Compliance · NIS2 · DORA
NIS2 and DORA on SAP systems: what can be checked, and how
The NIS2 directive and the DORA regulation require security measures you can demonstrate. On SAP systems part of those measures is technical and can be read from the system: SUPTime checks it and turns it into a report to sign.
Check by check
Five checks, each with its regulation
The article mapping is the one printed in the report. It supports an assessment; it is not legal advice.
| Check | Source | NIS2 art. 21 | DORA |
|---|---|---|---|
| Profile parameters | TH_GET_PARAMETER | (2)(d) supply chain security · (2)(i) cyber hygiene and access control | art. 9(4)(c) security policies · art. 9(4)(d) strong authentication |
| Standard users | USR02 | (2)(i) cyber hygiene · (2)(j) multi-factor authentication | art. 9(4)(d) identity and access management |
| Client modifiability | T000 | (2)(e) security in development and maintenance | art. 9(4)(b) prevention of unauthorized changes |
| Security Audit Log | RSAUPROF · RSAU_READ_LOG | (2)(b) incident handling | art. 10 detection of anomalous activities |
| Certificates | SSFR_GET_CERTIFICATELIST | (2)(h) cryptography and encryption | art. 9(4)(b) protection of data in transit |
Profile parameters
The values compared with the SAP Security Baseline
Read with TH_GET_PARAMETER: these are the active values, not the ones written in the profiles. Thresholds are set per installation, because a value acceptable in development is not in production.
| Parameter | Expected value | What it protects |
|---|---|---|
| login/min_password_lng | at least 8 | Minimum password length |
| login/password_expiration_time | at least 1 | Password expiry (0 means passwords never expire) |
| login/fails_to_user_lock | at most 5 | Failed attempts before the user is locked |
| login/no_automatic_user_sapstar | 1 | Disables the kernel's implicit SAP* user |
| snc/enable | 1 | SNC encryption of communications |
| gw/reg_info | set | Gateway reginfo file |
| gw/sec_info | set | Gateway secinfo file |
| gw/acl_mode | 1 | Gateway in restrictive ACL mode |
| rsau/enable | 1 | Security Audit Log enabled |
| icm/HTTPS/verify_client | at least 1 | Client certificate verification on HTTPS |
The report
A document to sign, tied to the data it read
Signature line
A cover page with the score summary and room for the signatory.
SHA-256 hash of the run
It ties the signature to precise data: if the data changes, so does the hash.
Remediation and references
For each check: outcome, value found, expected value, remediation and the NIS2 and DORA articles.
Raw evidence
An appendix with the data as it came from the system, for whoever needs to verify it.
Outcomes
PASS, FAIL and UNKNOWN
Data that was not read is not compliant data.
PASS
The value read meets the threshold.
FAIL
The value read does not meet it, and the report gives the remediation.
UNKNOWN
The data could not be read, because of a missing authorization or a missing source. It stays out of the score and the report says so.
How it is used
Switched on when you need it
Off by default
It queries production systems, so it is switched on deliberately from Settings.
Daily run
Every run is kept in the history, with its outcomes.
Traced
Every run and every report download goes into the hash-chained audit trail.
FAQ
NIS2, DORA and SAP
Does SUPTime make an SAP system NIS2 compliant?
No. It checks the technical part of the measures that can be read from the SAP system and produces the evidence. Compliance remains the assessment of whoever is responsible for it.
Which NIS2 checks does it run on SAP systems?
Profile security parameters against the SAP Security Baseline, unlocked standard users, modifiable production clients, certificate expiry and an active Security Audit Log.
Does the report also cover DORA?
Every check also lists the matching DORA articles, art. 9 and art. 10. It is the same document.
What happens if the user is missing an authorization?
The check comes out UNKNOWN, stays out of the score, and the report states how many checks it could not verify.
What format is the report?
Word (DOCX), with a signature line and the SHA-256 hash of the run. The signatory can edit the text; a PDF is one "Save as" away.
Declared limits
What it does not do
NIS2 and DORA are much broader than technical checks on SAP.
- It does not certify compliance and does not replace the assessment of whoever is responsible for it.
- It does not cover organizational measures: governance, supplier management, training, continuity plans.
- The standard users check only sees the client of the connection: covering all of them needs one user per client.
- RSAUPROF event classes and severity go into the evidence, but are not interpreted.
Need a NIS2 report on your SAP systems?
We will show you the report on a real system and what the user needs to read the data.