Why Auditors Are Reviewing SAP Acquisitions Under DORA
AIThis post was created with the assistance of artificial intelligence (AI).

🔍 Read the full analysis: Why Auditors Are Reviewing SAP Acquisitions Under DORA on Rymvard

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

TL;DR

Why Auditors Are Reviewing SAP Acquisitions Under DORA

Rymvard says it added a SAP HANA system-replication capacity check on October 4, 2026, aimed at helping managed service providers document whether a secondary host can support production after a takeover. DORA requires financial entities to manage ICT third-party risk and test recovery, but the tool is in early access and its example estate is illustrative, not a customer deployment.

Rymvard, a data-center capacity ledger in early access, added a check on October 4, 2026 that assesses whether an SAP HANA system-replication host can carry the production system after a takeover. The feature is intended to give providers serving financial institutions a per-system capacity result they can present during resilience reviews under the EU’s Digital Operational Resilience Act (DORA); the example estate shown by Rymvard is illustrative, not a customer deployment.

The check focuses on whether the secondary host has enough capacity for the primary system’s allocation if production must fail over. Rymvard says its calculation replaces the pair’s own replica and may count test or development systems on the secondary host as stoppable to free capacity. It does not count production systems belonging to other customers as stoppable. Results are reported as fits, fits after stopping named systems, does not fit with the shortfall shown in GiB, or unknown.

Data freshness affects the result. Rymvard says a replication status older than one hour, or a memory figure older than 24 hours, produces an unknown result rather than a passing assessment. For scale-out deployments, the system is judged as a whole using the weakest host pair. The output can be exported for each system, allowing a provider to show the calculation and identify a capacity gap, such as test systems that have grown into memory needed by the replica.

Rymvard illustrates the feature with a scenario involving a managed SAP provider serving financial institutions in Luxembourg. The company says the screens are from its running product but the estate is illustrative; no customer, site or operational outcome is implied. Rymvard is in early access, publishes no prices, and says pricing is agreed with early-access partners.

At a glance
announcementWhen: Added October 4, 2026; Rymvard says the…
The developmentRymvard added an early-access check that assesses whether SAP HANA secondary hosts have enough memory to carry production workloads after a system-replication takeover.
Why Auditors Are Reviewing SAP Acquisitions Under DORA

Operational resilience · Early access

Why Auditors Are Reviewing SAP Acquisitions Under DORA

A new Rymvard check asks one practical recovery question: can the secondary SAP HANA host carry production after a takeover? It can document a capacity result, while leaving the broader resilience assessment to providers and financial institutions.

Oct 4Feature announced · 2026
1 hourReplication data freshness
24 hoursMemory data freshness
Jan 17DORA applied · 2025

01 / What the check covers

A narrow question with audit value

Rymvard says the early-access feature evaluates whether a secondary HANA system-replication host has enough memory for the primary system’s production allocation.

Capacity comparison

Can the replica fit?

The calculation replaces the pair’s own replica and compares the required allocation with available capacity on the secondary host.

Conditional result

What can be stopped?

Test or development systems may be counted as stoppable to free capacity. Production workloads belonging to other customers are not.

Scale-out estates

Weakest pair governs

For scale-out deployments, the system is judged as a whole using its weakest host pair. Results can be exported per system.

02 / How a result is produced

From system data to a reviewable outcome

The result can show a fit, a condition to free space, a shortfall in GiB, or insufficiently fresh data.

01

Read the system pair

Collect replication status and memory figures for the primary and secondary systems.

02

Compare capacity

Assess whether the secondary host can carry the production allocation after takeover.

03

State the condition

Report a fit, named stoppable systems, a capacity gap, or an unknown result.

04

Export per system

Give providers evidence to discuss assumptions and identify capacity gaps in a review.

>1h

Replication status older than one hour produces an unknown result.

>24h

Memory data older than 24 hours produces an unknown result, not a pass.

03 / DORA in context

Capacity is one part of resilience

DORA is Regulation (EU) 2022/2554. Since January 17, 2025, it has applied to financial entities and covers digital operational resilience, ICT risk, third-party oversight, and recovery testing.

A financial institution that relies on an external SAP provider may need evidence that recovery arrangements can work in practice. A per-system capacity result can help surface a gap before a resilience test—for example, where test systems have grown into memory needed by a replica.

But host memory is only one dependency. Recovery procedures, service dependencies, input quality, and testing also matter. The provider remains responsible for validating the data and operational assumptions behind each assessment.

Capacity check→ Document assumptions→ Plan recovery test→ Broader resilience review

04 / Scope and evidence

What the announcement does—and does not—show

Rymvard describes a running product feature in early access, illustrated with a Luxembourg provider scenario.

Illustrative estate

The company says the screens show its product, but the estate is illustrative. No customer, site, or operational outcome is implied.

No compliance certification

The tool addresses a host-capacity question. It does not establish that a service can fully recover or that every DORA obligation is met.

Adoption not disclosed

No customer deployment, audit finding, measured recovery improvement, or independent validation has been disclosed.

Early access terms

Rymvard publishes no prices; it says pricing is agreed with early-access partners. Broader availability timing has not been announced.

