Gantt Chart for Technology Refresh
Enterprise technology refresh programs are deceptively complex. The visible work is replacing hardware and upgrading software. The real work is managing the organizational change across hundreds or thousands of employees, coordinating procurement across long lead times, sequencing deployments to avoid disrupting critical business operations, and disposing of old assets in compliance with data security requirements.
Without a Gantt chart, technology refresh programs typically suffer from one of two failure modes: big-bang deployments that overwhelm the helpdesk and cause widespread productivity disruption, or slow rolling replacements that drag on indefinitely while the oldest equipment remains in use. A Gantt chart sequences the refresh logically — risk-priority order, with enough time per wave to do it well without dragging out the program unnecessarily.
Phase 1: Current State Inventory (Weeks 1–6)
You cannot plan a refresh program without knowing what you have. Inventory is the unglamorous but essential first step.
Hardware inventory:
- All endpoint devices: laptops, desktops, workstations, tablets
- For each device: model, serial number, current user, purchase date, age, operating system version, RAM, storage
- Peripheral equipment: monitors, docking stations, printers, scanners, phones
- Infrastructure: servers, network equipment, storage (if in scope)
- Data sources: ITSM/CMDB (ServiceNow, Jira Service Management, Freshservice), MDM platform (Intune, Jamf), procurement records, manual audit for gaps
Software version inventory:
- Operating systems: Windows version (build numbers), macOS version, iOS/iPadOS, Android
- Core productivity software: Office/Microsoft 365 versions, browser versions
- Specialized software: line-of-business applications, version compatibility with new hardware and OS
- License inventory: what is licensed, to how many seats, at what cost, renewal dates
End-of-life and end-of-support dates:
- Hardware: manufacturer end-of-support dates (when security patches and warranty support end)
- Software: vendor end-of-life dates (Windows 10 end of support: October 2025; many organizations are using this to drive their refresh cycle)
- Applications: which applications have minimum OS version requirements that affect refresh sequencing?
Security vulnerability exposure:
- Identify devices running OS versions beyond end of support (no security patches available)
- Identify devices with known exploitable vulnerabilities in their current configuration
- Cross-reference with your vulnerability management program output
Synthesis:
- Complete device inventory in a structured format (CSV or CMDB) with all relevant attributes
- Age distribution: what percentage of devices are 0–2 years, 2–4 years, 4+ years?
- End-of-life summary: how many devices reach EOL in the next 6, 12, 24 months?
Phase 2: Refresh Prioritization (Weeks 5–10)
Not all devices can or should be replaced simultaneously. Prioritization determines the order that maximizes risk reduction and business impact.
Prioritization framework — rank each device on:
Risk score:
- Security risk: EOL/EOS operating system or hardware, known unpatched vulnerabilities, no BitLocker/FileVault encryption, no MDM enrollment
- Performance risk: RAM below current standard, storage below current standard, processor generation more than 3 generations behind
- Reliability risk: device age, prior repair history, user-reported reliability issues
Business impact:
- User role criticality: what is the business impact if this user's device fails?
