Talk to Jason

Is Your Legacy System Costing More to Keep Than to Replace?

Most sources on this topic give you a threshold, but none provide evidence for it. Even the places you'd expect to find real data don't offer any. Here's what you can actually check instead.

By Jason Flatford Updated

The short answer

  • There isn't a published crossover point. Standards, formal methods, and research don't set one, and the thresholds you hear about aren't backed by sources.
  • The claim that 60 to 80 percent of IT budgets go to maintenance can't be traced to a real source. The trail ends at a blank web page.
  • What really matters are dates. End-of-life dates are published and clear. Since March 2025, PCI DSS treats unsupported software as a documented issue, not just a judgment call.
  • Most projects don't go over budget. Out of 4,677 projects, the typical overrun is zero. The sample's mean is 80 percent, but there are enough extreme cases that the authors say the true average can't be calculated.
  • There are three good reasons to keep your system, starting with one people rarely mention: age alone isn't a problem.

There is no formula, and that is the answer

Most sources on this topic suggest a threshold: replace your system when annual maintenance is more than 30% of the original build cost, when repairs take four times longer than they used to, or when the cost crossover happens within two years.

I tried to find the sources for these numbers. None are cited. One modernization consultancy lists seven different numeric triggers, but not a single footnote.

This isn't by accident. The sources you'd expect to set a threshold simply don't provide one.

If the field's own research says this question is still unsolved, there's no agreed threshold. Anyone claiming otherwise is making it up. Here's what you can actually check.

The statistic you are about to be quoted

You'll probably hear that organizations spend 60 to 80 percent of their IT budgets on maintenance. I tried to track down the source. It leads from modernization blogs, to a magazine article that now returns a 404, to a consultancy page with no content. There's no real study behind it.

The number that is real, and checkable, is narrower. In July 2025 the US Government Accountability Office reported that about $83 billion, roughly 79 percent of planned federal IT spending across the major agencies, was for operations and maintenance rather than development or modernization. It also found that the eleven federal systems most in need of replacement are between 23 and 60 years old and cost around $754 million a year just to run.

Keep the context in mind: this data is about the US federal government, which has more legacy systems and stricter procurement rules than most. Using it as a general fact about all organizations is a common mistake, and careful readers will notice.

What actually decides it is dates, not economics

Here, the evidence is clear and easy to verify. Platform vendors publish the exact dates when they stop providing security updates, and those dates don't depend on your budget.

A few, from the vendors' own pages: PHP 7.4 stopped receiving security support on 28 November 2022, PHP 8.0 on 26 November 2023 and PHP 8.1 on 31 December 2025. Extended support for Windows Server 2012 R2 ended on 11 October 2023, with paid Extended Security Updates running only to 14 October 2026.

Published end-of-support dates for the platforms named above, from the vendors' own pages.
Product and version Support that ends Date
PHP 7.4Security support28 November 2022
PHP 8.0Security support26 November 2023
PHP 8.1Security support31 December 2025
Windows Server 2012 R2Extended support11 October 2023
Windows Server 2012 R2Paid Extended Security Updates14 October 2026

Then the part most people miss. Since 31 March 2025, PCI DSS Requirement 12.3.4 has required organizations in scope to review at least annually whether their hardware and software are still vendor-supported, and to document a remediation plan for anything that is not. If you take card payments, running end-of-life software stopped being a judgment call and became a documented finding.

So the real way to answer "is it time" isn't by using a ratio. List every platform your system relies on, check their end-of-life dates, and see which ones are past. This takes an afternoon and gives you something concrete to show your board.

The risk is shaped differently than you have been told

You'll also hear that software projects often go way over budget. But the best data tells a more useful, if less catchy, story.

