Fact-check note: Substantially reviewed September 4, 2026 for current security, privacy, compliance, cost-governance, and cutover guidance.

A cloud migration is not automatically modernization or cost reduction. It changes an application’s operating environment, responsibility model, dependencies, failure modes, and economics. Begin with the outcome a workload needs and compare retaining, retiring, repurchasing, relocating, rehosting, replatforming, and refactoring.

Discover the real workload

Inventory owners, users, dependencies, data classifications, service and recovery objectives, licenses, identity flows, networks, jobs, observability, backup and restore, retention, and legal or contractual constraints. Validate documentation with telemetry and operators. Record a business case, acceptance criteria, owner, and exit plan for each disposition.

Rehosting is a tradeoff

Moving with limited architectural change can rationally support a facility exit or deadline. It does not itself deliver elasticity, managed-service benefits, reliability, or savings. Benchmark demand, latency, throughput, availability, recovery, operational effort, licensing, and full cost before and after. If rehosting is interim, fund the later work.

Design for shared responsibility

Responsibilities vary by service model, provider, contract, configuration, and data. Maintain a matrix for identity, endpoints, operating systems, applications, data, encryption keys, networking, logs, backups, vulnerabilities, and incidents. Establish a governed landing zone with account boundaries, phishing-resistant administrator authentication, least privilege, egress policy, approved services and regions, logging, backup, configuration policy, and tested emergency access.

Protect transfers and temporary copies: minimize data, authenticate endpoints, encrypt in transit, reconcile integrity and completeness, restrict staging, log access, and dispose of temporary copies when allowed. Dedicated connectivity is not synonymous with encryption.

Apply obligations precisely

GDPR, HIPAA, PCI DSS, and FedRAMP have different scopes; none is a universal cloud-residency rule. Identify the entity, data, jurisdiction, service, contract, and control responsibility. An audit or provider certification does not make the customer configuration compliant or secure.

Model full lifecycle cost

Include compute, storage, data transfer, managed services, licenses, support, observability, security, backup, idle capacity, engineering, migration, dual running, incidents, and exit. Model demand and discounts explicitly, tag resources, assign owners, set budgets and anomaly alerts, and compare forecast with actual use. Do not present generic savings percentages as evidence.

Rehearse cutover and recovery

  1. Define functional, performance, security, data-quality, RTO/RPO, and business acceptance criteria.
  2. Rehearse migration with representative data and load; reconcile records and control totals.
  3. Document freeze, replication, DNS, identity, integrations, communications, decision authority, and stop conditions.
  4. Test rollback or compensating recovery. Some schema and data changes are not simply reversible.
  5. Observe both environments, retain evidence, verify backups and restores, and obtain explicit approval before decommissioning.

Build the portfolio context with a digital transformation roadmap, govern permissions through data access governance, and prepare operations using MLOps best practices.