Russian accounting software: how to migrate from 1C and BAS to A5

August 10, 2026 · 7 min

On 10 August 2026, the online newspaper Ekonomichna Pravda published an article titled "TCCs, Diia and miltech still use Russian software. Why Ukraine cannot get off 1C". It once again raised the issue of abandoning Russian software, using 1C and BAS as examples. This is why we are analysing the actual risks of such dependence and the practical path of migrating to the Ukrainian platform A5.

Legal status of Russian software as of August 2026

There are many myths surrounding the legal regulation of Russian software products. In particular, Draft Bill No. 13505, which proposed a direct ban on the use of hostile software products, was rejected and withdrawn from consideration on 30 June 2026. Therefore, this draft bill cannot be interpreted as an active general ban for private businesses.

At the same time, the official list of the State Service for Special Communications and Information Protection applies within the scope defined by law, particularly for state information resources and critical information infrastructure. Special restrictions should not be automatically applied to all private businesses, but companies should verify their own status, contractual requirements, and integrations with regulated counterparties.

It is also worth taking public analytics with a pinch of salt. For example, the mention of 1C or BAS in a company's job vacancies is not indisputable proof of the actual use of a specific product in current operations. It is merely an indicator of dependence that requires separate verification.

1C and BAS risks: a threat in the supply chain

The Ekonomichna Pravda article analyses in detail why the threat of using Russian software is real. The main risk is not that every software installation contains malicious code or embedded viruses. The primary danger is concentrated in the supply chain and the non-transparency of updates.

When the origin of updates, the team responsible for them, and the verification procedure are not transparent, each subsequent configuration change creates an uncontrolled risk. Regular changes to Ukrainian tax legislation force companies to keep their accounting systems up to date. If patches are created by unknown teams or downloaded from unverified sources, the risk of financial data compromise increases.

An assessment by the IT Ukraine Association within the "Hostile Software" project indicates that a significant portion of the market remains dependent on these systems. However, the methodology behind the 75% user figure on the project page has not been disclosed, so it should be treated as an approximate marker of the scale of the problem rather than official state statistics. The practical danger for businesses is economic and operational dependence on a non-transparent support chain.

Audit as the first step of migration and inventory of custom modifications

A complex accounting system cannot be reliably replaced by simply transferring licenses. Years of using 1C or BAS result in the system becoming cluttered with numerous specific customisations, reports, and integrations with other corporate solutions. Therefore, migration is a project of deep accounting transformation, not a simple replacement of an installation file.

The first step must be a detailed audit of the existing IT landscape. It is necessary to clearly document which business processes are tied to the old system, which external services exchange data with it, and what volume of historical information is critical to preserve.

Designing target architecture and transition roadmap

An evolutionary transition involves the phased deployment of new modules with parallel testing of reporting. This approach reduces the scope of simultaneous change and allows for a controlled comparison of accruals and transferred balances. Special attention should be paid to staff training, as the interface and operational logic of the new platforms differ from legacy systems.

For companies seeking to replace legacy systems, IQusion offers the A5 line of solutions — "A5 Accounting" and "A5 Personnel" — on the UnityBase platform. "A5 Accounting" covers accounting and tax reporting, assets and inventory, banking and Treasury, settlements with counterparties, VAT, budgeting, and statutory reporting. "A5 Personnel" automates HR records, organisational structure, working hours, orders, payroll, reporting, and electronic approval workflows. IQusion customises the solutions to the client's regulations, integrates them with the existing IT landscape, migrates data, and trains the team; this is a managed migration project, not an automatic conversion of old configurations.

To plan a migration project, the CIO and CFO should use an infrastructure readiness assessment tool, which helps identify potential bottlenecks before the active development phase begins.

  • Inventory of custom code: Determining the volume and criticality of modifications accumulated in 1C/BAS over the years.
  • Integration mapping: Documenting all data exchange points with CRM, ERP, banking systems, and state registries.
  • Assessment of update criticality: Analysing business processes that depend on regular changes in tax and accounting legislation.
  • Historical data audit: Determining the depth and volume of data that must be migrated to the new system, and cleaning up obsolete records.
  • Compatibility testing: Verifying infrastructure readiness for the deployment of new solutions.

Frequently Asked Questions

Is there a complete legislative ban in Ukraine on the use of 1C and BAS for private businesses?

No, as of August 2026, there is no general ban for all private businesses. Draft Bill No. 13505 was rejected in June 2026. The restrictions of the State Service for Special Communications and Information Protection apply to government institutions and critical infrastructure facilities.

Can all settings and configurations be automatically migrated from 1C to new systems?

No, automatic configuration conversion is impossible. The transition involves individual customisation to the client's regulations, integration design, and controlled migration of historical data.

What is the main security risk of using Russian software if it does not contain viruses?

The main risk is related to the supply chain. Due to the lack of official developer support, updates are created by non-transparent companies, which poses a threat of malicious code injection during a routine patch.

Sources