SStatWharf

Best SAP S/4HANA Security Software (2026): Top 9 Compared

Updated September 2026By StatWharf Editorial9 vendorsMethodology

Compare buyer fit, pricing notes and trade-offs. How entries are ordered.

Compare at a glance

Select a vendor for details and sources. Scroll the table horizontally on smaller screens.

SAP S/4HANA Security Software: vendor fit and recorded pricing
VendorConsider forPricing notes
OnapsisenterpriseEnterprises running SAP RISE or hybrid landscapes needing continuous vulnerability and threat coverageQuote-based (checked Sep 2026)
SecurityBridgeenterpriseBasis teams wanting a single SAP-native add-on covering patching, custom code and threat detectionQuote-based (checked Sep 2026)
PathlockenterpriseOrganizations wanting SAP cybersecurity pricing published upfront rather than quoted through salesFree; paid from $7,500/yr (checked Sep 2026)
Layer Seven SecurityspecialistSAP RISE customers wanting full-stack coverage without provisioning extra infrastructure through SAP ECSQuote-based (checked Sep 2026)
SaviyntenterpriseEnterprises standardising identity governance across SAP and non-SAP applications on one cloud platformQuote-based (checked Sep 2026)
Fastpathmid-marketMid-market and multi-ERP organizations wanting one access governance tool across SAP and other systemsQuote-based (checked Sep 2026)
XitingspecialistSAP Gold Partner customers wanting consulting-backed authorization and licensing work paired with a hybrid security platformQuote-based (checked Sep 2026)
SAP Enterprise Threat DetectionenterpriseSAP customers wanting SIEM-grade threat detection built and supported directly by SAPQuote-based (checked Sep 2026)
SoterionsmbMid-sized SAP shops needing business-friendly access risk reporting alongside S/4 FUE license optimisationQuote-based (checked Sep 2026)

These comparisons draw on public product information, not hands-on testing of every tool. Source records identify available references and checks; missing evidence is marked. Buyer fit is an editorial assessment, not a measured performance score. How to use this research.

SAP S/4HANA security software addresses risks that general SAP security tooling does not fully cover: a Fiori launchpad and tile-based authorization model that replaces much of the SAP GUI transaction-code map, an underlying SAP HANA database layer with its own authentication and audit surface, and a wave of role and authorization changes that a conversion from ECC forces on an existing landscape. Cloud and RISE with SAP deployments add a shared-responsibility question on top, since SAP secures the infrastructure while the customer remains responsible for custom code, user access and application-layer configuration.

The market splits into SAP-native cybersecurity add-ons such as SecurityBridge and Layer Seven Security, SAP-endorsed platforms such as Onapsis, SAP’s own Enterprise Threat Detection, access governance vendors such as Pathlock, Fastpath and Soterion, cross-application identity platforms such as Saviynt, and consulting-backed software from partners such as Xiting. The comparison orders the products by category fit, implementation tradeoffs and the pricing information available, with all pricing notes were recorded in September 2026.

Vendor details and trade-offs

Onapsis

enterprise
Consider forEnterprises running SAP RISE or hybrid landscapes needing continuous vulnerability and threat coverage
Pricing notesQuote-based (checked Sep 2026)
Product referenceonapsis.com
Feature to evaluateSAP Endorsed App status with a dedicated RISE with SAP security accelerator

Onapsis is a cybersecurity and compliance platform for SAP and Oracle applications, built by Onapsis Inc., a Boston-based company focused exclusively on business-critical application security. The platform is organized into Assess, Defend and Control product lines and carries Premium Certified SAP Endorsed App status, a distinction the vendor states no other cybersecurity and compliance product in that program holds. Onapsis Research Labs discovers SAP zero-day vulnerabilities and works directly with SAP and CISA on disclosure, feeding findings back into the platform as detection content and virtual patches.

Assess runs automated asset discovery and continuous vulnerability scanning across on-premises, cloud, RISE and BTP systems, correlating findings with threat intelligence at a stated false-positive rate under 5 percent. Defend adds real-time threat monitoring, zero-day virtual patching ahead of official SAP patches, and anomaly detection for SIEM integration. Control automates compliance testing for SOX, GDPR and NIST. The S/4HANA-specific work sits in the Secure RISE Accelerator, which maps vulnerability scanning, custom-code review and compliance validation to each SAP Activate phase, uses S/4HANA's Security Audit Log APIs to stream failed logons and sensitive-transaction use into a SOC in real time, and validates legacy custom code carried over from an ECC conversion before go-live.

Onapsis publishes no pricing; every plan is quoted after a scoping call, and the vendor confirms coverage across on-premises, private cloud and RISE with SAP without listing tiers. The platform suits large enterprises converting to or running S/4HANA that need continuous vulnerability, threat and compliance coverage from an SAP-endorsed vendor, particularly mid-RISE-migration. It is a heavier commitment than most tools here, spanning three licensed product lines, so smaller estates may find it more than needed.

Potential strengths

  • Holds Premium Certified SAP Endorsed App status, a distinction the vendor states no comparable cybersecurity and compliance product shares
  • Onapsis Research Labs supplies real-time zero-day threat intelligence and virtual patching ahead of official SAP patches
  • The Secure RISE Accelerator maps security tasks to each phase of SAP Activate for S/4HANA conversions and RISE migrations

Trade-offs

  • No pricing is published anywhere on the site, so budgeting requires a sales conversation before any tier is known
  • Coverage spans three separate product lines, Assess, Defend and Control, so licensing a full S/4HANA landscape can mean buying more than one module
Sources and status

SecurityBridge

enterprise
Consider forBasis teams wanting a single SAP-native add-on covering patching, custom code and threat detection
Pricing notesQuote-based (checked Sep 2026)
Product referencesecuritybridge.com
Feature to evaluateCertified ABAP add-on live in days with no external servers or agents

SecurityBridge is a cybersecurity platform built by SecurityBridge, a vendor that positions itself as the only SAP security product operating natively inside SAP rather than bolted on from an external server. The platform deploys as a certified ABAP add-on, with no external virtual machines, agents or additional attack surface to patch separately. The vendor states its software protects more than 8,000 production SAP systems worldwide, including fresh S/4HANA implementations and brownfield ECC conversions, and markets deployment in days rather than the months a separately hosted platform typically needs.

Core modules cover vulnerability management, automated patch management, code vulnerability analysis for custom ABAP, an interface traffic monitor, and threat detection feeding directly into Microsoft Sentinel, Splunk, QRadar and ServiceNow. Patch Management enriches every monthly SAP Security Note with system-specific relevance and offers one-click installation, which matters on S/4HANA landscapes where note volume rose after conversion. Compliance Automation ships preconfigured checks against a security baseline with audit-ready dashboards. For RISE with SAP customers, the vendor markets built-in threat detection, code scanning and patch automation needing no additional infrastructure inside the customer-managed portion of a RISE tenant, and the dashboard surfaces configuration drift such as unauthorized RFC connections common after a move onto HANA.

Pricing is not published; the site's pricing page is password-protected, and the vendor describes its licensing only as transparent and free of volume-based hidden costs, without stating figures. SecurityBridge suits Basis-led SAP teams wanting one add-on covering patching, custom code and threat detection without separate infrastructure. It is a weaker fit for security teams sitting organizationally outside Basis that want a tool managed independently, since the add-on model ties operation to existing SAP transport tooling.

Potential strengths

  • Deploys entirely as a certified SAP add-on with no external virtual machines or agents to patch and harden separately
  • Automated patch management enriches every monthly SAP Security Note with system-specific relevance and offers one-click installation
  • States it protects more than 8,000 production SAP systems, giving the vendor a large base of RISE and S/4HANA deployment experience

Trade-offs

  • The public pricing page is password-protected, so cost only becomes clear once a sales conversation begins
  • Running as an ABAP add-on ties administration to the Basis team's existing SAP tooling, which can slow adoption where security sits outside Basis
Sources and status

Pathlock

enterprise
Consider forOrganizations wanting SAP cybersecurity pricing published upfront rather than quoted through sales
Pricing notesFree; paid from $7,500/yr (checked Sep 2026)
Product referencepathlock.com
Feature to evaluatePublished edition pricing from a free scanner to a $30,000/year full-lifecycle bundle

Pathlock is an identity and application-access governance vendor headquartered in Denver, Colorado, whose SAP Cybersecurity Application Controls product line targets vulnerability management, code scanning and threat detection separately from its broader Application Access Governance suite. The company reports more than 1,300 customers, including named accounts such as Aramco, Toyota and Siemens. Unlike most vendors in this comparison, Pathlock publishes fixed annual prices for its SAP cybersecurity edition bundles rather than routing every buyer through a sales quote, and offers a self-guided in-browser tour of the interface before contacting sales.

The Advanced edition combines Vulnerability Management, Code Scanning, Transport Control, Threat Detection and Application Profiler modules under one licence. Transport Control screens change requests for critical objects and vulnerabilities before they reach production, marketed for securing S/4HANA migrations by catching risky transports carried over from an ECC system. Threat Detection analyzes more than 70 log sources against upward of 1,500 detection signatures. On the access side, Pathlock's separately licensed connector maintains distinct rulesets sized for each SAP generation, listing more than 137 segregation-of-duties risks for S/4HANA against over 207 for ECC, reflecting how the simplified S/4HANA authorization model changes the underlying risk catalogue.

The pricing page lists four editions: Free at $0 covering reduced-scope vulnerability management and code scanning; Essential from $7,500 per year adding full scope to those two modules; Professional from $15,000 per year adding transport control and threat detection; and Advanced at $30,000 per year adding the application profiler. Pathlock suits organizations wanting a published starting price before engaging sales, particularly mid-conversion projects needing transport screening. It fits less well where a single unified licence covering both cybersecurity and cross-application access governance is required, since Pathlock sells those as separate product lines.

Potential strengths

  • Publishes four named editions with fixed annual prices, unusual in a category dominated by quote-only vendors
  • Transport Control screens S/4HANA migration transports for critical objects and vulnerabilities before they reach production
  • Maintains separate SoD rulesets sized for S/4HANA, with more than 137 segregation-of-duties risks distinct from the larger ECC ruleset

Trade-offs

  • The free and Essential editions cover only vulnerability management and code scanning, leaving threat detection and transport control to higher tiers
  • Cybersecurity controls and cross-application access governance are sold as separate product lines, so a full S/4HANA security programme spans more than one purchase
Sources and status

Layer Seven Security

specialist
Consider forSAP RISE customers wanting full-stack coverage without provisioning extra infrastructure through SAP ECS
Pricing notesQuote-based (checked Sep 2026)
Product referencelayersevensecurity.com
Feature to evaluateAgentless ABAP add-on covering application, database and host layers under one licence

Layer Seven Security is a specialist SAP cybersecurity vendor that has focused on SAP application defense since 2010, selling a single product called the Cybersecurity Extension for SAP. The company describes the platform as agentless and SAP-certified, embedded in the application layer rather than watching SAP from an external server, and states it protects more than 100 global enterprise customers. The vendor markets the product around SAP RISE and Cloud ERP customers managed by SAP Enterprise Cloud Services, as an alternative to provisioning separate infrastructure inside that model, and holds Approved SAP Services Partner status for assessments built on the platform.

The Cybersecurity Extension installs as an ABAP add-on through standard transaction SAINT in roughly six hours and covers application, database and host layers under one licence. Daily automated scans check for more than 5,000 vulnerabilities and configuration weaknesses, more than 300 custom-code checks target ABAP developments, and over 1,200 threat patterns detect indicators of compromise with alerts forwarded to Splunk, QRadar and Sentinel. The product also includes access control analysis identifying users with access to sensitive and incompatible functions, which the vendor states covers segregation-of-duties risk specific to SAP S/4HANA business users, and a five-step hardening programme guides customers through network, RFC and administrative-privilege controls during a conversion.

Pricing is not published on the site; the vendor states licensing is competitively priced and lower cost than comparable platforms but gives no figures, and marketing pages lean on self-published comparisons and awards that buyers should verify independently. The product suits SAP RISE customers wanting one licence covering application, database and host protection without added infrastructure. It is a narrower fit for organizations needing cross-application governance beyond SAP, since the extension is built and sold as a single-platform SAP tool.

Potential strengths

  • Deploys as an ABAP add-on via standard transaction SAINT in about six hours, with no additional servers or agents
  • Covers application, database and host layers under a single licence rather than separate modules for each
  • Includes access control analysis that flags critical and segregation-of-duties risks for S/4HANA business users, not only system-level vulnerabilities

Trade-offs

  • No pricing is published; every figure on the site is a comparative claim rather than a quoted rate
  • Marketing materials lean heavily on self-published rankings and head-to-head comparisons that buyers should verify independently rather than take at face value
Sources and status

Saviynt

enterprise
Consider forEnterprises standardising identity governance across SAP and non-SAP applications on one cloud platform
Pricing notesQuote-based (checked Sep 2026)
Product referencesaviynt.com
Feature to evaluateSAP-certified S/4HANA connector inside a broader cross-application identity governance suite

Saviynt is a converged identity security platform vendor whose Enterprise Identity Cloud brings identity governance, application access governance, cloud privileged access and, more recently, AI-agent identity management under one cloud-native architecture. SAP support is delivered through an SAP-certified connector and an Application Access Governance module rather than a stand-alone SAP product, reflecting the vendor's broader positioning as a cross-application identity platform that treats SAP as one of many governed systems alongside Oracle, Workday and Salesforce, and the company states the SAP integration has been certified by SAP for performance, stability and interoperability at scale.

For SAP S/4HANA specifically, the connector supports full account and access import, and provisioning actions including creating, enabling, disabling and removing accounts and business role assignments, working against roles, T-codes and profiles rather than the flatter authorization objects used on older ECC systems. Application Access Governance layers AI-driven analytics on top, using pre-configured, application-specific rulesets to detect segregation-of-duties violations, prioritizing access risk across applications, and automating certification campaigns so reviews do not rely on periodic manual sign-off. A separate Identity Security Posture Management capability continuously monitors governance posture across Saviynt and any connected platform, extending beyond static point-in-time access reviews into ongoing drift detection as S/4HANA roles and business-role assignments change after go-live, which the vendor positions against the static rule sets typical of legacy SAP GRC installations.

Saviynt's own pricing page names Essentials, Pro and Premium tiers without listing numbers, and it states pricing scales by the number and type of identities under management, with all Saviynt-built connectors included in every tier at no extra cost. The platform suits organizations standardising identity governance across SAP and non-SAP systems on one console, particularly where S/4HANA sits alongside Oracle or Workday in the same identity programme. It is a heavier commitment than necessary for a buyer whose only requirement is SAP-specific access governance, where narrower specialist tools on this list are built and priced for that single purpose.

Potential strengths

  • SAP-certified integration provisions and governs S/4HANA roles, T-codes and profiles from the same console used for other enterprise applications
  • Application Access Governance applies AI-driven analytics to detect SoD violations across SAP alongside Oracle, Workday and other systems
  • Identity Security Posture Management continuously monitors governance posture rather than relying on periodic manual reviews

Trade-offs

  • SAP-specific security is one module inside a large identity governance platform, so buyers pay for cross-application breadth even if SAP is the only target
  • Pricing is negotiated by identity count and not published, so no entry price is available before a sales conversation
Sources and status

Fastpath

mid-market
Consider forMid-market and multi-ERP organizations wanting one access governance tool across SAP and other systems
Pricing notesQuote-based (checked Sep 2026)
Product referencedelinea.com
Feature to evaluateCross-ERP SoD analysis down to the S/4HANA Fiori tile and authorization object level

Fastpath is an application access governance product now sold by Delinea after the identity security vendor acquired Fastpath in 2024. The product, marketed as Fastpath Access Control and Fastpath Application Access Governance, focuses on segregation-of-duties analysis, user access reviews, compliant provisioning and change tracking across enterprise resource planning systems rather than SAP alone, and Delinea has begun folding parts of Fastpath's identity lifecycle expertise into its own platform since the acquisition closed, while continuing to sell and support the Fastpath products under their original names for existing and new customers.

For SAP specifically, the product analyzes segregation-of-duties and sensitive-access risk down to the transaction code or Fiori tile and the individual authorization object or field value, a level of granularity the vendor markets as necessary because SAP S/4HANA moved core transaction access into Fiori launchpad tiles that do not map one-to-one onto the older SAP GUI transaction codes. Change Tracking separately monitors modifications to configurations, parameters and sensitive data, showing before-and-after values so an S/4HANA conversion project can distinguish an intentional configuration change from an unauthorized one. The platform ships more than 20 proprietary rule sets covering SAP S/4HANA, Oracle, Workday, Microsoft Dynamics and other systems for organizations mid-way through a multi-ERP transition.

Pricing is not published on either the Fastpath or Delinea sites; every plan routes to a sales conversation rather than a self-service price list, and the product pages describe cost as varying by which modules are licensed, which ERP platforms are covered, and how many users are monitored. Fastpath suits mid-market and multi-ERP organizations that want one access governance tool spanning SAP alongside Oracle or Dynamics during a phased S/4HANA rollout. It does not cover SAP vulnerability scanning, patch management or custom-code security, so a full S/4HANA security programme built around it still needs a separate cybersecurity tool from elsewhere on this list.

Potential strengths

  • Analyzes segregation-of-duties and sensitive access risk down to the transaction code or Fiori tile and individual authorization object
  • Covers SAP, Oracle, Microsoft Dynamics and other ERPs from one platform, useful for organizations mid-way through an S/4HANA rollout alongside legacy systems
  • Change Tracking shows before-and-after values for configuration changes, distinguishing an intentional S/4HANA conversion change from an unauthorized one

Trade-offs

  • No published pricing on either the Fastpath or Delinea sites; every plan routes to a sales conversation
  • Cybersecurity vulnerability scanning and patch management are not part of the product line, so SoD coverage needs pairing with a separate tool for that work
Sources and status

Xiting

specialist
Consider forSAP Gold Partner customers wanting consulting-backed authorization and licensing work paired with a hybrid security platform
Pricing notesQuote-based (checked Sep 2026)
Product referencexiting.com
Feature to evaluateCloud-based Security Platform on SAP BTP purpose-built for S/4HANA licence and authorisation optimisation

Xiting is an SAP Gold Partner headquartered in Switzerland, founded in 2008 by SAP consultants, that combines a security consulting practice with an in-house software line covering authorization management, identity and access management, cybersecurity monitoring, and governance, risk and compliance. The company states it employs more than 130 people across six locations and serves more than 650 customers worldwide, with the Xiting Security Platform launched as its newest cloud product alongside its longer-standing authorization management, license analysis and role-testing tools.

The Xiting Security Platform runs on SAP Business Technology Platform and connects on-premise and cloud systems through the Xiting Connector, enabling cross-system risk analysis across hybrid landscapes that mix SAP S/4HANA with SuccessFactors, Ariba and non-SAP applications. Its modular services include identity consolidation as the central foundation, entitlement management for preparing authorizations and business roles, a provisioning framework for end-to-end access control, security monitoring with SIEM integration, and security patch management, each licensed individually as needed. The company markets a License Analysis service built specifically around the S/4HANA and SAP Cloud ERP Private shift to authorization-based user classification, and an Accelerated S/4HANA Migration offering that applies role and authorization remediation during the conversion project itself rather than only after go-live, alongside a Simplified SAP Fiori Administration capability aimed at the launchpad and catalogue assignment work a Fiori rollout otherwise leaves to manual configuration.

Pricing is quote-based and typically bundled with the underlying consulting engagement rather than sold as a standalone subscription with published tiers; the vendor states the platform is available worldwide on a subscription licensing model without listing rates, and free demonstrations are offered before any commercial commitment. Xiting suits organizations already engaging an SAP partner for role redesign or S/4HANA migration work that want the same firm to supply the supporting software. It is a narrower fit for buyers wanting a pure software purchase with no accompanying services relationship, since Xiting's delivery model is consulting-led.

Potential strengths

  • Xiting Security Platform runs on SAP BTP and connects on-premise and cloud systems for cross-system risk analysis in hybrid landscapes
  • License Analysis service is built specifically around S/4HANA and SAP Cloud ERP Private user classification changes
  • More than 130 in-house SAP security consultants back the software with implementation and role-remediation services

Trade-offs

  • Pricing is quote-based and typically bundled with project services, making like-for-like comparison with pure software vendors harder
  • Coverage is strongest in the DACH region, and English-language documentation is thinner than for larger global vendors
Sources and status

SAP Enterprise Threat Detection

enterprise
Consider forSAP customers wanting SIEM-grade threat detection built and supported directly by SAP
Pricing notesQuote-based (checked Sep 2026)
Product referencesap.com
Feature to evaluateCloud Edition built specifically for S/4HANA and delivered as a managed service by SAP

SAP Enterprise Threat Detection is SAP's own security information and event management application, sold directly by SAP rather than a third party, and available in an on-premise edition and a Cloud Edition delivered on SAP Business Technology Platform. SAP describes the Cloud Edition as the first real-time security event management and monitoring solution built specifically for SAP S/4HANA applications, shipped as a fully managed service rather than customer-operated software, which distinguishes it from the on-premise version that a customer's own team must size, install and run against its own SAP landscape.

