Triple Compliance refers to the simultaneous applicability of three EU regulatory frameworks. Each imposes its own documentation requirements on SAP change processes, yet their requirements overlap in substance: the Network and Information Security Directive 2 (NIS2, Directive (EU) 2022/2555), the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), and the EU AI Act (Regulation (EU) 2024/1689).
Substantive overlap: All three frameworks require a seamless audit trail documenting who made which change to which system, with what approval, and when. While they differ in scope, sanction frameworks, competent authorities, and application dates, they all rely on the same type of operational evidence.
As of May 2026, the application dates are as follows:
DORA has been applicable since January 17, 2025. SAP has been classified as a Critical ICT Third-Party Service Provider (CTPP) since November 2025 and is subject to direct oversight by the European Supervisory Authorities (ESAs), with BaFin acting as the national coordinating body in Germany. A February 2026 analysis by Computerwoche reports that approximately 44 percent of surveyed financial service providers are experiencing difficulties with DORA implementation.
NIS2 in Germany: The NIS2UmsuCG has been in effect since December 6, 2025, with no transition period. The BSI registration deadline passed on March 6, 2026. The BSI has been in the operational enforcement phase since May 2026. Approximately 29,500 entities in Germany are affected. Austria: The NISG 2026 comes into effect on October 1, 2026, with the Federal Office for Cybersecurity serving as the national authority.
EU AI Act: Article 4 (AI literacy) has been applicable since February 2, 2025. Article 5 (prohibited practices) has been applicable since February 2, 2025, and was expanded by the Digital Omnibus on May 7, 2026, to include bans on CSAM and nudifiers (applicable from December 2, 2026). Article 26 (operator obligations) and Article 50 (transparency obligations) apply from August 2, 2026, and were not postponed by the Omnibus. High-risk provider obligations under Annex III were postponed to December 2, 2027, and Annex I to August 2, 2028.
A February 2026 analysis by digital-chiefs.de characterizes the Triple Compliance situation as a regulatory overlap with redundant documentation requirements if each framework is operationalized separately. These parallel requirements raise a key operational question: should you implement an integrated audit trail or three parallel compliance programs?
The three frameworks require different categories of compliance that overlap at the SAP change process level.
Mandatory Category A: Audit Trail and Logging. DORA Article 28 requires risk management for ICT third parties, including traceable documentation. NIS2 Article 21 requires vulnerability handling and patch management with proof. EU AI Act Article 12 requires automatic logging with a minimum retention period of six months. In SAP practice: an audit trail at the object level, with every change linked to the initiator's identity, approval path, test coverage, security-relevant findings, and deployment timestamp.
Mandatory Category B: Incident Reporting. DORA Article 17 requires major incident reporting to the competent supervisory authority. NIS2 requires an early warning within 24 hours, an intermediate report within 72 hours, and a final report within one month. EU AI Act Article 26(5) requires the reporting of serious incidents to providers and market surveillance authorities. In SAP practice: a unified incident workflow that simultaneously serves the reporting paths for BaFin (DORA), the BSI (NIS2 and EU AI Act in Germany), and, where applicable, the providers.
Mandatory Category C: Supply Chain and Third-Party Risk Management. DORA Article 28 requires a third-party risk analysis for ICT service providers. NIS2 Article 21 mandates supply chain security obligations. The EU AI Act Article 26 requires the use of AI systems in accordance with provider instructions and a DPIA where required under GDPR. In SAP practice: an inventory of all external parties with read or write access, including Community MCP servers, external consultants, managed service providers, and BTP extension suppliers.
Mandatory Category D: Human Oversight and Approval Chain. DORA requires clear responsibility and approval paths in ICT risk management. NIS2 § 38 BSIG establishes personal liability for management. The EU AI Act Article 14 requires human oversight for high-risk AI systems, with the authority to intervene and stop operations. In SAP practice: four-eyes principle in the change workflow, escalation of ambiguous AI decisions, and documented management oversight.
