There is no article at the moment for migrating from the DAG to Duo SSO but within the next few weeks we will be adding documentation that talks about this more and a way to easily copy settings of a DAG application in the Duo Admin Panel to a new Duo SSO application in the Duo Admin Panel.
One of the biggest benefits of Duo SSO is it no longer requires you to host a web server yourself. Duo does this part for you. If you’re using a SAML IdP as your authentication source you won’t need any additional on-premises hardware. If you use Active Directory, instead of a DAG you’ll connect an Authentication Proxy to talk to Duo SSO. This Authentication Proxy only needs outbound access and doesn’t require any inbound ports to be opened.
Like @Jason_Waits mentioned, switching over your SAML apps requires updating identity provider information on the application’s side as well which is why you’ll need to move one application at a time.