Elevate Your SAP Environment: How Onapsis and SAP Native Tools Work Better Together
SAP native tools keep your systems running; Onapsis keeps them secure. Discover how combining your native SAP capabilities with the only SAP-Endorsed application security platform delivers total visibility, automated remediation, and comprehensive security and compliance across your SAP landscape.

SAP and Onapsis Both Play a Key Role in Protecting Your Business
A common question among SAP Basis and IT leaders is: “If we already have built-in SAP tools like SAP Solution Manager (SolMan), SAP Focused Run (FRUN), or SAP ABAP Test Cockpit (ATC), why do we also need Onapsis?”
The answer lies in understanding the distinct design goals of each platform:
- SAP native tools are predominantly built to support operations & uptime: Built primarily for SAP Basis Administrators, native utilities (SolMan, Focused Run, EarlyWatch, ATC) focus on system availability, performance monitoring, transport management, and lifecycle continuity.
- Onapsis is built for SAP cybersecurity & risk governance: Purpose-built to converge Cybersecurity, SAP Security, GRC, and Audit teams, Onapsis delivers proactive exposure management, zero-day threat intelligence, exploit and threat monitoring, multi-language code scanning for security and compliance, automated risk prioritization, and digital forensics.
Rather than replacing your existing SAP investments, Onapsis and SAP complement each other. Integrated directly into your native SAP frameworks, they together translate complex Basis technical data into actionable Cybersecurity intelligence.
Strategic Overview: The “Better Together” Functional Map
| Focus | Key Components & Capabilities | |
|---|---|---|
| SAP NATIVE TOOLS | Application Lifecycle, Availability & Uptime | Solution Manager / Focused Run (ALM & Transport Workflow) ABAP Test Cockpit (ATC) (Native Testing Framework) |
| ONAPSIS PLATFORM | Application Security, Threat Intel & DevSecOps | Onapsis Assess: Exposure Management with Business-Risk Prioritization & Note Validation Onapsis Control: Multi-Language Custom Code Security Testing & “One-Click Fix” Onapsis Defend: Research-driven Continuous Threat Monitoring with 2,500+ Rules for Exploit Detection, Insider Risk, & Zero-Days |
SAP Solution Manager (SolMan) & SAP Focused Run (FRUN) + Onapsis Assess
The Native Role: SolMan (via Configuration Validation, SOS, and System Recommendations) tracks landscape configuration homogeneity and can identify missing technical patches for Basis administrators. FRUN does similar work but for higher volume, significantly larger and more complex SAP landscapes.
The Value Gap in SolMan/FRUN:
- Not Security Focused: SolMan and FRUN are application lifecycle management (ALM) tools, not security platforms. While they contain some basic features checking for security-related items (e.g., missing Security Notes for your in-support SAP systems; checking that you have password policies enabled), they aren’t built for the in-depth, robust, or comprehensive security analysis that’s both expected and required at an enterprise level for mission-critical systems.
- No Business Risk Prioritization: SolMan treats all out-of-compliance parameters equally without business context, requiring hundreds to thousands of hours spent per month, manually sorting on Patch Tuesdays to understand what’s important to address.
- Incapable of Completely Validating Note Application: Over 50% of critical SAP Security Notes require manual post-installation configuration. How do you know if your systems were correctly configured or patched completely? SolMan cannot validate manual notes or workarounds, leading to false positives and negatives that need to be manually validated.
- SAP Basis Access Required: SolMan reports are technical and unreadable for Cybersecurity professionals who lack direct access to SAP.
How Onapsis Complements SolMan/FRUN:
- Broader Coverage and Exposure Management: Onapsis Assess scans across 6,000+ checks (ABAP, Java, HANA, BTP, SuccessFactors, BOBJ) and ranks vulnerabilities and issues by business impact, cutting manual review time from hundreds of hours to under 1 hour.
