Legacy Application Assessment Services

Know What You Have Before You Rewrite It. A forensic audit of your technical debt, risks, and modernization options.

$95KMedian Cost
4-8 WeeksTimeline
83%Success Rate
6-9 monthsROI Timeframe
15-25% Portfolio RationalizationTypical Savings

The Challenge

Legacy application assessment solves a visibility problem before it becomes an execution problem: organizations that begin modernization programs without a rigorous portfolio inventory migrate the wrong applications in the wrong order, or miss critical security vulnerabilities in systems they didn't know existed. Based on analysis of 445 engagements, organizations that skip formal assessment before modernization have a 40% higher wave failure rate and spend an average of 35% more on remediation than those with pre-migration assessments.

The CMDB accuracy problem compounds the visibility gap. Central configuration management databases become stale within 12–18 months as teams provision resources outside formal change management processes. Analysis of 445 engagements found that CMDB-only portfolio inventories miss an average of 32% of actual running applications — including "zombie applications" (running but not used) and "shadow IT" (deployed by business units without IT knowledge). These undiscovered applications are disproportionately likely to run EOL software, because they were forgotten before patching routines captured them.

The high success rate (83%) reflects that portfolio assessment is a well-understood, lower-risk engagement compared to migration execution. When it fails, the cause is almost always post-assessment: organizations commission assessments without pre-committed budget for remediation, resulting in a risk register that stays on a shelf.

How to Evaluate Providers

Legacy application assessment providers differentiate on discovery methodology, scoring rigor, and deliverable quality. The key question is: how do they find applications you don't know about?

Discovery methodology comparison:

MethodApplication CoverageTimeCost PremiumBest For
CMDB export only65–70%1 weekNoneKnown portfolios, internal awareness only
Network scanning85–90%2–3 weeks20–30%Finding shadow IT and undocumented systems
Agent-based discovery92–96%2–4 weeks30–50%Most complete — finds all running processes
Hybrid (scanning + CMDB + interviews)95–98%3–5 weeks25–40%Best balance of coverage and stakeholder context

Red flags:

  • Assessments that rely exclusively on CMDB exports (misses 30% of applications on average)
  • No business criticality scoring methodology beyond IT perspective (business owners know which systems drive revenue, not just IT)
  • T-shirt sizing effort estimates without methodology documentation (effort estimates with no rationale cannot be challenged or calibrated)
  • Deliverables in read-only PDF format (assessment outputs must be editable so teams can maintain them post-engagement)

What to look for: Providers with specific automated scanning tool expertise (CAST Highlight for large portfolios, Veracode for security-focused assessments), case studies from similar portfolio sizes and industries, and deliverables that include unlocked Excel and interactive dashboards.

Implementation Patterns

Successful legacy assessments combine automated scanning with business owner interviews. Automated tools provide coverage and objectivity; interviews provide business context that tools cannot infer from code.

Phased discovery pattern:

  1. Automated inventory (week 1–2): Network scanning identifies all running applications. Static code analysis tools (CAST Highlight, SonarQube) produce objective code quality metrics (cyclomatic complexity, technical debt ratio, security vulnerability counts). This phase is non-disruptive — no code changes, no downtime.
  2. Business criticality interviews (week 2–3): Application owners scored on business impact (revenue dependency, regulatory criticality, user count), business value (strategic vs commodity), and change frequency (how often does business need updates). IT perspective alone systematically underestimates business criticality for applications used by specific business units.
  3. 6 R's disposition (week 3–4): Apply the 6 R's framework to each application using combined technical scores (from automated analysis) and business scores (from interviews). The disposition framework: Rehost (move to cloud as-is), Replatform (minor cloud optimizations), Refactor (significant code changes), Repurchase (replace with SaaS), Retire (decommission), Retain (keep on-prem, don't migrate).
  4. Prioritized roadmap (week 4–6): Sequence migration waves by combining: quick wins (high value + low complexity), risk reduction (critical security vulnerabilities), and strategic alignment (applications blocking digital transformation goals).

Zombie application identification: Applications that generate network traffic but have no active business users are candidates for immediate retirement. The typical enterprise portfolio has 20–30% zombie applications — running, licensed, and patched for systems nobody needs. Retiring these before migration reduces total migration scope by 20–30% and produces immediate licensing and hosting savings.

Technical debt quantification: Assessment deliverables should include a $ estimate of technical debt, not just a "high/medium/low" rating. The SQALE method (CAST, SonarQube) estimates technical debt as the engineering hours required to bring code to acceptable quality standards. This enables direct ROI comparison: "fixing this application's technical debt costs $400K vs replacing it with a SaaS alternative for $80K/year."

Total Cost of Ownership

Legacy assessment is one of the highest-ROI modernization engagements because it prevents misallocation of much larger migration budgets. Based on 445 engagements, organizations that act on assessment findings avoid an average of $1.2M in migration waste (migrating wrong applications, encountering undiscovered dependencies, redundant remediation).

