GTR GOVERNMENT TECHNOLOGY REVIEW

Legacy System Modernization in State Government

State and local governments budgeted $144 billion for IT in 2024. Most of that money did not build anything new. It went toward …

Senior Writer · · 11 min read
Cover illustration for “Legacy System Modernization in State Government”
Government IT Infrastructure · July 20, 2026 · 11 min read · 2,485 words

State and local governments budgeted $144 billion for IT in 2024. Most of that money did not build anything new. It went toward keeping aging systems alive, systems that, in many cases, should have been replaced a decade ago. That is the central paradox of legacy modernization in state government: the systems that most need replacing are the same systems consuming the budget that would pay for their replacement. Think of it like spending your entire paycheck on patching a leaking roof, never saving enough to just build a new one. This is not primarily a funding problem. It is a prioritization and execution problem, and the states that are closing the modernization gap are doing so not because they found more money, but because they made sharper decisions about how to sequence the money they already had.

What "Legacy System" Actually Means in a State Government Context

The term gets used loosely, so it is worth being precise. A legacy system, in the government IT context, is not simply an old system. It is a system that can no longer be safely maintained, meaningfully extended, or integrated with modern infrastructure. Age is a symptom. The real problem is functional brittleness.

Many of these systems were written in COBOL, a programming language that dates to 1959. That is not a typo. COBOL still processes an estimated $3 trillion in financial transactions daily and runs 95% of U.S. ATM transactions. State unemployment systems, financial management platforms, and benefits administration tools follow the same pattern. Roughly 45 of the 50 states and the District of Columbia still run COBOL-based systems. Some federal systems exceed 50 years of continuous operation. The Department of Defense, until recently, ran applications on 1970s-era hardware using 8-inch floppy disks.

The reason "just upgrade it" is rarely a real option comes down to how these systems were built. They were constructed in languages and on hardware architectures that modern developers do not learn, on infrastructure that vendors no longer support, with security patch pipelines that have long since gone dry. Patching a system with no available patches is not a maintenance strategy. It is a holding pattern with a deteriorating floor beneath it.

How Modernization Has Ranked as a State CIO Priority, and What That Ranking Obscures

Legacy modernization has appeared on NASCIO's State CIO Top Ten priority list consistently from 2013 through 2023. For 2026, NASCIO's survey of 51 state and territory CIOs places it at number four, behind AI and generative AI, cybersecurity, and budget and cost control. That is a high ranking. It is also a damning one.

When a priority appears on the same top ten list for more than a decade without cycling off as a solved problem, the list is telling you something important: stated priority and funded execution are not the same thing. The gap between them is precisely where modernization projects stall.

NASCIO's 2026 framing of modernization is worth reading carefully. It encompasses not just platform replacement but business process improvement and governance, an acknowledgment that the technology swap is the easier half of the problem. What is also worth noting is that NASCIO has identified a trend of states providing supplemental funding dedicated specifically to IT modernization, routed directly to the CIO organization rather than left to individual agencies. That structural workaround matters, because it moves prioritization authority to the level where enterprise decisions can actually be made, rather than leaving each agency to compete for its own modernization budget in isolation.

The Security Exposure That Comes from Delaying Modernization

The security case for modernization is not theoretical. Eight of the eleven most critical federal legacy systems flagged by GAO in 2025 use outdated programming languages. Four have unsupported hardware or software. Seven are operating with known cybersecurity vulnerabilities and no credible remediation timeline.

Verizon's 2024 Data Breach Investigations Report found that attacks exploiting vulnerabilities as the initial access vector nearly tripled year over year, a 180% increase. Legacy systems with unpatched software are the clearest exposure point in any agency's attack surface. Many of these systems also cannot integrate with modern security information and event management platforms, the tools that collect and analyze real-time security logs. An agency running a COBOL-era system that cannot talk to its SIEM is not just vulnerable; it is blind to intrusion attempts as they occur.

The consequences are concrete. In July 2024, a ransomware attack attributed to the Rhysida group hit Columbus, Ohio, compromising the personal data of 500,000 individuals and exfiltrating 6.5 terabytes of sensitive data. The City Council subsequently allocated up to $7 million for recovery. Between 2014 and 2022, data breaches across local, state, and federal agencies cost governments an estimated $26 billion.

Security risk is not uniform across every legacy system. However, agencies running systems with known vulnerabilities and no remediation path carry the most concentrated exposure. That asymmetry should drive sequencing: the highest-risk systems deserve the first slot in the modernization queue, not the last.