Mandatory Category E: Training and Competence. All three regulations require training. NIS2 explicitly for management bodies (§ 38 BSIG). The EU AI Act Article 4 for personnel operating AI systems. DORA for ICT risk management personnel. In practice: a training program with documentation of attendance and content.
Risk 1: Three parallel compliance projects without consolidation. A typical DACH organization has NIS2 under the CISO, DORA in the IT risk function (often in audit or operational risk), and the EU AI Act in a newly created function (CAIO or as an extension of the compliance officer). If these three lines work separately, redundant requirements are placed on the same SAP team, doubling the workload.
Risk 2: Different sanction frameworks complicate prioritization. Sanctions for violations: EU AI Act up to 35 million EUR or 7 percent (Article 5 prohibitions), 15 million EUR or 3 percent (high-risk violations Articles 16, 26), 7.5 million EUR or 1 percent (information to authorities). NIS2 in Germany up to 10 million EUR or 2 percent (essential entities), 7 million EUR or 1.4 percent (important entities). DORA according to Article 35 depends on the member state's sanction regime, in Germany according to KWG/WpHG. In practice, the diversity of these frameworks leads to the most spectacular one (EU AI Act) attracting attention, while the most operationally acute one (NIS2 in the enforcement phase) remains under-prioritized.
Risk 3: Multiplicity of authorities in the event of an audit. DORA: BaFin and ESAs. NIS2: BSI in Germany, Federal Office for Cybersecurity in Austria. EU AI Act: BSI in Germany. In an audit scenario, multiple authorities are involved simultaneously. Anyone who has to answer to multiple supervisory authorities in the same quarter, with sometimes contradictorily formulated requests, is in a difficult position.
Risk 4: False assumption of the omnibus postponement. Anyone reading the headline "EU AI Act postponed" as a blanket relief overlooks the fact that NIS2 remains in enforcement and DORA has been applicable since January 2025. Even under the omnibus status of May 7, 2026, Articles 4, 5, 26, and 50 of the EU AI Act remain on their original timeline.
Risk 5: SAP Note 11599 constant. Productive ABAP transports are technically irreversible. This fact applies under all three regulations. A faulty change in an Annex III-relevant SAP system (EU AI Act), in a NIS2-affected sector, and in a DORA-CTPP constellation is an incident that must be reported three times and simply cannot be undone. Anyone bearing responsibility they can no longer structurally enforce is already at the point where oversight becomes a fiction.
First: Unified audit trail with multiple views. A change audit trail at the object level, maintained for every change regardless of the trigger (human, AI agent, external consultant). From this consolidated dataset, multiple views are generated: DORA view (third parties, ICT risk), NIS2 view (patch management, security findings), EU AI Act view (agent actions, human oversight). The goal is evidence without duplication.
Second: Consolidated incident workflow with multi-authority routing. One incident, one central workflow, three parallel reporting paths. BaFin, the BSI, and, where applicable, AI providers are served in parallel. The 24/72/month deadlines from NIS2 set the pace, which also dictates the reporting schedules for DORA and the EU AI Act.
Third: A shared supply chain inventory with triple tagging. Every external provider in the inventory receives three tags: DORA relevance (critical ICT service yes/no), NIS2 relevance (supply chain security obligation yes/no), and EU AI Act relevance (AI provider yes/no). Updating the inventory addresses all three regulatory frameworks simultaneously.
Fourth: Cross-functional governance forum. The CISO, IT risk function, and CAIO (or the assigned role) meet quarterly with a joint SAP compliance officer. Triple compliance topics are prioritized in this forum, and status updates are reported.
Fifth: Risk-based prioritization during the transition phase. The order of operational consolidation is clear under the current status: NIS2 first (in enforcement, 29,500 entities, management liability), then EU AI Act Articles 26 and 50 (August 2026), followed by DORA deepening (ongoing, CTPP reporting). Annex III high-risk provider conformity assessments can be planned under the Omnibus status without delay against the December 2027 deadline, with preparations beginning no later than summer 2027.
