A rebuild can change a site's design, its CMS, its content and its URLs, and each of these is a separate risk. Google's guidance on site moves says to change only one thing at a time. Its example is a site that wants a new domain, a new CMS and a new layout: do them one after another rather than together. Whether that is practical is a project decision, but it shows how Google thinks about the risk.
The same page sets out what to prepare. The new site should be tested thoroughly. Robots.txt and noindex rules used while the site was in development must be reviewed and removed when the move starts, so a development block does not carry over to the live site. Content that is not being carried across should return a 404 or 410. Each new URL should have a self-referencing canonical tag, internal links should point at the new URLs, and the server needs capacity for the heavier crawling Google may do after a move.
Google suggests timing a move for a period of lower traffic if possible, so fewer people are affected by any problems. It also says a move is complete only once Googlebot has visited every old and new URL at least once, because the move happens URL by URL. Google also says to expect temporary ranking fluctuation. For medium-sized sites it can take a few weeks or more for Google to show the new URLs, and longer for larger ones.
A rebuild that must not lose organic visibility is a good fit for our work. We cover website rebuilds with a search-friendly architecture, and with redirects mapped before launch and tested after. Our article on SEO changes that need sign-off before launch is relevant here.