- Remote vs. office user: remote workers with device failure have limited fallback options
- Shared device vs. personal device: shared devices (labs, kiosks, meeting rooms) have different refresh logic
Prioritization tiers:
- Tier 1 (Immediate): EOL OS, security-critical roles, high failure risk
- Tier 2 (Within 6 months): 4+ year old devices, significant performance gaps
- Tier 3 (6–18 months): 2–4 year old devices due for proactive refresh per standard lifecycle
- Tier 4 (18–36 months): newer devices not yet requiring refresh; track for inclusion in next cycle
Phase 3: Budget Approval and Procurement Planning (Weeks 8–14)
Budget development:
- Hardware costs: device count by category × unit cost (obtain quotes for volume pricing)
- Software costs: any additional licenses required (OS upgrades, Office licenses if not subscription, new software required for new hardware)
- MDM costs: Intune or Jamf licensing if not already deployed
- Labor costs: IT staff and any contracted deployment resources
- Training costs: user training and manager briefings
- Disposal costs: ITAD (IT Asset Disposition) vendor for certified destruction
Budget presentation:
- Cost by fiscal quarter (deployment is phased; so is cash outflow)
- Cost per device (useful for benchmarking and leadership credibility)
- Risk cost of not refreshing: estimated cost of a security incident on an EOL device, productivity cost of device failure
- Multi-year lifecycle plan: this refresh should be the first in a defined 3–4 year replacement cycle, not a one-time event
Procurement planning:
- Identify primary hardware vendor(s): Dell, HP, Apple (based on existing standards and pricing agreements)
- Negotiate volume pricing: most organizations with 100+ devices can negotiate significant discounts off list price
- Determine procurement timing: order in batches aligned to deployment waves rather than all upfront (reduces inventory carrying cost; allows spec adjustments between waves)
- Lead times: confirm current hardware lead times — supply chain constraints can extend lead times significantly
- Loaner pool: procure 5–10% additional devices for use during deployment wave (swap-and-return reduces deployment time per user)
Phase 4: Vendor Selection and Contract Execution (Weeks 10–16)
Hardware vendor selection:
- Confirm the preferred hardware standard (Windows laptop, MacBook, or mixed fleet)
- If changing the standard (e.g., moving from Windows to Mac or vice versa), this decision must be made before procurement
- Negotiate volume agreement with primary vendor
- Establish secondary vendor or marketplace for emergency replacement
Software license review:
- Microsoft 365 Enterprise Agreement: negotiate concurrent with hardware refresh (EA renewal timing often aligns with refresh projects)
- SaaS vendor rationalization: the refresh program is an opportunity to consolidate redundant tools
- Adobe, Zoom, other productivity tools: review license counts vs. active users
ITAD vendor selection:
- ITAD (IT Asset Disposition) manages secure data destruction and environmentally compliant disposal of retired devices
- Certification requirements: NAID AAA certified for data destruction, R2 or e-Stewards certified for environmental compliance
- Data destruction standard: NIST 800-88 (overwrite or physical destruction depending on storage type)
- Asset recovery value: many ITAD vendors offer residual value payments for devices with market value
- Certificate of destruction: vendor must provide per-device certificate of destruction for compliance records
Phase 5: Imaging and Configuration Management (Weeks 12–18)
Before deployment begins, the target device configuration must be defined and tested.
MDM platform:
- Intune (Microsoft): standard for Windows and co-managed Mac environments; deeply integrated with Azure AD and Microsoft 365
- Jamf: preferred for Mac-first or Mac-heavy environments; Apple Business Manager integration
- Both: if managing a mixed fleet
Device configuration:
- Golden image or cloud-provisioned configuration via MDM (zero-touch deployment via Autopilot or DEP)
- Required applications: define the standard app set that every device receives on enrollment
- Security configuration: BitLocker/FileVault, password policy, screen lock, endpoint protection agent, conditional access policies
- Network configuration: Wi-Fi profiles, VPN configuration
Configuration testing:
- Test image or MDM enrollment on representative device models from each category in the refresh scope
- Test with representative users from different functional groups (applications may vary by team)
- Identify and resolve any application compatibility issues before wave 1 deployment begins
Loaner pool preparation:
- Configure loaner devices to the same standard as deployment devices
- Loaner devices used for swap-and-return deployment: user gets a loaner while their old device is wiped and verified; user then receives their permanent new device
Phase 6: Pilot Group Deployment and User Acceptance Testing (Weeks 18–22)
Pilot group selection:
- 20–50 users representative of the broader organization
- Include: IT-savvy users who can identify issues early, power users with specialized software needs, remote workers, and less technically proficient users
- Exclude: users in the middle of critical project deadlines
Pilot deployment process:
- Deploy new devices to pilot group using the planned deployment process
- Monitor: enrollment success rate, application delivery success, user support ticket volume and categories
- Conduct user satisfaction survey after 1 week
- Document all issues and root causes
- Resolve systematic issues before wave 1 deployment
User acceptance testing focus:
- All required applications are present and functional
- Network connectivity (Wi-Fi, VPN, corporate resources) works correctly
- Peripheral connectivity (monitors, docking stations, printers) works as expected
- Performance is acceptable for the user's workload
- Data migration was complete (all files accessible, email synced, browser bookmarks migrated)
Pilot go/no-go decision is a milestone. Wave 1 deployment is a dependency.
