Sthenos Technologies · Original Research

The 2026 Legacy Modernization Cost and Risk Report

Every enterprise and agency buyer I talk to is carrying at least one system they are afraid to touch. This page pulls the public record on what that fear actually costs into one sourced reference: what it takes to keep aging systems running, what happens when organizations try to replace them, and why the odds are worse than most boards believe. The data comes from the GAO, McKinsey, the Standish Group, and CISQ, and every figure links back to where it came from.

Over $100 billion a year, systems up to 60 years old, and large projects running 45 percent over budget while delivering 56 percent less value than promised.

Jump to the sourced stat block

By the numbersThe legacy modernization benchmark at a glance

Eight headline figures, each pulled from a primary or reputable public source and linked to its origin. If you are a journalist, lift any of them. Just credit the source.

$100B+
Annual U.S. government IT spend, with about 80 percent going to operating and maintaining existing systems.

Source: GAO-25-107795 (2025)

23 to 60 yrs
Age range of the 11 most critical federal legacy systems; 8 of 11 use outdated languages and 7 of 11 have known cybersecurity vulnerabilities.

Source: GAO-25-107795 (2025)

45%
Average budget overrun on large IT projects (initial budgets above $15 million), which also deliver 56 percent less value than predicted.

Source: McKinsey and University of Oxford

17%
Share of large IT projects that go so badly (budget overruns above 200 percent) they threaten the very existence of the company running them.

Source: McKinsey and University of Oxford

31%
Share of software projects that succeed, per Standish CHAOS 2020; 50 percent are challenged and 19 percent fail outright.

Source: Standish CHAOS 2020, via Henny Portman (secondary)

$2.41T
Estimated cost of poor software quality in the U.S. in 2022, including roughly $1.52 trillion in accumulated technical debt.

Source: CISQ, Cost of Poor Software Quality 2022

10 to 20%
Share of the new-product technology budget CIOs say is diverted to resolving technical debt; debt is estimated at 20 to 40 percent of estate value.

Source: McKinsey Digital, Tech Debt (survey of 50 CIOs)

$337M/yr
Cost to operate and maintain 10 critical federal systems (about 8 to 51 years old) identified by GAO in 2019; the SSA rehired retirees for COBOL skills.

Source: GAO-23-106821 (2023)

Section 1, The spendMost of the money never reaches new capability

Start with where the money actually goes, because that is the part most modernization pitches skip.

The U.S. government spends more than $100 billion a year on information technology, and agencies typically report that about 80 percent of that goes to operating and maintaining existing systems, including legacy systems, rather than building anything new (GAO-25-107795). Sit with that ratio for a second. Four out of every five dollars are spoken for before a single piece of new capability gets funded, which is how an agency can spend enormous sums on IT for a decade straight and still be running the same systems at the end of it.

The private sector likes to assume this is a government problem. It is not. In a McKinsey Digital survey of 50 CIOs, respondents reported that 10 to 20 percent of the technology budget earmarked for new products is diverted to resolving technical debt, and they put the debt itself at 20 to 40 percent of the value of their entire technology estate before depreciation (McKinsey Digital). I have sat across from enough CIO budgets to tell you those self-reported figures are, if anything, polite.

My read: whether the buyer is a federal agency or a commercial CIO, most of the technology budget is pre-spent on keeping the past alive. Modernization fights for the leftovers, and that is exactly why the debt compounds year after year.

Section 2, The riskBig projects systematically overpromise and underdeliver

Maintenance is the slow bleed. Large modernization projects are where organizations actually get hurt, and the bigger the project, the worse the odds.

McKinsey and the University of Oxford studied more than 5,400 IT projects and found that the large ones, meaning initial budgets above $15 million, ran on average 45 percent over budget and 7 percent over schedule while delivering 56 percent less value than predicted, for a combined $66 billion in cost overruns (McKinsey and Oxford). Those are the averages, not the horror stories.

The tail is where it gets frightening. The same research found that 17 percent of large IT projects go so far off the rails, with budget overruns above 200 percent, that they threaten the very existence of the company running them (McKinsey and Oxford). A project that overruns by that much stops being an IT problem. It goes to the board, and sometimes it takes the company with it. I have watched executives treat that number as someone else's statistic right up until the moment it was theirs.

Zoom out past the megaprojects and the base rate is still ugly. Standish Group CHAOS 2020 puts software project outcomes at about 31 percent successful, while 50 percent are challenged and 19 percent fail outright (Standish CHAOS 2020, reported by Henny Portman, a secondary summary of the proprietary CHAOS figures). Most projects either struggle or die, that has been roughly true for as long as Standish has been counting, and every modernization plan I review still assumes it will be the exception.

Large IT projects, averages from the McKinsey and University of Oxford study of more than 5,400 projects.
MetricResult for large IT projects
Budget overrun45% over budget
Schedule overrun7% over schedule
Value delivered vs. predicted56% less value
Total cost overruns (aggregate)$66 billion
Projects that threaten company survival17%
Software project outcomes, Standish Group CHAOS 2020 (secondary summary of proprietary figures).
OutcomeShare of projects
Successful~31%
Challenged50%
Failed19%

Section 3, The federal angleSystems old enough to collect Social Security

If you want legacy risk made concrete, read the GAO. Federal oversight is the one place where somebody publishes the actual systems, their actual ages, and their actual exposure.

