Features Pricing Our AI AI Project Plan Generator
Industries Internal projects Use Cases Case Studies
Blog Knowledge library Comparisons PM Templates Free Tools Integrations AI Project Management API & Developers
Login Get started free
Example project plan

Project plan for a cloud migration

A cloud migration is more than moving servers: data processing agreements, third-country transfers, NIS2 supply chain security and a disaster recovery concept must be in place before the first application moves. This plan shows the migration of an IT service provider with 120 employees to Microsoft Azure and Microsoft 365.

No sign-up · opens instantly · 26 Weeks · 10 Phases · 54 Tasks · Budget approx. €817,500

This is how the plan looks in PathHub — click through the tabs or tick off tasks.

app.pathhub.ai/try?example=cloud-enOpen live
Example plan

Azure and Microsoft 365 Cloud Migration

This project will migrate the IT service provider’s servers, business applications, and selected collaboration services to Microsoft Azure and Microsoft 365 within six months. It covers workload discovery, target architecture, cloud-platform implementation, wave-based migration, backup and disaster recovery, operational transition, and training. GDPR requirements—including the provider DPA, transfer safeguards, ROPA updates, and DPIA screening—will be addressed before real personal data is migrated. NIS2 applicability and associated cloud risk-management and supply-chain evidence will also be assessed and documented.

Total Progress0%
26Weeks
0/10Phases
0/54Tasks
€817,500Budget
AI Recommendations KIAI Chat KIAI Tools KI

Phases

1

Phase 1: Mobilization, Governance and Scope Baseline

Pending · 1W · 0/3
CIO or IT Director
0

Establish governance, decision rights, workstreams, success criteria, and the six-month delivery baseline. The phase also establishes compliance gates, including the prohibition on migrating real data before the required contractual and privacy conditions are fulfilled.

Timeline

Timeline 10 PhasesStart: Oct 6, 2026
Phase / Task
Oct 2026
Nov 2026
Dec 2026
Jan 2027
Feb 2027
Mar 2027
W 1Oct 6
W 4Oct 27
W 7Nov 17
W 10Dec 8
W 13Dec 29
W 16Jan 19
W 19Feb 9
W 22Mar 2
W 25Mar 23
Mobilization, Governance and Scope BaselineOct 6 – Oct 12 · 1 wk · 0/3
Mobilization, Governance and Scope Baseline
Discovery, Inventory and Dependency MappingOct 13 – Nov 2 · 3 wk · 0/6
Discovery, Inventory and Dependency Mapping
Data Protection, NIS2 and Security AssessmentNov 3 – Nov 23 · 3 wk · 0/6
Data Protection, NIS2 and Security Assessment
Target Architecture, Landing Zone and Migration DesignNov 24 – Dec 14 · 3 wk · 0/7
Target Architecture, Landing Zone and Migration Design
Platform Build, Contractual Compliance and Readiness GateDec 15 – Jan 4 · 3 wk · 0/6
Platform Build, Contractual Compliance and Readiness Gate
Pilot and Migration Factory ValidationJan 5 – Jan 25 · 3 wk · 0/6
Pilot and Migration Factory Validation
Production Migration Wave 1Jan 26 – Feb 15 · 3 wk · 0/5
Production Migration Wave 1
Production Migration Wave 2Feb 16 – Mar 8 · 3 wk · 0/5
Production Migration Wave 2
Resilience Validation, Training and Operational AcceptanceMar 9 – Mar 22 · 2 wk · 0/5
Resilience Validation, Training and Operational Acceptance
Final Cutover, Hypercare and HandoverMar 23 – Apr 5 · 2 wk · 0/5
Final Cutover, Hypercare and Handover
PlannedIn progressCompletedBlockedMilestones

