Legacy systems rarely become expensive overnight. Their costs often rise gradually through support fees, specialist labour, security controls and operational friction.

Microsoft charges $61 per device for the first year of Extended Security Updates on Windows 10. The second year costs $122. The third costs $244. In Microsoft’s own words, “the price doubles every consecutive year, for a maximum of three years.”

That is what the cost of maintaining legacy systems looks like when a vendor is willing to publish it: not a flat line, but a curve that steepens on a schedule. Many legacy costs can behave this way, particularly when vendor support and specialist resources become more expensive. Very little of it is documented as clearly.

This guide separates what can actually be verified from what circulates as an estimate. It covers the prices vendors publish, the direct and hidden cost categories, why the number grows every year, a model you can run against your own estate, and the point at which continuing to pay stops being the cheaper option.

What Does it Cost to Maintain Legacy Systems?

That last point is worth being blunt about. Search this topic and you will find confident numbers: 60 to 80% of IT budgets go to legacy maintenance, a mid-size business spends $2 to $3 million a year, a single application costs $700,000 to $3 million. Trace them and most lead to another marketing page, an undated “industry data” attribution, or nothing at all. Any single figure quoted as the legacy system maintenance cost in 2026 should be treated cautiously, because legacy estates vary widely in complexity.

Three categories of figures are actually verifiable: prices vendors publish for extended support, spending that public bodies disclose, and research with a named author and methodology. The rest of this guide is built on those, and says so where it is estimating.

Public-sector disclosure gives the clearest view of the cost of legacy systems at scale. In GAO-25-107795, published 17 July 2025, the US Government Accountability Office reported that federal agencies have typically spent about 80% of their IT budgets operating and maintaining what already exists, amounting to roughly $83 billion of planned IT spending in FY2025. The same report examined the 11 federal legacy systems most in need of modernization: they ranged from about 23 to 60 years old and cost approximately $754 million a year to run between them. Eight of the 11 had no complete modernization plan.

That is one estate with unusual disclosure obligations, so it is not a benchmark for a private company. It is evidence that the 80% figure everyone quotes has a real source behind it, for at least one very large organization.

The Prices Vendors Actually Publish

The cleanest evidence of what legacy costs comes from the vendors charging for it. Two current examples set the pattern.

Microsoft, Windows 10. Support ended on 14 October 2025. Organizations that need patched machines past that date buy Extended Security Updates, priced per device through volume licensing.

ESU year Price per device Change
Year 1 $61 Baseline
Year 2 $122 Doubles
Year 3 $244 Doubles again

Table: Microsoft’s published Windows 10 ESU pricing, per device, via volume licensing. Total over three years is $427 per device, and the programme ends after year three.

Two details matter beyond the headline. Devices must be running version 22H2 to be eligible, so the cost of staying may include an upgrade you were avoiding. And Windows 10 virtual machines running on Azure, Windows 365 and Azure Virtual Desktop receive ESU at no additional cost, which is a pricing structure designed to make staying put more expensive than moving.

SAP, Business Suite 7. SAP’s published maintenance strategy runs mainstream maintenance for Business Suite 7 core applications until the end of 2027. Extended maintenance is then available for three years, from the start of 2028 to the end of 2030, at “a premium of two percent points on the maintenance basis for all support offerings.” After 2030, remaining customers move to customer-specific maintenance.

A two-point uplift sounds modest until you apply it to an eight-figure maintenance base and multiply by three years, and it arrives alongside every other cost in the sections below rather than instead of them.

The pattern generalises. When vendors price extended support at a premium, the additional cost can strengthen the business case for migration.

Direct Costs of Maintaining Legacy Systems

These are the legacy system maintenance costs that appear somewhere in a budget line, even if not always under a heading that names them. They are the easiest to quantify and the least likely to be the largest.

Cost category What drives it Where it sits
Extended or premium vendor support Per-device or percentage uplifts on retired versions, escalating annually IT operations
Hardware and hosting Aging servers, out-of-warranty equipment, specialist hardware with thin supply Infrastructure
Third-party licences Middleware, database and tooling versions pinned by the legacy application Software licensing
Specialist labour Premium rates for COBOL, RPG, PL/I, legacy middleware and retired framework skills Contractors and payroll
Compensating security controls Segmentation, virtual patching and dedicated monitoring for systems that cannot be patched Security
Interface upkeep Point-to-point integrations that break whenever anything upstream changes Integration and delivery
Regression testing Long manual test cycles because automated coverage was never built Delivery capacity

Table: Seven direct cost categories in legacy maintenance. Only the first three usually appear as an identifiable line item on a budget.

The direct number most organizations can produce quickly is support and licensing spend. For some estates, it may also be smaller than labour, infrastructure, security and integration costs.

Two of these lines behave differently from the rest. Specialist labour can become increasingly expensive as fewer engineers maintain expertise in retired platforms. And compensating security controls tend to accumulate, because each audit cycle more often adds a control than removes one, so the line can grow even in a year when nothing about the system changed.

