SAP S/4HANA

The Banking SAP Migration Checklist: 9 Things Regulated Institutions Must Settle Before ECC Support Ends in 2027

Maitsys SAP Team
Aug 12, 2026
7 min read

Share:
Nine questions before 2027. What regulated institutions must settle before ECC support ends.
TL;DR —Mainstream maintenance for SAP ECC 6.0 (EHP 6–8) ends December 31, 2027, with optional extended maintenance through December 31, 2030 at roughly a 2% premium on your existing maintenance base. For banks, insurers and other regulated institutions, the constraint is not the technology — it is auditability, historical data retention, and interface continuity.

Before you pick a migration path, settle these nine items:

  • Enhancement-pack version and eligibility
  • Regulatory reporting owner
  • Data retention and archiving strategy
  • Audit-trail continuity across cutover
  • The full interface inventory
  • Custom code and clean-core posture
  • Close-cycle baseline
  • Phased vs. big-bang risk tolerance
  • Internal audit sign-off gates

Institutions that finish this checklist first typically choose a selective/ phased transition rather than greenfield.

Why the 2027 date is different for a bank

Every SAP customer is looking at the same calendar. Mainstream maintenance for SAP ECC 6.0 enhancement packages 6 through 8 ends on December 31, 2027, followed by optional extended maintenance until December 31, 2030 for customers who qualify — priced at about a 2% premium on the existing maintenance basis, which in practice lands closer to a 9–12% total cost increase once SAP's annual index-linked uplift is layered on. SAP leadership has repeatedly confirmed the 2027 date is not moving.

What makes this different for a regulated institution is that ERP is not just a system of record — it is the evidence chain. When mainstream maintenance lapses, you stop receiving legally-required regulatory updates and security patches on the standard track. For a manufacturer that is an operational risk. For a bank it is a supervisory risk: your reporting stack is now running on an unsupported base while examiners are asking who signed off on it.

That reframes the question. It is not "when do we migrate?" It is "what evidence do we need to produce, continuously, through and after the migration?"

Fig. 1 — The Maintenance Runway

Mainstream Maintenance
Extended Maintenance · ~2% Premium · 9–12% All-in
Aug 2026
you are here
31 Dec 2027
mainstream ends
31 Dec 2030
hard stop
~17 months
of mainstream runway left
EHP 6+ only
below EHP 6, the 2030 fallback does not exist

Extended maintenance is a transitional fallback, not a plan — and it is only available to customers on enhancement pack 6 or above.

The 9-point checklist

Fig. 2 — Nine things to settle before you pick a path

01
Enhancement pack
confirms which runway you are on
02
Reporting owner
named, with veto on scope
03
Data retention
7–10 yrs — pick the pattern
04
Audit-trail continuity
traceable across cutover
05
Interface inventory
best predictor of duration
06
Clean-core posture
gates every SAP AI capability
07
Close-cycle baseline
no baseline, no business case
08
Approach & risk
phased dominates in regulated
09
Audit gates
checkpoints, not a post-mortem

Work the list before you choose brownfield, greenfield or selective — the answers decide the path for you.

1. Confirm your exact enhancement pack version — it decides your options

Extended maintenance eligibility depends on being onEHP 6 or above. Institutions still on EHP 5 or lower do not have the 2028–2030 runway as a fallback; the 2027 date is a hard wall. Pull the actual EHP level from your system, not from the last architecture deck. This single fact determines whether you have a 17-month runway or a 41-month one.

2. Name the regulatory reporting owner before you name the SI

Regulatory reporting is the workstream that breaks migrations in financial services, and it breaks for a structural reason: the SI is measured on go-live, the regulator is not. Those two clocks are in direct conflict, and unless someone inside the institution owns the mapping of every statutory and supervisory report to its source objects in the target system — with veto power on scope — the conflict resolves in favour of the go-live date every time. Name that person before you sign the SI contract, not after. If the answer is "the SI will figure it out," the answer is wrong.

3. Settle historical data retention before choosing a migration approach

Retention obligations in banking commonly run 7–10 years, and in some jurisdictions longer. You have three viable patterns: carry history into S/4HANA, retain a read-only legacy instance, or move history to a compliant archive with a documented retrieval SLA. Each has a different cost curve and a different examiner conversation. Pick one, price it, and document why.

4. Prove audit-trail continuity across cutover

The hardest question internal audit will ask is: "can you reconstruct a transaction that started in ECC and settled in S/4HANA?" Design the cutover so change logs, document numbers and approval records are traceable end-to-end across the boundary. This is a design decision, not a testing task — retrofitting it is expensive.

5. Inventory every interface, including the ones nobody owns

A typical ECC landscape in a bank exchanges data with core banking, payment rails and SWIFT, EDI partners, tax engines, treasury systems, CRM, regulatory reporting engines, and dozens of custom point-to-point interfaces built over two decades. Interface count — not module count — is the best early predictor of migration duration. Count them before you estimate.

