This checklist is for owners, COOs, CTOs and IT managers who suspect that one system, such as an ageing store, an ERP held together by spreadsheets or an internal tool nobody wants to touch, is holding the business back. It covers what to inspect and how to decide whether the system needs work at all. Choosing the route is the next step, covered in our digital transformation and legacy modernization guide.
In this guide
- When an assessment is worth doing
- The checklist: ten areas to assess
- How to run the assessment
- Scoring: business value against technical health
- From findings to a shortlist of routes
- Where AI helps in an assessment
- Alternatives and selection criteria
- How Netbase runs an assessment
- What delivery record exists, and what does not
- Limits of this checklist
- Frequently asked questions
- Next step
When an assessment is worth doing
Run a structured assessment when one of these triggers appears, not on a calendar:
- The platform, framework or database is near the end of its vendor support.
- Small changes take weeks, and every upgrade breaks something.
- Staff re-key orders, stock or customer data between systems by hand.
- A new process, channel or AI use case needs data the system cannot provide.
- The people who understand the system are leaving, or have left.
An assessment also protects you from the opposite mistake: replacing a system that is supported, secure and blocking nothing. A good assessment can end with "keep it, and look again next year".
The checklist: ten areas to assess
Work through every area, even where the answer seems obvious. AWS's guidance on detailed application assessment warns that teams often assume they fully understand their applications, and recommends validating that knowledge with data from tools rather than memory.
| Area | What to check | Evidence to collect |
|---|---|---|
| Business value | Which revenue, service or cost depends on the system; what breaks if it stops for a day | Named processes, users affected, downtime impact agreed with the business owner |
| Users and processes | Who uses it, for what, and where they work around it | Process map, list of spreadsheets and manual steps around the system |
| Code and architecture | Architecture type, coupling, test coverage, size of custom code, known hotspots | Architecture diagram, repository access, test report, list of custom modules |
| Platform and support | Versions of the language, framework, database and operating system, and their support end dates | Version inventory with the vendor's published end-of-support dates |
| Security | Known vulnerabilities, authentication, access control, encryption, logging | Scan results, access list, open findings from past audits or penetration tests |
| Data | Data model, quality, volume, ownership and retention rules | Schema, record counts, a data-quality sample, the owner of each data type |
| Integrations | Every system it sends data to or receives data from, and how | Interface list with protocol, direction, frequency and failure handling |
| Operations | Uptime, incidents, backups, recovery objectives and whether recovery has been tested | Incident history, backup schedule, recovery point and time objectives, last recovery test |
| People and knowledge | Who can change the system, and what is written down | Named maintainers, documentation, rules that live only in someone's head |
| Cost | Licences, hosting, support contracts and the staff time spent keeping it running | Twelve months of costs, including internal hours and workarounds |
Two areas deserve extra care. On platform support, CISA and the FBI list the use of end-of-life software among exceptionally risky product security practices, because unsupported products stop receiving security fixes. On security, a public standard such as the OWASP Application Security Verification Standard (ASVS) gives you a ready list of requirements to test against, instead of inventing your own.
How to run the assessment
A focused assessment of one system is a short, bounded piece of work. Keep it moving with a fixed sequence:
-
Name the owners
A business owner who can say what the system is worth, and a technical owner who can open every door: code, servers, cloud accounts and vendor contracts.
-
Collect before you interview
Pull versions, dependencies, access lists, costs and incident history first, so interviews confirm facts instead of producing them.
-
Map the process, not only the software
Walk through one real order, claim or request end to end and note every manual step and spreadsheet.
-
Interview the people who work around it
Users know which reports are wrong and which fields nobody trusts.
-
Test one risky assumption
For example, restore last night's backup to a test environment, or build and deploy the code from the repository alone.
-
Score each area
Use the value and health scales below, and write one sentence of evidence behind every score.
-
Write the shortlist and the unknowns
A short report with the scores, the two or three routes that remain, and what still needs checking.
Scoring: business value against technical health
Score business value and technical health separately, on a simple scale such as 1 (low) to 5 (high). The numbers are for comparison, not precision; the written evidence matters more.
- High value, low health. The urgent case: the business depends on a system that is fragile or unsupported. Modernize first.
- High value, high health. Keep it and invest in extending it, for example with integrations or automation.
- Low value, low health. A retirement candidate: move its job to another system or switch it off.
- Low value, high health. Leave it alone, and avoid adding new work to it.
When you assess several systems, place them all on the same two scales before you pick one. The system with the oldest technology is not always the one to modernize first; the one that blocks revenue, service or cost usually is. Our digital transformation roadmap shows how to rank initiatives across a whole business.
From findings to a shortlist of routes
An assessment should narrow the options, not make the final choice. AWS Prescriptive Guidance lists seven migration strategies: retire, retain, rehost, relocate, repurchase, replatform and refactor. A mid-market company also weighs a full rebuild. Use the findings to rule routes out:
- If platform support ends soon but the business rules still fit, replatforming stays on the list.
- If the code is valuable but slow to change, keep refactoring in slices on the list.
- If the design cannot hold the target process, keep rebuild or a packaged product on the list.
- If nobody can explain the rules the system enforces, add discovery before any rebuild.
