SStatWharf

Best SAP Security Tools (2026): Top 9 Compared

Updated September 2026By StatWharf Editorial9 vendorsMethodology

Compare buyer fit, pricing notes and trade-offs. How entries are ordered.

Compare at a glance

Select a vendor for details and sources. Scroll the table horizontally on smaller screens.

SAP Security Tools: vendor fit and recorded pricing
VendorConsider forPricing notes
Onapsis PlatformenterpriseLarge SAP and Oracle estates needing vulnerability, threat and code security in one platformQuote-based (checked Sep 2026)
bowbridge Anti-Virus for SAPspecialistAny SAP landscape with file uploads or downloads that standard antivirus tools missQuote-based (checked Sep 2026)
SecurityBridge Platformmid-marketSAP teams wanting in-system detection, code scanning and patch management in one toolNo list price on reviewed page (checked Sep 2026)
SAP Enterprise Threat DetectionenterpriseSAP-committed enterprises wanting SAP's own SIEM, including as a managed serviceQuote-based (checked Sep 2026)
Layer Seven Security (CXS)specialistBudget-conscious SAP teams wanting agentless vulnerability, threat and code securityQuote-based (checked Sep 2026)
IBM Security Guardium for SAP HANAenterpriseOrganizations already running Guardium elsewhere that want SAP HANA in the same programQuote-based (checked Sep 2026)
Pathlock SAP Threat DetectionenterpriseOrganizations evaluating Pathlock for access governance that also want real-time threat detectionFrom $15,000/year for the Professional edition, which includes Threat Detection (checked Sep 2026)
SAP Focused Run (CSA)enterpriseLarge landscapes already centralizing lifecycle management on SAP Focused RunQuote-based (checked Sep 2026)
Xiting Security PlatformspecialistMid-sized SAP shops wanting one vendor for authorization cleanup and compliance monitoringQuote-based (checked Sep 2026)

These comparisons draw on public product information, not hands-on testing of every tool. Source records identify available references and checks; missing evidence is marked. Buyer fit is an editorial assessment, not a measured performance score. How to use this research.

SAP security tools protect the running SAP estate: they scan for missing patches and insecure configuration, watch logs for attack or misuse in real time, check custom ABAP code for exploitable flaws before it reaches production, and scan files moving through SAP for malware. That is narrower than segregation-of-duties analysis or software asset optimization, which live in separate SAP tooling categories; a security tool answers whether the system is patched, correctly configured and free of active attacks, not whether a user’s authorizations create a fraud risk or a license contract is sized correctly.

The market splits into four groups. SAP sells native tooling: Enterprise Threat Detection for SIEM-style log correlation, and Focused Run’s Configuration & Security Analytics for compliance checking. Independent SAP-only platforms, led by Onapsis and SecurityBridge with Layer Seven Security as a lower-cost alternative, combine scanning, threat detection, code security and patch management under one console. Data-security platforms such as IBM Guardium extend database monitoring to SAP HANA. Specialists, including Xiting and bowbridge, cover one problem in depth. Compare documented fit, source status and trade-offs before shortlisting.

Vendor details and trade-offs

Onapsis Platform

enterprise
Consider forLarge SAP and Oracle estates needing vulnerability, threat and code security in one platform
Pricing notesQuote-based (checked Sep 2026)
Product referenceonapsis.com
Feature to evaluateFive-area coverage: vulnerability management, code security, threat detection, BTP security and compliance

The Onapsis Platform is a cybersecurity and compliance product for business-critical applications, built by Onapsis for SAP and Oracle landscapes across ERP, CRM, PLM, HCM, SCM and BI systems. Onapsis frames the product around five problems: vulnerability management, custom code security, threat detection, SAP Business Technology Platform security and compliance automation. The vendor positions itself as an SAP-endorsed solution, and customer references cite use for managing SAP Security Notes, prioritizing remediation and supporting SOX and PCI audit evidence.

Three core capabilities sit under that framing. Assess identifies vulnerabilities, understands risk and prioritizes remediation across the landscape, covering legacy on-premises systems and RISE with SAP. Defend continuously monitors for threats and misuse and integrates with SIEM tools. Control adds analytics, reporting and workflow automation for governance uses such as SOX or GDPR evidence. A separate custom code security capability analyzes new and migrated ABAP code before production, and dedicated Assess and Defend modules extend the same approach to SAP BTP. Security Advisor layers an AI-assisted, 360-degree view of security posture across these modules.