Budget

Budget: €817,500
External Consulting and Migration Delivery · €284,050Software, Cloud and Migration Infrastructure · €250,500Internal Personnel and Business Backfill · €239,050Training, Change Management and Operational Transition · €43,900
External Consulting and Migration Delivery€284,050
ItemQtyUnit priceTotal
Infrastructure discovery, inventory and dependency mapping specialist25 Person days€1,050€26,250
Azure target architecture and landing-zone consultant70 Person days€1,100€77,000
Migration engineering and production wave execution team95 Person days€950€90,250
Microsoft 365 tenant, Exchange, SharePoint and Teams migration specialist35 Person days€950€33,250
GDPR Art. 28 DPA negotiation, subprocessor and third-country transfer assessment; pre-production compliance gate before real-data migration15 Person days€1,150€17,250
ROPA update and DPIA screening or assessment for cloud processing; completion before Wave 1 readiness approval12 Person days€1,050€12,600
NIS2 applicability review and cloud supply-chain risk-management evidence pack; completion during Phases 3-412 Person days€1,100€13,200
Backup, disaster recovery testing and operational assurance specialist15 Person days€950€14,250
Software, Cloud and Migration Infrastructure€250,500
ItemQtyUnit priceTotal
Azure compute, storage, networking and monitoring consumption12 Person days€9,500€114,000
Microsoft 365 licensing and security services for 120 employees12 Person days€4,000€48,000
Azure Backup, Recovery Services vaults and disaster recovery replication12 Person days€3,000€36,000
Migration, discovery, data-transfer and validation tooling6 Person days€5,000€30,000
Non-production sandbox and temporary parallel-operation capacity6 Person days€3,750€22,500
Internal Personnel and Business Backfill€239,050
ItemQtyUnit priceTotal
Executive Sponsor and Steering Committee support12 Person days€900€10,800
Internal Program Manager and PMO60 Person days€850€51,000
Cloud and Infrastructure Lead / IAM Owner90 Person days€725€65,250
Application and Business Process Owners80 Person days€650€52,000
DPO, Legal and Procurement coordination30 Person days€750€22,500
Operations, Service Desk, Business Continuity and FinOps backfill60 Person days€625€37,500
Training, Change Management and Operational Transition€43,900
ItemQtyUnit priceTotal
Azure and Microsoft 365 administrator and engineer training10 Person days€900€9,000
Service desk and IT operations training8 Person days€800€6,400
User adoption, communications and key-user enablement20 Person days€750€15,000
Operational runbooks, cutover rehearsal and support handover preparation15 Person days€900€13,500

Risks

High

Incomplete Inventory and Hidden Dependencies

If the inventory does not identify undocumented interfaces, scheduled jobs, service accounts, data stores, or customer-facing workloads by the end of Week 4, migration waves may fail or cause unexpected service outages.

Countermeasure: The Head of Cloud and Infrastructure will require application-owner validation, automated discovery, dependency mapping, and formal inventory sign-off for every in-scope workload by the end of Week 4.
High

Data Loss or Extended Cutover Downtime

If replication, data reconciliation, rollback, or cutover tests fail during Weeks 14–16, production migration in Week 17 or later waves could cause data loss, prolonged downtime, or customer service disruption.

Countermeasure: The Migration Lead, application owners, and IT Operations will complete rehearsed cutover and rollback procedures, business acceptance testing, and go/no-go reviews before each production wave; any workload without a tested rollback plan will be deferred.
High

GDPR DPA or Third-Country Transfer Delay

If the cloud-provider data processing agreement, subprocessor review, or third-country transfer safeguards remain unresolved by Week 11, personal or customer data cannot legally be migrated or processed in the cloud.

Countermeasure: The DPO and Legal Counsel will complete the Art. 28 DPA, subprocessor assessment, data-location review, and transfer-impact assessment by Week 11; the CIO will prohibit real-data migration until the contractual and transfer requirements are approved.
High

Unacceptable Privacy Risks Identified by the ROPA or DPIA

If the updated record of processing activities or DPIA assessment identifies high-risk processing, excessive provider access, sensitive data exposure, or inadequate safeguards by Week 13, the target design or go-live date may need to change.

Countermeasure: The DPO, Legal Counsel, Security Manager, and business owners will update the ROPA and complete DPIA screening by Week 13, with remediation actions, residual-risk acceptance, or design changes approved before Wave 1.
High

NIS2 Applicability or Cloud Supply-Chain Evidence Is Incomplete

If NIS2 applicability is not determined by Week 7, or cloud risk-management and supplier-security evidence is incomplete by Week 9, the organization may face regulatory and audit exposure if it falls within NIS2 scope.

Countermeasure: The NIS2, Risk and Compliance Manager will document the applicability decision by Week 7 and complete the cloud risk assessment, supplier due diligence, incident requirements, and evidence pack by Week 9, with Steering Committee approval for any residual gaps.
High

Identity, Access and Microsoft 365 Coexistence Failure

If Entra ID synchronization, privileged access, conditional access, domain configuration, or application authentication fails during the pilot in Weeks 14–16, users or administrators may be locked out or unauthorized access may occur during production cutover.