Phase 7: Department-by-Department Rollout (Weeks 22–48)
The rollout is structured in waves organized by department and risk profile. Wave size should match IT team capacity to deploy and support without degrading day-to-day helpdesk service.
Wave planning criteria:
- Wave size: 50–200 users per wave is typical for a standard IT team; adjust based on team capacity and deployment method (white-glove vs. self-service)
- Wave sequencing: Tier 1 (highest risk) devices first; then by department with considerations for operational impact (avoid deploying to a department during their peak business period)
- Stagger within departments: don't refresh an entire team simultaneously; retain some users on old devices as functional backstop
Deployment methods:
- White-glove: IT technician meets with each user, deploys device in person, assists with any immediate issues. Highest quality, highest cost, lowest volume per day. Best for executives and power users.
- Drop-ship: device shipped pre-configured directly to remote user's home/office with self-service enrollment. Requires robust self-service instructions. Fastest for geographically distributed employees.
- Self-service: user picks up device from IT, follows self-service enrollment guide, calls helpdesk for issues. Middle ground.
Helpdesk readiness:
- Brief helpdesk on wave timing and what issues to expect
- Create knowledge base articles for common post-deployment issues
- Ensure helpdesk ticket triage separates refresh-related tickets for tracking
Gantt wave structure:
- One row per department wave
- Sub-tasks: scheduling user appointments, device pickup/delivery, enrollment confirmation, 48-hour follow-up
- Helpdesk escalation volume tracking as parallel monitoring row
Executive and VIP deployment:
- Separate track on the Gantt chart; typically white-glove regardless of wave
- Dedicate senior IT staff
- Minimize disruption to calendar — schedule around travel and major meetings
- Extend post-deployment support window (dedicated contact for 2 weeks vs. standard helpdesk)
Phase 8: Decommission and Asset Disposal (Weeks 26–52)
Asset disposal runs in parallel with deployment waves — as each wave completes, the retired devices from that wave enter the disposal process.
Data sanitization:
- For each retired device: verify BitLocker/FileVault encryption was active (if yes, decryption key destruction is sufficient for NIST 800-88 Purge-level compliance)
- For unencrypted drives or cases where overwrite is required: run certified secure erase tool
- For physically damaged drives or SSDs where software erase is insufficient: physical destruction via shredder or degausser
- Document data sanitization method per device serial number
ITAD handoff:
- Package retired devices by wave for ITAD pickup
- Provide device manifest to ITAD vendor (serial numbers, device type, storage type)
- ITAD performs data destruction and provides certificates of destruction per device
- ITAD processes devices for resale (functional devices), parts recovery (partially functional), or responsible recycling (end-of-life)
- ITAD issues environmental certificate and residual value payment (if applicable)
Internal records:
- Update CMDB/asset register to mark retired devices as decommissioned with destruction date and certificate reference
- Close MDM enrollment records for retired devices
- Recover software licenses from retired devices (where applicable)
Phase 9: Post-Refresh Performance Benchmarking (Week 52+)
Performance metrics:
- Device performance: compare helpdesk ticket volume per user (pre-refresh vs. post-refresh trend)
- Security posture: percentage of devices on supported OS, percentage encrypted, percentage enrolled in MDM
- User satisfaction: post-refresh survey on device performance and deployment experience
- Total cost: actual cost vs. budget, cost per device
Lifecycle planning output:
- Based on the refresh, establish the ongoing replacement cycle: 3-year for laptops, 4-year for desktops, annual for peripherals
- Update the CMDB with next replacement date for each refreshed device
- Build the technology refresh into the annual IT budget as a standard operational cost, not a one-time project
Building the Gantt Chart
Use gantt-chart.io to build your technology refresh Gantt chart. The key insight a Gantt chart provides for a tech refresh: procurement lead times, imaging and configuration work, and pilot deployment must all complete before wave 1 begins — but these three tracks can run in parallel with each other. Map them as parallel tracks with a single merge point at pilot go/no-go, and the Gantt chart will show you the true earliest date wave 1 can start. That date is almost always later than initial estimates, and knowing it early is far better than discovering it two weeks before the originally planned start.