SAP Commerce Cloud on Microsoft Azure and SAP Cloud for Customer on Amazon Web Services SOC 2 (ISAE 3000) Audit Report 2023 H1
The scope of this SOC report includes SAP Commerce Cloud system on Microsoft Azure and SAP Cloud for Customer system on Amazon Web Services.
SAP Commerce Cloud system supported by infrastructure managed by Microsoft Azure is a digital commerce platform offering a software-as-a-service (SaaS) model in the public cloud. Customers extend and build their own environment on top of the Commerce Cloud core codebase to achieve their desired e-commerce solution. All solutions run within the dedicated hyperscaler subscription of each customer. Customers can perform several self-service tasks through Cloud Portal.
SAP Cloud for Customer system supported by infrastructure managed by Amazon Web Services is an SAP Customer Relationship Management (CRM) Software-as-a-Service (SaaS) offering, powered by SAP HANA. It is a set of solutions for sales and service teams. All solutions are pre-integrated with SAP Business Suite and the solutions are supported on a wide range of browsers and mobile devices. SAP Cloud for Customer system supported by infrastructure managed by Amazon Web Services is a multi-tenant cloud offering that brings sales, customer service and social CRM together.
The SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls. These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems that are used to process users’ data and the confidentiality and privacy of the information processed by these systems. Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight. SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.
SAP Commerce Cloud on Microsoft Azure and SAP Cloud for Customer has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers the audit period 1. April 2022 to 31. March 2023 in the primary data center locations. The SAP Commerce Cloud System supported by Infrastructure managed by Amazon Web Services (AWS) is located in the following data centers: Frankfurt (Germany), Oregon (USA), Sao Paulo (Brazil), Sydney (Australia), and Virginia (USA). The SAP Cloud for Customer supported by Infrastructure managed by Microsoft Azure is located in the following data centers: Virginia (USA), Sydney (Australia), Sao Paulo (Brazil), Toronto (Canada), Hong Kong (China), Tokyo (Japan), Singapore (Singapore), Amsterdam (Netherlands), California (USA), London (United Kingdom), Pune (India), Shanghai (China), and Dubai (UAE), and the trust principles Security, Availability, and Confidentiality.
The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with non-disclosure agreement in place.