Countermeasure: The IAM and Security Manager will implement tested break-glass accounts, least-privilege roles, staged synchronization, access reviews, and rollback procedures by Week 15; IT Operations will complete user and administrator acceptance testing before the Week 16 go-live decision.
High

Backup or Disaster Recovery Controls Fail Testing

If backups cannot be restored, are not sufficiently isolated from ransomware, or fail agreed RTO/RPO tests during Weeks 14–24, the organization may be unable to recover critical customer and business services after an outage or security incident.

Countermeasure: The Business Continuity Manager and IT Operations will define workload-specific RTO/RPO targets by Week 10, configure protected backups and replication by Week 16, and complete documented restore, regional-failure, and ransomware recovery tests by Week 24.
Medium

Application Performance or Compatibility Degradation

If legacy applications experience latency, unsupported dependencies, licensing problems, or storage and network incompatibilities during the pilot or Wave 1, business processes and customer services may perform below acceptable levels.

Countermeasure: Application owners and the Migration Engineering Lead will conduct compatibility, load, interface, and latency testing during Weeks 14–16, remediate high-impact defects before production, and obtain documented business acceptance for each workload.
Medium

Cloud Consumption and Licensing Exceed the Approved Budget

If Azure resources are oversized, duplicate environments remain active, Microsoft 365 licensing is misaligned, or consumption controls are not operational by Week 17, first-year costs may exceed the EUR 900,000 program budget.

Countermeasure: The FinOps Owner and Finance will establish budgets, tagging, alerts, reservations or savings plans, license reconciliation, and monthly chargeback reporting by Week 13; the Steering Committee will approve any forecast variance above the agreed tolerance.
Medium

Insufficient Skills, Training and Operational Adoption

If administrators, service desk staff, and key users are not trained or runbooks are incomplete by Week 24, incident resolution may slow, operational errors may increase, and security controls may be bypassed after handover.

Countermeasure: IT Operations, HR/Learning and Development, and the Service Desk Manager will deliver role-based training, support scripts, escalation procedures, and approved runbooks by Week 24; operational acceptance will require completed training records and service-desk readiness.

Stakeholders

ES

Executive Sponsor and Steering Committee

Own funding, approve scope changes, accept material risks, and resolve escalated cross-functional decisions.

Involve: From Phase 1 and at every governance or go-live gate
CO

CIO or IT Director

Accountable for the target operating model, business continuity, final go-live approval, and project closure.

Involve: From Phase 1 through final handover
HO

Head of Cloud and Infrastructure

Owns Azure landing-zone design, network topology, technical standards, workload placement, and migration sequencing.

Involve: From Phase 1 through all migration waves
AA

Application and Business Process Owners

Validate application criticality, dependencies, data quality, downtime windows, test results, and business acceptance.

Involve: From Phase 2 through application acceptance
SI

Security, IAM and ISMS Manager

Defines identity, privileged access, encryption, logging, vulnerability management, and security acceptance criteria.

Involve: From Phase 2 through operational acceptance
DP

Data Protection Officer and Legal Counsel

Review the GDPR Art. 28 DPA, subprocessors, data residency, transfer safeguards, ROPA updates, and DPIA requirements.

Involve: From Phase 3 and before any real-data migration
NR

NIS2, Risk and Compliance Manager

Determines NIS2 applicability and maintains cloud risk-management, supply-chain security, and audit evidence.

Involve: From Phase 3 through compliance sign-off
IO

IT Operations, Service Desk and Business Continuity Manager

Defines monitoring, incident handling, backup, recovery, RTO/RPO, support procedures, and operational acceptance.

Involve: From Phase 2 through handover and hypercare
FP

Finance, Procurement and FinOps Owner

Controls licensing, cloud contracts, consumption budgets, supplier due diligence, and cost optimization.

Involve: From Phase 1 and throughout procurement and operations
HL

HR, Learning and Development, and Key User Representatives

Coordinate administrator training, user communications, adoption support, and role-specific process changes.

Involve: From Phase 5 through hypercare
MA

Microsoft/Azure Migration Partner and Microsoft Account Team

Provide specialist architecture, migration engineering, licensing guidance, platform evidence, and escalation support.

Involve: From Phase 1 through final cutover

Compliance

Mandatory

Execute a GDPR Art. 28 data processing agreement with the cloud provider, including processing instructions, confidentiality, security, audit rights, deletion/return provisions, and approved subprocessors. The signed agreement must be in place before any real personal or customer data is migrated.

DPO and Legal Counsel, with Procurement and the cloud provider Weeks 5–11; complete no later than Week 11 and before real-data migration
Mandatory

Assess third-country access and transfers under GDPR Arts. 44 ff., including provider support access, subprocessor locations, transfer-impact assessments, SCCs or other valid safeguards, and supplementary technical measures.