Sixth: External legal counsel as a constant. Triple compliance is not just a tooling problem. Classification under the EU AI Act, third-party contracts under DORA, and management responsibility under NIS2 (Section 38 BSIG) are highly complex legal disciplines. Legal advice is not optional.
Tools that support triple compliance operationalization in the SAP context are categorized by compliance requirement.
Provider / ToolAudit Trail SAP ChangeIncident WorkflowSupply Chain InventoryHuman OversightTraining ManagementSAP GRC Access ControlLimitedNot in scopeLimitedWorkflow-basedNot in scopeSAP IDMNot in scopeNot in scopeNot in scopeIdentity ManagementNot in scopePure SAP Cloud ALMPartial (ATC since June 2025, Auto-Trigger Q1/2026)Not in scopeNot in scopeLimitedNot in scopeRev-Trac PlatinumTransport-levelNot in scopeNot in scopeWorkflow-based (ShiftLeft SoD)Not in scopeBasis Technologies ActiveControl plus KlarioTransport-levelNot in scopeNot in scopeWorkflow-basedNot in scopeREALTECH SmartChangeTransport-levelNot in scopeNot in scopeWorkflow-basedNot in scopeESM Suite (Solutive AG)¹Object-level plus agent actionsNot in scope (external SOC connection)Not in scopeNative four-eyes principle, decision agent escalationNot in scopeOnapsis Security PlatformNot in scopeFull (security focus)LimitedNot in scopeNot in scopePathlockNot in scopeFullLimitedLimitedNot in scopeSOC tools (Splunk, IBM QRadar)Not in scopeFullVia data integrationNot in scopeNot in scopeIBM watsonx.governance, Credo AINot in scope (AI models)Not in scopeNot in scopeLimitedNot in scopeTraining platforms (Litmos, Cornerstone)Not in scopeNot in scopeNot in scopeNot in scopeFullGRC platforms (ServiceNow GRC, Diligent)LimitedLimitedFullWorkflow-basedLimited¹ Solutive AG is the initiator of the Change Orchestration Institute. ESM Suite is a product of Solutive AG. External customer attestation for SOX-ITGC reduction is available for Bruker (70 percent). All other capability statements are provided by the vendors.
Interpretation: Triple compliance cannot be mapped by a single tool. The typical architecture combines a change governance layer (audit trail in the change process), a security platform (vulnerability and incident), a SOC layer (incident workflow with regulatory reporting), a GRC platform (supply chain inventory and risk register), and a training platform.
NIS2, DORA, and the EU AI Act will be simultaneously applicable in May 2026. NIS2 in Germany has been in the operational BSI enforcement phase since May 2026. DORA has been applicable since January 2025, with SAP as a CTPP since November 2025. The EU AI Act, with Articles 4 and 5, has been applicable since February 2, 2025; Articles 26 and 50 apply from August 2, 2026 (not postponed by the Omnibus); and high-risk provider obligations under Annex III have been postponed to December 2, 2027.
The operational consequence for SAP-using companies: an integrated audit trail at the object level, a consolidated incident workflow with three parallel reporting paths, a shared supply chain inventory with triple tagging, and a quarterly governance forum covering all three disciplines. Three parallel compliance programs are inefficient and error-prone; a triple compliance architecture reduces effort and closes gaps.
First key takeaway: In 2026, SAP users will face the simultaneous impact of NIS2, DORA, and the EU AI Act. NIS2 has been in its operational enforcement phase since May 2026, DORA since January 2025 with SAP as a CTPP, and the EU AI Act—specifically Articles 4, 5, 26, and 50—takes effect on August 2, 2026. Three deadlines, one integrated set of obligations.
Practical recommendation: Consolidate obligations rather than running three parallel compliance programs. Five categories of requirements (audit trail, incident reporting, supply chain inventory, oversight, and training) form the common denominator.
Second key takeaway: Sanction frameworks vary, and the most outdated compliance program is often the one that is operationally the most urgent. NIS2 enforcement is receiving too little attention, while the EU AI Act dominates the headlines. If you prioritize based on sanctions, you must address NIS2 first.
