GAO: Information Technology: Agencies Need to Plan for Modernizing Critical Decades-Old Legacy Systems

Why GAO Did This Study

Each year, the federal government spends more than $100 billion on IT and cyber-related investments. Of this amount, agencies have typically reported spending about 80 percent on operations and maintenance of existing IT. This includes maintaining legacy systems that can pose significant challenges, such as increased costs and cybersecurity vulnerabilities.

In June 2019, GAO identified 10 critical federal legacy IT systems that were most in need of modernization. As of February 2025, agencies have completed three of the 10 modernizations. Of the seven remaining modernizations, agencies planned to complete four in the next few years, two in 5 or more years, and one does not yet have a planned completion date established.

GAO was asked to conduct an updated review of federal agencies’ current legacy systems. GAO’s specific objective for this report was to identify the federal legacy systems most in need of modernization and evaluate plans for modernizing them.

To do so, GAO asked the 24 Chief Financial Officers Act agencies to provide their three legacy IT systems most in need of modernization and obtained a total of 69 systems. GAO scored these systems based on 16 system attributes and associated point values, such as age, vendor support, use of legacy programming languages, degree of cybersecurity risk, and operating costs. GAO ranked the systems based on their scores and selected those with the highest scores.

For the resulting 11 systems, GAO compared the agencies’ modernization plans against leading practices. According to government and industry best practices, agencies’ documented plans for system modernization should include, at a minimum, (1) milestones, (2) a description of the work, and (3) details regarding disposition of the legacy system. GAO then analyzed agencies’ documented modernization plans for the selected systems to determine whether the plans included these elements.

This is a public version of a sensitive report that is being issued concurrently. Sensitive information, such as system names and identifiers, has been omitted.

What GAO Found

As determined by GAO’s review of 69 federal legacy IT systems, the 11 legacy systems most in need of modernization are maintained by 10 federal agencies. These agencies’ missions are essential to government operations such as health care, critical infrastructure, tax processing, and national security, and these legacy systems provide vital support to the agencies’ missions.

GAO identified 11 legacy IT systems as most in need of modernization (see table 1). Eight of the 11 systems use outdated languages, four have unsupported hardware or software, and seven are operating with known cybersecurity vulnerabilities. For example, both of the Department of the Treasury’s selected systems run on Common Business Oriented Language (COBOL) and Assembly Language Code—programming languages that have a dwindling number of people available with the skills needed to support them. In addition, the Environmental Protection Agency’s system contains obsolete hardware that is not supported by manufacturers and has known cybersecurity vulnerabilities that cannot be remediated without modernization…

The incomplete modernization plans are especially concerning for seven of the systems because they reportedly have modernizations already underway. These seven systems belonged to six agencies: Agriculture, Commerce, Defense, Health and Human Services, Transportation, and the Treasury.

Until agencies fully document modernization plans for critical legacy IT systems, their modernization initiatives will have an increased likelihood of cost overruns, schedule delays, and overall project failure. Project failure would be particularly detrimental not only because of wasted resources, but also because it would prolong the lifespan of increasingly vulnerable and obsolete systems. This could expose agencies and system clients to security threats and potentially significant performance issues. Further, there are likely more legacy systems needing attention beyond what is highlighted in this report.

GAO recommended nearly a decade ago, and has since made it a priority recommendation, that OMB direct agencies to identify legacy systems and/or investments needing to be modernized. OMB has not yet taken action. Given OMB’s lack of action, Congress requiring federal agencies to develop modernization plans for critical legacy systems can expedite agencies’ efforts.

Recommendations

GAO is making one matter for congressional consideration: Congress should consider requiring major federal agencies to develop modernization plans for their legacy systems that have been identified as most in need of modernization.

In the sensitive report, GAO is also making a total of eight recommendations to seven agencies to ensure that they fully document modernization plans for the selected legacy systems.

Three agencies agreed with GAO’s recommendations and three agencies neither agreed nor disagreed. In addition, one agency disagreed with its recommendation and GAO revised it to reflect updated information.

Access the report here.

A Public Benefit Corporation means the mission remains the mandate, even when it is hard. Learn more about OrangeSlices PBC



Not Yet an OrangeSlices Insider? Learn more about the OS PBC Insider Corporate and Individual Plans here. Plans start at $295 annually.

LEAVE A REPLY

Please enter your comment!
Please enter your name here