COBOLSTACK.COM
//BLOG    DD DSN=POSTS(THELADDE),DISP=SHR

2026-09-08 · CobolStack

The Ladder and the Map: What a 2030 Mainframe Career Looks Like, Rung by Rung and Region by Region

The skills gap moved. It is no longer a COBOL gap — the estate can't hire the bridge: AI, cloud, integration, security. A rung-by-rung reading of the COBOL-developer-to-platform-architect ladder, and a region-by-region map of who is forcing the climb.

Three weeks ago we took a Citi Vice President's argument — that the 2030 COBOL problem is a talent problem, not a technology problem — and read it as a build plan for the estate: what to preserve, whom to train, how to wrap, and why the through-line is proof. Vidyut Saha has since sharpened the same thesis in a second LinkedIn piece, with an accompanying infographic titled "MAINFRAME 2030 — Not the end. A new beginning." The question for 2030, he argues, is not "will the mainframe survive?" — it will, in banking, insurance, government, healthcare and the large enterprise — but "who will have the skills to modernize it?" And he adds two things the first article only gestured at: a career ladder (COBOL developer → modernization → +cloud/APIs → +DevSecOps/AI → enterprise-modernization or platform architect) and a map (installed estates in the US, delivery capacity in India, regulatory pressure in Europe, embedded legacy in Japan, banking and government in Australia).[1]

That is an opinion piece, and we will treat it as one. But the ladder and the map are the two dimensions the August post did not develop, and both turn out to be testable against published data. This post does that. It does not re-argue the case for verification — that is already made — it asks a narrower question: what does the skills gap actually consist of in 2026, what does each rung of Saha's ladder demand in practice, and who, region by region, is forcing people to climb it.

The gap moved

Start with the finding that reframes everything else. Kyndryl's 2025 survey of 500 senior IT and line-of-business leaders — split almost evenly across North America (26%), Latin America (25%), Asia-Pacific (24%) and Europe (25%) — asked which skills organizations cannot find for mainframe modernization. The answer is not COBOL. The top three shortage areas are AI and generative AI (42%), cloud (37%) and systems integration (33%). Legacy programming-language skills — "often presumed to be the biggest gap" in the report's own words — rank lower, cited by only 23%.[2] The single hardest mainframe skill to hire is security, at 45%.[2]

Read that against the workforce data and the shape of the problem is clear. The mainframe profession has already turned over: BMC's 20th annual survey (1,000-plus practitioners, fielded March–April 2025) found 66% identifying as millennial or Gen Z, up from 37% in 2018.[3] The platform's toolchain has already modernized around them: 67% of shops now run DevOps on the mainframe, 60% say Java is the most frequently used language on the platform, 72% report new applications being written in Java, SRE roles exist in 43% of organizations and platform engineers in 47%.[4] Yet Kyndryl still finds 70% struggling to find the right blend of skills, and the three reasons employers give are all about the bridge, not the legacy end of it: newcomers arrive without mainframe skills (46%), existing staff don't want to learn new mainframe skills (42%), and retirees take theirs with them (39%).[2] In banking specifically, a Rocket Software study of financial-services IT leaders across the US, UK, France, Germany and the Netherlands has 81% calling their mainframe skills gap very or extremely significant.[5]

So Saha is right about the direction, and the data says he is right about the composition. The 2030 shortage is not of people who can write COBOL. It is of people who can hold COBOL, JCL, CICS and DB2 in one hand and cloud, APIs, pipelines, security and AI in the other — and, as we'll get to, of people who can show a regulator that the two hands agree. That is a ladder problem: the industry has plenty of first rungs and almost no one on the top ones.