Pricing is not published, and no trial page is reachable; Onapsis Platform is sold as an annual subscription scoped to the modules and systems licensed, quoted after a scoping conversation. The product suits large SAP and Oracle estates, typically regulated enterprises, where combining vulnerability management, threat detection and compliance automation under one platform justifies a quote-only contract. It is a heavier commitment than a single-purpose scanner, so a buyer with a narrow requirement, such as patch tracking, should scope against Assess first.

Potential strengths

  • Assess, Defend and Control cover vulnerability management, real-time threat monitoring and ITGC automation together
  • Dedicated Assess and Defend modules extend coverage specifically to SAP Business Technology Platform
  • Security Advisor adds an AI-assisted, 360-degree view of overall SAP security posture

Trade-offs

  • No pricing or trial information is published anywhere on the vendor site
  • The five-area platform is more than a team with one narrow requirement, such as patch tracking, is likely to need
Sources and status

bowbridge Anti-Virus for SAP

specialist
Consider forAny SAP landscape with file uploads or downloads that standard antivirus tools miss
Pricing notesQuote-based (checked Sep 2026)
Product referencebowbridge.net
Feature to evaluateThe only content-security tool built for SAP's NW-VSI interface, with a choice of engines

bowbridge has built its product line around one narrow problem: scanning files that move in and out of SAP for malware, a job the vendor argues standard antivirus software cannot do because of how SAP handles files. Files uploaded to SAP are encrypted in transit and stored in an SAP-proprietary repository, which operating-system-level antivirus programs cannot see into, and while SAP exposes an anti-virus interface for this purpose, called NW-VSI, ordinary antivirus software cannot speak it. Anti-Virus for SAP Solutions is built against that interface, and bowbridge states it has met SAP's certification standards for four consecutive three-year periods.

The product scans files at upload and download, with a choice of engines: embedded engines from SOPHOS and McAfee, the open-source ClamAV engine, or a centralized virus-scanning server reached over the ICAP protocol, giving a buyer control over cost and engine preference rather than one fixed option. Scanning runs entirely in memory to avoid the disk overhead a traditional scan would add, and detection extends to cross-site scripting payloads hidden inside a file, with full access into SAPCAR archive contents rather than treating them as opaque.

Pricing is not published; prospective buyers can try the product for 30 days before contacting bowbridge for a quote. The product suits any organization running SAP with file upload or download capability, since unscanned file traffic is a gap general antivirus tools do not close. It is a narrow, single-purpose tool rather than a broad platform, fitting alongside a wider vulnerability or threat-detection product rather than replacing one.

Potential strengths

  • Purpose-built for NW-VSI, since SAP encrypts and stores uploaded files in a proprietary repository
  • Offers a choice of SOPHOS, McAfee, ClamAV, or ICAP-connected centralized scanning engines
  • SAP-certified for four consecutive three-year periods and recommended by SAP and McAfee

Trade-offs

  • Narrow, single-purpose scope: malware and content security only, not vulnerability or configuration
  • No published pricing; buyers get a 30-day trial before needing to contact the vendor
Sources and status

SecurityBridge Platform

mid-market
Consider forSAP teams wanting in-system detection, code scanning and patch management in one tool
Pricing notesNo list price on reviewed page (checked Sep 2026)
Product referencesecuritybridge.com
Feature to evaluateVirtual Patching automatically shields systems the moment a new SAP Security Note is issued

SecurityBridge Platform is a cybersecurity and compliance product for SAP, sold as a native, low-footprint add-on that the vendor states runs live in 48 hours, with prebuilt detection rules and compliance baselines enforcing controls inside SAP from day one. Rather than sitting alongside SAP as an external scanner, it installs inside the SAP stack and reads users, roles, code, logs, configuration and behavior directly from the ABAP and HANA layers it protects. The vendor states it protects more than 8,000 SAP production systems globally, and in 2023 it acquired Protect4S, a Dutch SAP security specialist, folding its vulnerability engine into the product.

The platform groups capability into modules covering Patch Management, Vulnerability Management, Code Vulnerability Analysis, Threat Detection, SIEM Integration, Privileged Access Management and Identity Protection, visible from a central Security Dashboard. A machine-learning layer underpins anomaly detection, adapting to a customer's own baseline. In October 2024, alongside the version 6.30 release, the vendor added Virtual Patching, linking Patch Management and Threat Detection so a system is shielded and administrators alerted for unpatched vulnerabilities as soon as SAP issues the Security Note on Patch Tuesday.

