Project plan for a cloud migration
A cloud migration is more than moving servers: data processing agreements, third-country transfers, NIS2 supply chain security and a disaster recovery concept must be in place before the first application moves. This plan shows the migration of an IT service provider with 120 employees to Microsoft Azure and Microsoft 365.
No sign-up · opens instantly · 26 Weeks · 10 Phases · 54 Tasks · Budget approx. €817,500
This is how the plan looks in PathHub — click through the tabs or tick off tasks.
Azure and Microsoft 365 Cloud Migration
This project will migrate the IT service provider’s servers, business applications, and selected collaboration services to Microsoft Azure and Microsoft 365 within six months. It covers workload discovery, target architecture, cloud-platform implementation, wave-based migration, backup and disaster recovery, operational transition, and training. GDPR requirements—including the provider DPA, transfer safeguards, ROPA updates, and DPIA screening—will be addressed before real personal data is migrated. NIS2 applicability and associated cloud risk-management and supply-chain evidence will also be assessed and documented.
Phases
Phase 1: Mobilization, Governance and Scope Baseline
Establish governance, decision rights, workstreams, success criteria, and the six-month delivery baseline. The phase also establishes compliance gates, including the prohibition on migrating real data before the required contractual and privacy conditions are fulfilled.
Phase 2: Discovery, Inventory and Dependency Mapping
Build a validated inventory of the current environment and identify the technical, business, identity, data, and operational dependencies that will determine the migration sequence.
Phase 3: Data Protection, NIS2 and Security Assessment
Determine the privacy, regulatory, contractual, and security conditions for the cloud migration early enough to influence the target design. Begin the required contractual work and establish the evidence needed for the later go-live gates.
Phase 4: Target Architecture, Landing Zone and Migration Design
Design and approve the Azure and Microsoft 365 target environment, migration waves, identity model, security controls, and operational architecture. The NIS2 cloud risk-management and supply-chain evidence is completed by Week 9, eight weeks before the first production go-live in Week 17.
Phase 5: Platform Build, Contractual Compliance and Readiness Gate
Build the cloud foundation and complete the statutory and privacy prerequisites before any production data migration. The Art. 28 DPA and third-country transfer safeguards are completed by Week 11, and the ROPA update and DPIA decision or assessment are completed by Week 13.
Phase 6: Pilot and Migration Factory Validation
Validate the migration factory, security controls, monitoring, backup, restore, support procedures, and rollback approach using non-production, synthetic, or otherwise approved test data before the first production migration.
Phase 7: Production Migration Wave 1
Migrate the first low-risk production workloads and selected Microsoft 365 services using the validated factory. This is the first production go-live and is executed only after all contractual, privacy, security, and operational gates have passed.
Phase 8: Production Migration Wave 2
Migrate the remaining business applications and higher-criticality workloads in controlled waves. Each cutover requires validated dependencies, business acceptance, rollback capability, and operational support coverage.
Phase 9: Resilience Validation, Training and Operational Acceptance
Prove that the migrated environment can be operated, secured, backed up, restored, and recovered within agreed objectives. Complete role-based training and obtain formal operational acceptance before final legacy transition.
Phase 10: Final Cutover, Hypercare and Handover
Complete the final cutover and legacy transition, stabilize the environment under hypercare, close critical defects, and transfer ownership to the support organization with complete operational and compliance evidence.
Timeline
Budget
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Infrastructure discovery, inventory and dependency mapping specialist | 25 Person days | €1,050 | €26,250 |
| Azure target architecture and landing-zone consultant | 70 Person days | €1,100 | €77,000 |
| Migration engineering and production wave execution team | 95 Person days | €950 | €90,250 |
| Microsoft 365 tenant, Exchange, SharePoint and Teams migration specialist | 35 Person days | €950 | €33,250 |
| GDPR Art. 28 DPA negotiation, subprocessor and third-country transfer assessment; pre-production compliance gate before real-data migration | 15 Person days | €1,150 | €17,250 |
| ROPA update and DPIA screening or assessment for cloud processing; completion before Wave 1 readiness approval | 12 Person days | €1,050 | €12,600 |
| NIS2 applicability review and cloud supply-chain risk-management evidence pack; completion during Phases 3-4 | 12 Person days | €1,100 | €13,200 |
| Backup, disaster recovery testing and operational assurance specialist | 15 Person days | €950 | €14,250 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Azure compute, storage, networking and monitoring consumption | 12 Person days | €9,500 | €114,000 |
| Microsoft 365 licensing and security services for 120 employees | 12 Person days | €4,000 | €48,000 |
| Azure Backup, Recovery Services vaults and disaster recovery replication | 12 Person days | €3,000 | €36,000 |
| Migration, discovery, data-transfer and validation tooling | 6 Person days | €5,000 | €30,000 |
| Non-production sandbox and temporary parallel-operation capacity | 6 Person days | €3,750 | €22,500 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Executive Sponsor and Steering Committee support | 12 Person days | €900 | €10,800 |
| Internal Program Manager and PMO | 60 Person days | €850 | €51,000 |
| Cloud and Infrastructure Lead / IAM Owner | 90 Person days | €725 | €65,250 |
| Application and Business Process Owners | 80 Person days | €650 | €52,000 |
| DPO, Legal and Procurement coordination | 30 Person days | €750 | €22,500 |
| Operations, Service Desk, Business Continuity and FinOps backfill | 60 Person days | €625 | €37,500 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Azure and Microsoft 365 administrator and engineer training | 10 Person days | €900 | €9,000 |
| Service desk and IT operations training | 8 Person days | €800 | €6,400 |
| User adoption, communications and key-user enablement | 20 Person days | €750 | €15,000 |
| Operational runbooks, cutover rehearsal and support handover preparation | 15 Person days | €900 | €13,500 |
Risks
Incomplete Inventory and Hidden Dependencies
If the inventory does not identify undocumented interfaces, scheduled jobs, service accounts, data stores, or customer-facing workloads by the end of Week 4, migration waves may fail or cause unexpected service outages.
