An initiative by Solutive AG
solutive.ag
Change & Release

The SAP CAP supply chain attack: what the April 2026 npm incident reveals about change governance

In late April 2026, official SAP CAP npm packages were compromised. The attack targets the development toolchain before the first transport. Analysis of the incident, the control points, and the consequences for change governance.
June 8, 2026
min read
13
Change & Release

NIS2 in Germany: BSI enforcement phase May 2026 and its consequences for SAP Change Management

NIS2 is the EU directive on cybersecurity. Transposed into German law via the BSIG. BSI audit phase active since May 2026; personal liability for management effective since December 2025.
May 18, 2026
min read
6
Change & Release

Triple Compliance 2026: NIS2, DORA, and the EU AI Act as an integrated change architecture challenge

Triple compliance in May 2026 refers to the simultaneous applicability of NIS2, DORA, and the EU AI Act. The three regulatory frameworks consume the same operational evidence: audit trail, incident reporting, supply chain inventory, human oversight, and training. An integrated architecture reduces effort and closes gaps.
May 11, 2026
min read
20
Change & Release

Cross-cutting audit trails: How SAP customers can cover the EU AI Act, SOX, NIS2, and DORA in a single architecture

Four regulations, four retention periods, four reporting logics: How to design an audit logging architecture that satisfies all of them simultaneously without storing logs four times.
May 4, 2026
min read
42
Change & Release

SAP DevOps and CI/CD for ABAP: A 2026 Reality Check on gCTS and Project Piper

A technical assessment of the landscape between standard solutions, community tools, and an impending toolchain gap
May 4, 2026
min read
40
Change & Release

Audit trail in the SAP change process: Requirements from the EU AI Act, SOX, NIS2, and DORA and their operational implementation

An audit trail in the SAP change process is the end-to-end, audit-proof recording of all activities related to a change.
April 29, 2026
min read
25
Change & Release

SOX and the four-eyes principle in the SAP change process: What must be technically enforceable and what is only documented

SOX Section 404 requires a verifiable internal control system for changes to financial SAP systems.
April 27, 2026
min read
21
Change & Release

Test automation and impact analysis in the SAP environment: From isolated tools to pipeline integration

Test automation and impact analysis in SAP environments must be considered together to reach their full potential.
April 27, 2026
min read
20
Change & Release

Change management in the SAP world: fundamentals and principles

Change management in SAP encompasses all changes to code, customizing, and configuration. It does not end with the transport.
May 21, 2025
min read
11
Change & Release

Transport management in SAP: From request to production deployment

Transport management controls the path of changes from the development system to production. Three classes of errors dominate daily operations.
May 6, 2025
min read
11
Change & Release

Release Governance: Planning, managing, and controlling SAP releases

Release governance manages the transition from individual changes to coordinated, controlled production cycles.
April 25, 2025
min read
12
Change & Release

The five-layer architecture for SAP Change Governance: who decides at which level

An analytical lens for SAP Change Governance: five layers with distinct tasks and decision-making rights, and why ALM is not the same as governance.
min read
16