The GAO reports that the 11 most critical federal legacy systems range from 23 to 60 years old. Of those 11, 8 use outdated programming languages and 7 operate with known cybersecurity vulnerabilities (GAO-25-107795). Think about what that combination means: code written in languages most of the current workforce never learned, carrying documented holes, sitting in seats the country cannot afford to have fail. Age by itself is survivable. Age plus a shrinking talent pool plus known vulnerabilities is a countdown.

And the workforce clock is already ringing. In 2019 the GAO identified 10 critical federal legacy systems ranging from about 8 to 51 years old, costing roughly $337 million a year to operate and maintain, and noted that the Social Security Administration had rehired retired employees to cover scarce COBOL skills (GAO-23-106821). When your maintenance plan involves calling people back out of retirement, the replacement decision has already been made for you. The only question left is whether you execute it on your schedule or on the system's.

Why this matters for oversight: the federal legacy inventory is the rare dataset where technical debt is auditable system by system. The ages are public, the languages are public, the vulnerabilities are public. It also puts a hard workforce clock on modernization timelines, because the people who understand these systems are retiring faster than the systems are.

Section 4, The national costPoor software quality is a trillion-dollar liability

Zoom all the way out and the bill stops looking like an IT line item.

The Consortium for Information and Software Quality (CISQ) estimated that poor software quality cost the U.S. $2.41 trillion in 2022, with accumulated software technical debt reaching roughly $1.52 trillion (CISQ, Cost of Poor Software Quality in the U.S., 2022). Put those figures next to national GDP and technical debt stops reading as an engineering complaint that gets triaged in a sprint. It is a macroeconomic drag, and every organization deferring modernization is quietly contributing its share.

National cost of poor software quality, CISQ 2022 report.
Measure2022 estimate
Total cost of poor software quality (U.S.)$2.41 trillion
Accumulated software technical debt~$1.52 trillion

Section 5, The evidence gapWhat the public data does not yet settle

Here is the part a vendor page would leave out.

The cost and risk of running legacy systems is well documented in public data. The return on modernizing them is not. Modernization ROI figures, the cost-reduction percentages and the multi-year payback claims, circulate everywhere, but when we traced them they led mainly back to vendor marketing rather than to any primary, independently published dataset. I sell modernization work for a living and I would still rather flag that gap than launder a marketing number through a benchmark page. If we could not chase a figure back to a resolvable origin, it is not on this page.

Open call for data: if a primary, independently published dataset quantifying legacy-modernization ROI exists, send it to us and we will cite it. Until then, treat any modernization-ROI claim that lacks a resolvable primary source the way you would treat any other sales number.

Practitioner viewWhy big-bang rewrites keep failing

The data all points one way: the bigger and more all-or-nothing a modernization effort is, the worse the odds. A 45 percent average overrun and a 17 percent existential-failure rate are not bad luck, they are the predictable result of betting years of accumulated change on a single cutover. The modernizations I have seen survive are the ones done in small verifiable increments, where every step ships working value and the old system keeps running until the new one has earned the right to replace it. Suleman Siddiqui, Advisor to the CEO at Sthenos Technologies

Methodology and sourcesHow this benchmark was assembled

This is a synthesis report, not original survey research. It aggregates publicly available figures from primary and reputable secondary sources, and every statistic on this page links to a resolvable URL. Nothing was modeled, extrapolated, or invented. Where a commonly cited modernization-ROI number could not be traced to a primary source, we flagged it instead of repeating it. Sthenos Technologies authored this report and did not commission or fund any of the underlying studies.

  1. U.S. Government Accountability Office, GAO-25-107795 (2025), federal IT spending, operations-and-maintenance share, and critical-system ages, languages, and vulnerabilities.
  2. U.S. Government Accountability Office, GAO-23-106821 (2023), 2019 inventory of critical federal legacy systems, operating cost, and COBOL workforce findings.
  3. McKinsey and University of Oxford, Delivering large-scale IT projects on time, on budget, and on value, study of more than 5,400 IT projects.
  4. McKinsey Digital, Tech debt: Reclaiming tech equity, survey of 50 CIOs.
  5. Standish Group CHAOS 2020, summarized by Henny Portman (secondary source; the underlying CHAOS figures are proprietary).
  6. Consortium for Information and Software Quality, The Cost of Poor Software Quality in the U.S.: A 2022 Report.

Cite this report

Journalists and researchers are welcome to cite the aggregated figures on this page with attribution to the primary sources above. A suggested citation:

Sthenos Technologies. "The 2026 Legacy Modernization Cost and Risk Report." Published July 13, 2026. https://sthenostechnologies.com/legacy-modernization-cost-risk-2026/

Canonical URL: https://sthenostechnologies.com/legacy-modernization-cost-risk-2026/

About the authorWho compiled this

SS

Suleman Siddiqui is Advisor to the CEO at Sthenos Technologies, an AI-first custom software and IT services firm in the Washington, DC metro area serving government agencies and commercial clients. Sthenos is an EDWOSB and WOSB.

Press contact: Suleman Siddiqui on LinkedIn.

Modernizing a system this benchmark describes?

If the plan on the table is a big-bang cutover, talk to us before you commit. We de-risk modernization through incremental delivery, and we are happy to compare notes, no pitch required.

Book a 30-minute call