No single GDS or integration partner is universally best — the right choice depends on your geography, airline mix, NDC ambitions, and how much your business can tolerate downtime during a booking spike. This scorecard gives you a structured way to compare GDS and API integration partners on the factors that actually predict a stable, scalable booking platform.
Who this is for: travel platform builders, OTA operators, and travel tech leads evaluating GDS connectivity or API integration partners for a booking system build or upgrade.
Before You Start Evaluating
- [ ] Map your primary markets — Amadeus dominates Europe, Sabre anchors North American airline connectivity, and Travelport is known for multi-source content
- [ ] Decide your NDC ambitions now, since GDS providers differ significantly in NDC Level certification and airline network breadth
- [ ] Document your peak booking load (holiday season, flash sales) to use as a stress-test benchmark
- [ ] Confirm which legacy systems (EDIFACT-based) still need to be supported alongside any NDC migration
GDS & API Architecture Questions
- Which GDS or GDSs does this integration support, and what's your certification level with each?
- What NDC certification level have you reached, and how many airlines does your NDC network actually cover?
- Do you support modern JSON APIs, legacy SOAP APIs, or both — and does the JSON API cover full functionality or a reduced subset?
- How do you architect for the multi-year hybrid period where NDC and EDIFACT both need to be supported simultaneously?
- What's your approach to normalizing data across multiple GDS sources into a single booking flow?
Certification & Compliance Questions
| Area | What to ask |
|---|---|
| Security certifications | Do you hold SOC 2, ISO 27001, or other relevant attestations, and when were they last audited? |
| GDS certification | Are your integrations formally certified by each GDS you connect to, not just "compatible"? |
| PCI compliance | How is payment data handled across the booking flow, and what's your PCI DSS posture? |
| Audit currency | A lapsed certification audit is functionally equivalent to no certification — confirm audit dates explicitly |
Uptime & Failover Questions
- [ ] What's the contractual uptime guarantee, not just a marketing claim — and what remedy applies if it's missed?
- [ ] What's the support response-time SLA, broken out by ticket severity?
- [ ] Can you share your status page history or recent incident postmortems?
- [ ] What redundancy and failover mechanisms are in place if a GDS connection or API goes down mid-transaction?
- [ ] How are integration components monitored, and how are customers notified during an incident?
Vendor Scorecard
| Criteria | Weight | Vendor A | Vendor B | Vendor C |
|---|---|---|---|---|
| GDS coverage relevant to our markets | ||||
| NDC certification level & airline breadth | ||||
| Uptime SLA & failover architecture | ||||
| Security certifications (current) | ||||
| Incident transparency (status page, postmortems) | ||||
| Integration cost & timeline |
Red Flags to Watch For
- Claims "NDC support" without specifying certification level or actual airline network coverage
- No willingness to share status page history or past incident postmortems
- Certifications that are years out of date with no recent audit
- Vague answers on failover — "we have redundancy" without specifics on what happens during an outage
- No clear plan for the multi-year period where both NDC and EDIFACT need to coexist
How to Use This
Weight NDC readiness heavily if airline distribution is core to your platform — this transition is running over multiple years, not a one-time switch, so you need a partner who has an explicit hybrid-period strategy, not one who treats NDC as a checkbox. Request actual incident history rather than accepting an uptime percentage at face value; a vendor confident in their reliability record will share it without hesitation.