SAP Designated as a Critical ICT third-party Service Provider under DORA

We are pleased to inform you that SAP has been officially designated by the European Supervisory Authorities (ESAs) as a Critical ICT Third-Party Service Provider (CTPP) under the Digital Operational Resilience Act (DORA).This designation means that SAP plays a vital role in supporting the digital infrastructure of the financial sector and will now be subject to direct oversight by the ESAs to ensure robust operational resilience and risk management.For our financial customers, this enhances transparency and trust, as it ensures that SAP meets the highest standards of security, continuity, and compliance in delivering ICT services to the financial industry Scarica il documento

Bring out your best.Regulatory Update DORA | PUBLICSAP Designated as a Critical ICT third-partyService Provider under DORAA new era in Trust, Resilience and Regulatory Excellence.We are pleased to inform you that SAP has been officially designated by the European Supervisory Authorities(ESAs) as a Critical ICT Third-Party Service Provider (CTPP) under the Digital Operational Resilience Act (DORA).This designation means that SAP plays a vital role in supporting the digital infrastructure of the financial sector andwill now be subject to direct oversight by the ESAs to ensure robust operational resilience and risk management.For our financial customers, this enhances transparency and trust, as it ensures that SAP meets the higheststandards of security, continuity, and compliance in delivering ICT services to the financial industry..What this Means for our Customers:With DORA coming into full effect in January 2025,financial institutions across the EU must meet newrequirements designed to improve their ability towithstand and recover from ICT-related disruptions.SAP’s designation as a critical ICT provider brings ourfinancial services customers the added confidence ofknowledge that:o We meet elevated standards for incidentdetection, reporting and response, ensuringcontinuity and clarity during critical moments.o We maintain internationally recognizedsecurity certifications including ISO 27001,SOC 2, ISO 22301, and PCI DSS with a focus oncontinuous improvement and regulatoryalignment .o We are directly overseen by Europeansupervisory authorities with enhanced scrutinyof our operational resilience, security, and riskmanagement.o Our contractual commitments are aligned withArticle 30 of DORA, supporting our customers'compliance obligations, including audit rights,subcontracting transparency, and exitstrategies.Our Continued Commitment:At SAP, we welcome regulatory initiatives like DORA,NIS2 and the RCE (Directive on the Resilience of CriticalEntities) that elevate resilience standards for Europe’sCritical infrastructure and essential and importantentities. These efforts are championed by ourSovereign Services and Delivery Unit and the SAPGlobal Security & Cloud Compliance team, who areworking to ensure that SAP continues to meet andexceed evolving expectations.Being designated as a Critical ICT Third-Party ServiceProvider is a regulatory classification made by the EUregulator. This puts SAP under central EU regulatorysupervision, which reduces the need for separatecustomer audits and simplifies customers’ own riskassessments providing additional assurance that SAP isregularly audited and kept in check by an independentauthority.(25/12) © 2025 SAP SE or an SAP affiliate company. All rights reserved.See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material