Practical recommendation: Prioritize during the transition phase: NIS2 first, then EU AI Act Articles 26 and 50, followed by a deeper dive into DORA. Plan your Annex III high-risk conformity assessment against the December 2027 deadline.
Third key takeaway: Triple compliance cannot be managed by a single tool. A typical architecture combines change governance, a security platform, an SOC layer, a GRC platform, and a training platform. External legal counsel is not optional.
Practical recommendation: Plan your tool architecture as a combination. Convene a cross-functional governance forum (CISO, IT Risk, CAIO, or equivalent role) on a quarterly basis.
Directive (EU) 2022/2555 (NIS2), EUR-Lex (T1). Regulation (EU) 2022/2554 (DORA), EUR-Lex (T1). Regulation (EU) 2024/1689 (EU AI Act), EUR-Lex (T1). BSI Act as amended by the NIS2UmsuCG, in force since December 6, 2025 (T1). ESA, SAP CTPP Designation, November 2025 (T1). BaFin, DORA supervisory priorities 2026 (T1). ENISA, Technical Implementation Guidance NIS2, June 2025 (T1). digital-chiefs.de, regulatory overlap NIS2/DORA/EU AI Act, February 2026 (T2). Computerwoche, DORA implementation survey, February 2026 (T2). Morrison Foerster, Flipping the NIS2 Switch, December 8, 2025 (T2). DLA Piper, NIS 2 Directive Transposed in Germany, February 11, 2026 (T2). Reed Smith, Germany Implements NIS2, January 23, 2026 (T2). Greenberg Traurig, NIS2 Implementation Germany, December 2025 (T2). securitytoday.de, NIS2 enforcement 2026, May 3, 2026 (T2). Bird & Bird, Digital Omnibus Provisional Agreement, May 7, 2026 (T2). Timelex, What survived the trilogue, May 7, 2026 (T2). Modulos AI, EU AI Act Delayed, May 7, 2026 (T2). A&O Shearman, AI Omnibus Trilogue Analysis, April 2026 (T2). Ropes & Gray, AI Omnibus Trilogue Analysis, April 2026 (T2). ai-act-service-desk.ec.europa.eu, FAQ Q1 2026 (T1). artificialintelligenceact.eu, Articles 4, 5, 12, 14, 26, 50, 99 (T1). Plesner Law Firm, April 6, 2026 (T2). SAPinsider 2026 Cybersecurity Benchmark Report, April 17, 2026 (T2). SecurityWeek, SAP April 2026 Patch Day with CVE-2026-27681 and CVE-2026-34256 (T2). innobu.com, SAP Joule 2026, April 2026 (T2). DSAG Investment Report 2026, dsag.de, February 2026 (T1). SAP News Center, SAP Business AI Release Highlights Q1 2026, April 21, 2026 (T1). SAP Note 11599, Reversing Transports, support.sap.com (T1). Solutive AG, ESM Suite v6.4.5 Documentation, March 2026 (Vendor source, user reference externally attested).
NIS2 in the enforcement phase: BSI reality as of May 2026, EU AI Act Article 26: What operator obligations mean in practice from August 2026 despite the Digital Omnibus, Digital Omnibus on AI of May 7, 2026, ISO/IEC 42001 in the SAP world: Provider-deployer separation, Audit trail cross-cutting: EU AI Act, SOX, NIS2, and DORA.
Christian Steiger is a co-founder and managing director of Solutive AG and has been working with SAP application lifecycle management, change orchestration, and transport governance in complex landscapes for over 15 years. His focus is on bridging the gap between SAP Basis practice and modern governance architectures, as well as integrating regulatory requirements into operational SAP processes.
Sarah Connor (pseudonym) is a compliance specialist focusing on European digital regulation, the EU AI Act, GDPR, NIS2, and DORA. She supports the Change Orchestration Institute as a co-author on regulatory topics and brings operational experience from compliance programs in the financial and industrial sectors.
The Change Orchestration Institute is an independent knowledge resource for SAP ALM, change orchestration, and AI governance. Initiator and research partner: Solutive AG, solutive.ag/kontakt.