Create a new DAG of the new version servers only.
Apply the certificates to the new servers with the correct subject names.
Set the autodiscover settings on the new servers to the valid URLs and SCP.
Recreate and custom receive connectors on the new servers
Add the new servers to any send connectors
Ensure you can send mail from the new servers to the internet and to other internal mailboxes with a test mailbox.
Then move the existing mailboxes to the new servers.
Once all moves are complete and things are working, remove the mailbox servers from the old DAG, remove Exchange from the servers, delete the old DAG and you are done.