Legacy Application Assessment Services
Know What You Have Before You Rewrite It. A forensic audit of your technical debt, risks, and modernization options.
On this page
- The Challenge
- How to Evaluate Providers
- Implementation Patterns
- Total Cost of Ownership
- Post-Engagement: What Happens Next
- Pain Points
- The 'Black Box' Problem
- M&A Due Diligence
- Cloud Migration Stalled
- Compliance Audit Panic
- Methodology
- Automated Discovery (1-2 weeks)
- Contextual Interviews (2 weeks)
- Analysis & Roadmap (2 weeks)
- Deliverables
- Team Composition
- Case Study
- Success Factors
- Decision Framework
- When to proceed
- When NOT to proceed
- Alternatives to consider
The Challenge
Legacy application assessment solves a visibility problem before it becomes an execution problem: organizations that begin modernization programs without a rigorous portfolio inventory migrate the wrong applications in the wrong order, or miss critical security vulnerabilities in systems they didn't know existed. Based on analysis of 445 engagements, organizations that skip formal assessment before modernization have a 40% higher wave failure rate and spend an average of 35% more on remediation than those with pre-migration assessments.
The CMDB accuracy problem compounds the visibility gap. Central configuration management databases become stale within 12–18 months as teams provision resources outside formal change management processes. Analysis of 445 engagements found that CMDB-only portfolio inventories miss an average of 32% of actual running applications — including "zombie applications" (running but not used) and "shadow IT" (deployed by business units without IT knowledge). These undiscovered applications are disproportionately likely to run EOL software, because they were forgotten before patching routines captured them.
The high success rate (83%) reflects that portfolio assessment is a well-understood, lower-risk engagement compared to migration execution. When it fails, the cause is almost always post-assessment: organizations commission assessments without pre-committed budget for remediation, resulting in a risk register that stays on a shelf.
How to Evaluate Providers
Legacy application assessment providers differentiate on discovery methodology, scoring rigor, and deliverable quality. The key question is: how do they find applications you don't know about?
Discovery methodology comparison:
| Method | Application Coverage | Time | Cost Premium | Best For |
|---|---|---|---|---|
| CMDB export only | 65–70% | 1 week | None | Known portfolios, internal awareness only |
| Network scanning | 85–90% | 2–3 weeks | 20–30% | Finding shadow IT and undocumented systems |
| Agent-based discovery | 92–96% | 2–4 weeks | 30–50% | Most complete — finds all running processes |
| Hybrid (scanning + CMDB + interviews) | 95–98% | 3–5 weeks | 25–40% | Best balance of coverage and stakeholder context |
Red flags:
- Assessments that rely exclusively on CMDB exports (misses 30% of applications on average)
- No business criticality scoring methodology beyond IT perspective (business owners know which systems drive revenue, not just IT)
- T-shirt sizing effort estimates without methodology documentation (effort estimates with no rationale cannot be challenged or calibrated)
- Deliverables in read-only PDF format (assessment outputs must be editable so teams can maintain them post-engagement)
What to look for: Providers with specific automated scanning tool expertise (CAST Highlight for large portfolios, Veracode for security-focused assessments), case studies from similar portfolio sizes and industries, and deliverables that include unlocked Excel and interactive dashboards.
Implementation Patterns
Successful legacy assessments combine automated scanning with business owner interviews. Automated tools provide coverage and objectivity; interviews provide business context that tools cannot infer from code.
Phased discovery pattern:
- Automated inventory (week 1–2): Network scanning identifies all running applications. Static code analysis tools (CAST Highlight, SonarQube) produce objective code quality metrics (cyclomatic complexity, technical debt ratio, security vulnerability counts). This phase is non-disruptive — no code changes, no downtime.
- Business criticality interviews (week 2–3): Application owners scored on business impact (revenue dependency, regulatory criticality, user count), business value (strategic vs commodity), and change frequency (how often does business need updates). IT perspective alone systematically underestimates business criticality for applications used by specific business units.
- 6 R's disposition (week 3–4): Apply the 6 R's framework to each application using combined technical scores (from automated analysis) and business scores (from interviews). The disposition framework: Rehost (move to cloud as-is), Replatform (minor cloud optimizations), Refactor (significant code changes), Repurchase (replace with SaaS), Retire (decommission), Retain (keep on-prem, don't migrate).
- Prioritized roadmap (week 4–6): Sequence migration waves by combining: quick wins (high value + low complexity), risk reduction (critical security vulnerabilities), and strategic alignment (applications blocking digital transformation goals).
Zombie application identification: Applications that generate network traffic but have no active business users are candidates for immediate retirement. The typical enterprise portfolio has 20–30% zombie applications — running, licensed, and patched for systems nobody needs. Retiring these before migration reduces total migration scope by 20–30% and produces immediate licensing and hosting savings.