- Rapidly Deployed Compensating Controls: Frequently, SAP systems may take longer to patch due to the mission-critical nature of the applications running therein. Onapsis will show you where an SAP system is vulnerable and let you deploy monitoring with a click, serving as a compensating control if your team is unable to immediately patch or remediate the flaw.
- Complete Note Validation: Automatically validates that technical patches and manual workarounds were fully implemented. In-product guidance will even dynamically adapt for your teams based on partial mitigation, thereby reducing severity and prioritization to help with patching.
- Business-Friendly Output and Integrations: Independently accessible outside of SAP with dashboards, Security Advisor (benchmarking), and management tools to help teams reduce exposure and fix vulnerabilities in SAP. Exports executive dashboards and compliance reports and integrates out-of-the-box with enterprise ITSM tools (ServiceNow, Jira, custom), allowing Basis teams to keep working in SolMan while Cybersecurity gets transparent visibility.
SAP ABAP Test Cockpit (ATC) / SAP Code Inspector (SCI) & SAP Code Vulnerability Analyzer (CVA) + Onapsis Control
The Native Role: ABAP Test Cockpit (ATC) / SAP Code Inspector (SCI) is SAP’s native testing framework, while Code Vulnerability Analyzer (CVA) provides static analysis (SAST) for ABAP source code during development.
The Value Gap in Native Code Tools:
- Restricted Language Scope: CVA scans ABAP code only, leaving Fiori, SAPUI5, HANA native (XSJS, CDS), and BTP Node.js code unmanaged and exposed.
- Limited, Less Effective Test Cases: The built-in ATC/SCI features only provide 5 security-related test cases. Paid CVA provides only 70 test cases total, while a free version made available for SAP migration customers covers only a minimal subset of S/4HANA compatibility checks.
- No Automated Remediation: CVA can identify some code errors based on its limited test cases, but provides no inline developer guidance or automated code repair.
How Onapsis Complements ATC & CVA:
- Comprehensive Testing (600+ Test Cases): Provides 120x the test coverage of ATC/SCI and 9x the coverage of CVA with high fidelity, consistent findings across static (SAST), dynamic (DAST), interactive (IAST), and software composition analysis (SCA) domains.
- Runs Natively Inside ATC…and Everywhere Else in Your Stack: Onapsis Control integrates directly into the SAP ATC framework, as well as several other areas of your SAP legacy or modern software development process. This includes modern IDEs (VS Code, Eclipse, SAP Business Application Studio), transport management (TMS, ChaRM), and CI/CD pipelines (Azure Pipelines, Piper, cTMS (Cloud ALM), Rev-Trac)).
- “One-Click Fix” Automated Remediation: Enables both inline developer spell-check (within an IDE) and automated bulk code correction for common security errors directly within the developer’s IDE.
SAP Enterprise Threat Detection (ETD) + Onapsis Defend
The Native Role: SAP ETD acts as an SAP-specific SIEM, gathering and storing event logs against which it runs rules to highlight security issues that may require investigation.
The Value Gap in SAP ETD:
- Lack of Threat Intelligence: ETD is not powered by threat intelligence. As a result, ETD is infrequently updated and comes with only ~85 (Cloud Edition) to 180 (On-Premise) basic attack patterns. Writing new rules requires manual effort and SAP threat knowledge and expertise that most enterprises don’t have.
- No Pre-Patch Zero-Day Protection: ETD cannot detect exploit activity targeting zero-day SAP vulnerabilities before an official SAP Security Note is released.
- High TCO and Operational Footprint: ETD On-Premises requires installing and managing large HANA systems, which often results in significant licensing and maintenance costs.
How Onapsis Complements SAP ETD:
- Deep Threat Intelligence: Threat insights and telemetry from the Onapsis Research Labs feed into the Onapsis Platform in the form of actual threat intel feeds and continually updated detection rules for advanced threat actor TTPs and public or private exploits.
- More Comprehensive External and Internal Threat Monitoring: Onapsis Defend monitors for both insider threat and external threat actors. It offers 2,500+ specialized SAP threat detection rules (including 600+ exploitation rules exclusive to Onapsis) out of the box and the ability to easily “Alert on Anything” that customers need.
