{"id":3939,"date":"2026-09-29T06:13:22","date_gmt":"2026-09-29T03:13:22","guid":{"rendered":"https:\/\/inferne.com\/blog\/asp-net-development\/"},"modified":"2026-09-29T14:53:54","modified_gmt":"2026-09-29T11:53:54","slug":"asp-net-development","status":"publish","type":"post","link":"https:\/\/inferne.com\/blog\/asp-net-development\/","title":{"rendered":"ASP.NET Development: From Web Forms and MVC to ASP.NET Core"},"content":{"rendered":"<p>Most ASP.NET development requests we see fall into two groups. Some teams want a new web application on ASP.NET Core. Many more are running an ASP.NET system on the .NET Framework, often Web Forms or MVC, that has handled a core business process for years and now raises hard questions about hosting, hiring, security and what comes next.<\/p>\n<p>For a legacy system, the goal is one you&#8217;re no longer afraid to touch. It&#8217;s patched and hardened now, its risky parts are covered by tests, and it has a path to modern .NET that moves one piece at a time while the business keeps running. For new builds the goal is simpler: ASP.NET Core done cleanly from the first commit.<\/p>\n<h2>What our ASP.NET development work covers<\/h2>\n<ul>\n<li>Line-of-business web applications such as portals, approval workflows, reporting and case management<\/li>\n<li>Customer-facing web apps that integrate with Microsoft identity, SQL Server and Office tooling<\/li>\n<li>Web APIs behind mobile apps, partner systems and single-page front ends<\/li>\n<li>Legacy Web Forms, MVC, Web API, WCF and ASMX services that need maintenance, integration work or a migration plan<\/li>\n<\/ul>\n<p>New work goes on ASP.NET Core, the cross-platform successor to classic ASP.NET, and follows the same discovery-to-launch process as the rest of our <a href=\"\/blog\/web-application-development\/\">web application development<\/a>. The wider platform is covered in our <a href=\"\/blog\/dotnet-development\/\">.NET development<\/a> article. This one sticks to the web layer, and to the legacy systems a lot of organizations still depend on.<\/p>\n<h2>The state of classic ASP.NET, honestly<\/h2>\n<p>Classic ASP.NET runs on the .NET Framework, and the .NET Framework is finished. Its final release line still gets security and reliability fixes because it ships as a component of Windows, and it stays supported for as long as the Windows version it runs on. So a Web Forms application isn&#8217;t unsupported. It&#8217;s frozen, and that has practical consequences:<\/p>\n<ul>\n<li>The framework gets no new features, and fewer new libraries target it.<\/li>\n<li>Hosting is limited to Windows Server and IIS, which narrows your container and cloud options.<\/li>\n<li>Web Forms and the server side of WCF were never ported to modern .NET. Moving them means rebuilding, not recompiling.<\/li>\n<li>The pool of developers who know Web Forms well is shrinking, and fewer of them want to work in it.<\/li>\n<\/ul>\n<p>None of this forces an immediate rewrite, but the system does need active care and a plan.<\/p>\n<h2>Keeping a legacy ASP.NET system secure<\/h2>\n<p>When we take over a .NET Framework application, the first pass is about risk. Features can wait.<\/p>\n<figure class=\"wp-block-image size-large\"><img width=\"900\" height=\"600\" src=\"https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-legacy-security-900x600.webp\" class=\"attachment-large size-large\" alt=\"A legacy server inside concentric walls with one guarded gate, a key kept deep inside and a watchtower for monitoring.\" loading=\"lazy\" sizes=\"auto, (max-width: 760px) 100vw, 720px\" decoding=\"async\" srcset=\"https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-legacy-security-900x600.webp 900w, https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-legacy-security-510x340.webp 510w, https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-legacy-security-768x512.webp 768w, https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-legacy-security.webp 1400w\" \/><\/figure>\n<ul>\n<li>Windows Server, IIS and .NET Framework updates go on a schedule, and TLS is limited to current protocol versions.<\/li>\n<li>ViewState and authentication cookies depend on the machine key, so it gets special attention. Attackers have used keys copied from public code samples or leaked in repositories to forge ViewState and run code on servers, so we rotate any keys that were ever exposed and keep all of them out of source control.