Cost model by portfolio size:

Portfolio SizeEngagement CostTypical Findings ValueROI Multiple
20–50 apps$30K–$60K$200K–$600K avoided waste4–10×
50–100 apps$75K–$150K$500K–$1.5M avoided waste5–10×
100–300 apps$200K–$400K$1M–$4M avoided waste4–10×

Hidden costs beyond the engagement fee:

Cost CategoryTypical RangeNotes
Application owner interview time$20K–$50K1–2 hrs × 20–50 stakeholders at $100–$150/hr fully loaded
CMDB enrichment post-assessment$15K–$40KIT team effort to update central inventory with findings
Findings presentation preparation$5K–$20KInternal stakeholder briefings beyond the executive presentation

Zombie app retirement savings: The median assessment finds 23% of portfolio applications are retirement candidates. For a 100-application portfolio, retiring 23 applications typically saves $300K–$800K in annual licensing, hosting, and maintenance costs — often recovering the full assessment cost within the first year.

Post-Engagement: What Happens Next

After a legacy assessment, you own an application portfolio inventory, technical debt heatmap, 6 R's disposition plan, and a sequenced modernization roadmap. The next step is committing budget to act on findings.

Typical post-engagement sequence:

  • Week 1–4 post-assessment: Review findings with executive team. Approve budget for modernization program. Assign internal application owners to each application in the disposition plan.
  • Month 1–3: Retire zombie applications (immediate cost savings, zero migration risk). Begin Wave 1 (highest-priority, lowest-complexity applications).
  • Month 3–12: Execute migration waves following the assessment roadmap. Reassess changed applications if major scope changes occur.
  • Month 12–24: Mid-program review. Validate that TCO projections from assessment are tracking actual results. Adjust wave sequencing if business priorities have shifted.

Keeping the assessment current: Portfolio assessments become stale within 18–24 months as applications are deployed, retired, and changed. Plan a lightweight refresh assessment every 18–24 months, or after major events (M&A, major cloud migration, significant new application deployments).

Connecting assessment to execution: The assessment roadmap should directly inform your migration program's Wave 1 scope. Organizations that let assessment deliverables sit without acting within 6 months typically re-commission assessments before acting — paying twice for the same analysis.


Pain Points

The 'Black Box' Problem

You have 50+ apps written in Java 6 or .NET 2.0. The original developers left 5 years ago. No one knows how they work, only that they break if you touch them.

M&A Due Diligence

You just acquired a company. Their CTO says the tech is 'modern'. You need a third-party audit to prove it's actually spaghetti code before you integrate it.

Cloud Migration Stalled

You tried to 'Lift & Shift' everything to AWS. It failed because the apps weren't cloud-ready. Now you need to know which ones to refactor and which to retire.

Compliance Audit Panic

Auditors are asking for a list of all systems running EOL (End of Life) software. You don't have that list. You need an automated inventory immediately.


Methodology

Automated Discovery (1-2 weeks)

Activities:

  • Static Code Analysis (CAST, SonarQube)
  • Infrastructure Scanning
  • Dependency Mapping Outcomes:
  • Raw Inventory Data
  • Vulnerability Report

Contextual Interviews (2 weeks)

Activities:

  • Interviews with remaining SMEs
  • Business value assessment (Is this app worth saving?)
  • Regulatory review Outcomes:
  • Business Criticality Scores
  • Hidden Knowledge Capture

Analysis & Roadmap (2 weeks)

Activities:

  • 6 R's Workshop
  • Cost-Benefit Analysis
  • Sequencing the roadmap Outcomes:
  • Final Assessment Report
  • Executive Presentation

Deliverables

  • Application Portfolio Inventory (Excel / CMDB Import): A complete list of every application, its language, framework version, database, and dependencies. No more 'I think we have that'.
  • Technical Debt Heatmap (Interactive Dashboard): Visual dashboard showing risk scores for every app. Based on code complexity (Cyclomatic), security vulnerabilities (CVEs), and EOL components.
  • 6 R's Disposition Plan (PPT + Excel): The verdict for each app: Rehost, Replatform, Refactor, Repurchase, Retire, or Retain. Includes estimated effort (T-shirt sizing) for each.
  • Cloud Suitability Scorecard (Excel): 0-100 score for every app's readiness for cloud. Checks for hardcoded IPs, local file storage, stateful sessions, and other cloud blockers.

Team Composition

  • Solution Architect: The 'Detective'. Digs into the code and architecture to find the truth.
  • Business Analyst: The 'Translator'. Maps technical complexity to business value.
  • Security Specialist: Checks for vulnerabilities and compliance risks.

Case Study

Industry: Manufacturing

Challenge: Global manufacturer had 400+ applications across 20 factories. No central inventory. Ransomware attack took down a critical plant because of an unpatched Windows 2003 server no one knew about.

Solution: Conducted automated portfolio assessment. Identified 120 'Zombie Apps' (running but not used) and 50 critical security risks.