The application reads large volumes of log data and correlates activity across the SAP landscape to build a complete picture of system behaviour, using an exclusive kernel API to send logs directly to the detection engine so that manipulating the audit trail on the source system does not hide an attack. Detection patterns identify known attack types automatically, and the Cloud Edition ships with more than 45 preconfigured attack use cases plus 24x7 alerting and monthly incident reporting under a shared baseline managed security service. Forensic investigation tools support threat hunting and anomaly detection, and user pseudonymization protects identity data during an investigation unless special authorization is granted, a control aimed at data-protection regulations such as GDPR.

Pricing is not published on the product page; SAP prices Enterprise Threat Detection through its standard price list and account teams, so a quote requires contacting SAP or an implementation partner directly rather than reading a rate off a public page. The product suits organizations that want threat detection built and supported by SAP itself, integrated tightly with S/4HANA's own audit log rather than a third-party read of it. Its scope is narrower than most other tools on this list, since it addresses threat detection and SIEM only, leaving vulnerability scanning, patch management and access governance to separate SAP or third-party products.

Potential strengths

  • Cloud Edition is purpose-built for S/4HANA applications and delivered as a fully managed 24x7 service on SAP Business Technology Platform
  • Uses an exclusive kernel API to send logs directly to the detection engine, making manipulation of the audit trail harder
  • Ships with more than 45 preconfigured attack use cases and correlates log data across the SAP landscape for forensic investigation

Trade-offs

  • On-premise deployment is infrastructure-heavy, requiring dedicated sizing and ongoing operation separate from the S/4HANA system itself
  • Scope is limited to threat detection and SIEM; vulnerability management, code scanning and access governance require separate SAP or third-party tools
Sources and status

Soterion

smb
Consider forMid-sized SAP shops needing business-friendly access risk reporting alongside S/4 FUE license optimisation
Pricing notesQuote-based (checked Sep 2026)
Product referencesoterion.com
Feature to evaluateAccess risk analysis paired with SAP Full User Equivalent license optimisation in one subscription

Soterion is a governance, risk and compliance and SAP licensing vendor that states it is not primarily a consultancy but a dedicated software provider for the SAP GRC market, distinguishing itself from vendors that sell mostly implementation services. The company reports serving more than 150 clients internationally and offers Soterion for SAP as on-premise software, a partner-run managed service, or a pay-per-use Compliance Cloud Platform, built as an independent application interfacing with SAP rather than an ABAP add-on locked into the SAP stack.

The core Access Risk Manager module identifies access risk by combining static authorization analysis with historical transaction usage data, then supports clean-up through risk remediation wizards and a What-if Allocation Simulator that tests a proposed role change against the current risk rule set before it is applied in the SAP system. A companion SAP License Manager addresses a change specific to the S/4HANA and SAP Cloud ERP Private transition: because SAP now classifies user licence type by assigned authorizations rather than legacy criteria, Soterion analyzes actual system usage to size the number of Full User Equivalent licences an organization genuinely needs, separate modules cover SAP Basis configuration review and elevated-rights monitoring, and an out-of-the-box SuccessFactors ruleset extends risk analysis to the HCM side of an S/4HANA landscape.

Pricing is not published; the vendor directs prospects to a demo request rather than a price list, though it markets flexible subscription options and a lower total cost of ownership than larger platform vendors. Soterion suits mid-sized SAP organizations that want business-friendly access risk reporting paired with S/4HANA licence optimization in one relationship, particularly those preparing a licence-cost business case ahead of a conversion. It is a narrower fit for buyers needing vulnerability scanning or custom-code security, which fall outside its GRC and licensing focus entirely, and for very large enterprises that have already standardised on a bigger cross-application governance platform.

Potential strengths

  • Translates technical GRC findings into business-friendly dashboards, reducing dependence on SAP security specialists for routine reviews
  • SAP License Manager analyses actual system usage to size Full User Equivalent licensing for S/4HANA and SAP Cloud ERP Private
  • What-if Allocation Simulator tests the risk impact of a role change before it is applied in the S/4HANA system

Trade-offs

  • Smaller vendor footprint than the larger platform players, with roughly 150 customers cited on its own site
  • No published pricing, and deployment scope is narrower than full cybersecurity suites since it does not cover vulnerability scanning or code security
Sources and status

Frequently asked questions

What does SAP S/4HANA security software cover that general SAP security tools do not?

General SAP security tools often assume the older transaction-code and dialog-transaction model of SAP GUI and ECC. S/4HANA-specific software adds coverage for the Fiori launchpad and tile authorization model that largely replaces that map, the SAP HANA database layer that sits beneath the application rather than a separate database, the authorization changes a system conversion forces, and the shared-responsibility questions that RISE with SAP and other cloud deployments raise once SAP manages the underlying infrastructure.

How does moving from ECC to S/4HANA change SAP security work?

A conversion changes the authorization model, not just the interface. Many ECC transaction codes are replaced or supplemented by Fiori apps assigned through catalogues and tiles, so existing roles need remapping. SAP HANA adds database-level authorization and audit settings absent from a classic AnyDB back end. License classification shifts from role-based assumptions to actual assigned authorizations, and tools such as Pathlock and Fastpath maintain separate, smaller rule sets for S/4HANA than for ECC.

What is Fiori catalogue and tile authorization, and why does it matter?

SAP Fiori apps are grouped into catalogues and exposed to users as tiles on a launchpad, with access controlled through PFCG roles that reference those catalogues and OData services rather than only classic transaction codes. A role that looks clean under transaction-code analysis can still expose a tile with broader OData access than intended. Tools built for S/4HANA, including Xiting's Fiori administration service and Fastpath's tile-level analysis, check this layer directly.

How is the SAP HANA database secured separately from the application layer?

SAP's own S/4HANA security guidance treats the HANA database as a distinct layer with its own users, roles, authentication and audit policies, even though end users authenticate through the ABAP application server above it. New S/4HANA systems ship with predefined mandatory HANA audit policies, and SAP recommends enabling database-level auditing alongside application logging. Database-layer access mainly concerns administrators, but weak controls there can bypass application-level authorization checks.

Which SAP S/4HANA security vendors publish their prices?

Pathlock is the clear exception in this comparison, publishing four named editions of its SAP Cybersecurity Application Controls product from a free tier to $30,000 per year. Every other vendor listed here, including SecurityBridge, Onapsis, Layer Seven Security, Saviynt, Fastpath, Xiting, SAP itself and Soterion, quotes pricing only after a sales conversation, whether because licensing depends on landscape size, identity count, modules selected, or a bundled consulting engagement.

How does RISE with SAP change security responsibility?

RISE with SAP moves infrastructure operation to SAP under a managed cloud contract, but SAP's own shared-responsibility position leaves customers accountable for custom code, user access design, application-layer configuration and data protection. Several vendors here, including Onapsis with its Secure RISE Accelerator and Layer Seven Security and SecurityBridge with agentless add-ons that avoid provisioning extra infrastructure inside a RISE tenant, market products specifically aimed at closing that customer-owned half of the model.

How should this comparison be used?

Use the documented product fit, source status, pricing and trade-offs to build a shortlist, then validate each finalist against your requirements, current vendor documentation and representative workflows.

Which tool suits a company just starting an S/4HANA conversion project?

Pathlock's Transport Control module and Onapsis's Secure RISE Accelerator are both built around the conversion or migration project itself, screening transports and mapping security tasks to SAP Activate phases respectively. Xiting's Accelerated S/4HANA Migration service and Soterion's SAP License Manager address the authorization-remediation and licence-sizing work that a conversion forces before go-live. The right starting point depends on whether the immediate priority is code and transport risk, project-phase security planning, or licence cost.

Suggest a vendor or correction

Send product details or factual corrections to editorial@statwharf.com. Corrections are free. For paid profile services, contact partnerships; payment does not determine editorial coverage or ordering.

Contact partnerships

First published September 2026. Page update dates reflect editorial changes, not a fresh check of every vendor.