Evidence to watch next: customer use, independent validation, and results from actual resilience tests. Until then, the feature is best understood as an early-access capacity check that may support one part of resilience documentation.

Documenting SAP Failover Capacity

DORA has applied since January 17, 2025, and requires financial entities to manage ICT risk, including risks linked to services supplied by ICT third parties. It also sets expectations for testing the recovery of critical services. A financial institution relying on an external provider for SAP systems may therefore need evidence that recovery arrangements are workable, not just a statement that replication is configured.

The new check addresses one narrow technical question within that broader oversight: whether a secondary HANA host has sufficient memory to take over the production allocation. A recorded result can help a provider and its financial-sector clients identify a gap before a resilience test. It does not, by itself, establish that an entire service can recover successfully or satisfy every DORA obligation. Capacity is only one element of operational resilience, alongside matters such as recovery procedures, dependencies and testing.

The distinction between a measured result and a general assurance matters in an audit. A result marked unknown because of stale data is not treated as a pass, while a result that depends on stopping specified non-production systems identifies a condition that must be understood and managed. That can make the assessment more useful than a simple yes-or-no claim, while leaving the provider responsible for validating the inputs and operational assumptions.

Amazon

SAP HANA system replication capacity check

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

DORA and HANA Replication

DORA is Regulation (EU) 2022/2554. It establishes requirements for financial entities’ digital operational resilience, including ICT risk management and oversight of ICT third-party providers. Its application date was January 17, 2025. The regulation’s requirements apply to financial entities; a technology provider’s tool does not itself certify compliance.

SAP HANA system replication maintains a secondary system that can be used in a takeover. Whether that arrangement can support production depends in part on available resources at the secondary site. If other workloads have consumed capacity, replication alone may not mean the secondary host can carry the primary allocation. Rymvard’s check is designed to surface that capacity issue for systems using HANA system replication, including scale-out systems assessed by their weakest host pair.

Rymvard describes itself as a capacity ledger for data centers. Its October 4 announcement concerns a specific feature, not a regulatory finding or an independent audit of a customer environment. The company says the product is operating in early access and uses an illustrative Luxembourg scenario to show how the check works.

“A replication status older than one hour or a memory figure older than 24 hours makes the result unknown — never fine.”

— Rymvard

Amazon

SAP HANA secondary host memory upgrade

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Limits of the Published Example

No customer deployment, audit finding or measured improvement in recovery outcomes has been disclosed. Rymvard says the Luxembourg provider scenario is illustrative and does not imply a real customer, site or outcome. The company also has not published pricing; it says terms are agreed with early-access partners.

The announcement does not establish whether auditors or financial institutions have adopted the exported results, or whether the check has been independently validated. It also does not describe how inputs are verified across all deployments or how providers should handle operational changes between measurements. The result addresses host memory capacity under stated assumptions; it is not a complete assessment of recovery readiness or DORA compliance.

Amazon

SAP HANA disaster recovery tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Early Access and Provider Testing

Rymvard says the feature is running and available in its early-access product. Providers considering it will need to determine whether the capacity data and stopping assumptions reflect their own live environments, and whether exported per-system results fit their internal resilience and audit processes. Any assessment based on stale replication or memory data will be marked unknown under the company’s stated rules.

The next evidence to watch for is customer use, independent validation or disclosed results from actual resilience tests. Rymvard has not announced a timeline for broader availability or public pricing. Until such details are available, the development is best understood as an early-access capacity check intended to support one part of third-party ICT resilience documentation, not as proof that a service meets DORA requirements.

Primary source: Regulation (EU) 2022/2554 (DORA) · via Rymvard

Amazon

SAP HANA high availability hardware

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What did Rymvard announce?

Rymvard added a check that assesses whether an SAP HANA system-replication secondary host can carry the primary system’s production allocation after a takeover. It can return a fit, conditional fit, capacity shortfall or unknown result.

Does the check certify DORA compliance?

No. It addresses a specific host-capacity question relevant to recovery planning. DORA covers broader ICT risk management, third-party oversight and resilience testing, and the tool is not described as a compliance certification.

Why can the result be marked unknown?

Rymvard says the result is unknown if replication status data is more than one hour old or memory data is more than 24 hours old. The company says stale data is not treated as a passing result.

Is the Luxembourg example based on a real customer?

Rymvard says the scenario is illustrative and does not imply a customer, site or outcome. The company describes the product as running in early access.

Primary source: Regulation (EU) 2022/2554 (DORA) · via Rymvard

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Anthropic Backtracks Spyware Targeting Chinese Users After Controversy

Anthropic has halted its spyware project targeting Chinese users following public and regulatory controversy, marking a significant policy shift.

CVE-2026-86218: N-able N-central Static Code Injection Vulnerability Actively Exploited (CISA KEV)

A critical vulnerability in N-able N-central is actively exploited, allowing pre-authentication remote code execution. Immediate mitigation is advised.

How to Choose Personal VPN Services

Learn how to choose, configure, and verify your personal VPN service for secure, private internet access. Clear instructions for all skill levels.

CISA Alert: Water Sector PLC Targeting

CISA issues alert about cyber threats targeting water sector PLC systems, highlighting ongoing malicious activities and potential risks to critical infrastructure.