Pricing is not published; cost is quoted after a scoping conversation based on systems and modules activated, sold as a yearly subscription. SecurityBridge suits SAP teams wanting in-system detection and patch tracking without standing up a separate external monitoring layer. It is a weaker fit for organizations needing database-layer auditing across non-SAP systems, since its logic is built around the SAP application and HANA layers rather than a general-purpose multi-database platform.

Potential strengths

  • States protection for more than 8,000 SAP production systems, installed natively inside the SAP stack
  • Virtual Patching, added in version 6.30, shields unpatched systems automatically on SAP Patch Tuesday
  • Vendor states the platform goes live in 48 hours with prebuilt detection content

Trade-offs

  • No pricing page is published; cost is quoted after a scoping conversation
  • Detection logic is built for the SAP application and HANA layers, not non-SAP databases
Sources and status

SAP Enterprise Threat Detection

enterprise
Consider forSAP-committed enterprises wanting SAP's own SIEM, including as a managed service
Pricing notesQuote-based (checked Sep 2026)
Product referencesap.com
Feature to evaluateSAP's own SIEM, fed by an exclusive kernel API and offered as a 24x7 managed service

SAP Enterprise Threat Detection, commonly abbreviated SAP ETD, is a security information and event management application built and sold by SAP SE itself rather than a third party. SAP positions it as real-time SIEM intelligence that enforces data governance and identifies cybersecurity threats as they happen, rather than during a later forensic review. It can be deployed on-premises or in the cloud, and SAP also offers it as a managed service operated around the clock, for buyers who want the capability without staffing a dedicated SAP security operations shift.

The application's core job is log correlation: it ingests a large volume of log data across the landscape and correlates it into a complete picture of activity, including forensic detection of previously unknown attack variants. An exclusive kernel API sends logs directly to ETD, which SAP notes makes tampering with the log trail more difficult. Detection patterns identify SAP-specific threats without custom code, and generated alerts support investigations that integrate with external processes, including user pseudonymization resolved only with special authorization. Detection operates at both the application server and database level.

SAP does not publish a list price for ETD; it is licensed under a standard SAP contract and quoted through sales or a partner, with cost driven by landscape size. It suits organizations committed to the SAP ecosystem that want detection logic built by the vendor that defines the transaction codes being analyzed, particularly where the managed-service option removes the need for in-house SAP SIEM expertise. It fits poorly for a smaller estate without any security operations function.

Potential strengths

  • Built and maintained by SAP, so detection content understands SAP-specific attack patterns
  • An exclusive kernel API sends logs directly to ETD, which SAP states resists tampering
  • Available as a 24x7 managed service for buyers without a dedicated SecOps shift

Trade-offs

  • SAP does not publish pricing; cost is quoted through sales and driven by landscape size
  • Requires a dedicated HANA-based deployment and staff who can act on the alerts it generates
Sources and status

Layer Seven Security (CXS)

specialist
Consider forBudget-conscious SAP teams wanting agentless vulnerability, threat and code security
Pricing notesQuote-based (checked Sep 2026)
Product referencelayersevensecurity.com
Feature to evaluateAgentless deployment in about six hours covering 5,000-plus vulnerability checks and 1,200 threat patterns

Cybersecurity Extension for SAP, referred to by the vendor as CXS, is built by Layer Seven Security, an SAP-certified partner that describes the product as an agentless platform protecting SAP S/4HANA, SAP RISE and SAP BTP from cyberattacks and advanced persistent threats. Designed for on-premises, cloud and hybrid architectures, it aims to close a gap the vendor calls out directly: standard security tools generally lack visibility into the SAP application layer, so CXS bridges SAP administration and IT security across the application, database and host layers.

The product organizes coverage into three pillars. Vulnerability management runs daily automated scans across more than 5,000 checks spanning SAP applications, databases and hosts. Threat detection applies more than 1,200 patterns to flag indicators of compromise and forwards alerts to SIEM tools including Splunk, QRadar and Sentinel. Custom code security detects more than 300 vulnerability types in ABAP and SAPUI5 and can automatically block a risky transport. Patch management flags missing security notes, and the vendor states deployment takes about six hours with no new agents, agentless by design.

