No single GDS or integration partner is universally best — the right choice depends on your geography, airline mix, NDC ambitions, and how much your business can tolerate downtime during a booking spike. This scorecard gives you a structured way to compare GDS and API integration partners on the factors that actually predict a stable, scalable booking platform.

Who this is for: travel platform builders, OTA operators, and travel tech leads evaluating GDS connectivity or API integration partners for a booking system build or upgrade.

Before You Start Evaluating

  • [ ] Map your primary markets — Amadeus dominates Europe, Sabre anchors North American airline connectivity, and Travelport is known for multi-source content
  • [ ] Decide your NDC ambitions now, since GDS providers differ significantly in NDC Level certification and airline network breadth
  • [ ] Document your peak booking load (holiday season, flash sales) to use as a stress-test benchmark
  • [ ] Confirm which legacy systems (EDIFACT-based) still need to be supported alongside any NDC migration

GDS & API Architecture Questions

  1. Which GDS or GDSs does this integration support, and what's your certification level with each?
  2. What NDC certification level have you reached, and how many airlines does your NDC network actually cover?
  3. Do you support modern JSON APIs, legacy SOAP APIs, or both — and does the JSON API cover full functionality or a reduced subset?
  4. How do you architect for the multi-year hybrid period where NDC and EDIFACT both need to be supported simultaneously?
  5. What's your approach to normalizing data across multiple GDS sources into a single booking flow?

Certification & Compliance Questions

AreaWhat to ask
Security certificationsDo you hold SOC 2, ISO 27001, or other relevant attestations, and when were they last audited?
GDS certificationAre your integrations formally certified by each GDS you connect to, not just "compatible"?
PCI complianceHow is payment data handled across the booking flow, and what's your PCI DSS posture?
Audit currencyA lapsed certification audit is functionally equivalent to no certification — confirm audit dates explicitly

Uptime & Failover Questions

  • [ ] What's the contractual uptime guarantee, not just a marketing claim — and what remedy applies if it's missed?
  • [ ] What's the support response-time SLA, broken out by ticket severity?
  • [ ] Can you share your status page history or recent incident postmortems?
  • [ ] What redundancy and failover mechanisms are in place if a GDS connection or API goes down mid-transaction?
  • [ ] How are integration components monitored, and how are customers notified during an incident?

Vendor Scorecard

CriteriaWeightVendor AVendor BVendor C
GDS coverage relevant to our markets
NDC certification level & airline breadth
Uptime SLA & failover architecture
Security certifications (current)
Incident transparency (status page, postmortems)
Integration cost & timeline

Red Flags to Watch For

  • Claims "NDC support" without specifying certification level or actual airline network coverage
  • No willingness to share status page history or past incident postmortems
  • Certifications that are years out of date with no recent audit
  • Vague answers on failover — "we have redundancy" without specifics on what happens during an outage
  • No clear plan for the multi-year period where both NDC and EDIFACT need to coexist

How to Use This

Weight NDC readiness heavily if airline distribution is core to your platform — this transition is running over multiple years, not a one-time switch, so you need a partner who has an explicit hybrid-period strategy, not one who treats NDC as a checkbox. Request actual incident history rather than accepting an uptime percentage at face value; a vendor confident in their reliability record will share it without hesitation.