Skip to main content
Guidance

Updated Definition of Legacy IT

Updated 17 August 2026

This document explains how the public sector currently defines the term ‘legacy IT’. It replaces any existing definitions of legacy IT used in the IT risk assessment framework. 

What is legacy IT? 

Legacy IT are systems whose continued use creates a persistent, unacceptable burden or risk and can no longer be supported or secured effectively or economically. 

This definition is deliberately centred on burden or risk, rather than age, technology type, hosting model or whether a technology is unfashionable.  

This establishes a common, measurable and uniform understanding of what we define as unacceptable, and what requires remediation. 

How is legacy status determined? 

A system is classified as legacy IT if it meets the unacceptable threshold in any of the following 7 legacy criterion. 

Each criterion represents a different way in which a system can create an unacceptable burden or risk. 

1. Out of support systems 

Software or hardware that is beyond its current support date by the original equipment manufacturer (OEM) or provider. This can include commercially procured software and hardware, or those provided free by open-source communities.   

2. Missing or inadequate contracts 

Contracts or licences which are required to manage and operate a system have expired or lapsed, with no suitable arrangements in place for service continuity, modernisation or decommission.    

3. Lack of required skills and knowledge 

When there are not enough individuals within an organisation who possess the expertise needed to effectively manage, maintain, and support outdated systems.  

4. Inability to meet user or business needs 

Failure to meet current business needs or adapt to future requirements.   

5. Unsuitable hardware 

Systems or devices that no longer work as required because the hardware is outdated, capacity is insufficient, they are prone to physical failures or cannot be easily repaired with available parts and services.    

6. Failure to meet minimum cyber security standards 

Persistent security weaknesses or vulnerabilities that are exploitable by hostile actors to gain unauthorised access, disrupt operations, or steal sensitive information.    

7. Reliance on a legacy dependency 

Reliance on an external dependency or system which is itself classified as legacy IT. 

What are the outcomes? 

Legacy IT is a classification, not scored, which means that if a system meets the threshold for unacceptable in any of the above criterion, then the system is classified as legacy and requires remediation. 

There are 3 outcomes to a review of a system.

Outcome Definition of outcome
Accepted The system is operating within the bounds of risk and burden considered normal and acceptable.
Action-Required The system is not yet legacy but will become legacy within the next 12 months if no action is taken.
Legacy The system carries an unacceptable risk or burden and must be remediated as an urgent priority.

Each criterion will have defined thresholds for what is considered legacy, where the risk or burden is unacceptable, and for action-required, where the risk or burden is not yet unacceptable but is likely to become so.  

Each criterion will outline these thresholds explicitly based on the risk owner’s risk appetite.