Every organisation still running SAP ECC has a decision to make before the end of 2027, and most are framing it wrongly. The instinct is to treat the S/4HANA question as a technical migration the IT function will handle. It is not. It is a choice about how much operational and compliance risk the business is willing to carry, made against a fixed date that SAP has said repeatedly it will not move.
What actually happens on 1 January 2028
Mainstream maintenance for SAP ECC 6.0 (Enhancement Packages 6–8) ends on 31 December 2027. The earlier packages, EHP 0–5, already lost mainstream maintenance at the end of 2025. The system does not switch off. What switches off is the safety net beneath it.
After the deadline, a firm that has done nothing falls automatically into customer-specific maintenance. That tier costs the same as mainstream maintenance but stops delivering the two things that matter most to a regulated business: new security patches and legal or regulatory updates. Every month after that, the gap between what your ERP does and what a current one does widens, and so does your exposure — unpatched vulnerabilities in the system that runs finance, procurement and supply chain, and a tax and reporting engine that no longer keeps pace with the law.
Free · 4 minutes
Do you actually know what you are running — and what it is about to cost you?
Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.
The three real options
Stripped of vendor noise, the board is choosing between three paths.
Migrate to S/4HANA. The strategic destination SAP is pushing toward. It is a database migration and, depending on approach, a process re-engineering exercise — not a simple upgrade. SAP has committed to maintaining at least one S/4HANA release until 2040, and releases from 2023 onward carry a seven-year maintenance window, so this is the option that ends the recurring deadline problem.
Buy extended maintenance to 2030. Available for EHP 6–8 at roughly a two-percentage-point premium on your existing maintenance base, with reduced scope. This buys three years, not a solution, and the private-edition transition route can stretch a subset of complex customers to 2033 — but only under a RISE with SAP commitment and already on HANA.
Take third-party support. Independent providers support ECC well beyond SAP’s dates at materially lower cost, covering security and regulatory updates SAP’s customer-specific tier does not. It is a deliberate strategic choice for firms whose migration case is genuinely unclear — but it forecloses SAP innovation and carries its own commercial and licensing complexity.
There is no universally correct answer. The right one depends on your regulatory exposure, the complexity of your landscape, and your internal capacity to run a multi-quarter programme without dropping the day job.
Why waiting is the expensive choice
The trap in a 2027 deadline is that it feels distant enough to defer. Two forces make delay costly in a way that is easy to miss.
The first is the consultant market. Roughly three in four SAP customers are already migrated or actively moving, and industry analysts project many thousands still on ECC as the deadline lands. When the remaining firms all reach for the same shrinking pool of certified S/4HANA consultants at once, day rates rise and timelines stretch — precisely when a late mover has the least room to absorb either.
The second is your own custom code. Every additional year of bespoke development bolted onto an ageing ECC instance is more code that has to be remediated or retired before any conversion. Delay does not hold the problem still; it grows it. There is also a functional cliff hidden in the timeline: most S/4HANA Compatibility Packs — the temporary bridges for ECC functions not yet reproduced in S/4HANA — expired at the end of 2025, with a few running to 2030. A migration today has to solve the technical move and the functional gaps at the same time, where earlier movers could sequence them.
The board’s job, not the IT department’s
The mistake most technology leaders make in front of the board is presenting this as a compliance project with a deadline. That framing invites deferral. The better framing is a risk-and-control decision with a hard financial dimension: what exposure are we carrying each month we run finance and supply chain on a system losing its security and regulatory updates, and what does each of the three paths cost us in money, disruption and optionality?
Answering that well needs an honest read of the landscape before a migration partner is anywhere near the room — license baseline and indirect-access exposure, custom-code volume, the real regulatory dependencies sitting on ECC, and internal capacity. That assessment is what turns “we’ll deal with it” into a plan a board can approve on the first pass, and it is worth commissioning independently of the firm that will later bid to do the migration.
Who this is for
This reading is for:
- Boards and audit committees at firms still running SAP ECC
- CFOs weighing migration cost against the risk of staying put
- CIOs and CTOs who have to turn “we’ll deal with it” into a defensible plan
- PE operating partners with an ECC-dependent portfolio company
Sixteen Pillars gives boards an independent, costed read of the ECC options before the migration vendors arrive, and governs the programme on the board’s behalf. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Build and rescue work
Hands-on delivery of this kind is handled by Sixteen Pillars Studio.
Looking at an acquisition, supplier, or major project?
The greatest risks are rarely visible in the executive summary. The Sixteen Pillars framework surfaces the technology risks that diligence usually misses.