<\/li>\n<li>Configuration gets hardened: debug compilation off, custom errors on, version headers removed, cookies set to HttpOnly and Secure, and request validation left on.<\/li>\n<li>The classic bugs get fixed. That means anti-forgery tokens on forms, parameterized queries everywhere, and authorization enforced on every page and endpoint instead of by hiding menu items.<\/li>\n<li>Old NuGet packages and bundled JavaScript libraries often carry known vulnerabilities, and many of them can be updated without touching the framework.<\/li>\n<li>Centralized logging and error monitoring go in early, so problems reach us before they reach users.<\/li>\n<\/ul>\n<h2>Moving to ASP.NET Core without a big bang<\/h2>\n<p>Rewriting a system that runs the business in one go is the riskiest option you have. We prefer incremental migration, an approach Microsoft documents and provides tooling for. It works in four stages:<\/p>\n<figure class=\"wp-block-image size-large\"><img width=\"900\" height=\"600\" src=\"https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-core-migration-900x600.webp\" class=\"attachment-large size-large\" alt=\"One gateway routing requests to a new modular building and to an old one, with a shared key passed between them.\" loading=\"lazy\" sizes=\"auto, (max-width: 760px) 100vw, 720px\" decoding=\"async\" srcset=\"https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-core-migration-900x600.webp 900w, https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-core-migration-510x340.webp 510w, https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-core-migration-768x512.webp 768w, https:\/\/inferne.com\/blog\/wp-content\/uploads\/2026\/09\/asp-net-development-core-migration.webp 1400w\" \/><\/figure>\n<ol>\n<li>A new ASP.NET Core app goes in front of the old one. Using the YARP reverse proxy, it forwards every request it doesn&#8217;t handle yet to the old application, so users still see one site.<\/li>\n<li>Microsoft&#8217;s System.Web adapters let both applications share authentication and session state during the transition.<\/li>\n<li>Shared code moves first. Business logic goes into class libraries that both applications can reference, targeting .NET Standard or both frameworks at once.<\/li>\n<li>From there, the migration goes route by route. Each page, controller or endpoint is rebuilt in ASP.NET Core, tested and switched over, until the old application can be turned off.<\/li>\n<\/ol>\n<h3>Decisions by technology<\/h3>\n<ul>\n<li>MVC and Web API port most directly. Controllers and views change, but the structure carries over.<\/li>\n<li>Web Forms pages get rebuilt, usually as Razor Pages, or as Blazor components when they&#8217;re highly interactive. Blazor&#8217;s component and event model feels familiar to Web Forms developers.<\/li>\n<li>WCF services can move to CoreWCF, an open-source port of the WCF server, or be replaced with REST or gRPC when every client can change.<\/li>\n<li>Windows Workflow Foundation has no official successor, so workflows are usually rewritten in code or moved to a maintained workflow engine.<\/li>\n<li>Entity Framework 6 runs on modern .NET. That lets the move to EF Core happen later, off the critical path.<\/li>\n<li>Code that leans on HttpContext.Current, Global.asax and web.config gets refactored toward dependency injection, middleware and standard configuration.<\/li>\n<\/ul>\n<h2>New ASP.NET Core applications<\/h2>\n<p>For new builds, the product decides the web model, not habit. Server-rendered applications, admin tools and content-heavy sites where SEO and simple hosting matter get Razor Pages or MVC. When a JavaScript front end or a mobile app sits in front, the backend is a Web API, built with controllers or minimal APIs. Angular is a common partner for .NET in enterprise teams, and our <a href=\"\/blog\/angular-development\/\">Angular development<\/a> article covers that side. Blazor fits internal tools, where a team that works only in C# benefits from using one language across the whole stack.<\/p>\n<p>Whichever model we pick, the quality bar stays the same. Integration tests run the real HTTP pipeline against a real database in a container. Authentication goes through ASP.NET Core Identity or your organization&#8217;s identity provider. Security headers and rate limiting sit at the edge, and structured logs and traces are in place from the first deployment. Because ASP.NET Core runs on Linux and in containers, it also opens up hosting options that are often cheaper than a Windows-only setup.