SAP Cloud for Customer and SAP Commerce Cloud SOC 2 Audit Report 2024 H1
The scope of this SOC report includes SAP Commerce Cloud system and SAP Cloud for Customer system.
SAP Commerce Cloud system supported is a digital commerce platform offering a software-as-a-service (SaaS) model in the public cloud. Customers extend and build their own environment on top of the Commerce Cloud core codebase to achieve their desired e-commerce solution. All solutions run within the dedicated hyperscaler subscription of each customer. Customers can perform several self-service tasks through Cloud Portal.
SAP Commerce Cloud Supported by Infrastructure Managed by Microsoft Azure is offered in the following data centers:
DC Locations | DC Providers |
Azure - US East – Virginia | Microsoft Azure |
Azure - Australia East - Sydney | Microsoft Azure |
Azure - Brazil South - Sao Paolo | Microsoft Azure |
Azure - Canada Central - Toronto | Microsoft Azure |
Azure - East Asia – Hong Kong | Microsoft Azure |
Azure - Japan – Tokyo | Microsoft Azure |
Azure - Southeast Asia – Singapore | Microsoft Azure |
Azure - West Europe –Amsterdam | Microsoft Azure |
Azure - West US - California | Microsoft Azure |
Azure - South UK – London | Microsoft Azure |
Azure - India Central - Pune | Microsoft Azure |
Azure - China East 2 - Shanghai | Microsoft Azure |
Azure - UAE North – Dubai | Microsoft Azure |
Azure - Hebei, China | Microsoft Azure |
SAP Cloud for Customer system is an SAP Customer Relationship Management (CRM) Software-as-a-Service (SaaS) offering. It is a set of solutions for sales and service teams. All solutions are pre-integrated with SAP Business Suite and the solutions are supported on a wide range of browsers and mobile devices. It is a multi-tenant cloud offering that brings sales, customer service and social CRM together.
SAP Cloud for Customer System Supported by Infrastructure Managed by Amazon Web Services is offered in the following data centers:
DC Locations | DC Providers | Services |
Central Canada, Canada | AWS | Standard SAP Cloud for Customer |
Frankfurt, Germany | AWS | Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer |
Oregon, USA | AWS | Standard SAP Cloud for Customer |
Sao Paulo, Brazil | AWS | Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer |
Sydney, Australia | AWS | Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer |
Virginia, USA | AWS | Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer |
Primary SAP Cloud for Customer Converged Cloud Data Center Regions in Scope:
DC Locations | DC Providers | Services |
Frankfurt, Germany | SAP Cloud Infrastructure (SCI) | Standard SAP Cloud for Customer |
Riyadh, Saudi Arabia | SAP Cloud Infrastructure (SCI) | Standard SAP Cloud for Customer |
Dubai, United Arab Emirates | SAP Cloud Infrastructure (SCI) | Standard SAP Cloud for Customer |
Shanghai, China | SAP Cloud Infrastructure (SCI) | Standard SAP Cloud for Customer |
Primary Intelligent Add-on for SAP Cloud for Customer Regions in Scope:
DC Locations | DC Providers | Services |
Frankfurt, Germany | AWS | Intelligent Add-On for SAP Cloud for Customer |
Sao Paulo, Brazil | AWS | Intelligent Add-On for SAP Cloud for Customer |
Sydney, Australia | AWS | Intelligent Add-On for SAP Cloud for Customer |
Virginia, USA | AWS | Intelligent Add-On for SAP Cloud for Customer |
SOC 2 reports are prepared in accordance with AT-C Section 205 and the International Standard on Assurance Engagements No. 3000. SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls. These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria). Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight. Please note that this examination's scope does not include the controls of any subservice organizations. SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.
SAP Cloud for Customer and SAP Commerce Cloud has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2023 to 31. March 2024, and the trust principles Security, Availability, Processing Integrity, and Confidentiality.
The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with a non-disclosure agreement in place.
The scope of this SOC report includes SAP Commerce Cloud system and SAP Cloud for Customer system.
SAP Commerce Cloud system supported is a digital commerce platform offering a software-as-a-service (SaaS) model in the public cloud. Customers extend and build their own environment on top of the Commerce Cloud core codebase to achieve their desired e-commerce solution. All solutions run within the dedicated hyperscaler subscription of each customer. Customers can perform several self-service tasks through Cloud Portal.
SAP Commerce Cloud Supported by Infrastructure Managed by Microsoft Azure is offered in the following data centers:
DC Locations | DC Providers |
Azure - US East – Virginia | Microsoft Azure |
Azure - Australia East - Sydney | Microsoft Azure |
Azure - Brazil South - Sao Paolo | Microsoft Azure |
Azure - Canada Central - Toronto | Microsoft Azure |
Azure - East Asia – Hong Kong | Microsoft Azure |
Azure - Japan – Tokyo | Microsoft Azure |
Azure - Southeast Asia – Singapore | Microsoft Azure |
Azure - West Europe –Amsterdam | Microsoft Azure |
Azure - West US - California | Microsoft Azure |
Azure - South UK – London | Microsoft Azure |
Azure - India Central - Pune | Microsoft Azure |
Azure - China East 2 - Shanghai | Microsoft Azure |
Azure - UAE North – Dubai | Microsoft Azure |
Azure - Hebei, China | Microsoft Azure |
SAP Cloud for Customer system is an SAP Customer Relationship Management (CRM) Software-as-a-Service (SaaS) offering. It is a set of solutions for sales and service teams. All solutions are pre-integrated with SAP Business Suite and the solutions are supported on a wide range of browsers and mobile devices. It is a multi-tenant cloud offering that brings sales, customer service and social CRM together.
SAP Cloud for Customer System Supported by Infrastructure Managed by Amazon Web Services is offered in the following data centers:
DC Locations | DC Providers | Services |
Central Canada, Canada | AWS | Standard SAP Cloud for Customer |
Frankfurt, Germany | AWS | Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer |
Oregon, USA | AWS | Standard SAP Cloud for Customer |
Sao Paulo, Brazil | AWS | Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer |
Sydney, Australia | AWS | Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer |
Virginia, USA | AWS | Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer |
Primary SAP Cloud for Customer Converged Cloud Data Center Regions in Scope:
DC Locations | DC Providers | Services |
Frankfurt, Germany | SAP Cloud Infrastructure (SCI) | Standard SAP Cloud for Customer |
Riyadh, Saudi Arabia | SAP Cloud Infrastructure (SCI) | Standard SAP Cloud for Customer |
Dubai, United Arab Emirates | SAP Cloud Infrastructure (SCI) | Standard SAP Cloud for Customer |
Shanghai, China | SAP Cloud Infrastructure (SCI) | Standard SAP Cloud for Customer |
Primary Intelligent Add-on for SAP Cloud for Customer Regions in Scope:
DC Locations | DC Providers | Services |
Frankfurt, Germany | AWS | Intelligent Add-On for SAP Cloud for Customer |
Sao Paulo, Brazil | AWS | Intelligent Add-On for SAP Cloud for Customer |
Sydney, Australia | AWS | Intelligent Add-On for SAP Cloud for Customer |
Virginia, USA | AWS | Intelligent Add-On for SAP Cloud for Customer |
SOC 2 reports are prepared in accordance with AT-C Section 205 and the International Standard on Assurance Engagements No. 3000. SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls. These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria). Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight. Please note that this examination's scope does not include the controls of any subservice organizations. SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.
SAP Cloud for Customer and SAP Commerce Cloud has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2023 to 31. March 2024, and the trust principles Security, Availability, Processing Integrity, and Confidentiality.
The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with a non-disclosure agreement in place.