{"url_path":"/sec/sapgf/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-02-26","source_url":"https://www.sec.gov/Archives/edgar/data/1000184/0001104659-26-020058-index.html","accession_number":"0001104659-26-020058","cik":"0001000184","ticker":"SAP","issuer_name":"SAP SE","edgar_url":"https://www.sec.gov/Archives/edgar/data/1000184/0001104659-26-020058-index.html","primary_entity_key":"0001000184","primary_entity_name":"SAP SE"},"word_count":2296,"has_tables":true,"body_markdown":"ITEM 16K. CYBERSECURITY\n\n**Risk Management and Strategy**\n\nWe have developed and implemented a cybersecurity risk management approach intended to protect the confidentiality, integrity, and availability of our critical systems, information, and our customers’ data. Our cybersecurity risk management approach and processes are part of our Executive Board-issued risk management policy that aligns our management of risk to our risk appetite, and is consistent with the methodologies, reporting channels and governance processes that apply across our enterprise risk management program to legal, compliance, strategic, operational, financial and other risk areas of the SAP Group. We have central processes and corresponding solutions to store, maintain, and report enterprise risk-relevant information, including cybersecurity risks.\n\nOur information security risk management approach employs sophisticated quantification techniques to measure security exposure with various criteria including financial terms, supporting strategic investment decisions across SAP. A satellite network of unit risk coordinators provides enterprise-wide risk identification and assessment, ensuring comprehensive coverage while enabling localized security decision-making. This integrated model transforms qualitative security concerns into quantifiable information security risks, allowing leadership to prioritize investments, allocate resources efficiently, and demonstrate measurable risk reduction.\n\nWe have designed and implemented a solid security and cloud compliance strategy in line with the overall SAP business, product, and technology strategies. To execute on that strategy, we establish and manage a risk-based cybersecurity framework for SAP according to well accepted industry frameworks and standards such as SOC, ISO, PCI, along with various required regional standards, and also voluntarily align with guidance from the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF).\n\nCybersecurity risks are reported regularly to the Executive Board through cumulative risk reporting and risk updates are steered via regular security updates to the Executive Board. The Supervisory Board’s Product and Technology Committee (PTC) and its Audit & Compliance Committee (ACC) are apprised of key cybersecurity risks. By bringing these risks to the attention of the Executive Board, the PTC, and the ACC as appropriate, SAP’s disclosure decision makers have an early and recurring opportunity to assess the materiality of these cybersecurity risks.\n\nKey elements of our cybersecurity risk management approach include:\n\n-a security team responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents;\n\n-a Global Risk Management Policy that applies to all employees and which is reviewed and updated as necessary;\n\n-an Executive Board-established early warning risk management system designed to enable transparency and compliance with applicable regulations;\n\n-risk assessments designed to help identify material cybersecurity risks to our critical systems, information, products, services, and our broader enterprise IT environment;\n\n-a third-party risk management process for service providers, suppliers, and vendors;\n\n-a Global Security Policy that applies to all employees and which is reviewed and updated as necessary;\n\n-the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls;\n\n122\n\n[Table of Contents](#TOC)\n\n-a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents and which is reviewed and updated as necessary; and\n\n-cybersecurity awareness training of our employees, consultants, incident response personnel, and senior management.\n\nSAP internal and external experts are engaged to evaluate SAP’s risk identification, assessment, and monitoring systems and processes, including with respect to cybersecurity risks. The PTC and ACC periodically request an independent review of the quality of our cybersecurity risk monitoring systems.\n\nAdditionally, our risk management systems are regularly audited by our external auditors and are subject to internal audits, including our cybersecurity monitoring systems. We consider the results of external and internal audits of our risk detection and monitoring systems and implement modifications as necessary. Finally, SAP engages third party legal consultants as necessary to assist with the implementation of legal requirements and industry standards, and to identify process weaknesses and track improvements.\n\nAs of the date of this filing, we have not identified risks from existing and known cybersecurity threats or incidents that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. However, we are subject to certain risks that if realized and sufficiently severe, are reasonably likely to materially affect our operations, business strategy or financial condition. See “*Risk Factors – Cybersecurity and Security: Cybersecurity attacks or breaches, and security vulnerabilities in our infrastructure or services or those of our third-party partners could materially impact our business operations, products, and service delivery.