<\/p>\n<h2>When to maintain, when to migrate<\/h2>\n<p>Not every legacy system should move. Our usual guidance:<\/p>\n<ul>\n<li><strong>Maintain and harden<\/strong> when the application is stable, changes rarely, and is due to be replaced within your planning horizon.<\/li>\n<li><strong>Migrate incrementally<\/strong> when the system is central, still evolving and expensive to replace. That describes most of the ASP.NET applications we&#8217;re asked about.<\/li>\n<li><strong>Replace<\/strong> when the business process has changed so much that the old data model no longer fits, or when an off-the-shelf product now covers the need.<\/li>\n<\/ul>\n<p>Sometimes ASP.NET isn&#8217;t the right destination at all. If your team works mainly in JavaScript or PHP and nothing else ties you to Microsoft&#8217;s platform, rebuilding in their stack can be the cheaper long-term choice. When that&#8217;s the case, we&#8217;ll recommend it.<\/p>\n<h2>How an engagement works<\/h2>\n<p>We usually begin with a focused assessment under NDA that looks at the codebase, the hosting and the dependencies. You get a written report with security findings ranked by severity, a breakdown of what can be migrated directly and what has to be rebuilt, and a phased plan that spells out the trade-offs of each option.<\/p>\n<p>That plan shapes the delivery team: .NET engineers, a QA tester who builds regression tests before anything moves, and a business analyst when undocumented behavior has to be recovered from the people who use the system every day. You follow progress through regular demos and written reports, and every change lands in your own repository with the documentation to support it.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>Is ASP.NET Web Forms still supported?<\/h3>\n<p>In a limited sense, yes. The .NET Framework it runs on still receives security fixes as part of Windows. It gets no new features, though, and it will never run on modern .NET.<\/p>\n<h3>Can we move from .NET Framework to modern .NET without a rewrite?<\/h3>\n<p>Partly. Class libraries, MVC controllers and Web API code often port with moderate changes. Web Forms pages and WCF server code have to be rebuilt or replaced. Incremental migration spreads that work out and keeps the system live throughout.<\/p>\n<h3>How long does a migration to ASP.NET Core take?<\/h3>\n<p>That depends on the size of the application and how much of it is Web Forms. After an assessment, you get a phased plan in which each phase delivers something usable on its own.<\/p>\n<h3>Should we migrate to Blazor?<\/h3>\n<p>For interactive internal tools built by a C# team, it&#8217;s a sensible target. For public-facing sites, Razor Pages or an API with a JavaScript front end is usually the safer choice.<\/p>\n<h3>Do we have to leave Windows hosting?<\/h3>\n<p>No. ASP.NET Core runs well on Windows and IIS too. Linux and containers become available if you want them later, but nothing forces the move.<\/p>\n<p>An ASP.NET system that carries more of your business than anyone is comfortable with deserves a clear picture of where it stands. <a href=\"https:\/\/inferne.com\/#contact\">Request a codebase assessment<\/a> and we&#8217;ll suggest a realistic first step.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How we build ASP.NET Core web apps, keep legacy Web Forms and MVC systems secure, and migrate them to modern .NET one route at a time.<\/p>\n","protected":false},"author":4,"featured_media":3940,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[312],"tags":[343,344,345,347,346],"class_list":["post-3939","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web","tag-asp-net","tag-asp-net-core","tag-c","tag-legacy-modernization","tag-web-forms"],"_links":{"self":[{"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/posts\/3939","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/comments?post=3939"}],"version-history":[{"count":3,"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/posts\/3939\/revisions"}],"predecessor-version":[{"id":4117,"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/posts\/3939\/revisions\/4117"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/media\/3940"}],"wp:attachment":[{"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/media?parent=3939"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/categories?post=3939"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/inferne.com\/blog\/wp-json\/wp\/v2\/tags?post=3939"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}