Yes you did the right thing by doing it in the Dev Environment, you will need to backup and stop all the CA services prior to the upgrade process. Point 1 is covered in this article - https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/ba-p/697674
Not sure why it started after few hours bit strange on Point 2 however without checking the logs and event viewer logs it will be difficult to analyse the issue. After upgrade also reissue the CRL to the CA and the clients so all are sync.
Please don't forget to upvote and Accept as answer if the reply is helpful