Why Onapsis

Elevate Your SAP Environment: How Onapsis and SAP Native Tools Work Better Together

SAP native tools keep your systems running; Onapsis keeps them secure. Discover how combining your native SAP capabilities with the only SAP-Endorsed application security platform delivers total visibility, automated remediation, and comprehensive security and compliance across your SAP landscape.

Technology professional wearing glasses reflected with digital data

SAP and Onapsis Both Play a Key Role in Protecting Your Business

A common question among SAP Basis and IT leaders is: “If we already have built-in SAP tools like SAP Solution Manager (SolMan), SAP Focused Run (FRUN), or SAP ABAP Test Cockpit (ATC), why do we also need Onapsis?”

The answer lies in understanding the distinct design goals of each platform:

  • SAP native tools are predominantly built to support operations & uptime: Built primarily for SAP Basis Administrators, native utilities (SolMan, Focused Run, EarlyWatch, ATC) focus on system availability, performance monitoring, transport management, and lifecycle continuity.
  • Onapsis is built for SAP cybersecurity & risk governance: Purpose-built to converge Cybersecurity, SAP Security, GRC, and Audit teams, Onapsis delivers proactive exposure management, zero-day threat intelligence, exploit and threat monitoring, multi-language code scanning for security and compliance, automated risk prioritization, and digital forensics.

Rather than replacing your existing SAP investments, Onapsis and SAP complement each other. Integrated directly into your native SAP frameworks, they together translate complex Basis technical data into actionable Cybersecurity intelligence.

Strategic Overview: The “Better Together” Functional Map

FocusKey Components & Capabilities
SAP NATIVE TOOLSApplication Lifecycle, Availability & UptimeSolution Manager / Focused Run (ALM & Transport Workflow)

ABAP Test Cockpit (ATC) (Native Testing Framework)
ONAPSIS PLATFORMApplication Security, Threat Intel & DevSecOpsOnapsis Assess: Exposure Management with Business-Risk Prioritization & Note Validation

Onapsis Control: Multi-Language Custom Code Security Testing & “One-Click Fix”

Onapsis Defend: Research-driven Continuous Threat Monitoring with 2,500+ Rules for Exploit Detection, Insider Risk, & Zero-Days

SAP Solution Manager (SolMan) & SAP Focused Run (FRUN) + Onapsis Assess

The Native Role: SolMan (via Configuration Validation, SOS, and System Recommendations) tracks landscape configuration homogeneity and can identify missing technical patches for Basis administrators. FRUN does similar work but for higher volume, significantly larger and more complex SAP landscapes.

The Value Gap in SolMan/FRUN:

  • Not Security Focused: SolMan and FRUN are application lifecycle management (ALM) tools, not security platforms. While they contain some basic features checking for security-related items (e.g., missing Security Notes for your in-support SAP systems; checking that you have password policies enabled), they aren’t built for the in-depth, robust, or comprehensive security analysis that’s both expected and required at an enterprise level for mission-critical systems.
  • No Business Risk Prioritization: SolMan treats all out-of-compliance parameters equally without business context, requiring hundreds to thousands of hours spent per month, manually sorting on Patch Tuesdays to understand what’s important to address.
  • Incapable of Completely Validating Note Application: Over 50% of critical SAP Security Notes require manual post-installation configuration. How do you know if your systems were correctly configured or patched completely? SolMan cannot validate manual notes or workarounds, leading to false positives and negatives that need to be manually validated.
  • SAP Basis Access Required: SolMan reports are technical and unreadable for Cybersecurity professionals who lack direct access to SAP.

How Onapsis Complements SolMan/FRUN:

  • Broader Coverage and Exposure Management: Onapsis Assess scans across 6,000+ checks (ABAP, Java, HANA, BTP, SuccessFactors, BOBJ) and ranks vulnerabilities and issues by business impact, cutting manual review time from hundreds of hours to under 1 hour.
  • Rapidly Deployed Compensating Controls: Frequently, SAP systems may take longer to patch due to the mission-critical nature of the applications running therein. Onapsis will show you where an SAP system is vulnerable and let you deploy monitoring with a click, serving as a compensating control if your team is unable to immediately patch or remediate the flaw.
  • Complete Note Validation: Automatically validates that technical patches and manual workarounds were fully implemented. In-product guidance will even dynamically adapt for your teams based on partial mitigation, thereby reducing severity and prioritization to help with patching.
  • Business-Friendly Output and Integrations: Independently accessible outside of SAP with dashboards, Security Advisor (benchmarking), and management tools to help teams reduce exposure and fix vulnerabilities in SAP. Exports executive dashboards and compliance reports and integrates out-of-the-box with enterprise ITSM tools (ServiceNow, Jira, custom), allowing Basis teams to keep working in SolMan while Cybersecurity gets transparent visibility.

