ISG Provider Lens® SAP Ecosystem - SAP Business AI and Business Technology Platform (BTP) Services - Germany 2026
Sovereign-by-design, automation and lifecycle governance redefine SAP sourcing across transform, run and BTP
This study reviews the SAP services market through three connected lenses: SAP S/4HANA System Transformation, SAP Application Managed Services and Business AI and SAP BTP Services. It reflects how enterprises increasingly treat SAP change as a lifecycle decision, where implementation choices, operational readiness and scalable innovation must align early. It also underlines a market reality in which cloud transition and security expectations have become inseparable from SAP delivery design.
Summarizing the findings, the German SAP S/4HANA implementations market follows a simple logic: the environment is tightening and enterprises are responding with pragmatism and stronger governance, with providers adapting their delivery models accordingly. The resulting patterns show up consistently across transformation programs, run services and BTP/AI roadmaps, as the same constraints shape all three.
Market context: Why the environment is changing
German enterprises are shaping SAP roadmaps in a macro environment that rewards risk control and predictable sequencing. Heightened policy uncertainty and weaker growth dynamics keep decision-makers cautious and make large, disruptive programs harder to justify without clear staging and measurable outcomes. Global and European growth is projected to remain moderate in 2026, reinforcing the preference for transformations that protect business continuity while still moving to a supportable future platform.
This macro setting lands on an SAP-specific pressure point: many enterprises must modernize while keeping operational stability, compliance posture and cost transparency intact. In Germany, this results in persistent cloud hesitation and decision friction that stems from data protection concerns, cost and the complexity of customized landscapes.
The environment is not only pushing the move to cloud; it is pushing the move with provable control, which increases the weight of governance, auditability and operating responsibility in SAP sourcing.
This move is shifting sovereign-by-design delivery from a niche requirement to a default discussion point in German SAP programs. Sovereignty is no longer interpreted only as location but as a set of design-time answers covering data residency, access control, audit evidence and the split of operating responsibility across SAP, hyperscalers and service providers. This shift in approach is reinforced by the European Commission’s Cloud Sovereignty Framework that sets sovereignty objectives and draws explicitly on compliance and resilience drivers, including NIS2, DORA and themes such as supply chain resilience and security auditability.
This is where the ISG Provider Lens report on cybersecurity becomes directly relevant to SAP programs. It is positioned not as an adjacent topic, but as a driver of operating model decisions. As stated in ISG’s Cybersecurity — Services and Solutions report 2025 for Germany, enterprises face a complex security landscape shaped by geopolitical challenges and rapid digitalization. They rely heavily on external providers due to cybersecurity skills shortages and regulatory demands. This structural shortage increases the importance of standardized controls, clearly defined operating responsibilities and automation in daily operations, as many enterprises are unable to meet their growing security and compliance requirements through staffing alone.
The broader sourcing market is reinforcing the move toward recurring services and automation-led delivery. According to ISG IndexTM data, the demand for technology services has reached a new high, with strong themes around AI, cloud and managed services. For SAP, this signals rising expectations that transformation and run offerings are delivered with industrialized methods, automation and measurable productivity outcomes.
Bridging into enterprise behavior, the context above creates a consistent buyer posture: modernize under constraints, insist on provable controls and reduce lifecycle friction through automation and fewer handoffs.
Enterprise priorities: How enterprises respond
Enterprises are responding to market shifts by treating S/4HANA transformation as a controlled sequence of decisions rather than a single, monolithic event. The key intent is to reduce risk and protect continuity while still unlocking modernization value, which naturally favors approaches that can stage scope and manage change incrementally. There is continued caution around large-scale cloud moves, where data protection concerns, cost and customization complexity remain central factors in timing and design choices.
This pragmatism is visible in the transformation pathways enterprises increasingly consider acceptable. Instead of framing the decision as a binary between keep everything and re-design everything, many buyers favor selective transition patterns that allow phased re-designing while retaining continuity for critical operations. This logic aligns with the report’s observations on the evolution of transformation approaches and the market’s emphasis on risk and feasibility while modernizing SAP ERP Central Component (ECC)-heavy environments. The buying decision shifts to prioritizing what can be changed safely without disrupting the business and what must be standardized to prevent recurring technical debt, rather than focusing solely on how quickly everything can be re-imagined.
A second enterprise priority is turning clean core intent into an operating discipline. Many buyers accept that customization-heavy cores drive future cost and the complexity with future upgrades, requiring a standardized core supported by controlled extensions and integration patterns. This change naturally elevates SAP BTP as the primary extension layer, while also raising a governance challenge. As BTP application counts rise, unmanaged extensions can re-create sprawl and dilute standardization gains. BTP governance and portfolio discipline are treated as mainstream requirements and not as specialist topics, as they link directly to long-term run costs and upgrade ability.
Automation across the lifecycle is becoming a baseline procurement expectation. Buyers increasingly look for tool-supported discovery and assessment, automated readiness checks, standardized testing and cutover practices and stronger instrumentation, which improve delivery predictability and steady-state support productivity, including AI-driven analysis to reduce manual effort and accelerate timelines. Clients’ expectations are not limited to transformation activities; they extend into run, where enterprises want lower effort per ticket, faster restoration and fewer repetitive tasks through automation.
