Compliance · NIS2 · DORA

NIS2 and DORA on SAP systems: what can be checked, and how

The NIS2 directive and the DORA regulation require security measures you can demonstrate. On SAP systems part of those measures is technical and can be read from the system: SUPTime checks it and turns it into a report to sign.

TH_GET_PARAMETERUSR02T000SSFR_GET_CERTIFICATELISTRSAUPROFRSAU_READ_LOG

Check by check

Five checks, each with its regulation

The article mapping is the one printed in the report. It supports an assessment; it is not legal advice.

CheckSourceNIS2 art. 21DORA
Profile parametersTH_GET_PARAMETER(2)(d) supply chain security · (2)(i) cyber hygiene and access controlart. 9(4)(c) security policies · art. 9(4)(d) strong authentication
Standard usersUSR02(2)(i) cyber hygiene · (2)(j) multi-factor authenticationart. 9(4)(d) identity and access management
Client modifiabilityT000(2)(e) security in development and maintenanceart. 9(4)(b) prevention of unauthorized changes
Security Audit LogRSAUPROF · RSAU_READ_LOG(2)(b) incident handlingart. 10 detection of anomalous activities
CertificatesSSFR_GET_CERTIFICATELIST(2)(h) cryptography and encryptionart. 9(4)(b) protection of data in transit

Profile parameters

The values compared with the SAP Security Baseline

Read with TH_GET_PARAMETER: these are the active values, not the ones written in the profiles. Thresholds are set per installation, because a value acceptable in development is not in production.

ParameterExpected valueWhat it protects
login/min_password_lngat least 8Minimum password length
login/password_expiration_timeat least 1Password expiry (0 means passwords never expire)
login/fails_to_user_lockat most 5Failed attempts before the user is locked
login/no_automatic_user_sapstar1Disables the kernel's implicit SAP* user
snc/enable1SNC encryption of communications
gw/reg_infosetGateway reginfo file
gw/sec_infosetGateway secinfo file
gw/acl_mode1Gateway in restrictive ACL mode
rsau/enable1Security Audit Log enabled
icm/HTTPS/verify_clientat least 1Client certificate verification on HTTPS

The report

A document to sign, tied to the data it read

Signature line

A cover page with the score summary and room for the signatory.

SHA-256 hash of the run

It ties the signature to precise data: if the data changes, so does the hash.

Remediation and references

For each check: outcome, value found, expected value, remediation and the NIS2 and DORA articles.

Raw evidence

An appendix with the data as it came from the system, for whoever needs to verify it.

Outcomes

PASS, FAIL and UNKNOWN

Data that was not read is not compliant data.

PASS

The value read meets the threshold.

FAIL

The value read does not meet it, and the report gives the remediation.

UNKNOWN

The data could not be read, because of a missing authorization or a missing source. It stays out of the score and the report says so.

How it is used

Switched on when you need it

Off by default

It queries production systems, so it is switched on deliberately from Settings.

Daily run

Every run is kept in the history, with its outcomes.

Traced

Every run and every report download goes into the hash-chained audit trail.

FAQ

NIS2, DORA and SAP

Does SUPTime make an SAP system NIS2 compliant?

No. It checks the technical part of the measures that can be read from the SAP system and produces the evidence. Compliance remains the assessment of whoever is responsible for it.

Which NIS2 checks does it run on SAP systems?

Profile security parameters against the SAP Security Baseline, unlocked standard users, modifiable production clients, certificate expiry and an active Security Audit Log.

Does the report also cover DORA?

Every check also lists the matching DORA articles, art. 9 and art. 10. It is the same document.

What happens if the user is missing an authorization?

The check comes out UNKNOWN, stays out of the score, and the report states how many checks it could not verify.

What format is the report?

Word (DOCX), with a signature line and the SHA-256 hash of the run. The signatory can edit the text; a PDF is one "Save as" away.

Declared limits

What it does not do

NIS2 and DORA are much broader than technical checks on SAP.

  • It does not certify compliance and does not replace the assessment of whoever is responsible for it.
  • It does not cover organizational measures: governance, supplier management, training, continuity plans.
  • The standard users check only sees the client of the connection: covering all of them needs one user per client.
  • RSAUPROF event classes and severity go into the evidence, but are not interpreted.

Need a NIS2 report on your SAP systems?

We will show you the report on a real system and what the user needs to read the data.

Request a demo