SAP ABAP Test Cockpit (ATC) / SAP Code Inspector (SCI) & SAP Code Vulnerability Analyzer (CVA) + Onapsis Control

The Native Role: ABAP Test Cockpit (ATC) / SAP Code Inspector (SCI) is SAP’s native testing framework, while Code Vulnerability Analyzer (CVA) provides static analysis (SAST) for ABAP source code during development.

The Value Gap in Native Code Tools:

  • Restricted Language Scope: CVA scans ABAP code only, leaving Fiori, SAPUI5, HANA native (XSJS, CDS), and BTP Node.js code unmanaged and exposed.
  • Limited, Less Effective Test Cases: The built-in ATC/SCI features only provide 5 security-related test cases. Paid CVA provides only 70 test cases total, while a free version made available for SAP migration customers covers only a minimal subset of S/4HANA compatibility checks.
  • No Automated Remediation: CVA can identify some code errors based on its limited test cases, but provides no inline developer guidance or automated code repair.

How Onapsis Complements ATC & CVA:

  • Comprehensive Testing (600+ Test Cases): Provides 120x the test coverage of ATC/SCI and 9x the coverage of CVA with high fidelity, consistent findings across static (SAST), dynamic (DAST), interactive (IAST), and software composition analysis (SCA) domains.
  • Runs Natively Inside ATC…and Everywhere Else in Your Stack: Onapsis Control integrates directly into the SAP ATC framework, as well as several other areas of your SAP legacy or modern software development process. This includes modern IDEs (VS Code, Eclipse, SAP Business Application Studio), transport management (TMS, ChaRM), and CI/CD pipelines (Azure Pipelines, Piper, cTMS (Cloud ALM), Rev-Trac)).
  • “One-Click Fix” Automated Remediation: Enables both inline developer spell-check (within an IDE) and automated bulk code correction for common security errors directly within the developer’s IDE.

SAP Enterprise Threat Detection (ETD) + Onapsis Defend

The Native Role: SAP ETD acts as an SAP-specific SIEM, gathering and storing event logs against which it runs rules to highlight security issues that may require investigation.

The Value Gap in SAP ETD:

  • Lack of Threat Intelligence: ETD is not powered by threat intelligence. As a result, ETD is infrequently updated and comes with only ~85 (Cloud Edition) to 180 (On-Premise) basic attack patterns. Writing new rules requires manual effort and SAP threat knowledge and expertise that most enterprises don’t have.
  • No Pre-Patch Zero-Day Protection: ETD cannot detect exploit activity targeting zero-day SAP vulnerabilities before an official SAP Security Note is released.
  • High TCO and Operational Footprint: ETD On-Premises requires installing and managing large HANA systems, which often results in significant licensing and maintenance costs.

How Onapsis Complements SAP ETD:

  • Deep Threat Intelligence: Threat insights and telemetry from the Onapsis Research Labs feed into the Onapsis Platform in the form of actual threat intel feeds and continually updated detection rules for advanced threat actor TTPs and public or private exploits.
  • More Comprehensive External and Internal Threat Monitoring: Onapsis Defend monitors for both insider threat and external threat actors. It offers 2,500+ specialized SAP threat detection rules (including 600+ exploitation rules exclusive to Onapsis) out of the box and the ability to easily “Alert on Anything” that customers need.
  • Pre-Patch Zero-Day Protection Before Security Notes Exist: Delivers zero-day pre-patch protection rules for potential attack or exploitation, updated, on average, 120 days before public SAP notes are released. All of this is a result of Onapsis’s world-class SAP threat research.
  • More Efficient Incident Response: For customers who use SAP ETD as their SIEM, Onapsis Defend can integrate directly with ETD (or other third-party SIEMs like CrowdStrike, Microsoft Sentinel, Splunk and others). Defend does the heavy lifting with the industry’s most comprehensive ruleset and sends critical alerts with mitigation and remediation guidance to SAP ETD for further incident management.