*”\n\n**Cybersecurity Governance**\n\n**(1)****Supervisory Board Oversight of Risks from Cybersecurity Threats**\n\nThe Supervisory Board, through the PTC and the ACC, governs the Executive Board’s oversight of SAP’s cybersecurity risk management approach.\n\nThe ACC reviews the effectiveness of SAP’s system for monitoring corporate security, which includes cybersecurity. The ACC coordinates with the members of the Executive Board, as well as the Chief Security Officer (CSO) and the Chief Security Compliance & Risk Officer (CSCRO), on the cybersecurity controls and other measures established by the Executive Board. The ACC is focused on cybersecurity risk and incident management and mitigation.\n\nThe PTC reviews and monitors the technical systems and processes intended to defend against cybersecurity attacks and improve the security of SAP’s infrastructure. The PTC coordinates with the members of the Executive Board as well as the CSO and the CSCRO on the potential and actual, if any, product and operational impacts of known cybersecurity risks and incidents. The PTC is focused on mitigating the product and operational-related impacts, if any, of cybersecurity risks and incidents.\n\nThe PTC and the ACC are informed about risks from cybersecurity threats by the Executive Board and security executives, with additional input from SAP’s Global Security & Cloud Compliance organization (SGSC), the Global Risk & Assurance Services organization (GR&AS), SAP Legal, Business Information Security Officers (BISOs), and internal and external cybersecurity and legal consultants. SAP’s Global Security & Cloud Compliance Office reports regularly to the PTC and to the ACC, as well as upon request and the occurrence of certain findings. In addition, the PTC and ACC often participate in meetings with the Executive Board or members thereof and security executives for the purpose of receiving information on and discussing SAP’s cybersecurity risks and risk management approach. The PTC and ACC participate in key decisions on cybersecurity-related issues, including risk materiality assessments, incident response and the provision of any necessary related disclosures.\n\n**(2)****Executive Board’s Role in Assessing and Managing SAP’s Material Risks from Cybersecurity Threats**\n\n**(i) Executive Board Role in Assessing and Managing Material Risks from Cybersecurity Threats and Executive Board Expertise**\n\nThe Executive Board is responsible for assessing and managing material risks, including cybersecurity risks. Specifically, the Executive Board supervises SAP’s efforts to prevent, detect, mitigate, and remediate cybersecurity risks through various means, including briefings from SAP security personnel and other SAP personnel involved in cybersecurity matters; threat detection and other intelligence information obtained from governmental, public, or private sources, including external consultants engaged by us; and alerts and reports produced by security tools deployed in the IT environment. In addition, the Executive Board supervises SAP’s internal cybersecurity personnel. Certain members of SAP’s Executive Board have engineering, computer science and data science backgrounds and degrees, and knowledge, skills, and hands on experience in cybersecurity risk and incident management.\n\n**(ii) Executive Board – Briefing on and Monitoring of Cybersecurity Risks and Incidents**\n\nThe Executive Board is regularly apprised of and monitors SAP’s initiatives to prevent, detect, mitigate, and remediate cybersecurity risks and incidents, including processes supported by SGSC, SAP’s BISOs, GR&AS, SAP Legal, the Cybersecurity Control Team, and external legal and cybersecurity experts. The SAP Security and Cloud Compliance Governance Model is designed to ensure executive engagement and facilitates shared responsibility in quarterly SAP Security Advisory Board and Security Council meetings and in periodic updates to the Executive Board.\n\n123\n\n[Table of Contents](#TOC)\n\nSAP Global Security & Cloud Compliance\n\nSGSC is co-led by SAP’s CSO and its CSCRO, both of whom report to the Member of the Executive Board for Customer Service & Delivery. SGSC is responsible for areas such as product and application security, cyber defense, operational security risk management, security compliance, physical security, as well as the Trust Office that supports customers and partners with security-related issues. SGSC coordinates with SAP Legal and reports to the ACC and/or the PTC as well as the Executive Board regarding the prevention, detection, mitigation and remediation of cybersecurity risks and incidents, including assessments of the materiality of cybersecurity risks and incidents. In addition, the SGSC reports to the Executive Board, the PTC and/or ACC as necessary outside of the quarterly reporting cadence on any potentially material cybersecurity risks and incidents.