The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
A legacy software audit establishes what you are really running, which parts are out of support, which risks matter and which do not. The outcome is a proportionate modernisation strategy: keep, upgrade, refactor, migrate or replace, component by component.
Synthetic example. Your audit is scoped to your question.
A legacy software modernisation review assesses an ageing application's technologies, support status, technical debt and business fit, then recommends the least disruptive route to a supportable future. It treats a complete rewrite as one option among several, not the default.
It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.
.NET 8 and .NET 9 both leave support on 10 November 2026; Windows Server and SQL Server versions are ageing out too.
Cyber Essentials, customers or insurers asking about unsupported software.
Fewer engineers want to work on Web Forms, WCF or VB.NET, and recruitment is getting harder.
Someone has suggested starting again. You want an independent view before committing the budget.
Framework, runtime, OS, database and library versions mapped against vendor support lifecycles.
How tightly components depend on each other, and which can be modernised independently.
APIs and libraries with no modern equivalent, such as Web Forms, WCF server, Remoting or third-party controls.
SQL Server version, stored procedures, schema health and migration constraints.
Third-party APIs, file drops, accounting packages and other systems that a change would affect.
Which features are used, which are critical, and where the system genuinely holds the business back.
Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.
We agree the systems in scope and the decision the review supports: stay, upgrade, migrate or replace.
Every framework, runtime, platform and library recorded with its support status and risk.
Upgrade blockers, coupling and technical debt assessed, with candidate approaches per component.
Each credible option explained with its benefits, risks, dependencies and indicative effort.
See how findings are presented in our anonymised sample report.
| Area | Supporting authority | How it shapes the audit |
|---|---|---|
| Secure development practices and software acquisition | Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology | Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software. |
| Cloud reliability, security, cost and operational maturity | Azure Well-Architected FrameworkMicrosoft | Structures Azure workload assessment around its five pillars: reliability, security, cost optimisation, operational excellence and performance efficiency. |
These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.
An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.
We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.
Due-diligence questionsRepository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.
Information securityWorking copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.
Data residencyAssemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.
Visit the Trust CentreWhere personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.
You may not need to. .NET Framework 4.8.1 remains supported as a component of supported Windows versions, so many Framework applications can stay where they are if the hosting platform and dependencies are kept current. The review identifies which parts are genuinely at risk and which are fine.
From 10 November 2026 Microsoft stops issuing security updates for .NET 8 and .NET 9. Applications keep running, but new vulnerabilities will not be patched. The supported path is .NET 10, a Long Term Support release. Read our guide to the .NET 8 and .NET 9 end of support.
Often, in stages. Web Forms has no direct equivalent in modern .NET, but pages can be migrated incrementally to Razor Pages or Blazor while the rest of the application keeps running. WCF services have migration routes including CoreWCF, gRPC or Web API. The review recommends the route per component.
No. Sometimes the right answer is to keep a stable system, patch the platform it runs on and invest elsewhere. The review exists to support a proportionate decision.
One evidence-based method, applied to the decision in front of you. Each specialist assessment can run on its own or as part of a comprehensive audit.
Keep, upgrade, refactor, migrate or replace: a proportionate modernisation decision for ageing .NET systems.
Tell us which systems are ageing and what is driving the question. We will scope a review that ends with a clear, costed set of options rather than a default rewrite.
Discuss Your Requirements All Software Audit ServicesCyber Essentials Plus certified · NDA as standard · UK-based team · Microsoft Partner · No obligation to appoint us for remediation