RISE with SAP: Fulfilling the Shared Security Responsibility Model

When transitioning to RISE with SAP, responsibility for cybersecurity is divided between SAP and the customer under the Shared Security Responsibility Model:

  • SAP Manages: “Security OF the Cloud” including infrastructure, hypervisors, OS, database uptime, and physical data center security.
  • Onapsis Helps Customers Manage: “Security IN the Cloud” including application vulnerability management, broader in-application risk exposure, custom code security, transport controls, user authorization policies, and application threat monitoring.

As an SAP Endorsed App (Premium Certified), Onapsis seamlessly automates and streamlines all customer-side responsibilities across your RISE with SAP environment.

SAP Enterprise Cloud Services offer premium-priced, managed Cloud Application Services (CAS) for areas of the customer’s responsibilities, similar to how third parties (e.g., systems integrators) offer managed services to customers.

An example of a security-related CAS for RISE customers is Application Security Updates. With this paid CAS managed service, the customer outsources their patch management operational tasks to SAP ECS. Instead of the customer handling the bulk of the application patching process, SAP will assist the customer and help take the technical patch from DEV through QAS to PRD. However, there remain some caveats for customers to note:

This leaves important areas that RISE customers still need to address, which is where Onapsis can help:

So, together, Onapsis and SAP CAS are complementary capabilities. When a RISE customer seeks to outsource areas of their own shared responsibility to SAP, CAS can provide relief, but security and compliance accountability remains with the customer. Onapsis provides the deep SAP security intelligence, expanded exposure management, and critical validation that enterprise customers require for security and compliance while also serving as the complementary technology control to “trust but verify” execution done on behalf of the customer.

By pairing SAP CAS with Onapsis, organizations can confidently outsource work for their teams to SAP while ensuring that they are completely eliminating SAP security blind spots, automating compliance evidence collection, protecting non-PRD systems, and securing their RISE with SAP transformation with real-time threat detection.

“Together, SAP and Onapsis provide enhanced security for RISE with SAP. SAP delivers a highly-secure and compliant RISE with SAP cloud infrastructure, enabling customers to focus solely on securing their SAP applications and data.

Onapsis strategically complements SAP’s role, delivering the essential security and compliance capabilities customers need to achieve this.”

– Roland Costea (former CISO, SAP ECS / RISE with SAP)

Feature Comparison Matrix: Onapsis Platform vs. SAP Native Capabilities

Capabilities & DomainsSAP Native Tools AloneOnapsis + SAP Native Tools (Integrated)
Primary Organizational FocusSystem Uptime & Basis OperationsSAP Application Cybersecurity & Compliance
Risk Exposure Across SAP LandscapeBasic config checks in SolMan (SOS); available, in-support Security Notes via System Recommendations6,000+ checks (including missing Security Notes or incomplete mitigation attempts) across ABAP, Java, HANA, BTP, BOBJ, and SuccessFactors
Validates Manual Notes & WorkaroundsNo (SolMan covers technical patches only)Yes (Validates configuration & manual steps)
Code Security Testing: Test Cases & Languages~5 test cases for security for ABAP only in free ATC/SCI

~70 security test cases for ABAP only in paid CVA
600+ test cases across multiple code languages such as ABAP, Fiori, UI5, HANA XSJS, BTP, Node.js – supporting your Secure Clean Core strategy.
Automated Code RemediationNo (Manual developer edits required)Yes (Offers “spell-check” feature in IDE for developers as well as “One-Click Fix” for select cases)
Real-Time Threat Detection Rules~85 to 180 “attack patterns” in SAP ETD2,500+ rules including 600+ Onapsis-exclusive exploit rules
Threat Intelligence NoneYes (Onapsis Research Labs feeds weekly Threat Dispatches and critical threat insights into the product)
Zero-Day Pre-Patch Threat ProtectionNo (No dedicated threat research team)Yes (Powered by Onapsis Research Labs. Anti-exploit rules added ~120 days prior to SAP patch release)
Executive & Compliance ReportingNo (Requires manual data exports)Yes (Out-of-the-box dashboards for CISO, SOC, and Auditors and full API suite to connect to business intelligence systems)

Maximize the Value of Your SAP Security Investments

Empower your Basis teams and help them focus on core operations while streamlining SAP security and compliance for the enterprise, wherever your SAP systems reside. Leverage Onapsis to complement your native SAP tools and build a complete defense-in-depth posture.