Skip to content
Pentagon Times
Government News

Federal IT Modernization Faces Aging Systems, Flat Funding and Transfer Authority

Federal IT modernization is caught between two facts: the Government Accountability Office reported in July 2025 that the 11 most critical federal legacy systems are up to 60 years old and mostly lack modernization plans; for fiscal 2027, the White House proposes no new Technology Modernization…

In a dim server hallway of off-white cabinets, two federal technicians in lanyards check a rack panel, their faces lit by indicator lights under cool overheads.
In a dim server hallway of off-white cabinets, two federal technicians in lanyards check a rack panel, their faces lit by indicator lights under cool overheads.

Federal IT modernization is caught between two facts: the Government Accountability Office reported in July 2025 that the 11 most critical federal legacy systems are up to 60 years old and mostly lack modernization plans; for fiscal 2027, the White House proposes no new Technology Modernization Fund dollars, relying on transfer authority capped at $100 million, per MeriTalk reporting.

What did GAO actually find?

In a report published July 17, 2025, GAO identified the government's most critical decades-old systems and graded agency plans to replace them. "Eight of the 11 systems use outdated languages, four have unsupported hardware or software, and seven are operating with known cybersecurity vulnerabilities," the report states, and the 11 legacy systems most in need of modernization are maintained by 10 federal agencies, per the GAO report on critical legacy systems.

The report's most uncomfortable detail is age: the systems on GAO's list span from 23 years old to 60 years old, and the oldest is operated by the Defense Department, per the report's table of systems. On planning, GAO found that only a minority of agencies had modernization plans containing all the elements GAO considers necessary, and at least two agencies, including Defense, had no plan at all for the flagged systems.

Why it matters is not nostalgia but exposure: outdated languages mean shrinking pools of qualified maintainers, unsupported hardware means unpatchable components, and known vulnerabilities in systems supporting missions from tax processing to national security are an auditable, dated risk on the public record.

What did GAO recommend, and to whom?

The July 2025 report's remedies ran to both branches. GAO recommended that Congress consider requiring agencies to develop modernization plans for critical legacy systems, and that the agencies operating the flagged systems complete plans containing the elements GAO defines, according to the report's recommendations section.

The branch matters. Recommendations to agencies depend on management follow-through that history shows is uneven; a statutory requirement converts a suggestion into an audit-ready obligation, which is why GAO escalates some findings to legislators rather than to executives alone.

The report is also a follow-on in a series: GAO has flagged critical legacy systems in earlier products across administrations, and the 2025 edition reads as a progress check in which the systems age faster than the plans mature. Whether Congress adopts the recommendation in authorization or appropriations law is the indicator to watch in the current cycle.

Why do legacy systems persist?

The persistence is structural, not accidental. A legacy system that still processes transactions is a working production asset; replacing it means re-engineering interfaces that dozens of other systems depend on, with no ribbon-cutting and high failure risk. Agencies rationally divert scarce IT budget to keeping the current stack compliant and operational.

Funding mechanics compound this. Large modernizations need multi-year money, while appropriations committees prefer annual control, and a failed high-profile project costs a career. The Technology Modernization Fund was created precisely to break that trap: a revolving fund that lends to agencies for modernization projects, with repayment from realized savings. Its recent trajectory shows the tension.

The result is the pattern GAO has documented across administrations: critical systems identified, plans requested, plans not delivered, and the can kicked to the next budget cycle with another year of runtime on hardware older than the workforce maintaining it.

How is the Technology Modernization Fund funded now?

Thinly, and by transfers. "The White House is not proposing new funding for the Technology Modernization Fund (TMF) in fiscal year (FY) 2027, instead relying on transfer authority to sustain the government's central IT modernization fund," MeriTalk reported on April 7, 2026, noting the proposal lets the General Services Administration, with OMB approval, collect up to $100 million in funding that would otherwise be unavailable for obligation from other agencies, per MeriTalk's report on the TMF proposal.

Congress's counter was modest. "House appropriators included $5 million in total funding for the TMF 'to remain available until expended,'" MeriTalk reported on April 20, 2026, a sum that "would match what Congress ultimately approved for FY 2026 TMF appropriations," per MeriTalk's coverage of the House spending bill.

ActionAmountDate
FY2026 enacted TMF appropriation$5 millionFY2026
House FSGG bill for FY2027$5 millionApril 2026
White House FY2027 proposalNo new funding; up to $100M transfer authorityApril 2026

Is procurement itself the bottleneck?

Partly. Modernization is not only a money problem; it is an acquisition problem. Requirements documents written around the legacy system's quirks, years-long solicitations and vendor lock all slow replacement, and GAO's finding that most agencies lack complete plans points at management capacity as much as dollars.

Transfer authority is itself a procurement-policy choice: sweeping unobligated balances into a central fund moves decisions from agencies to GSA and OMB, which is faster but concentrates both expertise and political risk. Whether that trade pays off depends on project selection discipline that the public record does not yet demonstrate.

What is unknown is stated as unknown: neither the administration nor appropriators have published a full accounting of TMF loan repayments against the new transfer mechanism in the documents reviewed. The testable claim is narrow, that a fund nourished at $5 million a year plus transfers cannot by itself carry eleven mission-critical replacements, several of them in agencies that GAO found had no modernization plan at all.

What should watchdogs track next?

Three indicators will tell the story over the coming cycle. First, whether GAO's recommendation landscape changes: if the next update shows agencies producing complete plans, the pressure worked; if the same systems reappear, the finding aged into wallpaper. Second, whether the transfer authority is actually executed and at what scale, since authority to collect up to $100 million is not the same as collection. Third, whether any of the flagged systems, particularly the oldest Defense Department entry, moves from operation to retirement with a dated transition plan.

which converts every modernization delay into accumulated risk measured in unpatched years. Budget committees can defer funding; the vulnerability clock does not defer.

For agencies, the practical reading of 2025-2026 is that central seed money has effectively evaporated and modernization must be funded from operating budgets, meaning the legacy problem now competes directly with daily service delivery in every appropriations hearing that follows.

More from our brands

Part of the VUGA Network

Sources

  1. Information Technology: Agencies Need to Plan for Modernizing Critical Decades-Old Legacy Systems — U.S. Government Accountability Office
  2. White House Proposes No New TMF Funding for FY 2027, Leans on Transfer Authority — MeriTalk
  3. House FSGG Bill Funds TMF at $5M, Boosts Cybersecurity and IT Flexibility — MeriTalk