🔍 Read the full analysis: How DORA Brings SAP Takeovers Into The Auditor’s Scope on Rymvard
Get monitors, keyboards and dev gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
TL;DR

Rymvard added an early-access check on Oct. 4, 2026, to assess whether secondary hosts in SAP HANA system-replication pairs can carry production allocations after a takeover. The company says each system receives a fit, conditional fit, shortfall or unknown result; the illustrative example is not a customer deployment or audit finding.
Rymvard said on Oct. 4, 2026, that its early-access data-center capacity ledger now checks whether a secondary host in an SAP HANA system-replication pair has enough capacity to take over the production system. The feature is aimed at helping financial-sector service providers document a technical part of recovery readiness under the EU’s Digital Operational Resilience Act (DORA); it does not by itself establish regulatory compliance or demonstrate a successful recovery test.
The check compares the secondary host’s available allocation with the primary system’s needs after a takeover. Rymvard says it accounts for replacement of the pair’s own replica and may count test or development systems on the secondary host as stoppable to free capacity. It explicitly excludes production systems belonging to other customers from the pool of workloads that could be stopped.
Rymvard assigns one of four outcomes: fits, fits after named systems are stopped, does not fit—with the shortfall stated in GiB—or unknown. A replication status more than one hour old, or a memory figure more than 24 hours old, produces an unknown result rather than a pass. For scale-out HANA, the calculation evaluates the system as a whole and uses the worst host pair.
The company says results can be exported per system for review by a service provider or auditor. Rymvard’s example describes a managed SAP provider serving financial institutions in Luxembourg, but says the scenario is illustrative, not a customer estate or reported outcome. It also says the displayed screens come from the running product, which is in early access.
Operational resilience · Early access · Oct. 4, 2026
How DORA Brings SAP Takeovers Into The Auditor’s Scope
Rymvard’s new capacity check asks whether an SAP HANA replication partner could carry production allocations after takeover. It gives providers and financial institutions a focused record to review—while leaving recovery testing and broader DORA duties firmly in view.
01 / The operational question
Can the secondary host carry production?
Replication can keep data available. Takeover readiness also depends on whether the destination has enough usable memory for the workload.
Capacity check
Compare the allocation
The check compares available allocation on the secondary host with the primary system’s needs after takeover.
Workload assumptions
Free eligible capacity
It accounts for replacing the pair’s own replica and may treat test or development systems as stoppable to free memory.
Customer boundary
Protect other production
Production systems belonging to other customers are explicitly excluded from the workloads that could be stopped.
02 / How the assessment flows
From replication data to a reviewable result
A system-level view is exportable per system for review by a service provider or auditor.
Read current inputs
Use replication status and memory figures, subject to freshness limits.
Model takeover
Evaluate the secondary host’s capacity against the primary allocation.
Account for stops
Potentially stoppable test and development workloads may release capacity.
Export per system
Review the outcome and assumptions alongside recovery evidence.
03 / Four possible outcomes
The result makes uncertainty visible
For scale-out HANA, Rymvard says the calculation evaluates the system as a whole and uses the worst host pair.
Available allocation covers the production system’s needs.
Named eligible systems must stop to release enough capacity.
The shortfall is stated in GiB for review and remediation.
Old status or memory data cannot produce a passing result.
Read the boundary: a capacity calculation does not prove a takeover will succeed under real conditions. It does not assess every dependency, procedure, governance control or contract that shapes operational resilience.
04 / Regulation and evidence
Why this technical record may matter
DORA brings third-party ICT risk into the resilience picture for covered financial entities. The tool addresses one infrastructure question within that wider work.
| Review area | What the feature offers | What it does not establish |
|---|---|---|
| Takeover capacity | ✓ System-level memory allocation check | ✗ Successful recovery under outage conditions |
| Readiness evidence | ✓ Exportable result for provider or auditor review | ✗ DORA compliance certification |
| Data quality | ✓ Stale inputs produce “unknown” | ✗ Independent validation of underlying data |
| Risk management | ~ One focused infrastructure check | ✗ All dependencies, controls or contractual duties |
DORA is Regulation (EU) 2022/2554. It has applied since Jan. 17, 2025, and includes digital operational resilience requirements for financial entities, including ICT risk linked to third-party providers. The regulation does not prescribe this particular tool or report format.
05 / Evidence limits
Early access calls for careful interpretation
Rymvard says the product is running, but the feature remains in early access. Independent performance evidence has not been provided in the announcement.
What is described
- A new SAP HANA takeover-capacity check in a data-center capacity ledger.
- Per-system results that can be exported for review.
- An illustrative managed-provider scenario involving Luxembourg and financial institutions.
What remains unverified
- No named customer, site, completed audit or operational outcome.
- No independent evaluation or published schedule for external validation.
- How calculations perform across configurations and how auditors assess exports.
