Compliance offerings from SAP

Explore our certificates, reports, and attestations.
Woman looking at her coworker.
NEW
EU AI Act Governance for Joule Agents

Learn how SAP governs its AI Agents — specifically Joule Agents — and how that governance framework addresses auditability, regulatory compliance, and human oversight under the EU AI Act.

Learn more
NEW
SOC & C5 Performance Calendar FY2025-2026

SAP is committed to timely and transparent reporting. SOC 1 reports are targeted for publication within 90 days after each performance period. SOC 2 reports follow a 12-month audit cycle, with the next release scheduled for the first half of 2026. For any questions, your account executive or customer success partner is ready to assist.

Sign in to My Trust Center to learn more
NEW
ISO/IEC 42001 for AI management systems

SAP has achieved certification for ISO/IEC 42001, the first global standard for AI management systems. This reflects our implementation of a structured, independently audited AI management system.

Learn more

How our compliance offerings support our customers’ business needs

placeholder

SAP is committed to prioritizing compliance through precise standards and practices that guarantee data integrity, regulatory adherence, and ethical conduct across our customers’ operations.

Compliance documents on demand

The SAP for Me customer portal is the central access point and the go-to destination for existing SAP customers to download eligible compliance documents on demand. The feature is available in the Portfolio & Products section of SAP for Me.

Access SAP for Me
SAP Central Cloud Services Reports

SAP will release new SOC 1, SOC 2, and C5 reports as SAP Central Cloud Services. These reports replace the previous SOC 1 SAP Business Technology Platform, SAP Cloud Infrastructure, and SAP Cell and Gene Therapy Orchestration and SAP Intelligent Clinical Supply Management reports.

Learn more
Controlled Goods Program (CGP)

SAP Canada Inc.’s registration in Canada’s Controlled Goods Program strengthens our commitment to national security and compliance with Canadian regulations. By meeting strict requirements for handling sensitive goods and technical data, SAP helps customers confidently manage controlled goods projects in a secure and trusted environment.

Learn more

SAP global compliance offerings

SAP builds its security foundation on global standards and compliance to meet evolving challenges. Explore our latest certifications, reports, and attestations for trusted assurance.

ISO/IEC 42001 AI management system

ISO 42001 sets audit requirements for responsible AI governance across policies, risk management, deployment, monitoring, and continuous improvement. it supports transparency, human oversight, security, privacy, and customers’ regulatory needs.

ISO 9001 Quality Management System

ISO 9001 is based on quality management principles (such as strong customer focus) that involve top SAP management.

ISO 27001 Security Management System

ISO/IEC 27001 provides a holistic, risked-based approach to security and a comprehensive and measurable set of information security management practices.

BS 10012 Personal Information Management System

BS 10012 includes employee security awareness training, risk assessments, data retention, and disposal.

ISO 27018 Code of Practice for Personally Identifiable information

ISO/IEC 27018 sets guidance for cloud service providers to protect personally identifiable information. It also supports ISO 27001 by recommending information security controls for protecting personal data in the public cloud.

ISO 27017 Code of Practice for Cloud Service Information Security

ISO/IEC 27001 provides information security controls for cloud services. It also supports ISO 27001 by providing guidance on cloud-specific information security controls.

Sustainability ISO 14001 and ISO 50001

A multisite certificate confirms that SAP’s environmental management system complies with the international ISO 14001:2015 standard. The appendix for this certificate includes all certified sites covered by SAP's environmental management system. At some sites we have a ISO50001:2018 certification, ensuring we are in line with energy management standards.

ISO 22301 Business Continuity Management System

Protects business operations from severe disruption, such as extreme weather, fire, natural disaster, theft, IT outage, and more.

SAP regional compliance offerings

UNITED STATES

Cybersecurity Maturity Model Certification (CMMC)

The Cybersecurity Maturity Model Certification (CMMC) framework is a U.S. Department of Defense (DoD) cybersecurity certification program for organizations that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). SAP is committed to supporting customers in understanding how SAP products and environments may be relevant to their CMMC compliance journey. Scenarios involving Controlled Unclassified Information (CUI), typically associated with CMMC Level 2 and Level 3 requirements, are currently supported only through SAP NS2 environments. Customers remain responsible for determining their own CMMC scope, implementing required controls, and obtaining applicable certification or assessment.

UNITED STATES

Federal Risk and Authorization Management Program (FedRAMP)

For government agencies, security is at the heart of every IT project. FedRAMP provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

CANADA

Canadian Cloud Compliance

SAP cloud services have been assessed by the Government of Canada against the Protected B/Medium Integrity/Medium Availability (PBMM) security control profile. SAP Sovereign Cloud for Canada has also been assessed against the Protected B High Value Asset (PBHVA) overlay. Additionally, SAP Canada Inc. is registered under Canada’s Controlled Goods Program (CGP), as required by Canadian regulations. Customers can verify our registration in the public CGP registry and request copies of our certificate and Canadian Centre for Cyber Security (CCCS) Cloud Assessment Summary Reports.

Compliance resources

placeholder

Ethics and compliance at SAP

By doing business the right way, in accordance with our Global Code of Ethics and Business Conduct, SAP positively impacts social and economic development, furthering education, justice, democracy, prosperity, development, and health worldwide.

Compliance frequently asked questions

SAP has held an ISO 9001 certificate since 1998. We’re also certified according to ISO 27001, ISO 22301, and BS 10012. All locations worldwide work according to one common process framework, including data security and privacy regulations. We regularly check compliance though internal reviews and audits.

It specifies a framework for implementing a personal information management system in compliance with the General Data Protection Regulation and mandates the implementation of such a system within corporate security programs. It describes a framework to manage the privacy of personal data and implement necessary policies, procedures, and controls to help ensure compliance with the GDPR.

The SOC 1 report covers all live customer systems during the audit cycle. It provides information about controls at a service-organization level that is relevant to the customer's internal control over financial reporting, known as IT general controls.

 

IT general controls cover:

  • IT strategy

  • Environment and organization

  • Logical and physical systems

  • Access controls

  • Program development

  • Change management

  • Computer operations such as incident management, backup, and monitoring

The SOC 2 report provides the management of a service organization, customers, and others with a report about the controls of a service organization that is relevant to the security, availability, and processing integrity of its system and the confidentiality and privacy of the data processed by that system.

 

While security is always assessed in each SOC 2 report, management may decide to scope in other trust services criteria: confidentiality, integrity, availability, and privacy.

Our current certification portfolio includes:

  • BSI C5 (Cloud Computing Compliance Controls Catalogs)

  • CSA STAR (Cloud Security Alliance Security Trust Assurance and Risk)

  • ISO 22301 (Business Continuity Management)

  • ISO/IEC 27001 (Information Security Management System)

  • ISO/IEC 27017 (Code of practice for Cloud service information security)

  • ISO/IEC 27018 (Code of practice for Personally identifiable information in public clouds)

  • ISO 9001 (Quality management systems)

  • PCI DSS (Payment Card Industry Data Security Standard)

  • SOC 1 and SOC 2 (System and Organization Controls) reports

  • TISAX (Trusted Information Security Assessment Exchange)

Bridge letters, also known as gap letters, are intended to cover the gap between the end date of the referenced report and the issue date of the bridge letter. Bridge letters provide customers with information as to whether there have been any significant changes to their controls environment that could adversely impact the conclusions reached in the most recently completed SOC report.

 

Find SOC 1 and SOC 2 bridge letters on SAP Trust Center.

The EU AI Act is a comprehensive new law designed to address potential risks to health, safety, and fundamental rights from the development and use of artificial intelligence technologies.

twitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixel