SAP Customer Data Solutions SOC 2 Audit Report 2025
This report covers SAP Customer Data Solutions (CDS) which encompasses the two products SAP Customer Data Cloud (CDC) and SAP Customer Data Platform (CDP).
SAP Customer Data Cloud (CDC) is a provider of Customer Identity, Consent & Profile management solutions. CDC helps companies build customer relationships, identify customers across different devices, consolidate data into customer profiles and integrate data into marketing and service applications.
SAP Customer Data Platform (CDP) was designed for social identities, use of mobile devices, consumer privacy and marketing. CDP provides developers with APIs to build and maintain registration, authentication, profile management, data analytics and third-party integration. Each customer's site has a unique API key, which is used for identification.
SAP CDS is offered in the following data center locations:
SOC 2 reports are prepared in accordance with AT-C Section 205 and the International Standard on Assurance Engagements No. 3000. SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls. These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria). Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight. Please note that this examination's scope does not include the controls of any subservice organizations. SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.
SAP Customer Data Solutions has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2024 to 31. March 2025, and the trust principles Security, Availability, Processing Integrity, and Confidentiality.
The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with a non-disclosure agreement in place.