1. Home
  2. Services
  3. Software Audits
  4. Legacy Modernisation Review
Legacy Software Modernisation Review

Old technology does not automatically mean a rewrite.

A legacy software audit establishes what you are really running, which parts are out of support, which risks matter and which do not. The outcome is a proportionate modernisation strategy: keep, upgrade, refactor, migrate or replace, component by component.

.NET Framework, Web Forms, WCF SQL Server & Windows Server Rewrite only if justified Support dates checked

What is a Legacy Software Modernisation Review?

A legacy software modernisation review assesses an ageing application's technologies, support status, technical debt and business fit, then recommends the least disruptive route to a supportable future. It treats a complete rewrite as one option among several, not the default.

It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.

When to commission one

Situations where this review pays for itself

Support dates are approaching

.NET 8 and .NET 9 both leave support on 10 November 2026; Windows Server and SQL Server versions are ageing out too.

Security or insurance pressure

Cyber Essentials, customers or insurers asking about unsupported software.

Skills are getting scarce

Fewer engineers want to work on Web Forms, WCF or VB.NET, and recruitment is getting harder.

A rewrite has been proposed

Someone has suggested starting again. You want an independent view before committing the budget.

What we assess

Six areas, each rated for impact and urgency

Technology & support status

Framework, runtime, OS, database and library versions mapped against vendor support lifecycles.

Architecture & coupling

How tightly components depend on each other, and which can be modernised independently.

Upgrade blockers

APIs and libraries with no modern equivalent, such as Web Forms, WCF server, Remoting or third-party controls.

Data & database

SQL Server version, stored procedures, schema health and migration constraints.

Integrations

Third-party APIs, file drops, accounting packages and other systems that a change would affect.

Business fit

Which features are used, which are critical, and where the system genuinely holds the business back.

How it works

From scoping to a prioritised plan

Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.

1
Day 1

Scope & objectives

We agree the systems in scope and the decision the review supports: stay, upgrade, migrate or replace.

Output: Scope note
2
Days 2+

Inventory & lifecycle

Every framework, runtime, platform and library recorded with its support status and risk.

Output: Technology and support inventory
3
Next

Code & architecture review

Upgrade blockers, coupling and technical debt assessed, with candidate approaches per component.

Output: Options per component
4
Final week

Options & roadmap

Each credible option explained with its benefits, risks, dependencies and indicative effort.

Output: Modernisation roadmap
What you receive

Clear findings, honest boundaries

  Deliverables

  • Technology and support-lifecycle inventory
  • Upgrade blockers and their workarounds
  • Options appraisal: retain, remediate, upgrade, migrate, replace
  • Indicative effort ranges and dependencies per option
  • Phased modernisation roadmap
  • Risks of doing nothing, stated plainly

See how findings are presented in our anonymised sample report.

What this review does not do

  • Effort ranges are indicative; fixed estimates follow further discovery.
  • Licensing costs depend on your agreements with Microsoft and other vendors.
  • We recommend replacement only where the evidence justifies it.
Methodology

Aligned with recognised guidance

Recognised technical and regulatory guidance the audit methodology is aligned with
AreaSupporting authorityHow it shapes the audit
Secure development practices and software acquisition Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software.
Cloud reliability, security, cost and operational maturity Azure Well-Architected FrameworkMicrosoft Structures Azure workload assessment around its five pillars: reliability, security, cost optimisation, operational excellence and performance efficiency.

These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.

Confidentiality & evidence handling

Your code, credentials and data, handled with care

An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.

NDA before detail

We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.

Due-diligence questions

Read-only by default

Repository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.

Information security

Evidence handled deliberately

Working copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.

Data residency

Cyber Essentials Plus

Assemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.

Visit the Trust Centre

Where personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.

Frequently asked questions

Legacy Modernisation Review, answered

Our .NET Framework application still runs. Why change anything?

You may not need to. .NET Framework 4.8.1 remains supported as a component of supported Windows versions, so many Framework applications can stay where they are if the hosting platform and dependencies are kept current. The review identifies which parts are genuinely at risk and which are fine.

What does the November 2026 end of support for .NET 8 and .NET 9 mean?

From 10 November 2026 Microsoft stops issuing security updates for .NET 8 and .NET 9. Applications keep running, but new vulnerabilities will not be patched. The supported path is .NET 10, a Long Term Support release. Read our guide to the .NET 8 and .NET 9 end of support.

Can Web Forms or WCF applications be modernised without a rewrite?

Often, in stages. Web Forms has no direct equivalent in modern .NET, but pages can be migrated incrementally to Razor Pages or Blazor while the rest of the application keeps running. WCF services have migration routes including CoreWCF, gRPC or Web API. The review recommends the route per component.

Will you always recommend modernisation?

No. Sometimes the right answer is to keep a stable system, patch the platform it runs on and invest elsewhere. The review exists to support a proportionate decision.

Plan a proportionate modernisation

Tell us which systems are ageing and what is driving the question. We will scope a review that ends with a clear, costed set of options rather than a default rewrite.

Discuss Your Requirements All Software Audit Services

Cyber Essentials Plus certified  ·  NDA as standard  ·  UK-based team  ·  Microsoft Partner  ·  No obligation to appoint us for remediation

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor