FedRAMP Authorized — Moderate Impact

SAP Concur Government by SAP (Concur). 6 compliance features verified.

Finance & Accounting

SAP Concur Government

by SAP (Concur)

Moderate ImpactAuthorized

Impact Level

Moderate

Status

Authorized

Pricing

mid market

Authorization Date: August 22, 2017 | Sponsoring Agency: GSA

Overview

SAP Concur Government provides FedRAMP Moderate authorized travel and expense management for government organizations. It automates travel booking, expense reporting, and invoice processing within a compliant environment. The platform enforces government travel regulations including FTR and JTR compliance.

Key Features

FedRAMP Moderate baseline controls
Travel booking management
Automated expense reporting
Invoice processing
FTR/JTR compliance enforcement
Receipt capture and OCR

Certifications & Authorizations

FedRAMP Moderate Authorization (3PAO validated)SOC 2 Type IIISO 27001:2013FIPS 140-2 Level 1 (cryptographic modules)NIST 800-53 Rev 4 controls implementationDoD Cloud Computing SRG IL2 compliancePCI DSS Level 1 Service Provider

Deployment Options

AWS GovCloud (US-East) — FedRAMP Moderate boundary
AWS GovCloud (US-West) — Secondary region deployment
Multi-tenant SaaS via FedRAMP authorized cloud service provider
Hybrid integration with on-premises Active Directory Federation Services
Government Community Cloud (GCC) deployment option
Dedicated tenant deployment within SAP's FedRAMP boundary

NIST 800-171 Compliance Coverage

87% of controls covered

How to Procure SAP Concur Government for Defense Contracts

SAP Concur Government is available through GSA MAS (Multiple Award Schedule) under SIN 518210C (Electronic Commerce/Catalog Solutions) and SEWP V contracts. Government pricing includes volume discounts and educational rates unavailable to commercial customers, typically 15-25% below commercial rates. The authorization boundary includes the core Concur application, supporting AWS infrastructure, and integration APIs but excludes customer mobile devices and third-party travel booking engines. Contracting officers must approve the Data Processing Addendum (DPA), Business Associate Agreement if handling PII, and integration security documentation. The typical procurement timeline spans 90-120 days including technical evaluation, security review, and contract negotiation. For Authority to Operate (ATO), leverage the existing FedRAMP authorization with agency-specific security assessment focusing on data flows and user access controls. Include SAP Concur Government in your CMMC assessment boundary if processing or storing Controlled Unclassified Information (CUI) related to travel/expense data. Document data classification, access controls, and audit capabilities to demonstrate CMMC Level 2 compliance for defense contractors.

Compliance Cross-References

SAP Concur Government's FedRAMP Moderate authorization directly supports DFARS 252.204-7012 compliance by providing adequate security controls for CUI processing in travel and expense workflows. The cloud service satisfies DFARS 252.239-7010 requirements through its approved external cloud service provider status and continuous monitoring capabilities. NIST 800-171 control families are addressed as follows: Access Control (AC) through role-based permissions and MFA requirements, System and Communications Protection (SC) via encryption in transit and at rest, and Audit and Accountability (AU) through comprehensive logging and monitoring. For CMMC Level 2, the service supports Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), and System and Communications Protection (SC) domains through its implemented security controls and automated compliance reporting features.

Defense Contractor Use Case

Defense contractors use SAP Concur Government for managing employee travel and expense reports, ensuring compliance with government travel regulations and contract billing requirements.

Frequently Asked Questions

What is the FedRAMP authorization level for SAP Concur Government?

SAP Concur Government is authorized at the FedRAMP Moderate impact level, with authorization granted on 2017-08-22 sponsored by GSA. The FedRAMP Moderate baseline includes approximately 325 security controls covering confidentiality, integrity, and availability.

Can defense contractors use SAP Concur Government for CUI?

SAP Concur Government is authorized at the FedRAMP Moderate baseline. While FedRAMP Moderate covers a broad range of government data, defense contractors handling CUI should carefully evaluate whether Moderate controls meet their specific DFARS 252.204-7012 and NIST 800-171 requirements. Some CUI categories may require FedRAMP High authorization depending on the sensitivity of the data and contract requirements.

How does SAP Concur Government pricing compare to commercial?

SAP Concur Government government pricing is generally competitive with commercial pricing, though the government edition may carry a premium of 10-20% to cover FedRAMP compliance and dedicated infrastructure costs. Mid-market organizations can often access government pricing through GSA Schedule contracts or reseller partners. Contact SAP (Concur) for a quote tailored to your organization size and requirements.

Browse All FedRAMP Authorized Tools

Search and filter 80+ FedRAMP authorized products for your defense contracting needs.

Open FedRAMP Finder

Get a defensible CUI architecture

This SAP Concur Government FedRAMP profile flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures