How do you know if your government tech is legacy IT? UK sets out seven criteria

By Richard Johnstone on 25/08/2026 | Updated on 25/08/2026

A old school computer to illustrate legacy technology

Photo: Shutterstock

Is your government hardware unsuitable for the job? Does the software on your government computer fail to meet minimum cybersecurity standards? Does your organisation lack the required skills and knowledge to effectively manage, maintain, and support outdated systems? Then you could be working with legacy IT, according to a new definition from the UK government.

The UK Government Digital Service has updated its definition of legacy IT, with the aim of understanding the different ways in which a system can create an unacceptable burden or risk to government.

The new definition sets out seven areas where systems could pose a risk to government operations if they are or become unmanaged legacy. These are:

  • Out of support systems: Software or hardware that is beyond its current support date, including commercially procured software and hardware, or open-source software.
  • Missing or inadequate contracts: Licences which are required to manage and operate a government system have expired, and no suitable arrangements are in place for service continuity, modernisation or decommissioning.
  • Lack of required skills and knowledge: There are not enough individuals within a government department or agency who possess the expertise needed to manage, maintain and support outdated systems.
  • Inability to meet user or business needs: Current systems fail to meet current business needs or adapt to future requirements.
  • Unsuitable hardware: Systems or devices no longer work as required because the hardware is outdated, capacity is insufficient, they prone to physical failures or cannot be easily repaired.
  • Minimum cyber security standards not met: This creates persistent security weaknesses or vulnerabilities that could be exploited by hostile actors to gain unauthorised access, disrupt operations, or steal sensitive information.   
  • Reliance on a legacy dependency: A government system or service itself relies on external dependency or systems that themselves meet the classification of legacy IT.

Public Service Data.AI is the UK’s flagship annual event for civil servants working to unlock the power of data and artificial intelligence across government. Brought to you by Global Government Forum and hosted by HM Government, the event will take place in London on 15 October 2026 and is free to attend for UK and international public servants. Find out more about the conference and register to attend

What happens if your system is defined as legacy?

The UK government’s legacy IT risk assessment framework is now being updated to reflect these new definitions. Thresholds will be set in each category for what is considered legacy, where the risk or burden is unacceptable, or where action is required to ensure the risk burden does not become unacceptable. Where a system meets the legacy definition, it means the system carries an unacceptable risk “and must be remediated as an urgent priority”.

Read more: UK closes AI pilots amid ‘strategic changes’ to prioritise legacy tech overhaul

Sign up: The Global Government Forum newsletter provides the latest news, interviews and features on AI, data, workforce, and sustainability in government.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *