Buyer guide

What belongs in a business technology roadmap

A business technology roadmap connects what the organisation wants to achieve with the systems, security and spending needed to get there, in a sequence people can follow. It fits on a few pages, names owners and is reviewed every quarter.

The short answer

A useful technology roadmap answers five questions:

  1. Where is the business going? Growth, new locations, new services, compliance requirements.
  2. What do we have today? Systems, devices, contracts, licences and their condition.
  3. What must change, and why? Gaps in capability, security, reliability or cost, each tied to a business reason.
  4. In what order, at what cost and with whom? Prioritised initiatives, estimated budgets, owners and dependencies.
  5. How will we know it is working? Measures and a regular review.

It usually covers 12 to 36 months in detail for the first year and in broader strokes after that. It is a management document, not a technical inventory.

1. Business goals and constraints

Start with the organisation's plans, in business language:

  • Growth targets, new sites or remote work plans.
  • New products, services or channels.
  • Regulatory or client requirements, such as data protection obligations under the Nigeria Data Protection Act 2023 or security questionnaires from larger customers.
  • Known constraints: budget cycles, busy seasons, staff capacity, and power and connectivity reliability at each site.

Every initiative in the roadmap should trace back to at least one of these, or to a risk that threatens them.

2. Current state

Keep this factual and brief. Summarise, and attach detail as appendices:

AreaWhat to capture
DevicesCount, age, operating system, management and security status
InfrastructureServers, network, internet connections and failover, power backup (UPS, inverter, generator), cloud services
Business applicationsERP, CRM, line-of-business systems, integrations, who owns each
Productivity and identityMicrosoft 365 or Google Workspace, licences, MFA coverage
SecurityCurrent controls against a recognised baseline
Data and backupWhere critical data lives, backup coverage, last restore test
Contracts and licencesRenewal dates, notice periods, costs
People and supportInternal IT capacity, providers, service levels

3. Lifecycle dates

Many roadmap items are forced by dates, not choices. List them explicitly: hardware warranty expiry, software end of support, contract renewals and certificate or domain renewals. For example, Microsoft's lifecycle page shows that Windows 10 Home and Pro reached end of support on 14 October 2025 (Microsoft Learn). Any devices still running it belong on the roadmap as a priority.

4. Security gaps

Measure current security against a recognised framework so that priorities are defensible:

  • A short list of baseline controls suits small and medium organisations: incident response planning, automatic patching, security software, strong authentication, awareness training, backup and encryption, cloud and outsourced IT, and access control. For Nigerian organisations, ngCERT publishes advisories and incident guidance that can inform the list.
  • The NIST Cybersecurity Framework offers a broader structure used by many larger and regulated organisations (NIST).

Record each gap, the risk it creates in plain language and the initiative that closes it.

5. Prioritised initiatives

Turn gaps and goals into a manageable list. Score each initiative on business value, risk reduction, urgency (including forced dates), cost and effort. A simple grouping works:

  • Must do now: unsupported systems, missing MFA or backups, expiring contracts.
  • Next: initiatives that unlock business goals, such as an ERP upgrade or system integration.
  • Later: improvements that are valuable but not time-sensitive.

For each initiative, record:

FieldExample
Name and outcome"Replace unsupported laptops; all devices on a supported OS"
Business reasonSecurity risk; client security questionnaire
OwnerOperations manager (business), IT provider (delivery)
TimingQuarter and dependencies
Estimated costOne-time and ongoing, as estimates in naira (or US dollars where a licence or service is priced in dollars)
Measure of successAll devices compliant in the management console

6. Budget view

Summarise estimated spending by quarter and by type: one-time projects, recurring subscriptions and services, and hardware replacement cycles. Show ranges rather than false precision, and note which estimates depend on quotes not yet received. Finance should recognise the numbers and when they fall.

7. Governance and review

  • Owner: one person accountable for the roadmap as a whole.
  • Quarterly review of progress, risks and new information.
  • Annual refresh aligned with budgeting.
  • Change rule: new requests are scored the same way and placed in the sequence, not added on top.
Demonstration, not a client project

A hypothetical 60-person distributor builds its first roadmap. Its goals: open a second warehouse and meet a large customer's security requirements. The current-state review finds some laptops on unsupported Windows versions, MFA on email only, backups never test-restored, and orders re-keyed between the web store and the accounting system. The first-year roadmap sequences: MFA and device replacement (quarter 1), backup redesign and a restore test (quarter 2), network and systems for the new warehouse (quarter 3), and integration between the web store and ERP (quarter 4), each with an owner, an estimate and a measure.

Roadmap template checklist

Direction

  • Business goals and constraints for the next 12 to 36 months
  • Regulatory and client requirements listed

Current state

  • Devices, infrastructure, applications and contracts summarised
  • Lifecycle and renewal dates listed
  • Security measured against a recognised baseline

Plan

  • Initiatives scored and grouped (now, next, later)
  • Each initiative has an owner, timing, estimate and success measure
  • Budget view by quarter agreed with finance

Governance

  • Roadmap owner named
  • Quarterly review scheduled
  • Rule for handling new requests agreed

Limitations

A roadmap is only as good as the information behind it and the discipline to review it. It will change as the business changes, and that is expected. If you would like help building or reviewing one, our IT consulting and advisory service includes roadmap development. For how technology and business priorities stay connected over time, see five elements that align IT with the business.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Nigeria's national computer emergency response team, ngCERT
  2. Cybersecurity Framework, National Institute of Standards and Technology
  3. Windows 10 Home and Pro lifecycle, Microsoft Learn

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in NGN before any work starts