DPO and Legal Counsel, with the Security Manager and cloud provider Weeks 5–11; approval required before any real-data migration
Mandatory

Update the record of processing activities under GDPR Art. 30 for Azure, Microsoft 365, identity services, backups, monitoring, support access, subprocessors, retention, and international transfers.

DPO, process owners, and Legal Counsel Weeks 5–13; complete at least four weeks before the Week 17 Wave 1 go-live
Mandatory

Screen processing under GDPR Art. 35 and complete a DPIA where the migration creates likely high-risk processing, extensive monitoring, sensitive-data processing, or significant provider access; document the decision and remediate identified risks.

DPO, Legal Counsel, Security/IAM Manager, and application owners Weeks 5–13; complete at least four weeks before the Week 17 Wave 1 go-live
Mandatory

Determine whether NIS2 applies based on sector, size, turnover, and service role. If applicable, document cloud risk management, supplier and supply-chain security, incident handling, business continuity, access control, and supporting evidence.

NIS2, Risk and Compliance Manager, CIO, Procurement, and Security Manager Applicability decision by Week 7; risk-management and supply-chain evidence by Week 9, at least eight weeks before Wave 1 go-live
Mandatory

Implement GDPR Art. 32 security measures, including least privilege, privileged-access management, encryption, secure configuration, logging, vulnerability management, monitoring, incident response, and appropriate backup protection.

Security/IAM Manager, Head of Cloud and Infrastructure, and IT Operations Design in Weeks 8–13; implementation and validation in Weeks 11–16, before Week 17 production migration and throughout operations
Mandatory

Review customer contracts, confidentiality obligations, data-residency commitments, customer notification duties, subprocessor approvals, service levels, and any restrictions on hosting or support access before workloads are assigned to Azure or Microsoft 365.

Legal Counsel, Customer Account Owners, Procurement, and CIO Weeks 2–13; complete for each workload before its migration wave
Optional

Define and document backup, disaster recovery, retention, restoration, and business-continuity controls against customer commitments and internal policy; test restoration, regional recovery, and ransomware scenarios and retain evidence.

Business Continuity Manager, IT Operations, Security Manager, and service owners Design in Weeks 8–13; implementation and testing in Weeks 14–24, before final operational acceptance

Milestones

  1. Week 1

    Approved project charter, scope baseline, governance model, six-month delivery plan, and compliance gate register.

    Depends on: Executive sponsorship, named workstream owners, and confirmed decision rights
  2. Week 4

    Validated inventory and dependency catalogue with application criticality, data classification, ownership, and preliminary migration disposition for every in-scope workload.

    Depends on: Approved scope baseline and access to discovery sources and application owners
  3. Week 7

    Approved privacy and regulatory assessment baseline, active DPA and transfer review, documented DPIA screening, NIS2 applicability decision, and prioritized security-gap register.

    Depends on: Validated workload, data-processing, supplier, and dependency information
  4. Week 10

    Approved target architecture, landing-zone design, identity and Microsoft 365 design, migration-wave plan, and NIS2 evidence pack completed by Week 9 where applicable.

    Depends on: Discovery baseline, security-gap register, and regulatory assessment
  5. Week 13

    Azure and Microsoft 365 foundation operational; signed DPA and documented transfer safeguards; updated ROPA; completed DPIA or documented decision; formal approval to begin controlled testing.

    Depends on: Approved target design, provider contracting, compliance decisions, and platform access
  6. Week 16

    Successful non-production pilot, tested migration and rollback runbooks, validated backup and restore evidence, and signed Wave 1 go-live decision.

    Depends on: Operational cloud foundation and formal testing-readiness approval
  7. Week 19

    Wave 1 production workloads operational from Week 17, with documented business acceptance, no unresolved critical defects, and updated migration procedures.

    Depends on: Signed Wave 1 go-live decision and completed production readiness checks
  8. Week 22

    All approved Wave 2 workloads migrated or formally excepted, with documented business acceptance and no unresolved critical migration blockers.

    Depends on: Wave 1 lessons incorporated and Wave 2 workload readiness confirmed
  9. Week 24

    Documented restore and DR test results meeting agreed objectives, completed training records, operational runbooks approved, and formal operational acceptance granted.

    Depends on: Production migrations completed and operations, service desk, and users available for validation
  10. Week 26

    Final cutover completed, legacy transition decision recorded, critical defects closed or accepted, operational ownership transferred, and project closure approved by Week 26.

