Cloud migration
Azure and Microsoft 365 Cloud Migration
The input
Migrate the servers and business applications of an IT service provider with 120 employees to the cloud (Microsoft Azure and Microsoft 365): inventory, target architecture, migration in waves, backup and disaster recovery concept, training. Completion in six months.
10
Phases
58
Tasks
26
Weeks
5
Obligations
10
Risks
12
Stakeholders
Schedule
1Mobilization, Governance and NIS2 Applicability
2Discovery, Inventory and Data Classification
3GDPR, Contractual and Compliance Readiness
4Target Architecture and Azure/Microsoft 365 Foundation
5Detailed Migration Waves and Pilot Readiness
6Pilot Migration and Validation
7Migration Wave 1
8Migration Wave 2 and Final Compliance Evidence
9Backup, Disaster Recovery and Cutover Readiness
10Production Cutover, Training and Hypercare
Week
04812162024
Obligations with lead time
- Statutory2–6 weeks before go-liveExecute the GDPR Article 28 data processing agreement with Microsoft/Azure, review the subprocessor list, and document the applicable GDPR Article 44–49 third-country transfer mechanism, transfer assessment
- Guide value2–4 weeks before go-liveUpdate the GDPR Article 30 record of processing activities for Azure and Microsoft 365, including purposes, data categories, recipients, locations, retention, and security measures.
- Guide value4–8 weeks before go-liveDetermine and document whether NIS2 applies based on sector, services, employee count, turnover, and customer role. If applicable, document cloud risk management, incident handling, business continuity
- RequiredImplement GDPR Article 32 and internal security controls for the target environment, including MFA, least privilege, privileged-access management, encryption, secure configuration, vulnerability management
- Establish a documented backup, disaster-recovery, and business-continuity capability with workload-specific RTOs and RPOs, isolated backup protections, restore procedures, failover runbooks, monitoring
Biggest risks
- highIncomplete Inventory or Hidden DependenciesMitigation: The Infrastructure and Operations Lead, Application Owners, and Migration Partner will perform automated discovery and dependency workshops, reconcile results with the CMDB
- highGDPR DPA or Third-Country Transfer DelayMitigation: The DPO, Privacy Counsel, Legal, Procurement, and Vendor Management will begin negotiations and transfer assessments in Week 1, complete the required documentation by Week 8
- highNIS2 Applicability or Cloud Supply-Chain GapMitigation: The CIO, Legal Counsel, CISO, and DPO will document the sector, size, turnover, customer-service role, and NIS2 applicability decision by Week 2.
+ 7 more
Stakeholders
Executive Sponsor / Managing DirectorCIO or IT DirectorMigration Program ManagerAzure and Microsoft 365 Cloud ArchitectInfrastructure and Operations LeadApplication and Data OwnersInformation Security Lead or CISOData Protection Officer / Privacy CounselLegal, Procurement and Vendor ManagementCustomer Service and Account Owners
Budget frame
€400,000
AI estimate, broken down by line item in the plan
External Consultants and Compliance€180,000
Internal Personnel€114,000
Software, Tooling and Test Environments€45,000
Workshops and Travel€31,000