\n\nBusiness Information Security Officers (BISO)\n\nEach of SAP’s product Lines of Business (LOB) has a BISO, who is a senior security leader assigned to manage the security strategy and operations of the LOB and coordinate with other BISOs through a BISO Council reporting to our CSO. These BISOs serve many important functions, including managing SAP’s risk within each LOB. It is the responsibility of each BISO to supervise and monitor the specific risks associated with their respective LOB. This facilitates the reporting of security threats to the Security & Risk Assurance (SRA) Team through the local unit risk coordinator. The SRA Team evaluates and measures the security risks using a cyber risk quantification tool. Once validated, these risks are recorded and included in the Global Enterprise risk register and subject to risk mitigation actions. In the event of an incident, the BISO helps manage the event and support the CSO, CSCRO and, ultimately, the Executive Board in their decision-making processes. BISOs are supported by local security resources to assist with implementing SAP’s security strategy and protections within the business and technology context best suited for the LOB in question. BISOs and SAP Legal coordinate on significant cybersecurity risks and incidents impacting their LOB.\n\nRisk Coordinator\n\nA Risk Coordinator assumes the delegated responsibilities of the business unit head to support risk management activities in the relevant areas of responsibility. However, not every LOB necessarily has a dedicated Risk Coordinator if the Business Unit Head is directly involved.\n\nGlobal Risk & Assurance Services Organization\n\nSAP’s GR&AS organization, led by our Chief Risk Officer/Chief Audit Executive (CRO), provides regular updates to the ACC, the PTC, and the Executive Board on SAP’s risk management systems and risks meeting SAP’s internal risk threshold. The CRO reports to SAP’s Group CFO and is responsible for designing and implementing SAP’s risk management system, with oversight by the Executive Board.\n\nCybersecurity Control Team\n\nSAP maintains a cross functional cybersecurity control team consisting of the CSO, the CSCRO, SVP Legal - Litigation and Cybersecurity, Chief Cybersecurity Counsel, Senior Corporate & Securities Counsel, Group Data Protection Officer & Head of SAP Data Protection, and members of SAP’s Global Accounting, Reporting & Tax department. This group meets on both a quarterly and an ad hoc basis to review cybersecurity issues, including but not limited to actual and potential cybersecurity incidents, thwarted attempts, cyber-related risks, and internal investigations (collectively, cybersecurity events). As part of its review and assessment, this group evaluates the implications, if any, of the cybersecurity events on SAP’s external reporting. Where appropriate, matters are escalated and discussed among SAP’s General Counsel, the Executive Board, the PTC and/or the ACC. Assessments ensue at this level with senior leaders from the Cybersecurity Control Team and cybersecurity consultants who provide the Executive Board, the PTC and/or the ACC with updates on an as-needed basis and in SAP Security briefings. SAP discusses any significant cybersecurity events, their impact on SAP's external reporting.\n\nEmployee Cybersecurity Education, Training and Compliance\n\nAs part of its risk mitigation strategy, SGSC conducts annual mandatory security training programs that provide education on key cybersecurity risks and specific threat profiles. A comprehensive portfolio of offerings is made available to the SAP workforce to address the diverse threats faced by organizations such as SAP and to reinforce SAP’s expectations of its employees. In addition to this regular education, the Executive Board, the PTC and the ACC receive training on cybersecurity topics from our CSO, CSCRO and internal security staff as part of the continuing education on cybersecurity topics that impact public companies.\n\nExecutive Clearing Board\n\nIn 2025 the Executive Board endorsed the creation of a new Executive Clearing Board (ECB) to enhance oversight of critical cross-board area topics and domains related to regulatory obligations, audits, product certifications, and attestations. The ECB provides an independent, high-level review, and escalation body for complex or cross-domain regulatory issues where accountability is unclear, ensuring strong governance while streamlining what is elevated to the Executive Board.\n\n124\n\n[Table of Contents](#TOC)\n\n**(iii) Executive Board Reporting of Cybersecurity Risks to the ACC and the PTC of the Supervisory Board**\n\nThe Executive Board regularly reports cybersecurity risks and incidents to the PTC and ACC, as outlined above, with a focus on significant risks and incidents. This reporting occurs through various processes with input from SGSC, GR&AS, SAP Legal, BISOs and internal and external cybersecurity and legal consultants. Additionally, the Executive Board often participates in meetings with each of the PTC and the ACC on cybersecurity-related issues, including risk materiality assessments, incident response, third party audit matters and the provision of any necessary related disclosures. In the case of a significant cybersecurity incident, the Executive Board, the PTC and/or the ACC coordinate as necessary with others both within SAP (including with respect to any significant cybersecurity incidents, the Disclosure Committee) and any outside experts involved in the matter on the determination of the materiality of cybersecurity risks and incidents to SAP and the provision of any related disclosures. Since SAP is a reporting entity under both German and U.S. laws, SAP adheres to both the Ad Hoc reporting requirements of the European Market Abuse Regulation and the U.S. federal securities laws requirements for periodic and annual disclosures.\n\n​\n\nPART III"}