Institutional gap · United States
Federal agencies are not required to plan replacement of decades-old critical systems, and OMB had not issued guidance as of February 2026
The Government Accountability Office screened 69 federal legacy IT systems submitted by agencies and selected the 11 most in need of modernization, held by 10 agencies. That list was published on 2025-07-17 in GAO-25-107795, a report to the House Committee on Oversight and Gover…
- Resolution status
- not confirmed
- Checked
- 2026-08-24
- Evidence type
- SecondaryPress reports and institutional documents
- Outlet
- The Government Accountability Office (GAO)
- Authoring mode
- Derived from press reports
- Views
- 20
Note: the number of members of the public affected is recorded as not derivable. The source publishes agency-reported counts of direct system users, most of whom are federal staff, and one of the eleven systems is reported as having no direct end users at all.
What is happening?
The Government Accountability Office screened 69 federal legacy IT systems submitted by agencies and selected the 11 most in need of modernization, held by 10 agencies. That list was published on 2025-07-17 in GAO-25-107795, a report to the House Committee on Oversight and Government Reform.
The eleven systems are about 23 to 60 years old, their hardware runs from 6 months to 23 years old, and together they cost about $754 million a year to operate and maintain. Eight of the eleven use legacy programming languages such as COBOL and assembly language code. Four carry hardware, software or an operating system the vendor no longer supports, and for two of them, at Interior and the Environmental Protection Agency, nothing in the stack is supported any longer. Seven operate with known cybersecurity vulnerabilities that the report states cannot be remediated without modernization, and eight cannot implement the OMB zero trust strategy without modernization.
The planning picture is narrower than a single count suggests. Agencies had documented modernization plans for nine of the eleven; only two systems, at Defense and Energy, had none at all. The report measures a plan against three key elements — milestones to complete the modernization, a description of the work necessary, and the disposition of the legacy system — and by that measure three plans were complete, at Homeland Security, Interior and the Environmental Protection Agency, while six were partial. That is the arithmetic behind the conclusion that eight of the eleven lack complete modernization plans. Lacking a complete plan and lacking a plan are different states, and the report separates them.
One of those six partial ratings is itself contested on the record. Agriculture did not agree with the finding, saying it had developed a plan in February 2025 and supplied it in draft in June 2025; the Government Accountability Office reviewed that document, found it partially met the key elements, revised the finding to give partial credit, and revised the recommendation to name the missing elements. Agriculture officials had earlier conceded that no final documented plan existed when they were asked in July 2024.
Of the ten systems named most critical in 2019, three modernizations were complete as of February 2025 and seven were still in progress. February 2025 is the as-of date the report gives for that count; 2025-07-17 is the publication date.
Whose problem is this?
| Role | Who |
|---|---|
| Affected | The agency missions these systems carry — tax processing, clinical and patient administration, personnel and payroll, biometric management, aeronautical information, radiation monitoring, and the operation of certain dams and power plants |
| Raised by | Government Accountability Office, in a chain of reports running from May 2016 to July 2025 |
| Decides | Office of Management and Budget, asked in 2016 to direct agencies to identify legacy systems needing modernization · agency heads and chief information officers · Congress, which holds both the appropriation and the power to impose a requirement |
| Bears the cost | Agency budgets. The eleven cost about $754 million a year to operate and maintain, and four of the eleven agencies had not calculated what modernization would cost |
How many members of the public sit behind those missions is not something this record answers. The report publishes reported counts of direct system users, which are overwhelmingly federal staff, and one of the eleven is reported as having no direct end users at all.
Where does this problem end?
| Axis | This is the problem | This is not the problem |
|---|---|---|
| What | The absence of a complete documented modernization plan for a system already judged most in need of modernization, and the absence of any rule requiring one | The age of a system by itself. The screen used 16 attributes, not age alone |
| Milestones, the work necessary, and the disposition of the old system — the three elements a plan is measured against | Whether a modernization, once funded and started, lands on time and on budget is a different question | |
| Who | The 10 agencies holding the 11 systems · OMB, which holds the open guidance recommendation · Congress, which holds the power to require | State, local and tribal systems are outside the remit of this audit |
| When | May 2016, when the guidance recommendation was made, through the recommendation status date of February 2026 | |
| Scale | The 11 most critical systems, together with the 65 systems reviewed in 2019 and the 69 screened in 2025 | The full extent of federal legacy IT, which the report says is unknown |
The line matters because the same symptom has two different sources behind it. A modernization can be running late, which is a delivery question. Or the document that governs it can be silent on what work remains and what becomes of the old system, which is a planning question, and no rule obliges anyone to close that silence.
What is the state now, and what should it be?
Now
| Indicator | Value | As of |
|---|---|---|
| Systems screened in the 2025 review | 69 | 2025-07 |
| Selected as most in need of modernization | 11, held by 10 agencies | 2025-07 |
| Age of those systems | about 23 to 60 years | 2025-07 |
| Age of their hardware | 6 months to 23 years | 2025-07 |
| Using legacy programming languages such as COBOL and assembly | 8 of 11 | 2025-07 |
| Some unsupported hardware, software or operating system | 4 of 11 | 2025-07 |
| Every hardware, software and operating system unsupported | 2 of 11, at Interior and EPA | 2025-07 |
| Known vulnerabilities that cannot be remediated without modernization | 7 of 11 | 2025-07 |
| Not capable of implementing the OMB zero trust strategy without modernization | 8 of 11 | 2025-07 |
| A documented modernization plan exists | 9 of 11 | 2025-07 |
| Plan includes all three key elements | 3 of 11, at Homeland Security, Interior and EPA | 2025-07 |
| Plan partial | 6 of 11, at Agriculture, Commerce, HHS, Transportation and Treasury | 2025-07 |
| No plan at all | 2 of 11, at Defense and Energy | 2025-07 |
| Combined annual operation and maintenance cost of the 11 | about $754 million | 2025-07 |
| Modernization already underway among the 8 with incomplete or missing plans | 7 of 8 | 2025-07 |
| Of the 10 named most critical in 2019, modernization complete | 3 | 2025-02 |
| Of that 10, still in progress | 7, six of them with an expected completion date | 2025-02 |
| Status of the 2016 recommendation that OMB direct agencies to identify legacy systems | open, unimplemented | 2026-02 |
| Status of the July 2025 Matter for Congressional Consideration | open, no legislative action recorded | 2026-02 |
Should be — the minimum the auditors set is a documented modernization plan that includes milestones to complete the modernization, a description of the work necessary to modernize the system, and details of the disposition of the legacy system. Those three elements are drawn from federal and industry modernization practice guides, not from a statute. No source in this record names a target number of completed modernizations, a target completion date for the eleven, or a target share of federal IT spending that should move off operations and maintenance.
How big is it?
The federal government spends more than $100 billion a year on IT and cyber investments and has reported spending about 80 percent of that on operating and maintaining existing systems. For fiscal year 2025 specifically, about $83 billion, or 79 percent of planned total IT spending across the 24 Chief Financial Officers Act agencies, was intended for operations and maintenance.
A caution the report attaches to that figure matters as much as the figure. How much of that operations and maintenance spending goes to legacy technology is uncertain, because OMB does not require agencies to record whether an investment counts as legacy IT. The report states plainly that the extent of legacy IT in the federal government is unknown.
| Cohort | Annual operation and maintenance | As of |
|---|---|---|
| The 11 most critical systems, 2025 review | about $754 million | 2025-07 |
| The 10 most critical systems, 2019 review | about $337 million | 2019 |
Appendix IV of the 2025 report publishes, for each of the eleven, the reported number of users, the annual operating cost, the modernization cost estimate and the potential savings.
| Agency | Reported users | Annual operating cost | Reported modernization cost |
|---|---|---|---|
| Agriculture | 85,000 | $103.8 million | agency has not calculated |
| Commerce | 7,800 | $41.4 million | agency has not calculated |
| Defense | 13,322 | $8.7 million | approximately $60 million to $90 million |
| Energy | 14,000 | $4.4 million | agency has not calculated |
| Health and Human Services | 15,000 | $71 million | between $4.0 billion and $5.9 billion, completion end of fiscal year 2035 |
| Homeland Security | 6,700 | $156 million | $630 million, with potential savings of $2 million a month |
| Interior | 46 | $2.3 million | $6.7 million, with potential savings of $750,000 a year |
| Transportation | 9,800 | $17.9 million | agency has not calculated |
| Treasury, tax processing system 9 | no direct end users | $331.8 million | $549 million, the initial estimate briefed to OMB in December 2023 |
| Treasury, tax processing system 10 | 75,000 | $15 million | no estimate yet, and $72 million is needed to develop a plan, prototypes and investigational work |
| Environmental Protection Agency | 54 | $1.6 million | $2.5 million, with potential savings of $166,000 a year |
The Treasury figure has a second number behind it. In April 2024 an independent cost estimate put that modernization at $1.25 billion, and officials said that estimate was skewed higher because it assumed a larger scale and complexity; the agency plans to reconcile the two by refining the estimate to a more accurate scope.
Those user counts are agency-reported direct system users. They are a headcount of people who sign in, not a count of the people whose tax, health or environmental business passes through these systems, and no beneficiary or citizen-impact figure appears anywhere in the report.
Under what conditions does it arise?
| Condition | Detail |
|---|---|
| Language and workforce | 8 of the 11 use COBOL or assembly language code. For one system the agency reported that the average age of its developers and technical subject matter experts is above 60, that it is difficult to find developers in those languages, and that the learning curve once they are found is significant |
| Components past vendor support | 4 systems carry some unsupported hardware, software or operating system, and 2 carry nothing supported at all. The report notes that hardware failure may cause outages and that outdated systems are harder to modify or upgrade |
| Vulnerabilities that outlast patching | 7 systems carry known vulnerabilities that cannot be remediated without modernization. One agency reported mitigating this by isolating the system, which is not interconnected with other components, the department network or the internet |
| Funding and contract sequencing | The reasons agencies gave for missing plan elements turn mostly on money and contracts arriving before detail can be written |
| No obligation to plan | The 2016 report found that agencies are not required to identify, evaluate and prioritize existing IT investments to decide whether they should be kept as-is, modernized, replaced or retired |
The explanations agencies gave for the gaps are on the record and they run in one direction. Agriculture said in July 2024 that it had not developed a plan because of insufficient staffing, and later that detail would follow once the path forward is confirmed, funding is approved and the software contract is awarded. Commerce said detailed plans would follow once funding is identified. Transportation said work schedules and decommissioning plans would be developed with the vendor once a contract is awarded. Defense said it had a 2015 plan that was never implemented and that it had been unable to secure funding against higher department priorities. Energy said an October 2023 proposal was no longer viable and that it had requested funding through the fiscal year 2026 budget process.
Energy also set out what it is doing in the meantime. It concurred with the recommendation, said management of the system had moved to its chief information officer, said it is migrating several functions with significant dependencies on that system to a new platform by December 2026 and will undertake formal modernization planning afterwards, and said the hardware and software is continuously maintained with the latest patches and updates in the interim.
What has been tried?
| Attempt | By whom | What was done | When |
|---|---|---|---|
| GAO-16-468 | Government Accountability Office | Found that agencies are not required to identify, evaluate and prioritize existing IT investments, and recommended that OMB direct agencies to identify legacy systems needing replacement or modernization | 2016-05-25 |
| GAO-19-471 | Government Accountability Office | Reviewed 65 legacy systems at 24 agencies and named the 10 most critical, ranging from 8 to 51 years old. Two agencies had plans incorporating leading practices and three had no documented plan. Eight recommendations went to eight agencies in a concurrent limited official use only report | 2019-06-11 |
| Implementation of those recommendations | Eight agencies | All eight had implemented the recommendation to develop modernization plans | as of 2024-04 |
| GAO-23-106821 | Government Accountability Office | Follow-up. Six agencies had made progress; Transportation and OPM had not developed complete modernization plans. The ten systems cost about $337 million a year to maintain | 2023-05-10 |
| Priority designation | Government Accountability Office | Designated the open 2016 recommendation to OMB a priority open recommendation | 2023-05-23 |
| GAO-25-107795 | Government Accountability Office | Screened 69 systems, named the 11 most in need, made eight recommendations to seven agencies in a concurrent sensitive report, and raised a Matter for Congressional Consideration asking Congress to require modernization plans | 2025-07-17 |
| Legacy IT Reduction Act of 2026, H.R. 8408 | Four House members, from both parties | Bill requiring agency chief information officers to compile a legacy IT inventory within one year and update it every five years, and agency heads to develop modernization plans within two years covering a five-year horizon. OMB would issue implementation guidance within 180 days and the Comptroller General would report on effectiveness within three years. No new funding is authorized and the Act sunsets six years after enactment | introduced 2026-04-21 |
What was found?
| Finding | Observed value | Evidence grade |
|---|---|---|
| The gap is completeness, not absence | 9 of 11 systems had documented plans; 3 were complete, 6 partial, 2 absent. The conclusion that eight lack complete plans is built from the six partials and the two absences | high — Table 5 and the conclusions section of the primary report, read in full |
| This is not a failure to start | 7 of the 8 systems with incomplete or missing plans reportedly have modernizations already underway, at Agriculture, Commerce, Defense, Health and Human Services, Transportation and Treasury. All 7 unfinished systems from the 2019 cohort are in progress, 6 with expected completion dates, and none is recorded as not begun | high — stated in the primary report |
| A recommendation can close while the underlying plan stays incomplete | All eight agencies had implemented the 2019 recommendations to develop modernization plans as of April 2024, and in July 2025 eight of eleven plans were still short of the key elements. Two of the eleven systems, at HHS and Interior, were also on the 2019 list of the ten most critical | high — both statements sit in the same report |
| The blockage named in the report is the absence of a requirement | Agencies may not be effectively planning for modernization in part because they are not required to. The 2016 recommendation that OMB direct agencies to identify legacy systems is open and unimplemented with a status date of February 2026, and OMB stated in February 2024 that it did not plan to issue additional guidance, in March 2024 that it considered the recommendation closed, and in January 2025 that it had actions planned but not underway | high — the report text and the published recommendation status record |
| The compulsion route exists on paper only | H.R. 8408 was introduced on 2026-04-21 and referred to the House Committee on Oversight and Government Reform. Only the introduced version exists, so no committee action has occurred. The parallel Matter for Congressional Consideration is open with a status date of February 2026 | high — the bill text and the bill details page at the Government Publishing Office |
| The operating cost of the eleven sits inside a far larger operations and maintenance base | The eleven were reported to cost about $754 million a year to operate and maintain. Separately, about $83 billion, 79 percent of planned fiscal year 2025 IT spending at the 24 CFO Act agencies, was intended for operations and maintenance. The two figures carry different scopes and different reporting periods | high — both figures printed in the primary report |
| The cost of the fix is often unknown to the agency holding it | 4 of the 11 agencies had not calculated a modernization cost. For one Treasury system the reported estimate of $549 million and an independent estimate of $1.25 billion differ by more than a factor of two and had not been reconciled | high — Appendix IV and its footnote |
| The affected public cannot be counted from this source | Reported user counts are direct system users, overwhelmingly federal staff, and one system reports none at all. No beneficiary or citizen-impact count is published | high — the absence is a property of the published report, checked across the full text |
| Security exposure is stated without an incident record | 7 systems carry vulnerabilities that cannot be remediated without modernization and 8 cannot implement the zero trust strategy, but outage and incident history is not published for any of the eleven | medium — the attribute counts are firm; the consequence is stated prospectively only |
Why is it still unsolved?
Institutional gap — the duty to plan does not exist, so not planning is not a failure to comply with anything.
1. No requirement. The 2016 report found that agencies are not required to identify, evaluate and prioritize existing IT investments to decide whether they should be kept as-is, modernized, replaced or retired, and recommended that OMB direct agencies to identify legacy systems needing replacement or modernization. The 2025 report returns to that finding and says agencies may not be effectively planning in part because they are not required to. 2. The guidance route stopped. OMB stated in February 2024 that it did not plan to issue additional guidance, and in March 2024 that it believed it had met the intent of the recommendation and considered it closed. The Government Accountability Office did not agree. In January 2025 OMB said it had actions planned that were not yet underway and gave no specifics. The recommendation status as of February 2026 is open and unimplemented, close to ten years after it was made. 3. The audit route reached its limit. The Government Accountability Office recommends and cannot compel. The 2016 recommendation was designated a priority open recommendation for OMB in May 2023, and in July 2025 the matter was escalated to Congress with a request that major agencies be required to develop modernization plans for the systems identified as most in need. 4. The legislative route has not moved. H.R. 8408 was introduced on 2026-04-21 and referred to committee. Only the introduced version exists, the bill authorizes no new funding, and it would sunset six years after enactment. 5. Where plans exist they stop where the money stops. Six of the nine documented plans miss at least one key element, and the reasons agencies give point to funding approvals and contract awards that have not happened yet.