The Workforce Problem That Makes Legacy Systems Harder to Leave Behind

The technology challenge is tractable. The workforce challenge is not, at least not on a long timeline.

Sixty percent of organizations using COBOL report that finding skilled developers is their single largest challenge. The average COBOL programmer is now 55 years old, with roughly 10% of that workforce retiring annually. Maryland IT Secretary Katie Savage has described COBOL retirements as a "significant operating risk," specifically because departing employees carry institutional knowledge of these systems with no succession plan in place. GAO IT specialist Nick Walsh has been even more blunt: some of the experts who know how to maintain critical legacy systems are not just retired. They are deceased.

The compounding logic here is worth sitting with. The longer a state waits to modernize, the fewer people remain who understand the existing system well enough to safely migrate it. Texas state employees under 30 carry a 38% turnover rate. Separately, 38% of state and local government employees report accelerating retirement plans. Younger staff have limited professional interest in learning systems that are already being phased out, or should be.

Gartner has predicted that the majority of modernization stalls will occur not because of technology limitations but because no one is left who understands the legacy system well enough to move it safely. So the workforce clock is the most underappreciated deadline in the entire modernization conversation. It does not pause for budget negotiations.

What Federal Modernization Outcomes Reveal About Why Projects Fail

The federal record is instructive, and not in an encouraging way. Six years after GAO identified the ten most critical federal legacy systems requiring modernization, only three had been completed as of July 2025: at the Small Business Administration, the Office of Personnel Management, and the Department of Defense. The remaining seven systems range from 23 to 59 years old. Together, the ten most obsolete systems cost roughly $337 million per year in operations and maintenance alone.

The VA Electronic Health Record modernization is the clearest cautionary case available. It was the fourth attempt to replace the VA's legacy EHR system. It began in 2017, first deployed in 2020, was paused in April 2023 following widespread clinician and patient dissatisfaction, and users at initial deployment sites remained generally dissatisfied as of late 2024. The project moved. It did not succeed.

What the federal evidence points to is a consistent set of failure patterns. Scope set too large. Insufficient input from end users before and during deployment. No fully documented modernization plan before execution began. Governance gaps at the oversight level. GAO's core finding is direct: agencies that lack fully documented modernization plans face a materially higher likelihood of cost overruns, schedule delays, and outright project failure. Failure, in turn, prolongs exposure to the exact vulnerabilities the modernization was supposed to eliminate.

The Department of Homeland Security, as of 2025, had not established a modernization timeline for its flagged system. That absence of a plan is itself a decision, and it carries consequences.

How States Making Progress Actually Sequence Their Modernization Work

The states demonstrating real progress share a common instinct: they treat sequencing as strategy, not scheduling.

Hawaii CIO Christine Sakuda has explicitly framed legacy modernization as a prerequisite for AI adoption. The state is modernizing its unemployment and financial management systems first, treating that sequence as a strategic dependency rather than running modernization and AI adoption in parallel. That is a meaningful architectural decision, not just a talking point.

Tennessee CIO Stephanie Dedmon has active modernization projects running simultaneously across the Department of Corrections, the Department of Children's Services, and the unemployment insurance platform. That suggests a portfolio management model operating at the CIO level rather than agency by agency, which distributes both risk and learning across the enterprise.

Minnesota IT Services' 2024 initiative moved major health and financial management application portfolios to consolidated, scalable infrastructure. The key outcome was not primarily a technology swap; it was centralized governance and reduced duplication. NASCIO's 2025 State CIO Survey identified consolidation and centralization as one of the defining trends shaping service delivery over the next one to three years. These states are reorganizing governance alongside technology, not after it.

The phasing principle that emerges across these examples is consistent: address systems with the highest security vulnerability and greatest workforce concentration risk first, then use early wins to build institutional confidence and the budget justification for the next phase. The VA case is partly a story about what happens when scope exceeds execution capacity. Resisting the impulse to modernize everything simultaneously is not timidity. It is discipline.

Modernization Approaches That Reduce Disruption to Active Services

No state agency can afford to go dark during a modernization. The services running on these legacy systems, unemployment insurance, benefits processing, financial management, are not optional. The approach has to be chosen accordingly.

The strangler fig pattern is one of the most pragmatic options available. New functionality is built incrementally around the legacy system, with the old system decommissioned in stages rather than replaced in a single cutover. This reduces the blast radius of any single failure point and allows the organization to learn as it goes.

