HUBLCORE

Monday, 10 August 2026 · London

Search

Technology 6 min read

Ukraine’s 1C/BAS problem is now a software-governance test

Legacy ERP skills remain visible in military and government hiring while Ukraine’s prohibited-software list expands. The challenge is shifting from sanctions policy to asset inventory, migration funding and accountable technology governance.

Ukraine’s 1C/BAS problem is now a software-governance test
Джерело зображення: Wikimedia Commons / Mrrrk.smith, CC BY-SA 4.0.

For technology leaders, Ukraine’s continuing 1C/BAS story is less about one accounting brand than about software governance under wartime pressure. The country has a growing legal mechanism for excluding sanctioned technology from sensitive systems, yet public hiring records still show demand for 1C/BAS knowledge in defense and government finance roles. The gap between those two facts is an implementation problem.

Military Unit A5118 advertised for an accountant in March and listed 1C, 1C Accounting and BAS skills. Military Unit A4640 sought a head of accounting and reporting with experience in 1C and BAS. A Kyiv regional territorial recruitment and social support center also listed familiarity with software such as 1C as useful for an accounting position.

A vacancy does not establish deployment architecture. It cannot show whether the software is the current system of record, an archive being retired or a compatibility requirement during migration. What it does show is institutional dependence on knowledge. From a governance perspective, that matters because human skills often outlive procurement decisions and reveal where legacy processes remain embedded.

The same pattern appears at Diia. A June 25 finance and economics vacancy expected strong 1C, BAS or analogous software skills. That should not be misreported as evidence that the Diia mobile app runs on 1C. The role was financial, while Diia’s public technical hiring separately covers mobile products, DevOps, systems analysis, APIs and application security. The relevant issue is back-office architecture, not the consumer interface.

This is a classic enterprise-technology asymmetry. Organizations modernize visible products first because customers and political leaders can see the benefit. Accounting systems are harder because they hold historical data and encode processes that must remain correct every day. A new app can launch in versions. A payroll or financial ledger cannot tolerate a period in which balances do not reconcile.

Ukraine’s legal framework raises the stakes. SSSCIP’s official guidance explicitly discusses 1C and BAS as products included because of the sanctioned rights holder, 1C LLC. It emphasizes that the prohibited list is a sanctions-policy instrument rather than a technical vulnerability rating. That is a useful governance distinction: legal provenance risk and technical exploit risk are related but not identical controls.

For covered systems, legal provenance is sufficient to require action. The restrictions apply to environments handling state information resources, official data, state secrets and critical information infrastructure. SSSCIP says the obligation does not disappear when a system is air-gapped. A prohibited component can make the system ineligible for security authorization or lead to revocation of an existing approval.

On July 17, the prohibited list expanded from 1,079 to 1,341 entries. A list of that size cannot be managed effectively through memory or occasional manual checks. It requires software asset management, ownership mapping, component inventories, supplier due diligence and an escalation process that assigns responsibility for replacement.

That is where the 1C/BAS case becomes instructive for any government or large enterprise. The real control is not “never buy product X again.” The control is the ability to answer four questions quickly: What software do we run? Who owns it? What data does it touch? What is our replacement plan if its legal or security status changes?

Migration also needs financial governance. ERP replacement includes data extraction, transformation, reconciliation, configuration, integrations, training and sometimes dual operation. Those costs are front-loaded, while the benefit — reduced strategic dependency — is distributed across the organization and the state. Individual departments therefore have incentives to postpone the project unless budgets and deadlines are explicit.

Ukraine is experimenting with one answer. On July 28, IT Ukraine and Germany’s GIZ launched an additional voucher round to support micro and small businesses replacing 1C/BAS with modern ERP platforms. It turns a national resilience goal into a funded transformation project, which is often the missing step in compliance programs.

The original claim also named Fire Point. MAIR verified Fire Point’s role as a Ukrainian defense-tech manufacturer but found no independent 1C/BAS evidence in the public vacancies reviewed. That company-specific element remains unverified and should not be repeated simply because the wider pattern is real.

The broader lesson is institutional. Technology sovereignty is not achieved when a procurement rule changes. It is achieved when an organization can discover dependencies, assign owners, finance migration, validate data and retire the old system. Ukraine’s 2026 job ads show that this final stage is still underway.