SAP Business Technology Platform SOC 2 (ISAE 3000) Audit Report 2023 H1

SAP Business Technology Platform (SAP BTP) is a technology platform that brings together application development, data and analytics, integration, automation, and AI capabilities in one unified environment. The platform offers users the ability to turn data into business value, compose end-to-end business processes, and build and extend SAP applications.

The services and solutions of SAP BTP are available on multiple cloud infrastructure providers. The multi-cloud foundation supports different environments, such as Cloud Foundry, ABAP, Kyma, and Neo, as well as multiple different regions and a broad choice of programming languages.

The SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems that are used to process users’ data and the confidentiality and privacy of the information processed by these systems.  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.


SAP Business Technology Platform has regularly prepared SOC 2 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period October 1, 2022 to March 31, 2023, and the trust principles Security, Availability, and Confidentiality.


The following locations and their IaaS provider are covered:

SAP BTP Region Name Infrastructure Provider 
UAE (Dubai) SAP 
Australia (Sydney) SAP 
China (Shanghai) SAP 
Japan (Tokyo) SAP 
Japan (Osaka) SAP 
KSA (Riyadh) SAP 
KSA (Dammam) SAP 
Europe (Rot) SAP 
Europe (Frankfurt) SAP 
Europe (Amsterdam) SAP 
Brazil (Sao Paulo) SAP 
Canada (Toronto) SAP 
US East (Ashburn) SAP 
US East (Sterling) SAP 
US West (Colorado Springs) SAP 
US West (Chandler) SAP 
US East (VA) Amazon Web Services (AWS) 
Canada (Montreal) Amazon Web Services (AWS) 
SingaporeAmazon Web Services (AWS) 
South Korea (Seoul) Amazon Web Services (AWS) 
Europe (Frankfurt) Amazon Web Services (AWS) 
India (Mumbai) Amazon Web Services (AWS) 
Brazil (São Paulo) Amazon Web Services (AWS) 
Australia (Sydney) Amazon Web Services (AWS) 
Japan (Tokyo) Amazon Web Services (AWS) 
US West (Oregon) Amazon Web Services (AWS) 
US East (VA) Microsoft Azure (Azure) 
US West (WA) Microsoft Azure (Azure) 
Canada (Toronto) Microsoft Azure (Azure) 
Europe (Netherlands) Microsoft Azure (Azure) 
Singapore Microsoft Azure (Azure) 
Australia (Sydney) Microsoft Azure (Azure) 
Japan (Tokyo) Microsoft Azure (Azure) 
UAE North (Dubai) Microsoft Azure (Azure) 
Switzerland (Zurich) Microsoft Azure (Azure) 
US Central (IA) Google Cloud Platform (GCP) 
Europe (Frankfurt) Google Cloud Platform (GCP) 
India (Mumbai) Google Cloud Platform (GCP) 

SAP BTP SOC2 Type 2 report covers within audit period the following services:

  • SAP BTP runtime:
    - SAP BTP, Neo runtime
    - SAP BTP, Cloud Foundry runtime
    - SAP BTP, Kyma runtime

  • SAP BTP, ABAP environment

  • SAP AI Launchpad

  • SAP Application Logging Service for SAP BTP

  • SAP Authorization and Trust Management service

  • SAP Build Work Zone, advanced edition (called «SAP Work Zone» until November 2022) 

  • SAP Business Application Studio

  • SAP Cloud Appliance Library

  • SAP Cloud Identity Services - Identity Authentication

  • SAP Cloud Management service for SAP BTP

  • SAP Connectivity service

  • SAP Conversational AI

  • SAP Data Custodian

  • SAP Data Quality Management

  • SAP Destination service

  • SAP Document Management service offered as a bundle and as single services:
    - SAP Document Management service, integration option
    - SAP Document Management service, application option

  • SAP Event Mesh

  • SAP Forms service by Adobe

  • SAP HANA Cloud, offered as a bundle and as single services:
    - SAP HANA Cloud, data lake
    - SAP HANA Cloud, SAP HANA database