Mean versus median cost overrun across 4,677 IT projects Across 4,677 IT projects, the mean cost overrun is 80 percent while the median cost overrun is zero. Most projects land near budget and the risk sits in a long tail. From Flyvbjerg and colleagues, 2022, open access. Mean cost overrun: 80% Median cost overrun: 0% 0% 50% 100% Same 4,677 projects. The mean is dragged by a long tail; the typical project is on budget.
Mean versus median cost overrun across 4,677 IT projects.
Measure Cost overrun
Mean80%
Median0%
Across the 4,677 IT projects that reported both an estimate and an actual cost, the mean cost overrun is 80 percent and the median is zero. They come from a collected sample of 5,392 projects worth $56.5 billion in 66 countries. The mode is also zero, and overruns and underruns are about equally frequent. The distribution is a power law, and in the tail it is heavy enough that the authors state the average cost overrun cannot be calculated at all. Flyvbjerg and colleagues, 2022, open access.

Look closely at the data, because it tells both sides. It's not true that software projects always run over budget. Most finish on budget. But don't get too comfortable, because the real risk is in the rare but severe overruns. An earlier study found about one in six projects went 200 percent over cost.

In practice, don't plan your replacement project based on the average result, because the average isn't what causes problems. Instead, plan so that if things go wrong, you can stop at any stage and still have something useful delivered.

Four questions that beat any threshold

  • Which parts of your system are already past their end-of-life date, and which ones are next? You can check this in an afternoon, and once it's written down, it's clear.
  • Can you still hire people who know this system? The issue isn't just whether the technology is old, but whether you can replace the person who understands it. A system that only one person knows is a bigger risk than an old system several people can support.
  • How long does it take to make a change now? Don't rely on opinions about technical debt. Instead, count the days between requesting a change and having it live, based on your last five changes. If that number is increasing, it's a warning sign.
  • What would actually break if the system stopped working today? Not every system is critical. Sometimes, systems are replaced that no one really needed.

If you answer these four questions, you usually won't need a ratio. The answer will be clear. If it's still not clear, that's a sign your system is probably fine and the real issue lies elsewhere.

When to keep it

There are three situations where keeping your system makes sense, and they're more common than the modernization industry admits.

If your system works, is supported, and doesn't need constant changes, that's a good thing. Age alone isn't a problem. A system that hasn't needed updates in six years is a success, not a liability. Often, "legacy" just means the software is complete.

If you can't explain what the replacement system does differently, it may not be worth it. Rebuilding the same features in a new framework just adds migration risk and brings back bugs you've already fixed.

If no one is responsible for the outcome, replacement projects often fail, not because of technical issues, but because key decisions aren't made. Make sure someone can make final calls before you spend money.

And for fairness, since the horror stories get repeated more than the rest: the audited record contains successes too. The GAO found the IRS modernization portfolio in 2024 mostly on schedule and about $512 million under plan, before it was paused for reasons that had nothing to do with overruns.

How I would approach it

A Diagnostic Week costs $2,500, fixed. For this question, the results are straightforward: you get an end-of-life list, a measure of change costs, an honest assessment of hiring risk, and a fixed quote for whatever the answer is. You keep all of this, no matter what you decide next.

Builds typically cost between $15,000 and $50,000, based on the Diagnostic Week. If the real issue is a process or a person, not your system, that's what the report will say. I'd rather tell you that than sell you an unnecessary replacement.

Common questions

When does legacy software cost more to keep than to replace?

There is no published threshold, and the ones you will find quoted are invented. Lehman's first law of software evolution stops at the word judgment, the Software Engineering Institute's formal method has you supply your own criteria, ISO/IEC/IEEE 14764's Replacement clause sets no numeric test, and a peer reviewed research agenda published in 2024 still lists this decision as an open problem.

What you can check instead are dates: which of your platform dependencies are past their published end-of-life, how long a change now takes compared with a year ago, and whether you could hire a replacement for the person who understands it.

Is it true that 60 to 80 percent of IT budgets go to maintenance?

That figure has no traceable source. Following it leads through modernization blogs to a magazine feature that now 404s, and from there to a consultancy page that loads successfully and contains no text at all.

The checkable version is narrower and federal. In July 2025 the US Government Accountability Office reported about $83 billion, roughly 79 percent of planned federal IT spending at major agencies, going to operations and maintenance rather than modernization. That is the US federal government specifically, not organizations in general.

