Pricing conditions are the rules that determine prices, discounts, surcharges, freight, and tax behavior in SAP SD. They are maintained through condition records and condition types, allowing organisations to apply consistent commercial logic while still supporting exceptions, negotiated terms, and tax treatment across transactions.
Expanded Definition
Pricing conditions are the rule set that SAP SD uses to calculate what a transaction should charge or credit, including list price, discounts, surcharges, freight, and tax treatment. They are not just a lookup table; they are a controlled decision layer made up of condition types, access sequences, and condition records that turn commercial policy into repeatable system behavior.
In practice, the term covers both the technical objects maintained in SAP and the business policy they represent. That distinction matters because pricing conditions can encode negotiated customer terms, seasonal incentives, or jurisdiction-specific tax logic, while still being evaluated consistently at order entry, delivery, billing, or settlement. Where organisations align this logic with NIST Cybersecurity Framework 2.0, the focus is on reliable governance, traceability, and controlled change. Definitions vary across vendors, but in SAP-centric usage the term is anchored in condition technique rather than generic pricing policy.
The most common misapplication is treating pricing conditions as a one-time master data setup, which occurs when teams ignore access sequence logic, validity dates, or tax determination dependencies.
Examples and Use Cases
Implementing pricing conditions rigorously often introduces maintenance overhead, requiring organisations to weigh commercial flexibility against the cost of governance, testing, and exception control.
- A sales team applies a customer-specific discount through a condition record so the negotiated rate is used automatically on every qualifying order.
- A logistics rule adds freight charges for selected shipping methods, allowing the billing document to reflect transport costs without manual intervention.
- A tax condition determines whether VAT, GST, or another levy applies based on destination, product class, or exemption status.
- A temporary promotion uses a validity window so the lower price expires automatically when the campaign ends, reducing manual cleanup.
- An organisation documents SAP pricing governance alongside its identity and access controls, using the Ultimate Guide to NHIs to reinforce why controlled system logic matters when automation can change business outcomes at scale.
For broader control design, teams often compare pricing-condition governance with policy enforcement patterns described in NIST Cybersecurity Framework 2.0, especially where approvals, auditability, and separation of duties are required.
Why It Matters in NHI Security
Pricing conditions matter in NHI security because they often sit behind automated business actions triggered by service accounts, integrations, bots, and AI agents. If those identities can change condition records without proper control, they can quietly alter revenue, margin, tax treatment, or freight charges at enterprise scale. NHIMG research shows that 97% of NHIs carry excessive privileges, which is a reminder that business-critical configuration is only as safe as the identity allowed to modify it, and 79% of organisations have experienced secrets leaks, with 77% of those incidents causing tangible damage, underscoring how operational misuse and credential exposure often travel together. That is why pricing logic should be treated as governed state, not just configuration convenience.
In SAP environments, weak controls around pricing conditions can also blur the line between authorised commercial change and fraudulent adjustment. The risk is especially acute when approvals are informal, transport paths are under-monitored, or service identities have broad update rights. Organizations typically encounter pricing-condition abuse only after a disputed invoice, margin erosion, or tax exception surfaces, at which point the term becomes operationally unavoidable to address.
For NHI governance, this makes pricing conditions relevant to Ultimate Guide to NHIs because the same identity that automates billing can also become the path by which commercial controls are bypassed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 | Business-critical config changes by NHI-administered accounts create integrity and abuse risk. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access is central when identities can modify commercial pricing controls. |
| NIST Zero Trust (SP 800-207) | GV.3 | Zero Trust governance applies to automated change paths that affect enterprise transactions. |
| NIST SP 800-63 | AAL2 | Stronger authenticator assurance supports sensitive administrative actions over pricing data. |
| NIST AI RMF | GV | AI-driven agents that touch pricing rules need governed oversight and traceability. |
Verify every pricing-condition change request, regardless of source identity or network location.
Related resources from NHI Mgmt Group
- How can organisations decide whether to move from seat-based to usage-based identity pricing?
- How do organisations keep least privilege current as identity conditions change?
- Why do virtualization drivers create such difficult bug-hunting conditions?
- How should organisations evaluate PAM beyond subscription pricing?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org