  • SAP HTML5 Application Repository service for SAP BTP

  • SAP Intelligent Robotic Process Automation

  • SAP Landscape Management Cloud

  • SAP Market Communication for Utilities

  • SAP Master Data Integration

  • SAP Multi-Bank Connectivity

  • SAP Platform Identity Provider service for SAP BTP

  • SAP Software-as-a-Service Provisioning service

  • SAP Subscription Billing

  • SAP Virtual Machine service

  • Application Autoscaler

  • Data Attribute Recommendation

  • Invoice Object Recommendation

  • Java Profiling for SAP BTP

  • Object Store on SAP BTP

  • Redis on SAP BTP / Redis on SAP BTP, hyperscaler option

  • UI5 flexibility for key users

  • SAP BTP, Kubernetes environment (internal only)

  • SAP Alert Notification service for SAP BTP

  • SAP ASE service

  • SAP Automation Pilot

  • SAP Build Work Zone, standard edition (called «SAP Launchpad service» until January 2023)

  • SAP Business Network Asset Collaboration

  • SAP Cloud for Energy

  • SAP Cloud Identity Services - Identity Provisioning

  • SAP Cloud Portal service

  • SAP Content Agent service

  • SAP Credential Store

  • SAP Data Intelligence

  • SAP Data Retention Manager

  • SAP Digital Manufacturing Cloud

  • SAP Document service

  • SAP Feature Flags service

  • SAP Git service

  • SAP HANA service for SAP BTP

  • SAP Information Collaboration Hub
    (Excluding Russia MDLP domestic reporting and Saudi Arabia Reporting)

  • SAP Job Scheduling service

  • SAP Leonardo Machine Learning Foundation

  • SAP Market Rates Management:
    - SAP Market Rates Management, Bring your own rates
    - SAP Market Rates Management, Refinitiv data option

  • SAP Mobile Services (incl. Agentry)

  • SAP OData Provisioning

  • SAP Private Link service

  • SAP Solutions Lifecycle Management service for SAP BTP

  • SAP Task Center

  • SAP Web IDE

  • Business Entity Recognition

  • Document Classification

  • Java Application Lifecycle Management for SAP BTP

  • MongoDB on SAP BTP

  • PostgreSQL on SAP BTP / PostgreSQL on SAP BTP, hyperscaler option

  • Service Ticket Intelligence

  • Unified Gateway (internal only)

  • SAP AI Core

  • SAP Analytics Cloud including SAP Digital Boardroom and SAP Analytics Hub

  • SAP Audit Log service

  • SAP Batch Release Hub for Life Sciences

  • SAP Business Accelerator Hub (called« SAP API Business Hub» until April 2023)

  • SAP Business Network for Logistics, offered as a bundle and as single services:
    - SAP Business Network Freight Collaboration
    - SAP Business Network Global Track and Trace
    - SAP Business Network Intelligent Insights
    - SAP Business Network Material Traceability

  • SAP Cloud Identity Access Governance

  • SAP Cloud Integration for data services

  • SAP Cloud Transport Management

  • SAP Continuous Integration and Delivery

  • SAP Custom Domain service

  • SAP Data Privacy Integration

  • SAP Datasphere (called until March 2023 « SAP Data Warehouse Cloud »), incl. SAP BW Bridge

  • SAP Document Center

  • SAP Entitlement Management

  • SAP Fiori Cloud

  • SAP Graph

  • SAP HANA spatial services

  • SAP Integration Suite, offered as a bundle and as single services:
    - SAP API Management
    - Cloud Integration
    - Integration Advisor
    - Open Connectors

  • SAP Keystore service

  • SAP Malware Scanning service

  • SAP Master Data Governance, cloud edition

  • SAP Monitoring service for SAP BTP

  • SAP Personal Data Manager

  • SAP Service Manager

  • SAP Sports One

  • SAP Usage Data Management service for SAP BTP

  • SAP Workflow Management offered as a bundle and as single services:
    - SAP Business Rules
    - SAP Process Visibility service
    - Workflow service

  • Commercial Infrastructure Service (internal only)

  • Document Information Extraction

  • Java Debugging for SAP BTP

  • OAuth 2.0 on SAP BTP

  • RabbitMQ on SAP BTP

  • UI Theme Designer

The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with non-disclosure agreement in place.