Whichever route remains, prefer one that can move in slices. Martin Fowler's Strangler Fig pattern describes building new parts around the old system and moving behaviour across gradually until the old system can be switched off. The pillar guide explains how to choose between rebuild, refactor and replatform, and the legacy modernization service shows how that move is planned and rehearsed.
Where AI helps in an assessment
AI tools shorten the slowest part of an assessment: understanding code and data nobody has documented. They can summarise modules, trace which functions touch which tables, draft missing documentation, and flag duplicated or unused code for a person to confirm. They do not replace the interviews, the business scoring or the decision. Treat every AI summary as a lead to verify, keep the code inside tools you have approved, and record which findings a person checked. Netbase works with the major commercial and open-source AI tools and models, chosen per project, under human review.
Alternatives and selection criteria
| Route | Strength | Weakness | Choose it when |
|---|---|---|---|
| Internal self-assessment | Cheapest; builds knowledge in your team | Blind spots where your team wrote or chose the system | The system is small and you have people with time and distance from it |
| Assessment by your current vendor | Knows the code and history | May favour the route it already sells or maintains | You trust the vendor and need speed more than independence |
| Independent assessment by another partner | Fresh view; comparable scores across systems | Needs onboarding time and full access | The decision is large, or internal opinions disagree |
| Tool-led discovery only | Fast, objective data on code, dependencies and traffic | Misses business value, workarounds and unwritten rules | As an input to any of the routes above, never on its own |
Choose by four criteria: how much money and risk ride on the decision, whether your team can judge the system without bias, how much of the system's knowledge is undocumented, and how soon a platform deadline forces a move.
How Netbase runs an assessment
At Netbase, an assessment is the discovery step of a six-step delivery lifecycle that runs from discovery and strategic alignment through architecture planning and agile execution to rollout and ongoing support. Discovery ends with a written route recommendation and its reasons, and most Netbase projects are then delivered on fixed-price contracts agreed after discovery. When the question spans more than one system, digital transformation consulting turns the assessment into a prioritized plan.
Security findings are handled with the same practices Netbase applies to its own delivery: secure code review and version control, TLS in transit and AES at rest, role-based access control, MFA for admin dashboards, vulnerability scanning and penetration testing, and disaster recovery. Netbase holds ISO 27001 certification and a SOC 2 Type II attestation; both cover Netbase's own operations, not your system. Details are on security and compliance. For how quality is governed once work starts, see software quality governance for outsourced delivery.
What delivery record exists, and what does not
- What exists. Netbase moved Netztech from Magento 1 to Magento 2 Commerce in 35 working days, including the migration of 11 extension modules. The Netztech migration is a published replatforming record of the kind an assessment leads to when platform support ends.
- What does not. No published Netbase record describes the assessment behind that migration, its scores or its duration, and Netbase publishes no standard assessment price or timeline. The scoring scale on this page is illustrative, not a Netbase method with measured results.
Limits of this checklist
- It covers one business system at a time; a portfolio of dozens of applications needs portfolio tooling and a program structure.
- It does not replace a security audit or a penetration test; it records whether they happened and what they found.
- Vendor support dates and the AWS and CISA guidance change; check them on the day you assess.
- For companies skipping legacy stages altogether, as in many emerging markets, see digital and AI transformation in emerging markets.
Plan the next step with a Netbase consultant
Frequently asked questions
A structured review of an existing system's business value and technical health: how it is used, how it is built and supported, how secure it is, what data and integrations it holds, and what it costs. It ends with a shortlist of routes and the evidence behind them.
It depends on the system's size, the documentation and how fast you can grant access. Collecting data first and interviewing second keeps it short; missing access is the most common delay.
A business owner and a technical owner together, with someone who has no stake in the outcome. Where your team built the system or your vendor maintains it, an independent reviewer reduces bias.
No. A system that is supported, secure and blocks nothing on your roadmap can be retained and reviewed again later. Modernize the systems that block revenue, service or cost first.
Next step
Share the system that worries you, what depends on it and any platform deadline, and we will book a solution review to agree the assessment scope and the evidence to collect first. You can also browse more Netbase insights.
Related services and solutions
AI-enabled digital transformation consulting that ends in a delivery plan
Netbase provides digital transformation consulting for mid-market companies to turn operational problems into a prioritized roadmap with a delivery path, not a strategy deck. We map your workflows, systems and data, rank every change by business value and risk, including where AI can remove manual work, and hand over a plan the same team can start building.
Learn More
AI-assisted legacy modernization that keeps your orders and data safe
Netbase provides legacy application modernization services for commerce and operations teams to move ageing platforms, such as Magento 1 stores, onto supported technology without losing orders, customers or data. AI speeds up code analysis and data mapping; every migration runs on a written, human-approved plan with rehearsal, staged cut-over and rollback, proven by Netztech's move to Magento 2.
Learn More
Multi-vendor marketplace development: vendors, catalog, payouts and AI search on one platform
A multi-vendor marketplace is a commerce platform where many independent sellers list, sell and get paid through one storefront. Netbase's marketplace solution covers vendor onboarding, a shared catalog, split payments and payouts, with AI for search, listing enrichment and fraud checks. For an EU fashion-tech marketplace, Netbase's work grew gross merchandise value (GMV) 47% and cut vendor onboarding time 60%.
Learn More
Discuss a project
Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.+84 937 869 689
91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam
Get in touch
Tell us what you want to build, modernize, or operate.