SAP Designated as a Critical ICT third-party Service Provider under DORA
Bring out your best.
Regulatory Update DORA | PUBLIC
SAP Designated as a Critical ICT third-party
Service Provider under DORA
A new era in Trust, Resilience and Regulatory Excellence.
We are pleased to inform you that SAP has been officially designated by the European Supervisory Authorities
(ESAs) as a Critical ICT Third-Party Service Provider (CTPP) under the Digital Operational Resilience Act (DORA).
This designation means that SAP plays a vital role in supporting the digital infrastructure of the financial sector and
will now be subject to direct oversight by the ESAs to ensure robust operational resilience and risk management.
For our financial customers, this enhances transparency and trust, as it ensures that SAP meets the highest
standards of security, continuity, and compliance in delivering ICT services to the financial industry.
.
What this Means for our Customers:
With DORA coming into full effect in January 2025,
financial institutions across the EU must meet new
requirements designed to improve their ability to
withstand and recover from ICT-related disruptions.
SAP’s designation as a critical ICT provider brings our
financial services customers the added confidence of
knowledge that:
o We meet elevated standards for incident
detection, reporting and response, ensuring
continuity and clarity during critical moments.
o We maintain internationally recognized
security certifications including ISO 27001,
SOC 2, ISO 22301, and PCI DSS with a focus on
continuous improvement and regulatory
alignment .
o We are directly overseen by European
supervisory authorities with enhanced scrutiny
of our operational resilience, security, and risk
management.
o Our contractual commitments are aligned with
Article 30 of DORA, supporting our customers'
compliance obligations, including audit rights,
subcontracting transparency, and exit
strategies.
Our Continued Commitment:
At SAP, we welcome regulatory initiatives like DORA,
NIS2 and the RCE (Directive on the Resilience of Critical
Entities) that elevate resilience standards for Europe’s
Critical infrastructure and essential and important
entities. These efforts are championed by our
Sovereign Services and Delivery Unit and the SAP
Global Security & Cloud Compliance team, who are
working to ensure that SAP continues to meet and
exceed evolving expectations.
Being designated as a Critical ICT Third-Party Service
Provider is a regulatory classification made by the EU
regulator. This puts SAP under central EU regulatory
supervision, which reduces the need for separate
customer audits and simplifies customers’ own risk
assessments providing additional assurance that SAP is
regularly audited and kept in check by an independent
authority.
(25/12) © 2025 SAP SE or an SAP affiliate company. All rights reserved.
See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material
Regulatory Update DORA | PUBLIC
SAP Designated as a Critical ICT third-party
Service Provider under DORA
A new era in Trust, Resilience and Regulatory Excellence.
We are pleased to inform you that SAP has been officially designated by the European Supervisory Authorities
(ESAs) as a Critical ICT Third-Party Service Provider (CTPP) under the Digital Operational Resilience Act (DORA).
This designation means that SAP plays a vital role in supporting the digital infrastructure of the financial sector and
will now be subject to direct oversight by the ESAs to ensure robust operational resilience and risk management.
For our financial customers, this enhances transparency and trust, as it ensures that SAP meets the highest
standards of security, continuity, and compliance in delivering ICT services to the financial industry.
.
What this Means for our Customers:
With DORA coming into full effect in January 2025,
financial institutions across the EU must meet new
requirements designed to improve their ability to
withstand and recover from ICT-related disruptions.
SAP’s designation as a critical ICT provider brings our
financial services customers the added confidence of
knowledge that:
o We meet elevated standards for incident
detection, reporting and response, ensuring
continuity and clarity during critical moments.
o We maintain internationally recognized
security certifications including ISO 27001,
SOC 2, ISO 22301, and PCI DSS with a focus on
continuous improvement and regulatory
alignment .
o We are directly overseen by European
supervisory authorities with enhanced scrutiny
of our operational resilience, security, and risk
management.
o Our contractual commitments are aligned with
Article 30 of DORA, supporting our customers'
compliance obligations, including audit rights,
subcontracting transparency, and exit
strategies.
Our Continued Commitment:
At SAP, we welcome regulatory initiatives like DORA,
NIS2 and the RCE (Directive on the Resilience of Critical
Entities) that elevate resilience standards for Europe’s
Critical infrastructure and essential and important
entities. These efforts are championed by our
Sovereign Services and Delivery Unit and the SAP
Global Security & Cloud Compliance team, who are
working to ensure that SAP continues to meet and
exceed evolving expectations.
Being designated as a Critical ICT Third-Party Service
Provider is a regulatory classification made by the EU
regulator. This puts SAP under central EU regulatory
supervision, which reduces the need for separate
customer audits and simplifies customers’ own risk
assessments providing additional assurance that SAP is
regularly audited and kept in check by an independent
authority.
(25/12) © 2025 SAP SE or an SAP affiliate company. All rights reserved.
See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material