients. Introduced in 2016, it helps customers choose a secure cloud provider and tailor a risk management system. C5 assures cloud services security by providing transparency via a standardized examination and reporting system. The 2020 version of C5 includes 125 criteria from 17 areas, based on national and international standards and publications.

 

SAP Fieldglass has regularly prepared C5 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period 1. April 2024 to 31. March 2025.

 

The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with non-disclosure agreement in place.