QUALITY, CONTINUITY & CLOUD SECURITY
HOW WE EARN YOUR CONFIDENCE DAILY
Your business demands the highest quality and availability from your digital infrastructure. Count on us to make sure that happens for you. To prove our continuous commitment to your success, our robust Integrated Management System combines:
- Quality Management System
- Business Continuity Management System
- Information Security Management System
Read on to learn the details.
QUALITY MANAGEMENT SYSTEM
Software and services designed for your success
Our ISO 9001-certified Quality Management System (QMS) is foundational for assuring high customer satisfaction, delivering the best-quality services and software as well as making continuous improvements. As part of our QMS, our system for Product Development, Professional Services and Global Support describes the processes, roles and rules that guide the daily work of every employee and how critical assets are secured. This framework:
- Assures compliance with laws and regulations on quality, safety and performance
- Safeguards our ability to support our customers
- Clearly defines transparent processes
- Enables a continuous stream of innovation in an agile development environment
- Builds in feedback to assure we supply quality software that creates a competitive advantage for our customers
The QMS is foundation of our Integrated Management System (IMS).
See certificates:
- ISO 9001 Quality Management System certified by DQS (English)
- ISO 9001 Quality Management System certified by DQS (German)
- ISO 9001 IQNet Quality Management System (English)
BUSINESS CONTINUITY MANAGEMENT SYSTEM
Because digital businesses never stop
Our ISO 22301-certified Business Continuity Management System incorporates an extraordinary degree of digitalization with best-practice governance processes, incident response teams and co-location of critical infrastructure and applications. This assures critical systems are available for our customers so they can meet their compliance requirements. Customers are guaranteed to get the services they need, quickly and effectively, even in a crisis situation. We continually align our Business Continuity Management System to changing requirements, review it regularly and improve continuously its efficiency.
See certificates:
- ISO 22301 Business Continuity Management System certified by DQS (English)
- ISO 22301 Business Continuity Management System certified by DQS (German)
CLOUD SECURITY
The Cloud Information Security Management Program (ISMP) secures Software AG Cloud with the highest industry standards.
Cloud Information Security Management System
The ISO/IEC 27000 standards series is a widely recognized set of international security standard that specifies security management best practices and comprehensive security controls. The foundation of this certification is the development and implementation of a Cloud Information Security Management System (ISMS).
The Software AG Cloud ISMS defines our approach to managing security for cloud services in a holistic, comprehensive manner and provides a suite of information security measures to:
- Protect cloud information assets from unauthorized access, use, disclosure, disruption, modification, inspection, recording or destruction
- Proactively identify security risks, prevent, detect and respond to security breaches and violations
- Comply with legal, regulatory and contractual requirements
- Adopt an overarching management process to ensure information security controls meet information security needs on an ongoing basis
The independent third-party auditors assessment, which validates compliance with the ISO/IEC 27001 standard, provides evidence that the Software AG Cloud ISMS is comprehensive and in accordance with industry-leading best practices.
Software AG has certification for compliance with ISO/IEC 27001:2013, ISO/IEC 27017:2015, and ISO/IEC 27018:2019. The standard cloud services in scope are listed in the certification scope statement.
See certificates:
- ISO 27001 Cloud Information Management System certified by DQS (English)
- ISO 27001 Cloud Information Management System certified by DQS (German)
- ISO 27017 Code of Practice for Information Security Controls for Cloud Services certified by DQS (English)
- ISO 27017 Code of Practice for Information Security Controls for Cloud Services certified by DQS (German)
- ISO 27018 Code of Practice for Protecting Personal Data in the Cloud certified by DQS (English)
- ISO 27018 Code of Practice for Protecting Personal Data in the Cloud certified by DQS (German)
- ISO 27001 IQNet Cloud Information Management System (English)
Service Organization Controls (SOC)
SOC reports are independent third-party examination reports that demonstrate how Software AG achieves key compliance controls and objectives. The purpose of these reports is to help you and your auditors understand Software AG controls established to support operations and compliance.
TOP BRANDS TRUST US
Nissan
“We spend less time on the mechanics of integration and can remain more focused on business requirements.”
- Steve Guss, Manager Systems Development, Nissan Europe
Learn more
TOP BRANDS TRUST US
MAPFRE
“Software AG ... delivered our proof-of concept faster than the other competitors with organized and professional practices and methodologies.”
- Diego Maldonado I Senior VP & CIO I MAPFRE Puerto Rico
Learn more
