Technical debt quantification: Assessment deliverables should include a $ estimate of technical debt, not just a "high/medium/low" rating. The SQALE method (CAST, SonarQube) estimates technical debt as the engineering hours required to bring code to acceptable quality standards. This enables direct ROI comparison: "fixing this application's technical debt costs $400K vs replacing it with a SaaS alternative for $80K/year."
Total Cost of Ownership
Legacy assessment is one of the highest-ROI modernization engagements because it prevents misallocation of much larger migration budgets. Based on 445 engagements, organizations that act on assessment findings avoid an average of $1.2M in migration waste (migrating wrong applications, encountering undiscovered dependencies, redundant remediation).
Cost model by portfolio size:
| Portfolio Size | Engagement Cost | Typical Findings Value | ROI Multiple |
|---|---|---|---|
| 20–50 apps | $30K–$60K | $200K–$600K avoided waste | 4–10× |
| 50–100 apps | $75K–$150K | $500K–$1.5M avoided waste | 5–10× |
| 100–300 apps | $200K–$400K | $1M–$4M avoided waste | 4–10× |
Hidden costs beyond the engagement fee:
| Cost Category | Typical Range | Notes |
|---|---|---|
| Application owner interview time | $20K–$50K | 1–2 hrs × 20–50 stakeholders at $100–$150/hr fully loaded |
| CMDB enrichment post-assessment | $15K–$40K | IT team effort to update central inventory with findings |
| Findings presentation preparation | $5K–$20K | Internal stakeholder briefings beyond the executive presentation |
Zombie app retirement savings: The median assessment finds 23% of portfolio applications are retirement candidates. For a 100-application portfolio, retiring 23 applications typically saves $300K–$800K in annual licensing, hosting, and maintenance costs — often recovering the full assessment cost within the first year.
Post-Engagement: What Happens Next
After a legacy assessment, you own an application portfolio inventory, technical debt heatmap, 6 R's disposition plan, and a sequenced modernization roadmap. The next step is committing budget to act on findings.
Typical post-engagement sequence:
- Week 1–4 post-assessment: Review findings with executive team. Approve budget for modernization program. Assign internal application owners to each application in the disposition plan.
- Month 1–3: Retire zombie applications (immediate cost savings, zero migration risk). Begin Wave 1 (highest-priority, lowest-complexity applications).
- Month 3–12: Execute migration waves following the assessment roadmap. Reassess changed applications if major scope changes occur.
- Month 12–24: Mid-program review. Validate that TCO projections from assessment are tracking actual results. Adjust wave sequencing if business priorities have shifted.
Keeping the assessment current: Portfolio assessments become stale within 18–24 months as applications are deployed, retired, and changed. Plan a lightweight refresh assessment every 18–24 months, or after major events (M&A, major cloud migration, significant new application deployments).
Connecting assessment to execution: The assessment roadmap should directly inform your migration program's Wave 1 scope. Organizations that let assessment deliverables sit without acting within 6 months typically re-commission assessments before acting — paying twice for the same analysis.
Pain Points
The 'Black Box' Problem
You have 50+ apps written in Java 6 or .NET 2.0. The original developers left 5 years ago. No one knows how they work, only that they break if you touch them.
M&A Due Diligence
You just acquired a company. Their CTO says the tech is 'modern'. You need a third-party audit to prove it's actually spaghetti code before you integrate it.
Cloud Migration Stalled
You tried to 'Lift & Shift' everything to AWS. It failed because the apps weren't cloud-ready. Now you need to know which ones to refactor and which to retire.
Compliance Audit Panic
Auditors are asking for a list of all systems running EOL (End of Life) software. You don't have that list. You need an automated inventory immediately.
Methodology
Automated Discovery (1-2 weeks)
Activities:
- Static Code Analysis (CAST, SonarQube)
- Infrastructure Scanning
- Dependency Mapping Outcomes:
- Raw Inventory Data
- Vulnerability Report
Contextual Interviews (2 weeks)
Activities:
- Interviews with remaining SMEs
- Business value assessment (Is this app worth saving?)
- Regulatory review Outcomes:
- Business Criticality Scores
- Hidden Knowledge Capture
Analysis & Roadmap (2 weeks)
Activities:
- 6 R's Workshop
- Cost-Benefit Analysis
- Sequencing the roadmap Outcomes:
- Final Assessment Report
- Executive Presentation
Deliverables
- Application Portfolio Inventory (Excel / CMDB Import): A complete list of every application, its language, framework version, database, and dependencies. No more 'I think we have that'.
- Technical Debt Heatmap (Interactive Dashboard): Visual dashboard showing risk scores for every app. Based on code complexity (Cyclomatic), security vulnerabilities (CVEs), and EOL components.
- 6 R's Disposition Plan (PPT + Excel): The verdict for each app: Rehost, Replatform, Refactor, Repurchase, Retire, or Retain. Includes estimated effort (T-shirt sizing) for each.
- Cloud Suitability Scorecard (Excel): 0-100 score for every app's readiness for cloud. Checks for hardcoded IPs, local file storage, stateful sessions, and other cloud blockers.
