Cloud and SaaS dependencies
Map the agreed services, integrations, identity systems, data flows and relevant contractual dependencies across Microsoft 365, Azure, AWS and selected SaaS platforms.
Understand your cloud dependencies. Decide where your data and applications belong. Build a practical plan to keep your options open.
In a focused 2–3 week engagement, Cleverina assesses your agreed Microsoft 365, Azure, AWS and SaaS environment, evaluates sovereignty, resilience and portability requirements, and develops a prioritised roadmap for your next cloud decisions.
Defined scope · Practical deliverables · One agreed portability or recovery test
Microsoft where appropriate. Sovereign infrastructure where needed.
Cloud decisions affect business continuity, access to data, operational costs and future flexibility. We help you understand which dependencies matter, where additional controls may be needed, and what moving or recovering selected services would realistically involve.
Your assessment answers three questions:
Map the agreed services, integrations, identity systems, data flows and relevant contractual dependencies across Microsoft 365, Azure, AWS and selected SaaS platforms.
Classify information and workloads by sensitivity, business importance, recovery objectives and relevant location or processing requirements.
Review applicable national, sector and procurement requirements together with relevant European sovereignty criteria. Where useful for planning, we assess the environment against proposed CADA assurance Levels 1–4 and, separately, against European Commission cloud sovereignty procurement criteria — clearly distinguishing current obligations, current procurement and assurance criteria, and emerging regulatory proposals. Proposed CADA requirements are not treated as mandatory law.
Identify technical and commercial dependencies — proprietary APIs, data export limitations, identity dependencies, licensing, contractual commitments, integration redevelopment, operational skills and migration effort — and the major cost drivers behind them. Where the available evidence supports it, we provide indicative effort estimates or cost ranges with clearly stated assumptions rather than exact exit costs.
Develop practical target-state options combining suitable hyperscaler services, European cloud infrastructure, local or private infrastructure and hybrid approaches, with high-level boundaries for data, identity, security, integrations and operations. This is an assessment-level target architecture, not a production-ready detailed implementation design.
For each relevant service or workload we recommend a direction where appropriate — retain, retain with additional controls, isolate, migrate, replace or investigate further — with the reason, dependencies and next decision required.
Perform a controlled export, backup/restore or portability test for one agreed workload or dataset in a separate target environment, where technically feasible. Document what can be recovered, what remains provider-dependent and which gaps require further work.
Each recommendation includes its rationale, dependencies and next steps, helping technical and business stakeholders agree on a realistic course of action.
Agree priorities, review the selected environment and map relevant dependencies.
Assess requirements, identify lock-in, compare target-state options and estimate the effort involved in changing or strengthening the current architecture.
Complete the agreed portability or recovery test and review findings, trade-offs and the prioritised roadmap with the customer team.
Timing starts once the agreed access, documentation and technical contacts are available. Scope, test feasibility and any third-party costs are confirmed before kickoff. Production migration, detailed solution design and application replacement are scoped separately.
Assess patient-facing applications, appointment workflows, analytics, clinical-support systems and integrations with particular attention to sensitive information, service continuity and operational dependencies.
We work with IT, security and data protection teams to evaluate appropriate hosting and architecture options and document the controls each workflow requires.
Microsoft when it fits the requirement. Sovereign options where the workload calls for them.
Healthcare at CleverinaNo. The assessment may recommend retaining existing Microsoft services, strengthening controls, separating sensitive workloads or moving selected components. Recommendations reflect the organisation's technical, operational and regulatory requirements rather than a preference for any particular provider.
Not necessarily. Portability varies significantly by service. Exporting data does not recreate application functionality, identity, permissions, workflows or integrations. The assessment identifies these dependencies and the work required to preserve the relevant business process.
No. It provides a technical assessment, identifies evidence and control gaps, and recommends implementation actions. It does not issue regulatory certification or replace legal advice. Proposed CADA criteria are treated as a planning reference where relevant. Current legal, sector and procurement requirements are considered separately.
Where relevant, we distinguish current requirements and procurement criteria from emerging regulation. Proposed CADA assurance concepts may be used as a planning reference, while existing cloud sovereignty frameworks and applicable national or sector requirements are assessed according to their actual status and relevance to the organisation.
It validates the agreed workload or dataset under defined test conditions. The report records what was exported or restored, what was successfully verified, which dependencies remained tied to the original provider, and what additional work would be required.
The assessment identifies the main technical and commercial cost drivers and can provide indicative ranges or effort estimates where sufficient information is available. A detailed migration quotation may require separate discovery and solution design.
Tell us which systems matter most and what is driving your review. We will help define an assessment scope around your priorities.