The mechanism is not that agencies are unaware of these systems or unwilling to begin. Seven of the eight systems with incomplete or missing plans already have modernizations under way. What is missing is the document that states what work remains and what becomes of the old system, and the rule that would require that document to exist.
What observation would mean it is solved?
Candidates — first, the number of the eleven whose documented plans contain all three key elements. Second, the number of modernizations actually completed, both among the eleven and among the seven 2019 systems still in progress. Third, the number of systems still carrying unsupported components or vulnerabilities that cannot be remediated without modernization. Fourth, whether a requirement to produce modernization plans exists at all, and what the status of the 2016 recommendation to OMB is.
The first alone is dangerous, and this record already shows why. The report itself says that documenting plans is just an initial step in an often lengthy process. All eight agencies that received the 2019 recommendations had implemented them as of April 2024, and the 2025 review still found eight of eleven plans short of the key elements. A plan count can rise while the condition it is supposed to measure does not move.
What is it connected to?
- Problem
us-federal-priority-recommendations-unimplemented— the priority open recommendation mechanism that this case sits inside, and the two touch at a named point. The 2016 recommendation that OMB direct agencies to identify legacy systems needing modernization was designated a priority open recommendation for OMB in May 2023, and its status as of February 2026 is open and unimplemented. - Federal cybersecurity — seven of the eleven carry vulnerabilities that cannot be remediated without modernization, and eight are reported as not capable of implementing the OMB zero trust strategy without modernization. The National Cybersecurity Strategy of March 2023 indicated that OMB would lead a multi-year plan to accelerate technology modernization, and that the plan would identify milestones to remove all legacy systems incapable of implementing the zero trust architecture strategy within a decade, or otherwise mitigate risks to those that cannot be replaced in that time frame.
- The wider modernization inventory — of the 65 systems identified in 2019 as in need of modernization, 28 were complete, 34 were under way and 3 had not begun as of February 2025, and planned completion dates existed for only 28 of the 37 that were unfinished.
What these sources do not say
- Which systems these are. A numeric identifier was substituted for every system name because of sensitivity concerns, and the detail was issued in limited official use only reports — GAO-19-351SU for the 2019 cohort and a concurrent sensitive version for 2025. Those reports are not public documents.
- The eight recommendations to seven agencies. The public report gives their number and their subject and does not itemise them; they live in the concurrent sensitive version.
- Outage and incident history. The report names the risk prospectively, noting that hardware failure may cause system outages and disrupt operations, and publishes no incident record for any of the eleven.
- How many members of the public are affected. The report publishes reported counts of direct system users and no beneficiary count, and one system is reported as having no direct end users.
- What OMB says about the escalation. OMB is recorded as having made statements in February 2024, March 2024 and January 2025 through the recommendation status record, and as having had no comments on the draft of the 2025 report. No OMB position on the Matter for Congressional Consideration is confirmed.
- Whether any product on this subject has appeared since GAO-25-107795. The publisher search page returned HTTP 403 to automated retrieval, so a newer product cannot be ruled out. The freshest confirmed signal in the table below is the recommendation status date of February 2026.