Hidden Costs of Legacy Systems

The hidden costs of legacy systems are not hidden because anyone conceals them. They are hidden because they land in budgets that nobody connects back to the system causing them.

Hidden cost How it shows up Whose budget absorbs it
Manual workarounds Staff re-keying between systems that cannot exchange data Operations headcount
Change friction Releases take months because nobody trusts the blast radius Delivery capacity, never itemised
Blocked initiatives Analytics, AI and customer-facing projects stalled on data access No budget line at all
Downtime and remediation Incident response, recovery and customer impact after failures Operational risk
Recruitment drag Longer hiring cycles and salary premiums for unfashionable skills HR and recruitment
Knowledge concentration Work stops when one person is unavailable, and their retirement is a live risk Unquantified until it happens
Insurance and audit Higher cyber premiums, more audit findings, more remediation commitments Risk and compliance
Opportunity cost of capital Money spent standing still is money not spent on anything that grows Never measured

Table: Eight hidden cost categories. Each lands in a budget other than the one paying for the legacy system, which is why the total is routinely understated.

Research puts a scale on the aggregate. The Consortium for Information and Software Quality, in its Cost of Poor Software Quality in the US: A 2022 Report authored by Herb Krasner, estimated the cost of poor software quality in the United States at at least $2.41 trillion, with accumulated technical debt at approximately $1.52 trillion, and named technical debt the largest barrier to modifying existing codebases. That report covers 2022 and has not been superseded with a comparable figure, so treat it as an order-of-magnitude anchor rather than a current-year number.

Why is the Cost of Maintaining Legacy Systems Rising Every Year?

  • The cost of maintaining legacy software is not a plateau: Four forces push it up on a predictable schedule, and understanding them is what makes a multi-year forecast credible rather than a straight-line copy of last year’s spend.
  • Vendor pricing escalates by design: The Windows ESU schedule above doubles annually. SAP’s extended maintenance adds a premium on top of a base that has usually already risen. Extended support is priced as a disincentive, not as a service tier.
  • The skills market tightens: As platforms age, organizations may face a smaller talent pool and higher costs for engineers with relevant expertise. This cost can rise significantly when the available talent pool shrinks and demand for specialist expertise remains high.
  • Technical debt compounds: Each change made under time pressure without refactoring makes the next change more expensive. CISQ named exactly this as the largest barrier to modifying existing code.
  • The compliance gap widens: Requirements move; a frozen system does not. As compliance requirements change, organizations may need additional controls to keep aging systems aligned with current security and audit expectations.

The practical consequence is that a business case built on this year’s spend understates the do-nothing option. Forecast the curve, not the line.

Also Read: How Legacy Application Modernization is Driving Business Agility?

How to Calculate your Legacy System Maintenance Costs?

Nobody else’s average will survive contact with your estate. This is the model to run instead, per system rather than across the portfolio.

1. Fix the scope

One system, with its interfaces, its infrastructure and the people who support it. Portfolio-level numbers hide the systems that are actually expensive.

2. Pull the direct costs from finance

Support, licences, hosting and hardware for that system, for the last full financial year. This usually takes a few days and gives you the floor.

3. Cost the labour honestly

Go beyond the named support team. Include the delivery time spent on regression testing, the operations hours spent on manual workarounds, and contractor spend attributable to the platform. Loaded rates, not salaries.

4. Price the risk

Expected downtime hours multiplied by your own cost-per-hour figure, plus any cyber insurance loading or open audit findings traceable to this system. Use your incident history rather than an industry average.

5. Name what is blocked

List the initiatives that cannot proceed until this system changes. You do not need to monetise them precisely, but estimating their business impact can strengthen the modernization business case.

6. Project three years, with escalation

Apply real escalation to each line rather than repeating year one. Vendor pricing where published, a realistic uplift on specialist labour, and a growth assumption on change friction.

For a benchmark on the maintenance side, our build versus buy analysis puts ongoing maintenance for custom software at 15 to 20% of the original build cost annually. A legacy system running well above that band is telling you something specific about its condition.

Maintenance vs Modernization: Where the Lines Cross

Modernization typically creates a significant upfront investment, while legacy maintenance can continue generating recurring costs over time. The decision is about where those two curves intersect, and four signals move the crossover point closer.

  • A published vendor end date: Windows 10 support ended 14 October 2025. SAP Business Suite 7 mainstream maintenance ends at the end of 2027. A dated cliff converts an open-ended decision into a deadline.
  • A single point of human failure: One person or contractor holding the knowledge is a risk with no insurance product attached to it.
  • Blocked revenue work: When the backlog of initiatives waiting on this system has commercial value attached, the opportunity cost stops being theoretical.
  • Escalating compensating controls: When each audit cycle adds another control to keep an unchanged system acceptable, you are paying an annually increasing fee to avoid a one-off cost.