    Depends on: Operational acceptance, final cutover authorization, and agreed legacy disposition

How this plan was created

This plan was created by PathHub AI from a single description: “Migrate the servers and business applications of an IT service provider with 120 employees to the cloud (Microsoft Azure and Microsoft 365): inventory, target architecture, migration in waves, backup and disaster recovery concept, training. Completion in six months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.

Obligations

Obligations with lead time: what many think of too late

These obligations are typically triggered by a cloud migration (example: Germany). PathHub AI schedules them with lead time, warns when the schedule is too tight and shows the rule with its criteria under “Rule & evidence”, which you tick off and back with evidence. Not legal advice.

Sign a data processing agreement with the cloud provider and check third-country transfers
Required 2–6 weeks before go-livestatutory
Rule & evidence

Why: With the migration, the provider processes your personal data.

Legal basis: GDPR Art. 28: contract before processing starts, including before migrating real data; for providers outside the EU also secure third-country transfers (Art. 44 ff.).

Rule from the compliance library
Cloud Contract Law
Criteria
  • Data Processing Agreement (DPA) with cloud provider
  • SLA with availability, RPO, RTO
  • Exit and portability clause
  • Data localisation and transfer mechanism (SCC / adequacy)

If breached: Civil claims for data loss; recourse depends on contract. GDPR fines for non-compliance.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Update the record of processing activities and check whether a DPIA is needed (GDPR Art. 30, 35)
Required 2–4 weeks before go-liveguide value
Rule & evidence

Why: Storage locations, sub-processors and access paths change.

Rule from the compliance library
GDPR (General Data Protection Regulation)
Criteria
  • Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
  • Complete record of processing activities (Art. 30) for all processes
  • Data Processing Agreements (DPA) with all sub-processors
  • Data Protection Impact Assessment (DPIA) for high-risk processing
  • Technical and organisational measures (TOM) documented

If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Document risk management and supply chain security for the cloud service (NIS2)
Important 4–8 weeks before go-liveguide value
Rule & evidence

Why: NIS2 requires risks from service providers to be assessed and contractually covered.

Applies: if the company falls under NIS2 (e.g. from 50 employees or EUR 10m turnover in covered sectors)

Rule from the compliance library
NIS2 Directive
Criteria
  • Documented IT risk management reviewed annually
  • Business continuity plan and disaster recovery tested
  • Multi-factor authentication (MFA) for critical systems
  • Encryption of all sensitive data (at rest + in transit)
  • Supplier security reviews (supply chain security)
  • Annual cybersecurity training for all employees

If breached: Fines up to €10 million or 2% of global annual revenue. Personal liability of management for gross negligence.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Involve the works council and conclude a works agreement on the cloud services
Important 6–12 weeks before go-liveguide value
Rule & evidence

Why: Services such as Microsoft 365 record employees' usage data.

Applies: only if a works council exists

Legal basis: Sec. 87(1) No. 6 BetrVG: cloud services with logs and analytics are suitable for monitoring performance or behaviour.

Rule from the compliance library
Works Constitution Act (BetrVG)
Criteria
  • Enable works council election from 5 eligible employees upward
  • Co-determination on working time, monitoring systems, IT rollouts (§87)
  • Hearing before every dismissal (§102) — written with reasons
  • Balance-of-interests and social plan on operational changes (§111)

If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
All typical initiatives and their obligations: planning internal projects

Frequently asked questions

How long does a cloud migration take?
In the example plan, a cloud migration takes 26 weeks in 10 phases. The actual duration depends on company size, starting point and available resources — with your company context PathHub adjusts the schedule accordingly.
What does a cloud migration cost?
The example plan estimates about €817,500, split into 23 budget line items with quantity and unit price. The largest items are External Consulting and Migration Delivery, Software, Cloud and Migration Infrastructure. This is an AI estimate as a starting point, not a quote.
What are the risks of a cloud migration?
The plan lists 10 risks with countermeasures. Rated highest: Incomplete Inventory and Hidden Dependencies; Data Loss or Extended Cutover Downtime; GDPR DPA or Third-Country Transfer Delay.
Who needs to be involved in a cloud migration?
Among others, the plan includes these people: Executive Sponsor and Steering Committee, CIO or IT Director, Head of Cloud and Infrastructure, Application and Business Process Owners, Security, IAM and ISMS Manager, Data Protection Officer and Legal Counsel. For each role it states why and from when to involve them.
Can I adapt the plan to my company?
Yes. Open the plan in PathHub without signing up, adjust phases and tasks or describe your own initiative — with company context (departments, approval processes, works council, compliance requirements) every further plan gets more precise.

More project plan examples

Adapt this plan to your company

Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.

Open plan →