SAP Business Technology Platform (SAP BTP) is a technology platform that brings together application development, data and analytics, integration, automation, and AI capabilities in one unified environment. The platform offers users the ability to turn data into business value, compose end-to-end business processes, and build and extend SAP applications.

The services and solutions of SAP BTP are available on multiple cloud infrastructure providers. The multi-cloud foundation supports different environments, such as Cloud Foundry, ABAP, Kyma, and Neo, as well as multiple different regions and a broad choice of programming languages.

The SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems that are used to process users’ data and the confidentiality and privacy of the information processed by these systems.  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.


SAP Business Technology Platform has regularly prepared SOC 2 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period October 1, 2022 to March 31, 2023, and the trust principles Security, Availability, and Confidentiality.


The following locations and their IaaS provider are covered:

SAP BTP Region Name Infrastructure Provider 
UAE (Dubai) SAP 
Australia (Sydney) SAP 
China (Shanghai) SAP 
Japan (Tokyo) SAP 
Japan (Osaka) SAP 
KSA (Riyadh) SAP 
KSA (Dammam) SAP 
Europe (Rot) SAP 
Europe (Frankfurt) SAP 
Europe (Amsterdam) SAP 
Brazil (Sao Paulo) SAP 
Canada (Toronto) SAP 
US East (Ashburn) SAP 
US East (Sterling) SAP 
US West (Colorado Springs) SAP 
US West (Chandler) SAP 
US East (VA) Amazon Web Services (AWS) 
Canada (Montreal) Amazon Web Services (AWS) 
SingaporeAmazon Web Services (AWS) 
South Korea (Seoul) Amazon Web Services (AWS) 
Europe (Frankfurt) Amazon Web Services (AWS) 
India (Mumbai) Amazon Web Services (AWS) 
Brazil (São Paulo) Amazon Web Services (AWS) 
Australia (Sydney) Amazon Web Services (AWS) 
Japan (Tokyo) Amazon Web Services (AWS) 
US West (Oregon) Amazon Web Services (AWS) 
US East (VA) Microsoft Azure (Azure) 
US West (WA) Microsoft Azure (Azure) 
Canada (Toronto) Microsoft Azure (Azure) 
Europe (Netherlands) Microsoft Azure (Azure) 
Singapore Microsoft Azure (Azure) 
Australia (Sydney) Microsoft Azure (Azure) 
Japan (Tokyo) Microsoft Azure (Azure) 
UAE North (Dubai) Microsoft Azure (Azure) 
Switzerland (Zurich) Microsoft Azure (Azure) 
US Central (IA) Google Cloud Platform (GCP) 
Europe (Frankfurt) Google Cloud Platform (GCP) 
India (Mumbai) Google Cloud Platform (GCP) 

SAP BTP SOC2 Type 2 report covers within audit period the following services:

  • SAP BTP runtime:
    - SAP BTP, Neo runtime
    - SAP BTP, Cloud Foundry runtime
    - SAP BTP, Kyma runtime

  • SAP BTP, ABAP environment

  • SAP AI Launchpad

  • SAP Application Logging Service for SAP BTP

  • SAP Authorization and Trust Management service

  • SAP Build Work Zone, advanced edition (called «SAP Work Zone» until November 2022) 

  • SAP Business Application Studio

  • SAP Cloud Appliance Library

  • SAP Cloud Identity Services - Identity Authentication

  • SAP Cloud Management service for SAP BTP

  • SAP Connectivity service

  • SAP Conversational AI

  • SAP Data Custodian

  • SAP Data Quality Management

  • SAP Destination service

  • SAP Document Management service offered as a bundle and as single services:
    - SAP Document Management service, integration option
    - SAP Document Management service, application option

  • SAP Event Mesh

  • SAP Forms service by Adobe

  • SAP HANA Cloud, offered as a bundle and as single services:
    - SAP HANA Cloud, data lake
    - SAP HANA Cloud, SAP HANA database