Another priority is governance that spans transform + run, as enterprises want fewer handoffs and accountability gaps between implementation and operations. Buyers increasingly expect operational runbooks, service acceptance criteria, monitoring setup and knowledge continuity to be designed early in the program instead of being treated as a post-go-live stabilization effort. This approach connects directly to sourcing preferences; when governance and tooling span the lifecycle, enterprises can reduce transition cost, control risk and accelerate continuous improvement after go-live.
Sovereign-by-design requirements underpin the above-mentioned priorities, giving them clearer definitions. Buyers are moving from broad concerns about data storage to concrete questions about data access, control of privileged actions, producing evidence for auditors and splitting operating responsibilities across parties. This move is consistent with the EU’s framing of sovereignty as measurable objectives and with NIS2 elevating cybersecurity expectations across critical sectors. NIS2 sets a unified legal framework for cybersecurity across critical sectors and calls for a national strategy and coordinated enforcement, which increases attention on operational controls and thirdparty dependencies. For regulated industries, expectations extend further into the oversight of critical ICT providers, reinforcing buyer attention on transparency of controls, responsibility splits and concentration risk. This move pushes sovereign-by-design questions from being an optional consideration to becoming the core of SAP sourcing and operating model design.
These priorities translate into a clear expectation: deliver faster with fewer defects, operate with more automation and auditable controls and reduce friction across implementation and operations.
Provider dynamics: How providers adapt
Providers are industrializing delivery across the SAP lifecycle, as enterprises expect predictable outcomes within time, cost and governance constraints. Industrialization is reflected in more standardized methods for assessment, planning, testing and cutover, alongside repeatable patterns for integration and extension design. It is also demonstrated in the increased emphasis on tooling and automation with tool-supported assessments, automated readiness checks and AI-driven analysis designed to reduce manual interventions and accelerate timelines.
Leading providers are also treating sovereign-bydesign as a demonstrable delivery and operating model capability. Instead of leaving sovereignty topics to contract language, many delivery approaches now require explicit answers on data residency, identity and access boundaries, privileged access management, audit evidence generation and the division of operational responsibilities across platform layers.
Another shift among providers is the convergence of transform + run into fewer handoffs, as buyers increasingly expect lifecycle accountability rather than projectonly accountability. This convergence changes how providers structure governance and delivery staffing, building knowledge continuity and operational readiness early and by design. It also changes how success is defined: beyond go-live, buyers are looking for stable operations, measurable automation outcomes and a controlled roadmap for continuous improvement.
In managed services, providers are responding to the same pressures by pushing AIOps and automation deeper into daily operations. The market is moving toward automated triage, enrichment, guided resolution and self-healing patterns integrated into standard ITSM workflows, with enterprises expecting productivity gains without losing change control and auditability. This shift is not driven by a single provider but reflects the broader market dynamics. As highlighted in ISG’s cybersecurity study for Germany, skills shortages and regulatory demands increase reliance on external providers, forcing providers to scale operations through automation and standardized controls.
In Business AI and SAP BTP services, providers’ response increasingly centers around governance and portfolio management instead of build execution. As extension counts rise, enterprises demand development standards, integration patterns and lifecycle management, alongside cost transparency and controls that prevent extension sprawl. BTP governance becomes crucial here as it preserves clean core intent and keeps AI adoption manageable from both compliance and operations perspectives. This report supports this underlying logic by linking the need for standardization and toolled discipline to reduced manual effort and improved predictability across SAP change.
The combined effect of these provider dynamics is a market that increasingly competes on operational proof: measurable automation outcomes, auditable controls and lifecycle governance that reduces transitions and risk.
Outlook
Sovereign-by-design will become increasingly explicit, testable and embedded in SAP program architecture and contracting. The focus is shifting toward assessing sovereignty through evidence and operating responsibility, rather than relying solely on hosting location statements. For Germany-focused SAP programs, cloud assurance expectations will continue to push for standardized proof of control effectiveness and transparency. SAP delivery models will be clearer about access paths, logging, audit evidence production and responsibility splits across ERP, platform services, identity layers and managed operations.
Automation will also shift from being assumed to being measured. Buyers will increasingly ask for quantified cycle time reduction in transformation activities and measurable operational outcomes in run, such as lower incident volumes, faster mean time to restore and reduced effort per ticket. This change aligns with the broader services market trajectory. As stated in ISG’s Europe ISG Index, AI, cloud and managed services are strengthening the region’s technology services demands, signaling the prioritization of automation-led delivery and recurring services among buyers. The market implication is that providers will face increasing pressure to demonstrate how automation is governed, how it integrates with ITSM and change processes and how it preserves auditability in regulated settings.
The convergence of transform + run should further accelerate, as enterprises want fewer transitions and clearer accountability for stability and continuous improvement. Providers will need to show operational readiness embedded in implementation plans, including standardized runbooks, monitoring and observability design, service acceptance criteria and knowledge continuity. This need is consistent with the ongoing enterprise caution and the need for more tool-supported, predictable delivery approaches that reduce manual effort and uncertainty.
Business AI and SAP BTP Services will become more portfolio-led and governed as adoption scales. BTP will be treated less like a set of isolated projects and more like a managed product landscape, with standards, lifecycle controls and cost transparency. In practice, this approach will strengthen the demand for BTP governance constructs that keep clean core principles intact while enabling controlled innovation. Enterprises are actively trying to reduce run costs and compliance friction created by unmanaged extension growth.
Access to the full report requires a subscription to ISG Research. Please contact us for subscription inquiries.