Do most software replacement projects run over budget?

No, and the best dataset says so clearly. Across the 4,677 IT projects that reported both an estimate and an actual cost, the median cost overrun is zero and so is the mode, with overruns and underruns about equally frequent.

The danger is the shape rather than the average. The distribution is a power law with a tail heavy enough that the authors state the average overrun cannot be calculated. An earlier study, Flyvbjerg and Budzier 2011, put roughly one project in six at 200 percent over cost. Plan so the tail cannot kill you rather than planning around the average.

What is the strongest signal that it really is time?

A published end-of-life date that has already passed on something load-bearing, especially where compliance applies. Since 31 March 2025, PCI DSS Requirement 12.3.4 has required organizations in scope to review annually whether their software is still vendor-supported and to document a remediation plan for anything that is not.

At that point the decision has stopped being an economic judgment and become a documented finding.

When should I keep the old system?

When it works, is still supported and has not needed changing, because age is not a defect. When you cannot describe what the replacement does differently, since rebuilding the same features in a newer framework buys you migration risk and every bug you already fixed once. And when nobody owns the outcome, because replacement projects usually fail on unmade decisions rather than on technology.

Sources

I opened each of these and checked it against the figure it supports, on the date shown.

  1. Lehman, Programs, Life Cycles, and Laws of Software Evolution, Proceedings of the IEEE 68(9), 1980: the first law, that a program keeps changing until it is judged more cost effective to replace the system with a recreated version. Checked .
  2. Software Engineering Institute, Options Analysis for Reengineering (OAR): A Method for Mining Legacy Assets (CMU/SEI-2001-TN-013): the method has the team develop its own screening criteria, such as cost or effort levels, rather than supplying a threshold. Checked .
  3. ISO/IEC/IEEE, 14764:2022 Software life cycle processes, Maintenance (official preview): the table of contents lists clause 6.1.8, Replacement. Checked .
  4. Assunção, Marchezan, Egyed and Ramler, Contemporary Software Modernization: Perspectives and Challenges to Deal with Legacy Systems (SE 2030, 2024): challenge C5 of its ten-challenge research agenda is "Decide among replace, maintain, evolve, re-engineer, or migrate". Checked .
  5. US Government Accountability Office, GAO-25-107795: Agencies Need to Plan for Modernizing Critical Decades-Old Legacy Systems: about $83 billion (79 percent) of planned fiscal year 2025 IT spending for operations and maintenance, and 11 critical legacy systems about 23 to 60 years old costing about $754 million a year. Checked .
  6. PHP, Unsupported Branches: end of life for PHP 7.4 on 28 November 2022, PHP 8.0 on 26 November 2023 and PHP 8.1 on 31 December 2025. Checked .
  7. Microsoft, Windows Server 2012 R2 lifecycle: extended support ended 11 October 2023, and Extended Security Update Year 3 ends 14 October 2026. Checked .
  8. PCI Security Standards Council, PCI DSS v4.0.1: Requirement 12.3.4, an annual review that technologies still receive vendor security fixes and a senior-management-approved plan to remediate outdated technologies, a best practice until 31 March 2025. Checked .
  9. Flyvbjerg and colleagues, The Empirical Reality of IT Project Cost Overruns, Journal of Management Information Systems (2022): 4,677 of 5,392 projects with both costs, a mean overrun of 80 percent with median and mode near zero, and the statement that the average overrun cannot be calculated. Checked .
  10. Flyvbjerg and Budzier, Why Your IT Project May Be Riskier Than You Think, Harvard Business Review (2011): one in six of 1,471 projects with a cost overrun of 200 percent on average. Checked .
  11. US Government Accountability Office, GAO-25-107611: IRS Is Developing a New Modernization Framework: in fiscal year 2024, 181 projects on time and nine significantly late, spending about $1.5 billion, $512 million less than planned, before the March 2025 pause. Checked .

Bring me your end-of-life list

It only takes fifteen minutes. If your system is old, supported, and working well, I'll tell you that honestly, so you can stop worrying.

Book a 15-minute call