  • SAP HTML5 Application Repository service for SAP BTP

  • SAP Intelligent Robotic Process Automation

  • SAP Landscape Management Cloud

  • SAP Market Communication for Utilities

  • SAP Master Data Integration

  • SAP Multi-Bank Connectivity

  • SAP Platform Identity Provider service for SAP BTP

  • SAP Software-as-a-Service Provisioning service

  • SAP Subscription Billing

  • SAP Virtual Machine service

  • Application Autoscaler

  • Data Attribute Recommendation

  • Invoice Object Recommendation

  • Java Profiling for SAP BTP

  • Object Store on SAP BTP

  • Redis on SAP BTP / Redis on SAP BTP, hyperscaler option

  • UI5 flexibility for key users

  • SAP BTP, Kubernetes environment (internal only)

  • SAP Alert Notification service for SAP BTP

  • SAP ASE service

  • SAP Automation Pilot

  • SAP Build Work Zone, standard edition (called «SAP Launchpad service» until January 2023)

  • SAP Business Network Asset Collaboration

  • SAP Cloud for Energy

  • SAP Cloud Identity Services - Identity Provisioning

  • SAP Cloud Portal service

  • SAP Content Agent service

  • SAP Credential Store

  • SAP Data Intelligence

  • SAP Data Retention Manager

  • SAP Digital Manufacturing Cloud

  • SAP Document service

  • SAP Feature Flags service

  • SAP Git service

  • SAP HANA service for SAP BTP

  • SAP Information Collaboration Hub
    (Excluding Russia MDLP domestic reporting and Saudi Arabia Reporting)

  • SAP Job Scheduling service

  • SAP Leonardo Machine Learning Foundation

  • SAP Market Rates Management:
    - SAP Market Rates Management, Bring your own rates
    - SAP Market Rates Management, Refinitiv data option

  • SAP Mobile Services (incl. Agentry)

  • SAP OData Provisioning

  • SAP Private Link service

  • SAP Solutions Lifecycle Management service for SAP BTP

  • SAP Task Center

  • SAP Web IDE

  • Business Entity Recognition

  • Document Classification

  • Java Application Lifecycle Management for SAP BTP

  • MongoDB on SAP BTP

  • PostgreSQL on SAP BTP / PostgreSQL on SAP BTP, hyperscaler option

  • Service Ticket Intelligence

  • Unified Gateway (internal only)

  • SAP AI Core

  • SAP Analytics Cloud including SAP Digital Boardroom and SAP Analytics Hub

  • SAP Audit Log service

  • SAP Batch Release Hub for Life Sciences

  • SAP Business Accelerator Hub (called« SAP API Business Hub» until April 2023)

  • SAP Business Network for Logistics, offered as a bundle and as single services:
    - SAP Business Network Freight Collaboration
    - SAP Business Network Global Track and Trace
    - SAP Business Network Intelligent Insights
    - SAP Business Network Material Traceability

  • SAP Cloud Identity Access Governance

  • SAP Cloud Integration for data services

  • SAP Cloud Transport Management

  • SAP Continuous Integration and Delivery

  • SAP Custom Domain service

  • SAP Data Privacy Integration

  • SAP Datasphere (called until March 2023 « SAP Data Warehouse Cloud »), incl. SAP BW Bridge

  • SAP Document Center

  • SAP Entitlement Management

  • SAP Fiori Cloud

  • SAP Graph

  • SAP HANA spatial services

  • SAP Integration Suite, offered as a bundle and as single services:
    - SAP API Management
    - Cloud Integration
    - Integration Advisor
    - Open Connectors

  • SAP Keystore service

  • SAP Malware Scanning service

  • SAP Master Data Governance, cloud edition

  • SAP Monitoring service for SAP BTP

  • SAP Personal Data Manager

  • SAP Service Manager

  • SAP Sports One

  • SAP Usage Data Management service for SAP BTP

  • SAP Workflow Management offered as a bundle and as single services:
    - SAP Business Rules
    - SAP Process Visibility service
    - Workflow service

  • Commercial Infrastructure Service (internal only)

  • Document Information Extraction

  • Java Debugging for SAP BTP

  • OAuth 2.0 on SAP BTP

  • RabbitMQ on SAP BTP

  • UI Theme Designer

The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with non-disclosure agreement in place.