- Pre-Patch Zero-Day Protection Before Security Notes Exist: Delivers zero-day pre-patch protection rules for potential attack or exploitation, updated, on average, 120 days before public SAP notes are released. All of this is a result of Onapsis’s world-class SAP threat research.
- More Efficient Incident Response: For customers who use SAP ETD as their SIEM, Onapsis Defend can integrate directly with ETD (or other third-party SIEMs like CrowdStrike, Microsoft Sentinel, Splunk and others). Defend does the heavy lifting with the industry’s most comprehensive ruleset and sends critical alerts with mitigation and remediation guidance to SAP ETD for further incident management.
RISE with SAP: Fulfilling the Shared Security Responsibility Model
When transitioning to RISE with SAP, responsibility for cybersecurity is divided between SAP and the customer under the Shared Security Responsibility Model:
- SAP Manages: “Security OF the Cloud” including infrastructure, hypervisors, OS, database uptime, and physical data center security.
- Onapsis Helps Customers Manage: “Security IN the Cloud” including application vulnerability management, broader in-application risk exposure, custom code security, transport controls, user authorization policies, and application threat monitoring.
As an SAP Endorsed App (Premium Certified), Onapsis seamlessly automates and streamlines all customer-side responsibilities across your RISE with SAP environment.

“Together, SAP and Onapsis provide enhanced security for RISE with SAP. SAP delivers a highly-secure and compliant RISE with SAP cloud infrastructure, enabling customers to focus solely on securing their SAP applications and data.
Onapsis strategically complements SAP’s role, delivering the essential security and compliance capabilities customers need to achieve this.”
– Roland Costea (former CISO, SAP ECS / RISE with SAP)
Feature Comparison Matrix: Onapsis Platform vs. SAP Native Capabilities
| Capabilities & Domains | SAP Native Tools Alone | Onapsis + SAP Native Tools (Integrated) |
|---|---|---|
| Primary Organizational Focus | System Uptime & Basis Operations | SAP Application Cybersecurity & Compliance |
| Risk Exposure Across SAP Landscape | Basic config checks in SolMan (SOS); available, in-support Security Notes via System Recommendations | 6,000+ checks (including missing Security Notes or incomplete mitigation attempts) across ABAP, Java, HANA, BTP, BOBJ, and SuccessFactors |
| Validates Manual Notes & Workarounds | No (SolMan covers technical patches only) | Yes (Validates configuration & manual steps) |
| Code Security Testing: Test Cases & Languages | ~5 test cases for security for ABAP only in free ATC/SCI ~70 security test cases for ABAP only in paid CVA | 600+ test cases across multiple code languages such as ABAP, Fiori, UI5, HANA XSJS, BTP, Node.js – supporting your Secure Clean Core strategy. |
| Automated Code Remediation | No (Manual developer edits required) | Yes (Offers “spell-check” feature in IDE for developers as well as “One-Click Fix” for select cases) |
| Real-Time Threat Detection Rules | ~85 to 180 “attack patterns” in SAP ETD | 2,500+ rules including 600+ Onapsis-exclusive exploit rules |
| Threat Intelligence | None | Yes (Onapsis Research Labs feeds weekly Threat Dispatches and critical threat insights into the product) |
| Zero-Day Pre-Patch Threat Protection | No (No dedicated threat research team) | Yes (Powered by Onapsis Research Labs. Anti-exploit rules added ~120 days prior to SAP patch release) |
| Executive & Compliance Reporting | No (Requires manual data exports) | Yes (Out-of-the-box dashboards for CISO, SOC, and Auditors and full API suite to connect to business intelligence systems) |
Maximize the Value of Your SAP Security Investments
Empower your Basis teams and help them focus on core operations while streamlining SAP security and compliance for the enterprise, wherever your SAP systems reside. Leverage Onapsis to complement your native SAP tools and build a complete defense-in-depth posture.
