SAP Cloud for Customer and SAP Commerce Cloud SOC 2 Audit Report 2024 H1

The scope of this SOC report includes SAP Commerce Cloud system and SAP Cloud for Customer system.

 

SAP Commerce Cloud system supported is a digital commerce platform offering a software-as-a-service (SaaS) model in the public cloud. Customers extend and build their own environment on top of the Commerce Cloud core codebase to achieve their desired e-commerce solution. All solutions run within the dedicated hyperscaler subscription of each customer. Customers can perform several self-service tasks through Cloud Portal.

 

SAP Commerce Cloud Supported by Infrastructure Managed by Microsoft Azure is offered in the following data centers:

DC Locations

DC Providers

Azure - US East – Virginia

Microsoft Azure

Azure - Australia East - Sydney

Microsoft Azure

Azure - Brazil South - Sao Paolo

Microsoft Azure

Azure - Canada Central - Toronto

Microsoft Azure

Azure - East Asia – Hong Kong

Microsoft Azure

Azure - Japan – Tokyo

Microsoft Azure

Azure - Southeast Asia – Singapore

Microsoft Azure

Azure - West Europe –Amsterdam

Microsoft Azure

Azure - West US - California

Microsoft Azure

Azure - South UK – London

Microsoft Azure

Azure - India Central - Pune

Microsoft Azure

Azure - China East 2 - Shanghai

Microsoft Azure

Azure - UAE North – Dubai

Microsoft Azure

Azure - Hebei, China

Microsoft Azure

SAP Cloud for Customer system  is an SAP Customer Relationship Management (CRM) Software-as-a-Service (SaaS) offering. It is a set of solutions for sales and service teams. All solutions are pre-integrated with SAP Business Suite and the solutions are supported on a wide range of browsers and mobile devices. It is a multi-tenant cloud offering that brings sales, customer service and social CRM together.

 

SAP Cloud for Customer System Supported by Infrastructure Managed by Amazon Web Services is offered in the following data centers:

DC Locations

DC Providers

Services

Central Canada, Canada

AWS

Standard SAP Cloud for Customer

Frankfurt, Germany

AWS

Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer

Oregon, USA

AWS

Standard SAP Cloud for Customer

Sao Paulo, Brazil

AWS

Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer

Sydney, Australia

AWS

Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer

Virginia, USA

AWS

Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer

Primary SAP Cloud for Customer Converged Cloud Data Center Regions in Scope:

DC Locations

DC Providers

Services

Frankfurt, Germany

SAP Cloud Infrastructure (SCI)

Standard SAP Cloud for Customer

Riyadh, Saudi Arabia

SAP Cloud Infrastructure (SCI)

Standard SAP Cloud for Customer

Dubai, United Arab Emirates

SAP Cloud Infrastructure (SCI)

Standard SAP Cloud for Customer

Shanghai, China

SAP Cloud Infrastructure (SCI)

Standard SAP Cloud for Customer

Primary Intelligent Add-on for SAP Cloud for Customer Regions in Scope:

DC Locations

DC Providers

Services

Frankfurt, Germany

AWS

Intelligent Add-On for SAP Cloud for Customer

Sao Paulo, Brazil

AWS

Intelligent Add-On for SAP Cloud for Customer

Sydney, Australia

AWS

Intelligent Add-On for SAP Cloud for Customer

Virginia, USA

AWS

Intelligent Add-On for SAP Cloud for Customer

SOC 2 reports are prepared in accordance with AT-C Section 205 and the International Standard on Assurance Engagements No. 3000. SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria).  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  Please note that this examination's scope does not include the controls of any subservice organizations.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.

 

SAP Cloud for Customer and SAP Commerce Cloud has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2023 to 31. March 2024, and the trust principles Security, Availability, Processing Integrity, and Confidentiality.

 

The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with a non-disclosure agreement in place.

The scope of this SOC report includes SAP Commerce Cloud system and SAP Cloud for Customer system.

 

SAP Commerce Cloud system supported is a digital commerce platform offering a software-as-a-service (SaaS) model in the public cloud. Customers extend and build their own environment on top of the Commerce Cloud core codebase to achieve their desired e-commerce solution. All solutions run within the dedicated hyperscaler subscription of each customer. Customers can perform several self-service tasks through Cloud Portal.

 

SAP Commerce Cloud Supported by Infrastructure Managed by Microsoft Azure is offered in the following data centers:

DC Locations

DC Providers

Azure - US East – Virginia

Microsoft Azure

Azure - Australia East - Sydney

Microsoft Azure

Azure - Brazil South - Sao Paolo

Microsoft Azure

Azure - Canada Central - Toronto

Microsoft Azure

Azure - East Asia – Hong Kong

Microsoft Azure

Azure - Japan – Tokyo

Microsoft Azure

Azure - Southeast Asia – Singapore

Microsoft Azure

Azure - West Europe –Amsterdam

Microsoft Azure

Azure - West US - California

Microsoft Azure

Azure - South UK – London

Microsoft Azure

Azure - India Central - Pune

Microsoft Azure

Azure - China East 2 - Shanghai

Microsoft Azure

Azure - UAE North – Dubai

Microsoft Azure

Azure - Hebei, China

Microsoft Azure

SAP Cloud for Customer system  is an SAP Customer Relationship Management (CRM) Software-as-a-Service (SaaS) offering. It is a set of solutions for sales and service teams. All solutions are pre-integrated with SAP Business Suite and the solutions are supported on a wide range of browsers and mobile devices. It is a multi-tenant cloud offering that brings sales, customer service and social CRM together.

 

SAP Cloud for Customer System Supported by Infrastructure Managed by Amazon Web Services is offered in the following data centers:

DC Locations

DC Providers

Services

Central Canada, Canada

AWS

Standard SAP Cloud for Customer

Frankfurt, Germany

AWS

Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer

Oregon, USA

AWS

Standard SAP Cloud for Customer

Sao Paulo, Brazil

AWS

Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer

Sydney, Australia

AWS

Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer

Virginia, USA

AWS

Standard SAP Cloud for Customer and Intelligent Add-ons for SAP Cloud for Customer

Primary SAP Cloud for Customer Converged Cloud Data Center Regions in Scope:

DC Locations

DC Providers

Services

Frankfurt, Germany

SAP Cloud Infrastructure (SCI)

Standard SAP Cloud for Customer

Riyadh, Saudi Arabia

SAP Cloud Infrastructure (SCI)

Standard SAP Cloud for Customer

Dubai, United Arab Emirates

SAP Cloud Infrastructure (SCI)

Standard SAP Cloud for Customer

Shanghai, China

SAP Cloud Infrastructure (SCI)

Standard SAP Cloud for Customer

Primary Intelligent Add-on for SAP Cloud for Customer Regions in Scope:

DC Locations

DC Providers

Services

Frankfurt, Germany

AWS

Intelligent Add-On for SAP Cloud for Customer

Sao Paulo, Brazil

AWS

Intelligent Add-On for SAP Cloud for Customer

Sydney, Australia

AWS

Intelligent Add-On for SAP Cloud for Customer

Virginia, USA

AWS

Intelligent Add-On for SAP Cloud for Customer

SOC 2 reports are prepared in accordance with AT-C Section 205 and the International Standard on Assurance Engagements No. 3000. SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria).  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  Please note that this examination's scope does not include the controls of any subservice organizations.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.

 

SAP Cloud for Customer and SAP Commerce Cloud has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2023 to 31. March 2024, and the trust principles Security, Availability, Processing Integrity, and Confidentiality.

 

The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with a non-disclosure agreement in place.