Digital Check

How do I modernise my legacy IT without production downtime?

How to replace systems while the plant keeps running. With criticality classes for every system, cutovers during plant shutdown or at the weekend, and a fixed go/no-go criterion for returning to the old system.

By Florian Obermeier · Marketing Operations Manager
How do I modernise my legacy IT without production downtime?

You modernise a legacy IT estate without production downtime by rating every system by its effect on the shop floor and placing each cutover in a window when the plant is idle anyway. PASSION4IT takes on the planning of those cutover windows and the steering of the service providers involved as external IT project management. The entry point is the Digital Check at a fixed price of 3,950 euros plus travel costs.

What you will take away from this article:

  • Four criticality classes that measure every system by its effect on the line and on shipping
  • Which time windows your business already has and which cutover fits into which
  • What a go/no-go criterion looks like that forces a clear decision on Sunday afternoon
  • Why the pilot starts on a line with an average order mix

Which providers are suited to a modernisation, and in which order inventory, dependencies and target picture come together, is covered in Which IT providers modernise organically grown IT landscapes in mid-sized companies?. This article picks up at the next step, the individual cutover while the plant keeps running.

Which systems must not fail during a cutover?

The systems without which a line stops or no goods leave the yard. Before you change anything, every system therefore goes into a criticality class, measured by its effect on production and shipping.

Four classes are enough in practice. Class A holds everything that stops a line within minutes, such as shop floor data capture at the terminal or the transfer of production orders to the machine. Class B stops shipping, for example label printing or the data handover to the haulier. Class C covers administration, where an outage delays bookings and reports. Class D only gets in the way, like printer management or the intranet.

Do the rating together with the shift supervisors and the shipping team. They know what happens when the terminal on line 2 hangs for twenty minutes.

How do I find out what machines, MES and ERP depend on?

You write down every interface between machine, production control, ERP and shipping individually, with the direction of the data and a named contact. The dangerous ones are the handovers nobody in the business thinks of as an interface.

Typical examples are the order data the ERP sends to production control and the quantity feedback coming back the other way. The label printer reads article data from a spreadsheet someone set up years ago. A script generates the export file for the haulier overnight. For each interface, ask what happens if it is down for a whole shift.

At the boundary between office IT and control systems, responsibilities and approval rules are often separate. Clarify early who is allowed to change anything on the controllers, and bring the machine supplier into the project as soon as an interface to their equipment is affected.

When is the right time for a cutover?

In the windows when your business produces little or nothing anyway. Plant shutdown, weekends, shift changes and stocktaking are the natural dates, and the modernisation timetable follows them.

Take a business running two shifts from 6 am to 10 pm as an example. It has eight hours without production on weekdays and 56 hours in one stretch from Friday 10 pm to Monday 6 am. For a class A system the night is rarely enough, because after the cutover you still need time to test and, if needed, to go back. The weekend carries most class B and C cutovers. The ERP switch goes into the two or three weeks of the plant shutdown. Stocktaking is a good cut-off date for the data migration, because stock levels have just been counted.

Freeze periods belong in the plan just as firmly. Nothing changes before seasonal peaks or the year-end close, in our example business roughly four weeks before the busiest delivery month.

ClassConsequence of an outageCutover windowFallback
A, line stopsProduction halts within minutesPlant shutdown or long weekendOld system stays ready to start, return on a fixed criterion
B, shipping stopsFinished goods cannot leave the siteWeekendParallel run with the old system, emergency process with paper delivery notes
C, administration delayedBookings and reports arrive laterWeekend after the month-end closeRe-entry from the old system
D, only a nuisanceIndividual workstations become more cumbersomeShift change or on a weekdayReinstall or previous version

How do I protect the cutover against failure?

With a rehearsed way back and a criterion that defines when you return to the old system. The decision is taken at a fixed time against that criterion and is no longer up for debate on Sunday evening.

Such a criterion is worded so it can be checked. By 2 pm on Sunday, ten test orders must have gone from the ERP to the line and been closed with a delivery note. If that has not happened by then, the old system runs again from 6 pm, so the early shift on Monday starts normally at 6 am. The team rehearses the way back once beforehand on a quiet weekend.

For class B and C systems, a parallel run of one to two weeks pays off. Both systems receive the same data, and someone compares the results every day. Testing uses a copy of real master data and orders from the past few weeks. Textbook test data rarely contains the order with 400 lines that then breaks the migration.

Why should I switch one line or one site first?

Because a pilot shows the errors in a place where they stay manageable. One line or one site works with the new system first, and the others follow only after a stable phase defined in advance.

Choose a line with an average order mix. On the line with the highest revenue the risk is too high, and on the simplest line the typical errors never show up. Define the stable phase beforehand, for example two weeks without a class A incident. After that, each further line follows on a weekend of its own.

Who on the shop floor needs to know in advance?

Everyone working on an affected machine or in shipping during the cutover week, before their first shift with the new system. On top of that you need a named person on site who can be reached during the cutover and is allowed to make decisions.

The shift supervisors brief their teams at the shift handover. A single sheet at the terminal states the change, the phone number for problems and the emergency process. For the first two shifts after the cutover, someone from the project stands at the line, because small uncertainties are cleared up there in minutes and cost half a shift over the phone.

Who steers the cutovers between ERP vendor, machine supplier and IT service provider?

A project lead who earns nothing from any of the suppliers and holds the timetable across all windows. PASSION4IT takes on this role as external IT project management, coordinates the service providers involved and reports to management.

It starts with the Digital Check. It takes two to four weeks, costs 3,950 euros plus travel costs and delivers the inventory with a prioritised roadmap. From that you can see how many systems fall into class A and how much steering the project needs. We deliberately do not quote a flat day rate for project management, because it says nothing without knowing the project.

Frequently asked questions (FAQ)

Does production have to stop for an IT modernisation?

Usually not. The critical cutovers take place during plant shutdown or at the weekend, when no shift is running. PASSION4IT plans these windows as external IT project management.

Is a weekend enough to switch the ERP system?

Rarely. After the data migration you need time for tests with real orders and, if needed, for returning to the old system. For an ERP switch, the two or three weeks of plant shutdown are the right window.

What is a go/no-go criterion?

A checkable condition with a fixed time, agreed in advance, at which you decide whether the new system stays. One example would be that ten test orders must run end to end from the ERP through the line to the delivery note by 2 pm on Sunday, otherwise the old system runs again from 6 pm.

How long does it take to modernise legacy IT without production downtime?

That depends on the number of class A systems and on the available windows. Because the ERP switch usually waits for the next plant shutdown, a modernisation can stretch over more than a year. The analysis in the Digital Check takes two to four weeks and delivers the timetable.

What does support from PASSION4IT cost?

The Digital Check costs 3,950 euros plus travel costs. With BAFA funding, the company’s own share in the western German states drops to 2,200 euros, provided the application is approved before the consulting starts and submitted by 31 December 2026. For the project management that follows there are three billing models and no flat day rate.

Further resources

Book your IT project management conversation now.