The article you find out is the best one for Migrating The Active Directory Certificate Service, just follow it.
About your questions:
1. Do I simply bring that server down and configure a new subordinate after backing up and restoring CER-01?
Yes, you do.
2. Is there anything that I need to save or backup from CER-03?
No, by default, Network Device Enrollment Service obtains its service certificates based on the CEP Encryption and Enrollment Agent (Offline) certificate templates. These templates do not allow the export of private keys by default, so you will be unable
to back up the certificate with its private key by default. If you have a need to recover NDES, you can reinstall the service or install NDES on another computer.
3. Are there any other tips/tricks to doing any of this?
No, the article has told enough.
A older one, same content but you could check the comments below, they are meaningful.
https://blogs.technet.microsoft.com/canitpro/2014/11/11/step-by-step-migrating-the-active-directory-certificate-service-from-windows-server-2003-to-2012-r2/
Regards
Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact
tnmff@microsoft.com.