The licence is the smallest number: on a legacy migration it’s only 20-40% of total cost, with 60-80% going to integration, migration and QA. Then legacy platforms eat 40-60% of every dev sprint in maintenance, and breach exposure compounds it (IBM 2026: $4.99M global, $11.5M US average). The real total cost of ownership is the compounding maintenance and opportunity cost you stopped noticing.
Every legacy platform is quoted on the one number that looks reasonable — the licence. It is also, by the industry’s own accounting, the smallest part of what you will actually spend.
The most expensive number in a commerce platform decision is the one nobody puts on the slide. Boards approve migrations against a licence quote, because a licence quote is tidy, annual and easy to compare. Then the project lands, and the licence turns out to have been the cheap part. This is not a rounding error. It is the structural reason legacy commerce keeps costing more than anyone budgeted, and it is worth looking at squarely.
The licence is 20-40%. Where does the rest go?
According to replatforming analyses from BigCommerce, Elogic and others across 2026, the platform licence typically accounts for only about 20-40% of a migration or replatform project’s total cost. The remaining 60-80% is implementation, ERP integration, data migration and QA — the unglamorous, hard-to-estimate work of making the new thing actually fit the business. That ratio is remarkably stable across project sizes, which tells you something: the licence is not the product you are buying. The integration is.
The 2026 cost bands make the scale concrete. A mid-market replatform runs roughly $150K-$300K over five to ten months. An enterprise rebuild lands at $500K-$2M or more. A large ERP or mainframe programme sits in the $1M-$10M+ range. In every band, the visible licence line is a minority of the spend, and the majority hides inside the integration work that boards approve last and understand least.
The tax you pay every sprint
The migration cost is the one-off. The compounding cost is worse. The same analyses find that legacy platforms silently consume 40-60% of every development sprint in workaround maintenance, backports and patch fire-drills. Read that as a standing tax on your engineering capacity: for every two engineers you employ, something close to one is servicing the platform’s age rather than building anything a customer would notice.
This is where the real total cost of ownership lives, and it almost never appears in the business case. A licence renewal is a number you can negotiate. A permanent 40-60% haircut on your team’s output is an opportunity cost that quietly redraws your roadmap — every feature that ships late, every experiment you never ran, every competitor who moved while you were backporting a patch. Over a three-year horizon that opportunity cost dwarfs the migration invoice, and unlike the invoice, it never stops.
The cost band nobody lists: exposure
There is one more line that legacy carries and rarely admits: risk. Old code accretes unpatched surface, and the price of that surface is now measurable. IBM’s Cost of a Data Breach 2026, reported via Help Net Security, puts the global average breach at $4.99M and the US average at $11.5M. A single serious incident can therefore exceed the entire cost of the enterprise rebuild you kept deferring. The maintenance tax and the breach exposure are not separate problems; they are the same problem seen from two angles. The sprints you spend firefighting are the sprints you are not spending on the hardening that would have kept the incident out.
Put the three costs together and the picture inverts. The headline you compared vendors on — the licence — is the smallest of the four numbers that actually determine what the platform costs you: licence, integration, the recurring sprint tax, and expected breach exposure. Optimising the visible 20-40% while ignoring the invisible rest is how organisations end up genuinely surprised by a bill they technically approved.
What actually reduces the compounding part
If the expensive part is integration and ongoing maintenance, then the lever that matters is architecture, not price. A modern, self-hosted stack that keeps its capabilities modular — payments, subscriptions, catalogue, CMS, booking, each able to switch on or off without a restart — attacks the maintenance tax directly, because you are not carrying twenty years of coupled edge cases to change one thing. It also collapses some of the integration cost by doing more of the heavy lifting itself; VBWD’s own write-up on the 40-minute catalogue and the legacy commerce tax walks through why raw import throughput changes the economics of a migration, though as always with vendor benchmarks the figures are directional and vary by platform and data shape.
Now the honest caveat, because this cuts both ways. Modern architecture buys you speed, auditability and a smaller maintenance tax, but it trades away something real: the two decades of accumulated edge-case maturity that a long-standing incumbent has ground in. For most businesses — those whose complexity lives in their domain, not in the platform’s ancient corners — that is the right trade, because they get the compounding savings and give up quirks they never relied on. For a minority whose entire operation is wound around one legacy platform’s specific behaviours, it is not. The discipline is to know which one you are before you sign anything, and to price the compounding costs — not just the licence — when you decide.
The mistake is not choosing legacy or choosing modern. The mistake is deciding on the 20-40% you can see and letting the 60-80% you cannot see decide the outcome for you.
If this maps to a conversation happening inside your own organisation, the useful next step is specific rather than generic: see your own workload on modern, self-hosted infrastructure. Request an enterprise installation and bring the numbers you’re trying to improve.
Sources: BigCommerce and Elogic replatforming analyses (2026); IBM Cost of a Data Breach 2026, via Help Net Security.