Team Composition
- Solution Architect: The 'Detective'. Digs into the code and architecture to find the truth.
- Business Analyst: The 'Translator'. Maps technical complexity to business value.
- Security Specialist: Checks for vulnerabilities and compliance risks.
Case Study
Industry: Manufacturing
Challenge: Global manufacturer had 400+ applications across 20 factories. No central inventory. Ransomware attack took down a critical plant because of an unpatched Windows 2003 server no one knew about.
Solution: Conducted automated portfolio assessment. Identified 120 'Zombie Apps' (running but not used) and 50 critical security risks.
Results:
- → Retired 120 apps (saving $2M/year in licensing/hosting)
- → Patched/Ring-fenced all critical vulnerabilities in 30 days
- → Created 3-year modernization roadmap for core ERP
Success Factors
- Access to Source Code (No code, no assessment)
- Access to Production Infrastructure (Read-only)
- Availability of SMEs (Even if they only know a little)
Decision Framework
When to proceed
- You have 20+ applications and no central inventory of which are business-critical versus zombie apps
- A cloud migration or major modernization program is planned in the next 12 months and you need to sequence the work
- An M&A transaction requires technical due diligence on an acquired company's application portfolio
- A compliance audit has requested documentation of all systems running EOL software
- A new CTO or CIO has joined and needs an honest landscape assessment before committing to a roadmap
When NOT to proceed
- You have fewer than 5 applications — a manual inventory is faster and more accurate
- You already know exactly what you want to modernize and the scope is defined — start execution directly
- You have no budget to act on findings — commissioning an assessment without remediation budget wastes investment
- Your portfolio was assessed within the last 12 months and no major changes have occurred
Alternatives to consider
- Cloud Readiness Assessment: More focused on migration suitability and TCO than overall portfolio health — Best for: Organizations specifically planning cloud migration rather than broad portfolio modernization
- Modernization Strategy Services: Combines portfolio assessment with strategic roadmap and financial modeling — Best for: Organizations needing both portfolio analysis and board-level business case
Interactive Assessment
Legacy Application Complexity Scorer
Answer 5 questions to assess modernization complexity. This drives strategy (rehost vs refactor vs rewrite).
Recommended Partners
Java Monolith Decomposition Analysis
Best for: Assessing Java apps for microservices migration
Software Health Assessment (ISO 25010)
Best for: M&A due diligence and quality benchmarking
Healthcare Legacy Systems
Best for: HIPAA-compliant healthcare application assessment
Strategic Modernization Assessment
Best for: Combining technical + business value analysis
Automated Code Analysis (CAST Highlight)
Best for: Large portfolios (100+ apps) needing rapid assessment
Legacy Language Experts (COBOL, Fortran, PL/I)
Best for: Mainframe and midrange application analysis
Frequently Asked Questions
Do legacy application assessment services use automated tools?
Yes, we use static analysis tools like CAST, SonarQube, and Micro Focus Enterprise Analyzer to scan code, but Senior Architects interpret the results to find architectural flaws and business logic that tools miss. Tools find syntax errors; architects find strategic problems.
What if we don't have documentation for our legacy applications?
That's normal and expected. We specialize in 'Software Archaeology' - reading code to reverse-engineer business logic without docs. 80% of our clients have zero documentation. We interview remaining SMEs and use code analysis to reconstruct how systems actually work.
How much do legacy application assessment services cost?
$30K-$400K depending on scope. Single app deep dive (2-3 weeks) = $30K-$60K. Portfolio assessment (20-50 apps, 4-6 weeks) = $75K-$150K. Full IT landscape (100+ apps, 8-12 weeks) = $200K-$400K. ROI: Typical clients retire 15-25% of portfolio, saving millions in maintenance costs.
How long does a legacy application assessment take?
2-12 weeks depending on complexity. Single application = 2-3 weeks. Portfolio (20-50 apps) = 4-6 weeks. Enterprise landscape (100+ apps) = 8-12 weeks. We deliver assessments quickly because you need data to make budget decisions - not 6-month analysis paralysis projects.
What happens after the assessment?
You get a prioritized roadmap with 6 R's disposition (Rehost/Replatform/Refactor/Repurchase/Retire/Retain) for each app. You own all the data (Excel, code scan reports, architecture diagrams). Then you bid out execution work to multiple vendors using our independent assessment - this saves millions vs letting the vendor doing assessment also do the rewrite.
Can you assess mainframe applications and COBOL code?
Yes. Legacy assessment covers all platforms: Mainframe (COBOL, PL/I, Assembler), Midrange (AS/400, RPG), Client-Server (PowerBuilder, VB6, Delphi), and Early Web (ColdFusion, Classic ASP). We have specialized tools and architects for each platform. If it's old and undocumented, we can assess it.
Chief Analyst, Software Modernization Intelligence · 10+ years B2B market research
Last reviewed:
445 samples analyzed