See the evidence
| Item | Source | Confirmation |
|---|---|---|
| 69 systems screened and scored on 16 attributes · 11 most in need at 10 agencies · system ages about 23 to 60 years · hardware 6 months to 23 years · 8 using legacy languages · 4 with some unsupported components · 2 with nothing supported, at Interior and EPA · 7 with vulnerabilities not remediable without modernization, one of which is reported to be mitigated by system isolation, the system not being interconnected with other components or with the department network or the internet · 8 unable to implement the zero trust strategy · about $754 million a year | GAO-25-107795, Information Technology: Agencies Need to Plan for Modernizing Critical Decades-Old Legacy Systems, full report | 2026-08-24 |
| The three key elements of a plan · 3 complete plans at Homeland Security, Interior and EPA · 6 partial at Agriculture, Commerce, HHS, Transportation and Treasury · 2 systems with no plan, at Defense and Energy · the conclusion that eight of the eleven lack complete modernization plans | Same report, Table 5 and Conclusions | 2026-08-24 |
| Seven of the eight systems with incomplete or missing plans reportedly have modernizations already under way, at Agriculture, Commerce, Defense, HHS, Transportation and Treasury | Same report | 2026-08-24 |
| Reasons agencies gave for missing plan elements, including the Agriculture statement of insufficient staffing in July 2024, the Defense 2015 plan that was never implemented, and the Energy proposal of October 2023 that was no longer viable | Same report | 2026-08-24 |
| Three of the 2019 ten complete as of February 2025 — Defense in fiscal year 2020, Small Business Administration in April 2023, Office of Personnel Management in September 2024 — and seven in progress, six with expected completion dates | Same report, Table 2 | 2026-08-24 |
| Of the 65 systems from the 2019 review, 28 complete, 34 in progress and 3 not begun as of February 2025, with planned completion dates for 28 of the 37 unfinished | Same report, Table 3 | 2026-08-24 |
| All eight agencies had implemented the 2019 recommendations to develop modernization plans as of April 2024 | Same report | 2026-08-24 |
| Two of the eleven systems, at HHS and Interior, were also on the 2019 list of the ten most critical, and two more, at Commerce and Defense, were on the 2019 list of 65 | Same report, Table 4 footnotes | 2026-08-24 |
| More than $100 billion a year on federal IT with about 80 percent on operations and maintenance · about $83 billion, 79 percent, of planned fiscal year 2025 IT spending at the 24 CFO Act agencies · the extent of federal legacy IT is unknown and OMB does not require agencies to record whether an investment is legacy IT · the National Cybersecurity Strategy of March 2023, the multi-year modernization plan OMB was to lead under it, and the milestone of removing all legacy systems incapable of implementing the zero trust architecture strategy within a decade | Same report, Background and figure 1 | 2026-08-24 |
| Per-system reported users, annual operating costs, modernization cost estimates and potential savings for all eleven systems, including the $549 million initial Treasury estimate briefed to OMB in December 2023 and the April 2024 independent estimate of $1.25 billion that officials said was skewed higher · the workforce constraint reported for one system, where the average age of developers and technical subject matter experts on the team is above 60 and assembly language developers are hard to find | Same report, Appendix IV | 2026-08-24 |
| Agency comments — Agriculture disagreed, saying a plan had been developed in February 2025, and the finding was revised to partial credit after a June 2025 draft plan was reviewed · Energy concurred, described a platform migration due December 2026 and interim patching · Defense and Transportation concurred · Commerce, HHS and Treasury neither agreed nor disagreed · the Social Security Administration commented on budgetary considerations · OMB and 16 other agencies had no comments | Same report, Agency Comments and Our Evaluation | 2026-08-24 |
| The 2016 recommendation to OMB, the designation as a priority open recommendation in May 2023, the OMB statements of February 2024, March 2024 and January 2025, and the statement that nine years had passed without action | Same report | 2026-08-24 |
| GAO-16-468, Information Technology: Federal Agencies Need to Address Aging Legacy Systems — the origin of the OMB guidance recommendation, and its status of open and unimplemented with no OMB update recorded as of February 2026 | GAO product page | 2026-08-24 |
| Report number, title and publication date of 2025-07-17, and the summary findings including that only three of the eleven had plans containing all three key elements | GAO product landing page | 2026-08-24 |
| The Matter for Congressional Consideration carries status open with a status date of February 2026 and a note that legislative action has not yet occurred · the eight recommendations to seven agencies are itemised only in the concurrent sensitive version | GAO product page, recommendations tab | 2026-08-24 |
| GAO-19-471 — 65 legacy systems across 24 agencies, the 10 most critical ranging from 8 to 51 years old, two agencies with plans incorporating leading practices and three with no documented plan | GAO product page | 2026-08-24 |
| GAO-23-106821, published 2023-05-10 — six agencies had made progress, Transportation and OPM had not developed complete modernization plans as of May 2023, and the ten systems cost about $337 million a year to maintain | GAO product page | 2026-08-24 |