Results:

  • → Retired 120 apps (saving $2M/year in licensing/hosting)
  • → Patched/Ring-fenced all critical vulnerabilities in 30 days
  • → Created 3-year modernization roadmap for core ERP

Success Factors

  • Access to Source Code (No code, no assessment)
  • Access to Production Infrastructure (Read-only)
  • Availability of SMEs (Even if they only know a little)

Decision Framework

When to proceed

  • You have 20+ applications and no central inventory of which are business-critical versus zombie apps
  • A cloud migration or major modernization program is planned in the next 12 months and you need to sequence the work
  • An M&A transaction requires technical due diligence on an acquired company's application portfolio
  • A compliance audit has requested documentation of all systems running EOL software
  • A new CTO or CIO has joined and needs an honest landscape assessment before committing to a roadmap

When NOT to proceed

  • You have fewer than 5 applications — a manual inventory is faster and more accurate
  • You already know exactly what you want to modernize and the scope is defined — start execution directly
  • You have no budget to act on findings — commissioning an assessment without remediation budget wastes investment
  • Your portfolio was assessed within the last 12 months and no major changes have occurred

Alternatives to consider

  • Cloud Readiness Assessment: More focused on migration suitability and TCO than overall portfolio health — Best for: Organizations specifically planning cloud migration rather than broad portfolio modernization
  • Modernization Strategy Services: Combines portfolio assessment with strategic roadmap and financial modeling — Best for: Organizations needing both portfolio analysis and board-level business case

Interactive Assessment

Legacy Application Complexity Scorer

Answer 5 questions to assess modernization complexity. This drives strategy (rehost vs refactor vs rewrite).

1. Do you have current technical documentation?
2. How many external dependencies does it have?
3. Estimated lines of code (LOC)?
4. Are SMEs (Subject Matter Experts) available?
5. What testing coverage exists?

Recommended Partners

vFunction logo
vFunction

Java Monolith Decomposition Analysis

Best for: Assessing Java apps for microservices migration

50 case studiesMidSizeUSA
Software Improvement Group (SIG) logo
Software Improvement Group (SIG)

Software Health Assessment (ISO 25010)

Best for: M&A due diligence and quality benchmarking

300 case studiesEnterpriseNetherlands (Global coverage)
Modernizing Medicine logo
Modernizing Medicine

Healthcare Legacy Systems

Best for: HIPAA-compliant healthcare application assessment

40 case studiesMidSizeUSA
Thoughtworks logo
Thoughtworks

Strategic Modernization Assessment

Best for: Combining technical + business value analysis

200 case studiesEnterpriseGlobal
CAST Software logo
CAST Software

Automated Code Analysis (CAST Highlight)

Best for: Large portfolios (100+ apps) needing rapid assessment

600 case studiesEnterpriseGlobal (HQ: New York)
Micro Focus logo
Micro Focus

Legacy Language Experts (COBOL, Fortran, PL/I)

Best for: Mainframe and midrange application analysis

1000 case studiesEnterpriseGlobal

Frequently Asked Questions

Do legacy application assessment services use automated tools?

Yes, we use static analysis tools like CAST, SonarQube, and Micro Focus Enterprise Analyzer to scan code, but Senior Architects interpret the results to find architectural flaws and business logic that tools miss. Tools find syntax errors; architects find strategic problems.

What if we don't have documentation for our legacy applications?

That's normal and expected. We specialize in 'Software Archaeology' - reading code to reverse-engineer business logic without docs. 80% of our clients have zero documentation. We interview remaining SMEs and use code analysis to reconstruct how systems actually work.

How much do legacy application assessment services cost?

$30K-$400K depending on scope. Single app deep dive (2-3 weeks) = $30K-$60K. Portfolio assessment (20-50 apps, 4-6 weeks) = $75K-$150K. Full IT landscape (100+ apps, 8-12 weeks) = $200K-$400K. ROI: Typical clients retire 15-25% of portfolio, saving millions in maintenance costs.

How long does a legacy application assessment take?

2-12 weeks depending on complexity. Single application = 2-3 weeks. Portfolio (20-50 apps) = 4-6 weeks. Enterprise landscape (100+ apps) = 8-12 weeks. We deliver assessments quickly because you need data to make budget decisions - not 6-month analysis paralysis projects.

What happens after the assessment?

You get a prioritized roadmap with 6 R's disposition (Rehost/Replatform/Refactor/Repurchase/Retire/Retain) for each app. You own all the data (Excel, code scan reports, architecture diagrams). Then you bid out execution work to multiple vendors using our independent assessment - this saves millions vs letting the vendor doing assessment also do the rewrite.

Can you assess mainframe applications and COBOL code?

Yes. Legacy assessment covers all platforms: Mainframe (COBOL, PL/I, Assembler), Midrange (AS/400, RPG), Client-Server (PowerBuilder, VB6, Delphi), and Early Web (ColdFusion, Classic ASP). We have specialized tools and architects for each platform. If it's old and undocumented, we can assess it.

Peter Korpak

Chief Analyst, Software Modernization Intelligence · 10+ years B2B market research

Last reviewed:

445 samples analyzed