Pricing is not published; CXS is sold as a subscription quoted directly by Layer Seven Security based on systems covered. The vendor states more than 100 global enterprises use the product. CXS suits SAP teams wanting vulnerability, threat and code security together from a smaller, services-rooted vendor with fast, agentless deployment. It is a less natural fit for a buyer wanting the largest ecosystem, since Layer Seven Security is considerably smaller than the two market leaders it is most compared against.

Potential strengths

  • Daily scans cover more than 5,000 vulnerability checks across applications, databases and hosts
  • Custom code security detects 300-plus vulnerability types and can block a risky transport
  • Deployment onto existing infrastructure takes about six hours with no new agents

Trade-offs

  • No published pricing; cost is quoted directly by the vendor based on systems covered
  • Considerably smaller than Onapsis and SecurityBridge, the two vendors it is most compared against
Sources and status

IBM Security Guardium for SAP HANA

enterprise
Consider forOrganizations already running Guardium elsewhere that want SAP HANA in the same program
Pricing notesQuote-based (checked Sep 2026)
Product referenceibm.com
Feature to evaluateMore than 92 out-of-the-box SAP HANA vulnerability assessments built on CVEs

IBM Security Guardium Data Protection is IBM's enterprise data security platform, and IBM publishes a dedicated variant, Guardium Data Protection for SAP HANA, extending the same discovery, monitoring and vulnerability-assessment engine to SAP's in-memory database. IBM frames the SAP-specific challenge directly: sensitive data can be dispersed across hundreds of columns, ruling out simple column-level monitoring, while misconfigured privileges and missing patches leave the environment exposed regardless of the ABAP layer above it. Guardium also covers other relational, big data and cloud sources, so SAP HANA is one environment inside a broader program.

For SAP HANA specifically, Guardium runs automated discovery and classification to find where sensitive data lives, using pre-built templates for CCPA, SOX, PCI, GDPR, PII and HIPAA, and monitors access in real time based on the who, what, where, when and how of each operation. Guardium ships with more than 92 out-of-the-box SAP HANA vulnerability assessments built on CVEs and SAP's own recommended practices, with results flowing into tools such as ServiceNow. Pre-built policies let the platform block activities automatically and integrate with SecOps and ITOps tooling.

IBM does not publish a fixed price; it is sold through IBM sales and cloud marketplace listings requiring a custom quote, with cost driven by data sources under management. It suits organizations already running Guardium across other databases that want SAP HANA folded into the same program. It is a weak substitute for the SAP-application-layer controls elsewhere here, since the HANA variant addresses the database layer only and does not scan ABAP code or authorizations.

Potential strengths

  • Discovers and classifies sensitive HANA data using templates for CCPA, SOX, PCI, GDPR and HIPAA
  • Real-time monitoring captures the who, what, where, when and how of each data access
  • Integrates with SecOps and ITOps tooling, including ServiceNow, for incident response

Trade-offs

  • Covers the HANA database layer only, not ABAP custom code or authorizations
  • Sold as part of a broader multi-database platform, not a purpose-built SAP product
Sources and status

Pathlock SAP Threat Detection

enterprise
Consider forOrganizations evaluating Pathlock for access governance that also want real-time threat detection
Pricing notesFrom $15,000/year for the Professional edition, which includes Threat Detection (checked Sep 2026)
Product referencepathlock.com
Feature to evaluateMore than 70 log sources correlated against 1,500-plus SAP-specific detection signatures

Pathlock's SAP Threat Detection Tool for Enterprise is a real-time monitoring and anomaly-detection product from Pathlock, a large access-governance and application-security vendor whose SAP portfolio also includes segregation-of-duties analysis and access certification. This module is scoped specifically to detecting and responding to threats across a running SAP landscape rather than analyzing who is entitled to do what, which is why it appears in a security-tools comparison rather than an access-governance one; Pathlock frames the problem as manual threat detection failing to keep up with log volume across SAP cloud and on-premises systems.

The product analyzes more than 70 log sources across an SAP landscape and correlates events using more than 1,500 out-of-the-box, SAP-specific detection signatures to surface misconfigurations, vulnerabilities and multi-step attack patterns, including insider threats and data exfiltration attempts. It enriches each event with context to speed root-cause investigation, offers flexible search, and prioritizes alerts by severity. Dashboards and reports are built for different stakeholders, and the product integrates with external SIEM and SOAR platforms so enriched SAP events feed existing workflows.