API-layer approaches accomplish something similar: wrapping the legacy system with modern interfaces that enable data exchange with newer platforms before full migration occurs. It buys time and enables integration without requiring a complete lift. It is not a permanent solution, but it is a legitimate bridge.

Parallel running, operating legacy and new systems simultaneously while staff validate outputs, is expensive. It is also the safest option for high-criticality services where an undetected failure would have immediate consequences for residents. For benefits systems processing tens of thousands of transactions daily, that expense is often justified.

Pilot-then-scale is the sequencing logic that underlies most successful state efforts. Tennessee's agency-by-agency structure and Minnesota's consolidation approach both reflect this. Deploy to one jurisdiction, learn from it, then scale.

One step that is consistently underestimated and consistently skipped: capturing institutional knowledge before the people who hold it leave. Systems with poor documentation, which is the norm in COBOL-era platforms, require intensive knowledge-capture work before any migration begins. Skip this step and the migration will fail partway through, not because the technology was wrong, but because no one knew what the old system was actually doing. As one state IT director put it after a failed migration: "We didn't have a documentation problem. We had a 'the only person who knew how this worked retired in 2019' problem."

What Governance Structures Actually Support Sustained Modernization Over Time

Technology choices are reversible. However, governance structures determine whether progress survives leadership transitions and budget cycles. That distinction is the difference between a project and a program.

NASCIO's supplemental funding trend is a governance mechanism, not just a financing one. Routing dedicated modernization budgets to the CIO organization rather than leaving them to individual agencies centralizes prioritization authority at the level where enterprise decisions can be made consistently. Without that centralization, modernization competes with every other agency priority in every annual budget cycle, and it loses.

The Legacy IT Reduction Act of 2026, introduced by a bipartisan House group in April 2026 in direct response to the July 2025 GAO audit, would require agency CIOs to inventory every legacy system and develop five-year strategic plans. The significance of that legislation is not its mandates but what those mandates reveal: having a complete inventory and a documented plan are not advanced practices. They are baseline requirements. Many agencies do not have them.

GAO's finding that OMB failed to act on its 2016 recommendation to direct agencies in modernization efforts, and that GAO subsequently escalated to Congress, illustrates what happens when oversight accountability is absent across multi-year timelines. Modernization is long-cycle work. Without defined ownership, documented milestones, and periodic external review, it drifts.

The governance elements that appear consistently in successful cases are not complicated. An enterprise legacy system inventory. A documented modernization roadmap with clear milestones. Defined ownership at the CIO level. And periodic review by someone outside the immediate organization. After all, you cannot prioritize what you have not catalogued, and you cannot sustain progress through leadership changes without institutional accountability structures that outlast any individual.

Where State Modernization Efforts Stand Now and What the Next Few Years Will Reveal

The 2026 NASCIO rankings show modernization holding near the top of state CIO priorities alongside AI and cybersecurity. Hawaii's sequencing logic, modernize first and then layer AI, suggests these two priorities are increasingly being understood as structurally linked rather than parallel tracks. You cannot build modern data pipelines on top of systems that cannot share data. So the AI ambition and the modernization obligation are converging.

The federal timeline illustrates the cost of delay with precision. Seven of the original ten flagged systems remain in operation, some approaching or past 60 years old, collectively consuming hundreds of millions of dollars annually just to keep running. The next federal completions due, at Education and Transportation, will be instructive. The Department of Homeland Security, with no timeline in place, will be equally instructive in the other direction.

For state agencies, the workforce retirement curve is the least forgiving constraint in the entire equation. Budget conditions change. Political priorities shift. Instead of widening, the window to capture institutional knowledge from COBOL-era system experts closes continuously with each retirement.

The pattern across every successful case in the available evidence is consistent and unglamorous: a documented plan, a defined sequence, governance accountability, and the discipline to run pilot phases before scaling. None of that requires a breakthrough technology. None of it requires a procurement revolution. It requires a sustained commitment to execution, maintained across budget cycles, leadership transitions, and the considerable institutional pressure to delay what is difficult in favor of what is urgent.

That is the real modernization problem. And that is exactly why it has been on the priority list for more than a decade.

Sources

  1. gao.gov
  2. mlogica.com
  3. centralsquare.com
  4. fedscoop.com
  5. nlc.org
  6. nascio.org

More in Government IT Infrastructure