Data Loss or Extended Cutover Downtime
If replication, data reconciliation, rollback, or cutover tests fail during Weeks 14–16, production migration in Week 17 or later waves could cause data loss, prolonged downtime, or customer service disruption.
GDPR DPA or Third-Country Transfer Delay
If the cloud-provider data processing agreement, subprocessor review, or third-country transfer safeguards remain unresolved by Week 11, personal or customer data cannot legally be migrated or processed in the cloud.
Unacceptable Privacy Risks Identified by the ROPA or DPIA
If the updated record of processing activities or DPIA assessment identifies high-risk processing, excessive provider access, sensitive data exposure, or inadequate safeguards by Week 13, the target design or go-live date may need to change.
NIS2 Applicability or Cloud Supply-Chain Evidence Is Incomplete
If NIS2 applicability is not determined by Week 7, or cloud risk-management and supplier-security evidence is incomplete by Week 9, the organization may face regulatory and audit exposure if it falls within NIS2 scope.
Identity, Access and Microsoft 365 Coexistence Failure
If Entra ID synchronization, privileged access, conditional access, domain configuration, or application authentication fails during the pilot in Weeks 14–16, users or administrators may be locked out or unauthorized access may occur during production cutover.
Backup or Disaster Recovery Controls Fail Testing
If backups cannot be restored, are not sufficiently isolated from ransomware, or fail agreed RTO/RPO tests during Weeks 14–24, the organization may be unable to recover critical customer and business services after an outage or security incident.
Application Performance or Compatibility Degradation
If legacy applications experience latency, unsupported dependencies, licensing problems, or storage and network incompatibilities during the pilot or Wave 1, business processes and customer services may perform below acceptable levels.
Cloud Consumption and Licensing Exceed the Approved Budget
If Azure resources are oversized, duplicate environments remain active, Microsoft 365 licensing is misaligned, or consumption controls are not operational by Week 17, first-year costs may exceed the EUR 900,000 program budget.
Insufficient Skills, Training and Operational Adoption
If administrators, service desk staff, and key users are not trained or runbooks are incomplete by Week 24, incident resolution may slow, operational errors may increase, and security controls may be bypassed after handover.
Stakeholders
Executive Sponsor and Steering Committee
Own funding, approve scope changes, accept material risks, and resolve escalated cross-functional decisions.
CIO or IT Director
Accountable for the target operating model, business continuity, final go-live approval, and project closure.
Head of Cloud and Infrastructure
Owns Azure landing-zone design, network topology, technical standards, workload placement, and migration sequencing.
Application and Business Process Owners
Validate application criticality, dependencies, data quality, downtime windows, test results, and business acceptance.
Security, IAM and ISMS Manager
Defines identity, privileged access, encryption, logging, vulnerability management, and security acceptance criteria.
Data Protection Officer and Legal Counsel
Review the GDPR Art. 28 DPA, subprocessors, data residency, transfer safeguards, ROPA updates, and DPIA requirements.
NIS2, Risk and Compliance Manager
Determines NIS2 applicability and maintains cloud risk-management, supply-chain security, and audit evidence.
IT Operations, Service Desk and Business Continuity Manager
Defines monitoring, incident handling, backup, recovery, RTO/RPO, support procedures, and operational acceptance.
Finance, Procurement and FinOps Owner
Controls licensing, cloud contracts, consumption budgets, supplier due diligence, and cost optimization.
HR, Learning and Development, and Key User Representatives
Coordinate administrator training, user communications, adoption support, and role-specific process changes.
Microsoft/Azure Migration Partner and Microsoft Account Team
Provide specialist architecture, migration engineering, licensing guidance, platform evidence, and escalation support.
Compliance
Execute a GDPR Art. 28 data processing agreement with the cloud provider, including processing instructions, confidentiality, security, audit rights, deletion/return provisions, and approved subprocessors. The signed agreement must be in place before any real personal or customer data is migrated.
Assess third-country access and transfers under GDPR Arts. 44 ff., including provider support access, subprocessor locations, transfer-impact assessments, SCCs or other valid safeguards, and supplementary technical measures.
Update the record of processing activities under GDPR Art. 30 for Azure, Microsoft 365, identity services, backups, monitoring, support access, subprocessors, retention, and international transfers.
Screen processing under GDPR Art. 35 and complete a DPIA where the migration creates likely high-risk processing, extensive monitoring, sensitive-data processing, or significant provider access; document the decision and remediate identified risks.
Determine whether NIS2 applies based on sector, size, turnover, and service role. If applicable, document cloud risk management, supplier and supply-chain security, incident handling, business continuity, access control, and supporting evidence.
Implement GDPR Art. 32 security measures, including least privilege, privileged-access management, encryption, secure configuration, logging, vulnerability management, monitoring, incident response, and appropriate backup protection.
Review customer contracts, confidentiality obligations, data-residency commitments, customer notification duties, subprocessor approvals, service levels, and any restrictions on hosting or support access before workloads are assigned to Azure or Microsoft 365.
Define and document backup, disaster recovery, retention, restoration, and business-continuity controls against customer commitments and internal policy; test restoration, regional recovery, and ransomware scenarios and retain evidence.
Milestones
- Week 1
Approved project charter, scope baseline, governance model, six-month delivery plan, and compliance gate register.
Depends on: Executive sponsorship, named workstream owners, and confirmed decision rights - Week 4
Validated inventory and dependency catalogue with application criticality, data classification, ownership, and preliminary migration disposition for every in-scope workload.
Depends on: Approved scope baseline and access to discovery sources and application owners - Week 7
Approved privacy and regulatory assessment baseline, active DPA and transfer review, documented DPIA screening, NIS2 applicability decision, and prioritized security-gap register.
Depends on: Validated workload, data-processing, supplier, and dependency information - Week 10
Approved target architecture, landing-zone design, identity and Microsoft 365 design, migration-wave plan, and NIS2 evidence pack completed by Week 9 where applicable.
Depends on: Discovery baseline, security-gap register, and regulatory assessment - Week 13
Azure and Microsoft 365 foundation operational; signed DPA and documented transfer safeguards; updated ROPA; completed DPIA or documented decision; formal approval to begin controlled testing.
Depends on: Approved target design, provider contracting, compliance decisions, and platform access - Week 16
Successful non-production pilot, tested migration and rollback runbooks, validated backup and restore evidence, and signed Wave 1 go-live decision.
Depends on: Operational cloud foundation and formal testing-readiness approval - Week 19
Wave 1 production workloads operational from Week 17, with documented business acceptance, no unresolved critical defects, and updated migration procedures.
Depends on: Signed Wave 1 go-live decision and completed production readiness checks - Week 22
All approved Wave 2 workloads migrated or formally excepted, with documented business acceptance and no unresolved critical migration blockers.
Depends on: Wave 1 lessons incorporated and Wave 2 workload readiness confirmed - Week 24
Documented restore and DR test results meeting agreed objectives, completed training records, operational runbooks approved, and formal operational acceptance granted.
Depends on: Production migrations completed and operations, service desk, and users available for validation - Week 26
Final cutover completed, legacy transition decision recorded, critical defects closed or accepted, operational ownership transferred, and project closure approved by Week 26.
Depends on: Operational acceptance, final cutover authorization, and agreed legacy disposition
How this plan was created
This plan was created by PathHub AI from a single description: “Migrate the servers and business applications of an IT service provider with 120 employees to the cloud (Microsoft Azure and Microsoft 365): inventory, target architecture, migration in waves, backup and disaster recovery concept, training. Completion in six months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.
Obligations with lead time: what many think of too late
These obligations are typically triggered by a cloud migration (example: Germany). PathHub AI schedules them with lead time, warns when the schedule is too tight and shows the rule with its criteria under “Rule & evidence”, which you tick off and back with evidence. Not legal advice.
Rule & evidence
Why: With the migration, the provider processes your personal data.
Legal basis: GDPR Art. 28: contract before processing starts, including before migrating real data; for providers outside the EU also secure third-country transfers (Art. 44 ff.).
- Data Processing Agreement (DPA) with cloud provider
- SLA with availability, RPO, RTO
- Exit and portability clause
- Data localisation and transfer mechanism (SCC / adequacy)
If breached: Civil claims for data loss; recourse depends on contract. GDPR fines for non-compliance.
Rule & evidence
Why: Storage locations, sub-processors and access paths change.
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: NIS2 requires risks from service providers to be assessed and contractually covered.
Applies: if the company falls under NIS2 (e.g. from 50 employees or EUR 10m turnover in covered sectors)
- Documented IT risk management reviewed annually
- Business continuity plan and disaster recovery tested
- Multi-factor authentication (MFA) for critical systems
- Encryption of all sensitive data (at rest + in transit)
- Supplier security reviews (supply chain security)
- Annual cybersecurity training for all employees
If breached: Fines up to €10 million or 2% of global annual revenue. Personal liability of management for gross negligence.
Rule & evidence
Why: Services such as Microsoft 365 record employees' usage data.
Applies: only if a works council exists
Legal basis: Sec. 87(1) No. 6 BetrVG: cloud services with logs and analytics are suitable for monitoring performance or behaviour.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Frequently asked questions
More project plan examples
Adapt this plan to your company
Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.
Open plan →