Pathlock publishes pricing for this module through its Cybersecurity Application Controls edition page, which lists Threat Detection starting in the Professional edition at $15,000 a year; the module is not sold as a standalone line item outside that bundle. The tool suits organizations already evaluating Pathlock for access governance that also want real-time threat detection under the same vendor relationship. It is a less natural standalone choice for a team wanting threat detection only, since the module is typically positioned as part of Pathlock's wider access-risk relationship rather than sold on its own.

Potential strengths

  • Analyzes 70-plus log sources using over 1,500 out-of-the-box SAP-specific detection signatures
  • Enriches raw log events with context to speed root-cause investigation
  • Integrates with external SIEM and SOAR platforms to feed enterprise security workflows

Trade-offs

  • Typically sold as part of Pathlock's broader access-governance relationship, not standalone
  • Threat Detection is priced only as part of the Professional edition ($15,000/year) or higher of Pathlock's Cybersecurity Application Controls bundle, not as a standalone line item
Sources and status

SAP Focused Run (CSA)

enterprise
Consider forLarge landscapes already centralizing lifecycle management on SAP Focused Run
Pricing notesQuote-based (checked Sep 2026)
Product referencesupport.sap.com
Feature to evaluatePolicy-based Validation, Changes, Search and Store Browser built into SAP's own ALM platform

SAP Focused Run is an SAP-owned application lifecycle management product for large SAP landscapes, sold and supported directly by SAP SE, and Configuration & Security Analysis, abbreviated CSA, is the capability inside it most relevant to a security buyer. CSA becomes available once a managed system has completed Single System Integration, after which Simple Diagnostics Agents on each system collect configuration data and transfer it to the central Focused Run system, where it is compared against the previous snapshot and stored in HANA tables that make up the Configuration and Change Database.

CSA, launched from the Focused Run Fiori launchpad, provides four views: Validation checks configuration items against a defined policy, such as a password-length setting, reporting results at the system, check, or systems-by-checks matrix level with drilldown; an Exemptions function suppresses a specific check-and-system pair for a period without disabling it landscape-wide. Changes shows configuration drift over time, Search finds items across large landscapes, and Store Browser exposes the raw data. Supported products span NetWeaver ABAP and Java, S/4HANA, and databases including HANA, ASE, MaxDB and Oracle.

SAP prices Focused Run by gigabytes of monitoring data stored, so cost scales with the number of managed systems; SAP does not publish a rate card, and buyers negotiate through SAP sales or a partner. Focused Run suits large SAP landscapes already centralizing lifecycle management, where adding CSA is a small incremental step once the platform is deployed. It is a poor starting point for an organization not already committed to Focused Run for broader landscape management.

Potential strengths

  • Validation reports configuration compliance at system, check, or full matrix level with drilldown
  • An Exemptions function suppresses a specific check for a period without disabling it landscape-wide
  • Supports NetWeaver ABAP and Java, S/4HANA, and databases including HANA, ASE, MaxDB and Oracle

Trade-offs

  • Requires Single System Integration and Simple Diagnostics Agents before CSA becomes available
  • Licensed by gigabytes stored, on top of Focused Run's own separate HANA infrastructure
Sources and status

Xiting Security Platform

specialist
Consider forMid-sized SAP shops wanting one vendor for authorization cleanup and compliance monitoring
Pricing notesQuote-based (checked Sep 2026)
Product referencexiting.com
Feature to evaluateAbout 150 pre-built assessments paired with a separate real-time SIEM Cockpit

Xiting is a Swiss SAP security specialist best known for its authorization management tooling, but the vendor also sells a distinct internal control system product, called Security Architect, aimed at continuous vulnerability and compliance monitoring rather than authorization design. Xiting frames Security Architect as the operational counterpart to that authorization work: once access has been designed and cleaned up, Security Architect watches the running system afterward for configuration drift and emerging vulnerabilities, so a buyer should be clear which of its products addresses which problem before requesting a quote.

Security Architect ships with roughly 150 pre-built, configurable compliance and vulnerability assessments covering SAP system settings, built around SAP Baseline Security, DSAG and GDPR requirements, and centralizes monitoring so a team can check multiple SAP systems from one place. Vulnerabilities and compliance violations surface through alerting, reports and dashboards, with a mitigation-control framework for prioritizing remediation. For real-time detection rather than periodic checking, Xiting offers a separate, complementary product called SIEM Cockpit, which identifies security events as they happen and forwards them to an external SIEM; a buyer wanting both typically licenses the two together rather than treating Security Architect alone as complete.

