What a technology roadmap has to contain.
A good technology roadmap is boring in the right ways. It says what you'll run, what it costs per year, what you're retiring, and in what order. Every item carries a number and an owner. It names the two or three things you should not do this year, because a plan that approves everything has decided nothing. If your roadmap can't survive a CFO asking "why this quarter and not next," it isn't a roadmap. It's a wish list with a logo on it. The test is simple and most deliverables fail it: hand the document to your senior sysadmin and see whether they can start on Monday. If they can't, you bought a diagnosis and called it a plan.We read the estate first, and we split the fee.
We start with what you actually run. Contracts, licence renewals, end-of-support dates, the switch nobody's rebooted since 2019. Risk usually sits in three places: kit past vendor support, a single person who's the only one who knows something, and renewals that auto-stack because nobody owns the calendar. We price the fix and the do-nothing option side by side, and you choose. There's a conflict of interest in that, so I'll name it. Most IT consulting in this country is a pre-sales motion: the assessment is free, the recommendation happens to be the vendor with the best margin, and the roadmap has a purchase order at the end of it. We build and run infrastructure too, so our exposure is real. The fix isn't a vow of poverty, it's writing the assessment fee and the build fee as separate engagements you can award separately. Ask any firm you're talking to whether they'll do that.Canadian context changes the sequencing.
Bill C-8 received royal assent on 2026-06-15, and its Part 2 critical cyber systems rules are law but not yet in force, with no operators designated (Public Safety Canada, 2026). So a roadmap that budgets for that work in the right year is prudent, and one that panics is expensive. PIPEDA is the constant: outsourcing the work never outsources the accountability (Office of the Privacy Commissioner of Canada). Data residency, breach exposure at a record $7.11M average in Canada (IBM, 2026-07-29), and provincial rules like Quebec's Law 25 all belong in the plan, not in a footnote after you've signed. An IT modernization strategy that ignores the regulatory calendar gets re-sequenced later, at someone else's price.