SAP Cloud Infrastructure SOC 1 (ISAE 3402) Audit Report 2023 H2

SAP Cloud Infrastructure (SCI) spearheads SAP’s 4+1 strategy and supports the adoption and governance of all services deployed as part of SAP’s Cloud Infrastructure Strategy. Specifically, this refers to the management of public cloud hyperscalers and SAP’s internal IaaS known as SAP Converged Cloud.

 

SAP Converged Cloud

 

Converged Cloud is SAP’s standardized Infrastructure as a Service (IaaS) offering to support all of SAP’s cloud business on a global scale. SAP Converged Cloud provides access to a vendor-agnostic hardware infrastructure architecture as well as infrastructure orchestration and automation services in all SAP. With SAP Converged Cloud, it is possible to deploy applications into data centers without needing to deploy a solution-specific infrastructure stack (the application infrastructure) beforehand.

 

The SAP Converged Cloud infrastructure landscape is hosted either in SAP SE owned data centers or co-location data centers, as detailed below:

DC Locations

United Arab Emirates: Dubai

Australia: Sydney

China: Shanghai

Japan: Tokyo

Japan: Osaka

Saudi Arabia: Riyadh

Saudi Arabia: Dammam

Germany: St. Leon-Rot

Germany: Walldorf

Germany: Frankfurt

Netherlands: Amsterdam

Brazil: São Paulo

Canada: Toronto

USA: Ashburn, VA

USA: Newtown Square, PA

USA: Sterling, VA

USA: Colorado Springs, CO

USA: Chandler, AZ

 

SAP Multi Cloud

 

The SAP Multi Cloud organization provides a ‘platform of enablement’ for Lines of Business (LoB) in the public cloud, providing costing services such as billing and cost optimization, architecture consultation and application design and security safeguards, tool engineering to automate and expand services offerings and hyperscaler operational support.

 

The SAP Multi Cloud infrastructure landscape is hosted in the following locations and their respective IaaS providers:

SOC 1 reports are prepared in accordance with AT-C section 320, Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting, and evaluate the effect of the controls at the service organization on the user entities’ financial statements. SOC 1 reports are specifically intended to meet the needs of the entities that use service organizations (user entities) and the CPAs that audit the user entities’ financial statements (user auditors).  SOC 1 Type 1 report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design of controls to achieve the related control objectives as of a specified date, whereas a SOC 1 Type 2 also includes the operating effectiveness of controls to achieve the related control objectives throughout a specified period.

 

SAP Cloud Infrastructure has regularly prepared SOC 1 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period 1. April 2023 to 30. September 2023.

 

The use of these reports is restricted to the management of the service organization, user entities, and user auditors. A copy of this report is available for all SAP Cloud Infrastructure customers who had productive and had financially-relevant systems during the audit period covered by the report.

SAP Cloud Infrastructure (SCI) spearheads SAP’s 4+1 strategy and supports the adoption and governance of all services deployed as part of SAP’s Cloud Infrastructure Strategy. Specifically, this refers to the management of public cloud hyperscalers and SAP’s internal IaaS known as SAP Converged Cloud.

 

SAP Converged Cloud

 

Converged Cloud is SAP’s standardized Infrastructure as a Service (IaaS) offering to support all of SAP’s cloud business on a global scale. SAP Converged Cloud provides access to a vendor-agnostic hardware infrastructure architecture as well as infrastructure orchestration and automation services in all SAP. With SAP Converged Cloud, it is possible to deploy applications into data centers without needing to deploy a solution-specific infrastructure stack (the application infrastructure) beforehand.

 

The SAP Converged Cloud infrastructure landscape is hosted either in SAP SE owned data centers or co-location data centers, as detailed below:

DC Locations

United Arab Emirates: Dubai

Australia: Sydney

China: Shanghai

Japan: Tokyo

Japan: Osaka

Saudi Arabia: Riyadh

Saudi Arabia: Dammam

Germany: St. Leon-Rot

Germany: Walldorf

Germany: Frankfurt

Netherlands: Amsterdam

Brazil: São Paulo

Canada: Toronto

USA: Ashburn, VA

USA: Newtown Square, PA

USA: Sterling, VA

USA: Colorado Springs, CO

USA: Chandler, AZ

 

SAP Multi Cloud

 

The SAP Multi Cloud organization provides a ‘platform of enablement’ for Lines of Business (LoB) in the public cloud, providing costing services such as billing and cost optimization, architecture consultation and application design and security safeguards, tool engineering to automate and expand services offerings and hyperscaler operational support.

 

The SAP Multi Cloud infrastructure landscape is hosted in the following locations and their respective IaaS providers:

SOC 1 reports are prepared in accordance with AT-C section 320, Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting, and evaluate the effect of the controls at the service organization on the user entities’ financial statements. SOC 1 reports are specifically intended to meet the needs of the entities that use service organizations (user entities) and the CPAs that audit the user entities’ financial statements (user auditors).  SOC 1 Type 1 report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design of controls to achieve the related control objectives as of a specified date, whereas a SOC 1 Type 2 also includes the operating effectiveness of controls to achieve the related control objectives throughout a specified period.

 

SAP Cloud Infrastructure has regularly prepared SOC 1 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period 1. April 2023 to 30. September 2023.

 

The use of these reports is restricted to the management of the service organization, user entities, and user auditors. A copy of this report is available for all SAP Cloud Infrastructure customers who had productive and had financially-relevant systems during the audit period covered by the report.