Pricing is not published; Xiting quotes cost after a project-based conversation about which modules and how many systems a customer wants covered, with implementation delivered as a consulting engagement. It suits mid-sized SAP shops wanting one vendor for both authorization cleanup and ongoing monitoring. It is a weaker fit for an organization wanting real-time threat detection without also budgeting for the separate SIEM Cockpit.

Potential strengths

  • Centralizes roughly 150 pre-built compliance and vulnerability assessments across SAP systems
  • Built around SAP Baseline Security, DSAG and GDPR requirements, not a generic checklist
  • A companion SIEM Cockpit product adds real-time event detection and forwarding

Trade-offs

  • Security Architect alone is not real-time detection; that needs SIEM Cockpit separately
  • Implementation is typically a consultant-led engagement, not a self-service rollout
Sources and status

Frequently asked questions

What do SAP security tools protect against?

SAP security tools protect the running SAP estate rather than the business logic that decides who can approve a payment. They scan for missing patches and insecure configuration, watch logs for signs of active attack or misuse, check custom ABAP code for exploitable flaws before production, and in some cases scan files for malware. That scope sits alongside, not inside, access governance and license management, separate SAP tooling categories.

How do SAP security tools differ from SAP access risk and license management tools?

Access risk and license management tools answer different questions about the same SAP estate. Access risk tools analyze whether combined authorizations create a segregation-of-duties conflict, and license tools measure whether a contract is sized correctly. The tools here instead ask whether the system is patched, correctly configured and free of active attacks, which is why Pathlock and other dual-purpose vendors are represented here only by their threat-detection and code-security modules.

Which vendors in this comparison publish their prices?

None of the nine vendors publish a price list, tier pricing or a reachable pricing page; every listing here is quote-based. That is typical for enterprise SAP security software, where cost depends heavily on the number of SAP systems, the modules licensed and, for SAP's own products, the underlying HANA infrastructure required to run them. Buyers should expect a scoping call before receiving any number.

How should this comparison be used?

Use the documented product fit, source status, pricing and trade-offs to build a shortlist, then validate each finalist against your requirements, current vendor documentation and representative workflows.

What is the difference between SAP Enterprise Threat Detection and a third-party option like SecurityBridge or Layer Seven Security?

SAP Enterprise Threat Detection is built and licensed by SAP itself, runs on a dedicated HANA system, and is available as a 24x7 managed service. SecurityBridge and Layer Seven Security install inside or alongside the SAP stack and bundle vulnerability scanning and patch management alongside threat detection in one subscription. A buyer wanting broader coverage in one console typically looks at the third-party platforms instead.

How do these tools help with SAP's monthly security patch releases?

SAP publishes Security Notes on a fixed monthly Patch Day. Several vendors automate the response: SecurityBridge's Virtual Patching shields a system as soon as a new Note is issued, and Layer Seven Security's CXS flags missing notes as part of its patch management pillar. SAP Focused Run's CSA can run Security Note policy files against a landscape to track which systems still need one applied.

Do these tools cover custom ABAP code, or only standard SAP configuration and patching?

Coverage varies by vendor. Onapsis, SecurityBridge and Layer Seven Security include dedicated code security scanning, checking ABAP and, in some cases, SAPUI5 code for exploitable flaws before a transport reaches production. SAP ETD, SAP Focused Run's CSA, IBM Guardium, Pathlock's threat module and bowbridge do not scan custom code at all; instead, they each focus on log correlation, configuration compliance, database monitoring or malware scanning.

Can these tools run on RISE with SAP, SAP BTP or cloud-hosted SAP systems, or only classic on-premises landscapes?

Most platform-scale vendors here explicitly support modern deployment models. Onapsis documents coverage for RISE with SAP and offers dedicated Assess and Defend modules for SAP BTP specifically. Layer Seven Security's CXS is built for SAP S/4HANA, SAP RISE and SAP BTP together, and SAP ETD can be deployed on-premises or in the cloud. bowbridge's cloud edition also extends its file scanning to SAP BTP as well.

Suggest a vendor or correction

Send product details or factual corrections to editorial@statwharf.com. Corrections are free. For paid profile services, contact partnerships; payment does not determine editorial coverage or ordering.

Contact partnerships

First published September 2026. Page update dates reflect editorial changes, not a fresh check of every vendor.