| Full text of H.R. 8408, Legacy IT Reduction Act of 2026 — inventory within one year and every five years thereafter, modernization plans within two years covering a five-year horizon, inventories to Congress on request, plans to Congress within 30 days of OMB submission, OMB implementation guidance within 180 days, a Comptroller General effectiveness report within three years, no new funding authorized, and a sunset six years after enactment | U.S. Government Publishing Office, govinfo | 2026-08-24 |
| H.R. 8408 was introduced on 2026-04-21 in the 119th Congress and referred to the House Committee on Oversight and Government Reform, and only the introduced version exists | U.S. Government Publishing Office, govinfo bill details | 2026-08-24 |
| Negative control — H.R. 8408 of the 118th Congress is an unrelated bill designating a Postal Service facility in Florida, which rules out the reading that the Legacy IT Reduction Act is an earlier bill renumbered | U.S. Government Publishing Office, govinfo | 2026-08-24 |
| The bill was introduced by four House members from both parties, and the one-year inventory and two-year plan requirements as described in press coverage | FedScoop, House bill wants CIOs, agency heads to hit the gas on legacy IT phase-outs, 2026-04-29 | 2026-08-24 |
| Press account of the three completed modernizations from the 2019 ten and the per-agency expected dates | FedScoop, 2025-07-17 | 2026-08-24 |
| The real names of the 11 systems and of the 2019 ten, and the itemised eight recommendations to seven agencies | Concurrent limited official use only reports — GAO-19-351SU and the unnumbered 2025 sensitive version | URL not confirmed: these are not public documents and no public page carries them. The public report substitutes a numeric identifier for every system name because of sensitivity concerns |
| Outage and incident history of the eleven systems | GAO-25-107795 | Not published by the source: the full report was read end to end. It names the risk that hardware failure may cause outages and carries no incident record for any of the eleven |
| A secondary account of the finding that eight plans fall short of the key elements | FedGov Today | URL not confirmed: the publisher site returned navigation, podcast listings and event content with no matching article, and no title or date for such an article is on record. The claim is stated directly in the conclusions of the primary report above, so no secondary source is required for it |
| Live legislative status of H.R. 8408 from the bill tracking services | congress.gov · govtrack.us · legiscan.com | URL not confirmed: each returned HTTP 403 to automated retrieval. The status above is taken from the Government Publishing Office pages instead |
| Any product on this subject published after GAO-25-107795 | GAO search, and general web search engines | URL not confirmed: the publisher search page and the search engines returned HTTP 403 or a CAPTCHA to automated retrieval. Direct product pages by report number were served, so the chain GAO-16-468 to GAO-19-471 to GAO-23-106821 to GAO-25-107795 is confirmed, but a later product cannot be ruled out |
This table holds 27 evidence rows, 22 of which carry a source you can open · 3 distinct sources. How this table is made
People affected
Estimated range Not derivable
The reason and what is missing are listed under “What is missing” below
What is missing 1
Grouped by how it gets filled, not by block number — that axis is the only one that tells a reader what can be done next.
- Derived valueThe affected population could not be derived
The primary source publishes a reported count of direct system users for each of the eleven systems, and those users are overwhelmingly federal staff. One of the eleven, a tax processing system, is reported as having no direct end users at all. No beneficiary count, caseload figure or citizen-impact figure appears anywhere in the report, so the population this problem actually reaches, the people whose tax, health, environmental and benefit business passes through these systems, has no first term to start a chain from. Substituting the direct user counts would swap a narrower denominator for the one the document asserts while looking like it filled the gap.
A count of the people served by each of the eleven business lines rather than the people who sign in to the system; an overlap factor, because one person can appear behind more than one of those lines; and a rule for separating the share of a program carried by the legacy component from the share already carried by modernized parts of the same program.
Needs a new measurement
Voting and commenting require you to be signed in. Sign in from the account page
Comments
The comment was empty, so nothing was posted.
The comment exceeded the limit, so nothing was posted. We do not truncate and save.
You just posted a comment. Please try again in a moment.
The target comment could not be found, so nothing was posted.
You must be signed in to comment.
You have already reported this comment. Each person counts once — to withdraw it, use Cancel report under Reports you filed on the notifications page.
This report has already been reviewed. A judged report cannot be filed again or withdrawn.
No reason was chosen, or Other was picked without a note, so the report was not filed.
You cannot report your own comment or your own profile. Use Delete to take down your own comment.
Report received. Once 3 different people report it, the comment is hidden until review finishes — the outcome appears on your notifications page.
Voting and commenting require you to be signed in. Sign in from the account page
No comments yet.