Two signals point the other way. A stable, contained, well-documented system with an active support contract and nobody waiting on its data is not a modernization priority, whatever its age. And a system due for retirement on a business timeline of its own should not be modernized on the way to the exit.

Legacy System Modernization Costs: Key Factors to Consider

Legacy system modernization costs vary by approach more than by system size. Rehosting is the cheapest route available. Full rebuild or replacement sits at the top, because development is a minority of the bill once migration, testing, training and parallel running are counted.

Our software product modernization guide puts modernization scope between $20,000 and $400,000 or more, with complexity, integrations, data migration and the modernization approach driving the final cost. Legacy system migration costs sit inside that range and are driven by the number of interfaces and the condition of the data rather than by data volume.

Four factors move a quote:

  • Interface count, because each connected system is a separate build, test and cutover.
  • Data condition, because duplicates, orphans and undocumented fields convert directly into effort.
  • Parallel running, because operating both systems through a verification period is a real and sustained cost.
  • Evidence and compliance scope, because regulated estates carry a documentation burden that is project cost, not overhead.

Where delivery is outsourced, rates vary enough by model and region to move the total materially. Our guide to choosing a software development outsourcing partner covers how to compare on that basis rather than on headline rate alone.

How to Reduce Legacy System Maintenance Cost in 2026?

Not every answer is a modernization programme. Five actions reduce spend without one, and they buy time for the ones that need it.

1. Decommission what nobody uses

Most estates carry systems still licensed, hosted and patched that no longer serve a live process. This is the cheapest saving available and the one most often skipped, because finding them requires an inventory nobody owns.

2. Consolidate duplicate capability

Mergers and departmental purchasing leave organizations running several systems that do the same job. Retiring the weakest removes a full cost stack rather than trimming one.

3. Renegotiate before the cliff, not after

Support pricing is most negotiable while you still have the option to leave. Once a published end date has passed, leverage goes with it.

4. Automate the regression testing

Manual test cycles are a recurring cost and the reason change is slow. Building automated coverage is a one-off investment that reduces the cost of every subsequent change, including the modernization itself.

5. Wrap rather than rebuild where it fits

An API layer in front of a stable core can unblock the work that is actually waiting, at a fraction of replacement cost, and it makes later replacement incremental. Our legacy application modernization guide sets out the approaches in more detail.

An accurate inventory can often reveal quick cost-saving opportunities before the organization commits to modernization, and it is worth more than any external benchmark.

Getting Outside Support to Control Legacy System Costs

Organizations that lack the time or internal visibility to build a per-system cost model often bring in external support for the first assessment. The approach in this guide suggests what to look for. A good partner costs each system individually rather than across the portfolio, includes labour, risk and blocked work alongside direct spend, and projects costs with real escalation instead of repeating last year’s figures. It should also be willing to recommend decommissioning, consolidation or an API wrapper where these cost less than modernization, rather than defaulting to a full programme.

When modernization is the right call, the work usually spans several disciplines. Legacy software modernization services typically include application modernization consulting, software re-engineering, code refactoring, data modernization, API upgradation, cloud modernization and cybersecurity enhancements. Where the assessment shows that a rebuild makes more sense than a refactor, a custom software development practice handles the replacement.

Product Design

Partner with Experts

Frequently Asked Questions

What is technical debt, and where does it show up in an IT budget?

open-icon close-icon

Technical debt is the accumulated cost of past shortcuts in code and architecture, paid back as extra effort on every future change. It rarely appears as its own line. It surfaces as longer delivery estimates, larger regression test cycles and more contractor time, which is why it is usually absorbed into delivery capacity rather than recognised as debt.

How do legacy systems affect IT maintenance budgets?

open-icon close-icon

They crowd out everything else. Because support, compensating controls and specialist labour all escalate annually, a legacy-heavy estate consumes a growing share of a budget that is usually flat. The visible symptom is that the discretionary and innovation portion shrinks each year without anyone deciding that it should.

Do legacy systems increase cyber insurance costs?

open-icon close-icon

Unsupported software and unpatchable systems are standard underwriting questions, and they can affect both premium and the conditions attached to cover. The practical cost is often the remediation commitments a policy requires rather than the premium itself. Check your current policy wording against your actual estate before assuming you are covered.

How can legacy system modernization reduce maintenance costs?

open-icon close-icon

Modernization removes whole cost categories rather than trimming them: the extended support premium disappears, compensating controls become unnecessary once a system can be patched normally, and specialist contractor dependency ends. Savings arrive per system as each one is retired, which is why phased programmes show returns before the programme completes.

How do you budget for legacy maintenance when the cost keeps rising?

open-icon close-icon

Budget the escalation explicitly rather than repeating last year’s figure. Apply the published vendor schedule where one exists, a realistic market uplift on specialist labour, and your own incident trend on downtime. A three-year forecast built that way is defensible in a budget review; a flat-line assumption is not.