Security and Compliance After 2027: What Losing SAP Patches Really Means


This is a gradual degradation, not a cliff edge, and that gradualness is precisely why it is dangerous. Nothing breaks on January 1, 2028. What accumulates instead, quarter over quarter, is a widening gap between what your ERP system can defend against and what a live vendor- supported system down the street can defend against. Compliance risk compounds in the same way — tax law and regulatory reporting requirements do not freeze just because your ERP support has, and an unpatched system's ability to keep pace with those changes falls further behind every filing period.
For Canadian finance and compliance functions specifically, this lands in a familiar place: audit exposure. An auditor reviewing internal controls over an ERP system running without vendor security or legal updates is going to ask pointed questions about compensating controls, and “we have a plan to migrate eventually” is a materially weaker answer than “we are already migrating on a scheduled timeline.” Reputational and regulatory exposure from a control failure tends to be far more expensive, and far more visible, than the migration project that would have prevented it.
Extended maintenance, available through 2030 for enhancement packages 6 through 8, does buy real time — it keeps security patches and legal updates flowing at a roughly 2% premium on existing fees. But it is a bridge with a hard endpoint. Customer-specific maintenance, the tier everyone eventually lands in without a further agreement, provides essentially none of that: no new security patches, no new legal or regulatory updates, and no guaranteed response times, at the same cost as full support.
© Orpington Technologies Inc.
www.orpingtontech.com
Page
2
of
3