Home / Blog / SAST for Delphi, COBOL, and ABAP: A Vendor Coverage Reality Check

SAST for Delphi, COBOL, and ABAP: A Vendor Coverage Reality Check

Three languages run banking cores, ERP systems, and hospital software, and most enterprise SAST platforms do not parse them. This is a coverage check across Fortify, Checkmarx One, Veracode, HCL AppScan, Black Duck, and DerScanner, with the evaluation questions that decide whether a legacy scan is real or a green pipeline over skipped files.

Content

Make Your Applications Secure Today

Sign up for a personalized demo to see how DerScanner can meet your Application Security needs

In January 2026, the TIOBE index delivered a small surprise: Delphi/Object Pascal climbed back to the top 10, taking the ninth place with a 1.98% rating, just ahead of R (TechRepublic's coverage of the January index). A language released back in 1995 now ranks above fancy stacks that often flood conference talks.

Delphi is one of three languages that quietly run a massive share of the systems people trust with their money and their medical records on a daily basis. The other two are COBOL and ABAP. Together they sit inside banking cores, ERP systems, government registries, and hospital software. And the vendor market gets thin when it comes to looking for static analysis tools.

 

The base is enormous and not going anywhere

DXC Technology, citing Reuters, puts 43% of US core banking systems on COBOL, along with 95% of ATM swipes and 80% of in-person transactions, running on roughly 220 billion lines of code still in production. Communications of the ACM estimates that around $3 trillion in daily commerce flows through COBOL systems. 

Meanwhile the average COBOL developer is about 55 years old, and roughly 10% of that workforce retires every year. As we wrote in Claude Is Rewriting COBOL, AI translation preserves the business logic while replacing the language, the architecture, the dependencies, and the infrastructure, and those four layers are where vulnerabilities actually live. So whether an estate stays on COBOL for another decade or heads into an AI-assisted rewrite, its code needs analysis on both sides of the migration anyways.

When it comes to SAP, you may notice that every non-trivial SAP installation accumulates custom ABAP: reports, interfaces, enhancements, entire modules. The Onapsis Research Labs benchmark, built on data from hundreds of real-world SAP systems, found that the average system runs nearly 4 million lines of custom ABAP, that 70% of custom programs contain at least 1 critical issue, and that a typical system carries 118 critical code issues, with code injection and missing authorization checks leading the list. The SAPinsider S/4HANA migration benchmark ranks custom code adaptation among the top three technical barriers in migration programs. This is the code that runs payroll, invoicing, procurement, and logistics at the largest enterprises on the planet.

Delphi, on the other hand, powers Windows desktop software across healthcare, manufacturing, logistics, and retail: lab systems, warehouse management, point-of-sale, industrial control panels. 

Embarcadero keeps shipping releases (RAD Studio 13.1 Florence arrived in March 2026), and a network of regional partners (like Barnsten in Benelux, Code Secure s.r.o. in Czech Republic and Slovakia, or Konto d.o.o. in the Balkans) sell licenses, provide trainings, and migrate services to active development teams. The TIOBE ranking is a lagging indicator that the ecosystem is alive and new code is being written.

 

Who scans what

Here is how coverage of the three languages compares across the enterprise SAST platforms most often found on shortlists, based on each vendor's public documentation (as of July 2026):

Language

DerScanner

Fortify

Checkmarx One

Veracode

HCL AppScan

Black Duck

COBOL

Yes

Yes

No

Yes, compiled binaries only

Yes

No

ABAP

Yes

Yes

No

No

No

No

Delphi

Yes, native 

+ SCA

Yes

No

No

No

No

Language lists change, and coverage varies by version, so treat this table as a starting point for a proof of concept rather than a final verdict.

DerScanner built its language list around the legacy gap. It covers 43 languages, with Delphi, Pascal, COBOL, ABAP, PL/SQL, VB6, VBA, LotusScript sitting alongside the modern stacks. Delphi gets a native parser, code quality analysis, and the latest SCA for the Delphi ecosystem, covering third-party components in RAD Studio projects. The whole platform deploys on-premise, including fully air-gapped installations.

 

Four questions that separate a real evaluation from a checkbox

  1. Ask how the parser handles what surrounds the code. COBOL programs lean on copybooks and embedded EXEC SQL and EXEC CICS blocks, and a parser that cannot resolve an include or an embedded block silently drops the file that contains it. 

  2. Ask how the code reaches the scanner in the first place: ABAP lives inside the SAP system rather than in a Git repository, and Delphi projects pull in VCL and commercial component packs, so the extraction path decides what actually gets analyzed. 

  3. Run the proof of concept on production code and compare parsed files against skipped ones; the skip rate is the real coverage number. 

  4. Confirm the findings map to CWE and OWASP classifications, because for regulated industries the scan exists to produce audit evidence, and unmapped findings produce none.

The pattern across the market is clear enough. Legacy language coverage was expensive to build and unfashionable to maintain, so most vendors let it go. The code it was meant to protect stayed exactly where it was.

 

If part of the portfolio is written in Delphi, COBOL, or ABAP and it has never been through a static analyzer, a proof of concept answers the coverage question in days, using real code instead of a datasheet. Book a DerScanner demo and bring the project the last scanner could not parse. For a deeper look at how legacy analysis works in practice, see how DerScanner approaches Delphi code quality and the SAST product overview.

Loading blogs...
Get Started

Ready to Reduce Technical Debt and
Improve Security?

Clean code. Fewer risks. Stronger software

dashboard