6. Take your clean-core posture seriously now, not in phase 3

SAP's extensibility model now runs a four-level A–D maturity framework, giving you a structured path off modifications and toward ABAP Cloud and side-by-side BTP extensions. The reason this matters on day one rather than day 400:every SAP AI capability — Joule, embedded analytics, autonomous agents — is designed against a clean, standardized core. A migration that carries your modifications forward technically succeeds and strategically fails.

7. Baseline your close cycle before you touch anything — you get one chance

This is the item institutions skip and cannot recover. The moment cutover happens, your pre-migration baseline is gone: you can no longer measure it, only estimate it, and an estimate will not survive a CFO's scrutiny when you claim the benefit eighteen months later. Record four numbers now — days-to-close, manual journal entries per close, reconciliation exception rate, and restatement history. It takes a week. Skipping it means the entire financial case for the program becomes unfalsifiable, which is another way of saying unprovable.

8. Match the approach to your risk tolerance, honestly

Brownfield preserves history and process, greenfield buys a clean core at the cost of a re-implementation, and selective/bluefield splits the difference. In heavily regulated environments, risk tolerance — not ambition — usually decides, and phased or selective transitions dominate for a reason: they keep the evidence chain intact and the blast radius small.

The uncomfortable version of this conversation: brownfield is often chosen because it is the path of least organisational resistance, not because it is the right answer. It carries your modifications forward, which means you clear the 2027 deadline and inherit the clean-core problem intact — you have bought time, not capability. That is a defensible decision if you make it deliberately and budget for the remediation. It is an expensive accident if you drift into it.

Fig. 3 — Choosing your path

Brownfield

Technical conversion

  • History preserved
  • Core stays as-is
  • Lowest disruption
Carries your modifications forward

Selective / Bluefield

Phased, entity by entity

  • History preserved
  • Clean core, phased
  • Smallest blast radius
Most common in regulated institutions

Greenfield

Re-implementation

  • Cleanest core
  • Process redesign
  • Highest control rebuild
Controls and reporting rebuilt from zero
Risk tolerance decides — not ambition.

In regulated environments the middle column wins most of the time, because it keeps the evidence chain intact.

9. Put internal audit and the regulator on the plan, early

Build audit checkpoints into the plan as gates, not as a post-go-live review. The institutions that struggle are the ones where internal audit first sees the migration design six weeks before cutover.

What this means for your timeline

Working backwards from December 31, 2027: a regulated, multi-entity S/4HANA program with a serious regulatory reporting workstream is rarely under 18 months, and the market's delivery capacity tightens sharply through 2027 as the deadline concentrates demand. If you are starting the assessment in late 2026, you are on time. If you are starting the assessment in mid-2027, extended maintenance is no longer a strategic choice — it is the only option left, and you will be paying the premium for a decision you deferred.

FAQ

When exactly does SAP ECC support end?

Mainstream maintenance for SAP ECC 6.0 (enhancement packages 6–8) and SAP Business Suite 7 core applications ends December 31, 2027. Optional extended maintenance is available to eligible customers until December 31, 2030.

How much does SAP extended maintenance cost?

Extended maintenance from 2028 to 2030 is priced at approximately a 2% premium on the existing maintenance basis. Accounting for SAP's annual index-linked increases, the practical total increase reported is in the range of 9% to 12%.

Can banks just stay on ECC after 2027?

Technically the system keeps running, but you lose access to standard support, security patches and — critically for regulated institutions — legally-required regulatory updates. That creates supervisory exposure, not just operational risk.

Which migration approach is best for a bank — brownfield, greenfield or selective?

In regulated environments, selective/phased transitions are the most common choice because they preserve historical data and the audit trail while limiting the blast radius of any single cutover. Greenfield delivers the cleanest core but requires re-implementing controls and reporting from scratch.

How long does an S/4HANA migration take for a financial institution?

For a multi-entity regulated institution with a full regulatory reporting workstream, 18+ months is a realistic planning assumption. Interface count and custom-code footprint are the two strongest predictors of duration.

Do we need a clean core before we can use SAP Joule and AI agents?

Effectively, yes. SAP's AI capabilities are designed to run against a standardized core, and heavy modifications block them. Clean core is best treated as a migration design constraint rather than a later cleanup project.

Get Your SAP Readiness Assessment

Find out where your migration actually stands — enhancement pack level, interface count, and clean-core exposure — before your SI quotes the project.

Book Your Assessment

Banking SAP migration checklistSAP S/4HANA for financial servicesECC 2027 deadline bankingRegulated ERP migrationSAP extended maintenance 2030
M

About Maitsys

We guide regulated institutions through complex SAP S/4HANA migrations with a focus on compliance, clean core, and business value.

Related Articles

Want to Learn More?

Connect with our experts to discuss how we can help transform your business.

Connect with Us

© 2026 MAITSYS. All Rights Reserved.