Sungard AS maintains the following ISO standards and guidelines, and industry-specific regulations in the United Kingdom.

IL2/IL3

Sungard AS has Pan Government Accreditation (PGA) for Impact Level 3 (IL3), for our private cloud infrastructure. This bridges across different levels of security via an accredited Gateway, meaning that Customers can meet government criteria for processing data classified as 'Official', including information marked Official Sensitive, which broadly combine the previous IL2 and IL3 classifications.

ISO 14001

Sungard AS works within the guidelines of this environmental management standard. However, certification has not been achieved. Sungard AS’ Sustainability Policy is based on a company-wide commitment to embed sustainability factors into the core operations of Sungard AS' business.

ISO/IEC 20000

Sungard AS maintains an ISO20000 Certification for the Service Management System that delivers Managed Services to Customers in North America, Europe, India and other Global Customers provisioned from Thornton, CO; Philadelphia, PA; Pune, India; and Hounslow, UK.

ISO 22301

Sungard AS maintains an ISO22301 Certification for the Business Continuity Management System for all Sungard AS Facilities in the United Kingdom and Ireland.

ISO/IEC 27001

Sungard AS maintains an ISO27001 Certification for the Information Security Management System for Managed Services, Recovery Services and Cloud Services at all Sungard AS Facilities Globally.

ITIL

Sungard AS' delivery team is organised around a service-centric operating model, based on an ITIL v3 (Information Technology Infrastructure Library) and ITSM (Information Technology Service Management) structure, and grounded in our ISO 20000-1 certification.

PCI-DSS

Though not required to be compliant, Sungard AS maintains a PCI-DSS Certification for its Central Management Network to enable Customers who are required to be compliant achieve their own Certification.

SSAE-18/ISAE3402

Sungard AS utilises an independent third party to perform a SOC1-Type 2 Assessment for Managed Services annually.