NumberWhat it measuresSource
42% · 37% · 33%top three mainframe-modernization skill shortages: AI/gen-AI, cloud, systems integrationKyndryl, 2025[2]
23%cite a lack of legacy programming-language skills — the presumed gap that isn't the biggest oneKyndryl, 2025[2]
45%say security is the hardest mainframe skill to hireKyndryl, 2025[2]
60% / 67%Java the most-used language on the platform / DevOps in use on the mainframeBMC survey, 2025[4]
43% / 47%organizations with SRE roles / with platform engineers on the mainframe (35% and 31% more planning to add them)BMC survey, 2025[4]
81%financial-services IT leaders (US, UK, FR, DE, NL) rating their mainframe skills gap very or extremely significantRocket Software / Hanover Research[5]
91%organizations anticipating hiring mainframe system administrators or application developers within 1–2 yearsIBM Mainframe Skills Council, citing the 2024 Global Mainframe Skills Report[6]

The ladder, rung by rung

Saha's ladder is five rungs. Here is each one with what a real estate demands at that level — drawn from the survey data above and from the day-to-day of running one — and, in the last column, the one capability that separates someone on that rung from someone merely titled for it. We call it the proof skill. It is the same discipline at every level, applied to a wider blast radius each time.

RungWhat Saha namesWhat the estate actually demandsThe proof skill
1COBOL developerread and change COBOL, JCL, VSAM, CICS and DB2 fluently — and do it in Git with a pipeline, because two-thirds of shops already do[4]re-run last night's job on a copy and show the output bytes are unchanged before touching anything
2Mainframe modernizationimpact analysis across programs, copybooks, jobs and data stores; business-rule extraction; capturing a behavioral baseline for code that never had teststurn "I think this rule does X" into an executable fixture that fails if X changes
3+ Cloud / APIsexpose transactions as services; Java on the platform (the most-used language in 60% of shops[4]); the systems-integration skill a third of employers can't find[2]prove the API returns what the 3270 screen returned — same packed-decimal edge cases, same error paths
4+ DevSecOps / AIpipelines that gate on evidence; security — the single hardest hire[2]; AIOps, where 65% already use generative AI on the platform[3]treat AI output as a candidate, not a result: nothing an assistant emits reaches cutover without a differential run behind it
5Enterprise modernization / platform architectportfolio decisions per application (keep, wrap, refactor, replace); workforce design; the regulatory evidence trail described in the next sectionanswer a supervisor's question — "show me this still behaves identically" — with artefacts, not assurances

Two observations on the table. First, the rungs are cumulative, not sequential replacements. A rung-5 architect who has lost the rung-1 ability to read a COMP-3 truncation is not a senior mainframer; they are a cloud architect with a legacy vocabulary, and Kyndryl's employers already have plenty of those.[2] Second — and this is where we would extend Saha's framing — the proof column is not a sixth skill bolted on at the top. It is the thing the other four are for. Every rung raises the cost of being wrong, and the industry's own answer to "how do we let AI and cloud near the core?" has been, uniformly, evidence.[2] The person who can generate that evidence at estate scale is the 2030 winning profile Saha describes — deep legacy knowledge, modern engineering, business-domain understanding — with the missing verb supplied: proves.

The same job, five questions Hand five people the same nightly settlement job. The rung-1 engineer asks "what does this step do?" The rung-2 engineer asks "what would break downstream if I changed it?" Rung 3 asks "which of these outputs should be a service?" Rung 4 asks "what in the pipeline stops a bad change reaching Friday's run?" And the architect asks "which of these five answers can I put in front of the regulator?" The ladder is not five job titles. It is one job, seen from five altitudes — and the climb is measured by how much of the estate you can vouch for.

How the climb actually happens

Employers already know what they are doing about it, and the mix is instructive. Kyndryl's respondents rank upskilling existing staff first (44%), automating processes to reduce dependency on specific skills second (40%), hiring third (36%) and leaning on AI fourth (35%) — and three-quarters (74%) bring in external providers regardless.[2] On the supply side, IBM's Mainframe Skills Council — clients, partners, academia, user groups and open communities — is building role-based competency frameworks and learning paths, and reports that 60% of surveyed organizations already work with vendors offering bootcamps, training or apprenticeships.[6]

Notice the shape of that list. "Upskill" is the rung-1-to-rung-2 move; "automate away the dependency" and "lean on AI" are rung-4 moves being made by organizations that mostly do not yet have rung-4 people; and "external provider" is how an estate rents rungs it cannot grow. The climb, in other words, is being attempted from both ends simultaneously — and the middle rungs, where the legacy knowledge and the modern engineering have to fuse inside one person, are the thin part. That is why the BMC data matters: the generation now running these systems is not the one that built them,[3] so the fusion has to be manufactured, on purpose, with hours on a system where mistakes have consequences. We build those systems and that curriculum — the courses are laid out rung by rung on purpose — but the point here is structural, not commercial: nobody climbs from rung 2 to rung 4 on slides.

The map: who is forcing the climb, region by region

Saha's geography is a talent-market observation — where the estates are, where the delivery capacity sits, where the regulation bites. We would put it more sharply. In every region on his map, the institution forcing people up the ladder is not the CIO. It is the supervisor. Between 2021 and 2025, regulators on four continents converted "can you change this system safely and show us?" from good practice into an obligation with a date on it — and an obligation to demonstrate operational resilience is, in disguise, a demand for rung-4 and rung-5 skills.

RegionSaha's characterizationThe published fact that makes it a skills demand
United Statesthe largest installed estatesGAO flagged ten critical federal legacy systems in 2019; as of February 2025 three had been modernized. The eleven systems in its 2025 review are 23 to 60 years old, and both Treasury systems reviewed run on COBOL and Assembler — languages GAO describes as having "a dwindling number of people available with the skills needed to support them."[7]
European Unionregulatory pressureDORA entered into force 16 January 2023 and applies from 17 January 2025 to 21 categories of financial entity, with mandatory ICT risk-management frameworks, third-party risk provisions and an operational-resilience testing programme including advanced testing.[8] Kyndryl's 2025 report names DORA specifically as a regulation shaping modernization strategy.[2]
United Kingdom(Europe, non-EU)Firms in scope of the FCA's operational-resilience rules (PS21/3) had until 31 March 2025 to show they can operate every important business service within its impact tolerance under severe disruption.[9]
Japandeeply embedded legacyMETI's 2018 DX Report coined the "2025 Digital Cliff": annual economic losses of up to ¥12 trillion after 2025 if complex, outdated, black-boxed systems remain in place.[10] The cliff has a face: after eight system failures between February and September 2021, the FSA issued Mizuho Bank and Mizuho Financial Group business-improvement orders, citing disregard for system risk and governance failures that had also featured in its 2002 and 2011 outages.[11] In May 2025 METI's Legacy Systems Modernization Committee published its report on eliminating legacy systems.[12]
Australiabanking and governmentAPRA's CPS 230 has been in force since 1 July 2025 for every APRA-regulated bank, insurer and superannuation trustee: identify critical operations, set tolerance levels for their disruption, stay within them through severe disruption, and manage service-provider risk — with notification duties for tolerance breaches.[13]
Indiadelivery capacityThe region shows up in the data from the other side of the contract: 74% of organizations use external providers for modernization,[2] and Kyndryl's report lists India's 2023 Digital Personal Data Protection Act alongside DORA among the regulations shaping mainframe plans.[2] That Indian delivery teams do the rung-2 and rung-3 work for estates on four continents is Saha's observation, not a survey figure — we note it as such.[1]

Look at what the regulators are actually asking for. "Operate within impact tolerance under severe disruption." "A testing programme including advanced testing." "Identify critical operations and demonstrate you can keep them running." None of these can be satisfied by a rung-1 skill set, however deep — the COBOL is not the problem. Nor can they be satisfied by a rung-3 cloud engineer who cannot read the batch chain the critical operation depends on. They are satisfied by someone who can map a critical operation to the jobs, programs and datasets that implement it, rehearse its failure and recovery, and produce the evidence — which is the ladder's upper half, described in prudential-standard language. The map and the ladder are the same picture.

A supervisor's question is a rung-5 question "Show us that after the change, the important business service still behaves within tolerance" is, operationally, "show us the new behaves like the old, under load, on the bad days." Every region on Saha's map now asks it in its own dialect. The 2030 winning profile is whoever can answer it in all of them — which is why we think the geography of talent will matter less than the geography of evidence: a fixture that proves a settlement run is unchanged is admissible in Frankfurt, Sydney, Tokyo and Washington alike.

What a distributed talent model actually requires

If the estates are in one set of countries and much of the delivery capacity in another — Saha's map, and the 74% external-provider figure agrees with him[2] — then the talent model is distributed whether anyone designed it or not. Three things follow, and none of them is a hiring policy.

The tooling for all three — environments, rung-mapped courses, the Seam analyzer for the evidence — is what we sell, and we will leave it at that. The argument stands without the catalog.