06 / What evidence comes next
Validation is the next milestone
Rymvard says early-access pricing is agreed individually with partners. It has not announced a broader release date or named adopters.
The useful next evidence is whether providers apply the check to real SAP estates, find and remediate capacity gaps before resilience testing, and validate the assumptions and data behind each system result.
07 / Key questions
What auditors and providers should know
What does the new check assess?
Whether the secondary host in an SAP HANA system-replication pair can carry the primary system’s allocation after takeover, using the capacity and status data available to the tool.
What if the data is stale?
Replication status older than one hour or memory data older than 24 hours yields an unknown result, not a pass.
Does it establish DORA compliance?
No. It addresses one infrastructure-capacity question that may support resilience preparation. It is not certification and does not replace broader risk management or recovery testing.
Is Luxembourg a customer deployment?
No. Rymvard describes that managed-provider scenario as illustrative; no customer, site or actual operational outcome is implied.
Primary source: Regulation (EU) 2022/2554 (DORA) · announcement and product details via Rymvard.
Evidence for SAP Recovery Capacity
For financial institutions relying on externally operated SAP environments, a standby site is useful only if its systems can support the required workload when a primary host fails. The new check focuses on that operational question: whether a replication partner has enough memory capacity for takeover, and whether the answer rests on current data.
DORA has applied since Jan. 17, 2025, and requires covered financial entities to manage ICT risk, including risks linked to third-party providers, and test the recovery of critical services. An exportable, system-level result could give a provider and its financial-sector customers a concrete record to examine when preparing resilience tests. It could also flag a capacity gap—such as test systems occupying memory needed by a replica—before a test or incident.
The limits matter. A capacity calculation is not proof that a takeover will succeed under real conditions, and a report alone does not satisfy every DORA obligation. The feature addresses a specific infrastructure question; it does not assess all dependencies, recovery procedures, governance controls or contractual arrangements involved in operational resilience.
As an affiliate, we earn on qualifying purchases.
DORA and HANA Replication
Regulation (EU) 2022/2554, commonly called DORA, sets digital operational resilience requirements for banks, insurers and other financial entities. Its scope includes ICT services provided by third parties. The regulation’s requirements make the resilience of outsourced technology relevant to both the regulated institution and the service arrangements on which it depends.
Many SAP environments use HANA system replication to maintain a secondary system at another site. Replication can keep data available, but readiness for takeover also depends on whether the destination host has adequate resources. Rymvard’s feature is designed to check memory allocation at that point, rather than treating replication status alone as evidence that production can run at the secondary site.
Rymvard describes itself as a capacity ledger for data centers and says it publishes no prices, with pricing agreed individually with early-access partners. Its announcement does not provide independent testing results, customer references or evidence of use in a completed audit.
“A replication status older than one hour or a memory figure older than 24 hours makes the result unknown — never fine.”
— Rymvard
Data center capacity management software
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Limits of the Early-Access Evidence
Rymvard has not identified a customer using the feature or provided an independent evaluation of its calculations. The Luxembourg managed-provider scenario is explicitly illustrative, and no customer, site or operational outcome is implied. The company says the product is running, but remains in early access.
It is also unclear how the check performs across different customer configurations, how operators validate the underlying memory and replication data, or how auditors will assess its exported results. DORA does not prescribe this particular tool or report format. The calculation therefore should not be read as a regulator’s approval, a compliance certification or a guarantee that recovery will work during an outage.
SAP HANA standby host capacity check
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Early-Access Rollout and Validation
Rymvard says pricing is agreed with early-access partners and has not published a price list. The company has not announced a broader release date, named adopters or set out a schedule for external validation. The next useful evidence will be whether providers use the check on real SAP estates and whether its exported results help identify and remediate capacity gaps before resilience testing.
For now, financial institutions and their providers would need to review the calculation’s assumptions, data freshness and system-specific findings alongside their own recovery procedures and testing evidence. The feature offers a way to record one aspect of takeover readiness; its wider value will depend on how it performs in operational deployments.
Primary source: Regulation (EU) 2022/2554 (DORA) · via Rymvard
enterprise disaster recovery testing tools
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What does Rymvard’s new SAP check assess?
It checks whether the secondary host in an SAP HANA system-replication pair can carry the primary system’s allocation after a takeover, using the capacity and status data available to the tool.
What happens if the data is stale?
Rymvard says results are marked unknown if replication status is more than one hour old or memory data is more than 24 hours old. Stale information is not recorded as a passing result.
Does the feature establish DORA compliance?
No. It addresses one infrastructure-capacity question that may support resilience preparation. It is not a compliance certification and does not replace broader risk management or recovery testing.
Is the Luxembourg example a customer deployment?
No. Rymvard says the managed-provider scenario is illustrative and does not represent a customer, site or actual outcome. The company says its product is in early access.
Primary source: Regulation (EU) 2022/2554 (DORA) · via Rymvard
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