Rise, transform, reposition

Saha closes on three verbs — rise, transform, reposition — and the line that "the mainframe isn't the technology story of the past — it could be one of the most interesting talent stories of the next four years."[1] We would give the verbs owners. Rise is the individual's: the ladder exists, the middle rungs are empty, and the data says employers will pay for anyone who fuses the two halves.[2] Transform is the estate's: it has already happened underneath — Java, DevOps, SRE, generative AI on the platform[3][4] — and the workforce has to catch up to its own tooling. Reposition is the market's, and it has been done by the regulators: on four continents the mainframe is no longer the system you must keep running but the system you must prove you can keep running. That is a career story, and a better one than "COBOL programmers wanted." It is just not a story about COBOL.

On LinkedIn

This post responds to Vidyut Saha's LinkedIn piece on the 2030 mainframe talent model and its accompanying "MAINFRAME 2030 — Not the end. A new beginning." infographic — an opinion piece by a practitioner, which is how we have cited it: for its framing, never for a figure. Our earlier response to his first article, with the estate-level plan this post builds on, is here.

Sources

  1. Vidyut Saha (Vice President, Enterprise Platforms — Mainframe & Distributed Systems, Citi) — LinkedIn op-ed on the 2030 mainframe talent model, with the "MAINFRAME 2030 — Not the end. A new beginning." infographic, 2026. Opinion, not a statistical source; cited for its framing only.
  2. Kyndryl — 2025 State of Mainframe Modernization Survey Report (500 leaders; NA 26% / LatAm 25% / APAC 24% / Europe 25%; skills-shortage composition 42/37/33/23%; security 45%; workforce challenges 46/42/39%; talent strategies 44/40/36/35%; 74% external providers; DORA and India DPDP cited as drivers)
  3. BMC — 20th Annual BMC Mainframe Survey (66% millennial/Gen Z vs 37% in 2018; 65% using generative AI with the mainframe; 1,000+ respondents, fielded 31 March–15 April 2025), September 2025
  4. BMC — DevOps Insights From the 2025 BMC Mainframe Survey (67% DevOps on the mainframe; Java most-used language for 60%; 72% new apps in Java; SRE 43% + 35% planning; platform engineers 47% + 31% planning)
  5. Rocket Software — Mainframe AI Study, conducted by Hanover Research (81% of banking/financial-services IT leaders in the US, UK, France, Germany and the Netherlands rate their mainframe skills gap very or extremely significant), 2026
  6. IBM — Mainframe Skills Council brings the global community together to grow mainframe talent (91% anticipate hiring mainframe sysadmins/developers in 1–2 years; 60% work with vendors on bootcamps/training/apprenticeships; role-based competency frameworks), citing the 2024 Global Mainframe Skills Report
  7. U.S. GAO — GAO-25-107795, Information Technology: Agencies Need to Plan for Modernizing Critical Decades-Old Legacy Systems (3 of 10 modernizations complete as of February 2025; systems 23–60 years old; Treasury COBOL/Assembler skills), 17 July 2025
  8. ESMA — Digital Operational Resilience Act (DORA): in force 16 January 2023, applies from 17 January 2025; ICT risk management, third-party risk, operational-resilience testing programme
  9. FCA — Operational resilience (PS21/3): firms had until 31 March 2025 to operate important business services within impact tolerances
  10. Tokyo Foundation — Osamu Sudoh, Current Status of Japan's DX/GX Policies (quoting METI's 2018 DX Report: the "2025 Digital Cliff", annual losses of up to ¥12 trillion after 2025), 25 March 2024
  11. Japan Financial Services Agency — Administrative Actions against Mizuho Bank, Ltd. and Mizuho Financial Group, Inc. (business improvement orders after eight system failures February–September 2021; prior failures 2002 and 2011), 26 November 2021
  12. METI — Comprehensive Report Compiled by the Legacy Systems Modernization Committee to Eliminate Legacy Systems, 28 May 2025
  13. APRA — Prudential Standard CPS 230 Operational Risk Management (in force 1 July 2025; critical operations, tolerance levels, service-provider management, all APRA-regulated entities)

External figures are as published by their sources at the dates shown. The career-ladder reading and the regional mapping are ours; where a claim rests on Mr Saha's opinion rather than a published number, the text says so.