Cloud strategy & resilience

Sovereign Cloud & Exit-Readiness Assessment

Understand your cloud dependencies. Decide where your data and applications belong. Build a practical plan to keep your options open.

In a focused 2–3 week engagement, Cleverina assesses your agreed Microsoft 365, Azure, AWS and SaaS environment, evaluates sovereignty, resilience and portability requirements, and develops a prioritised roadmap for your next cloud decisions.

Defined scope · Practical deliverables · One agreed portability or recovery test

Microsoft where appropriate. Sovereign infrastructure where needed.

Know what it would take to change providers

Cloud decisions affect business continuity, access to data, operational costs and future flexibility. We help you understand which dependencies matter, where additional controls may be needed, and what moving or recovering selected services would realistically involve.

Your assessment answers three questions:

  1. 1.Where should each application and dataset run?
  2. 2.What could prevent us from moving or recovering it elsewhere?
  3. 3.What should we improve first?

What we assess

Cloud and SaaS dependencies

Map the agreed services, integrations, identity systems, data flows and relevant contractual dependencies across Microsoft 365, Azure, AWS and selected SaaS platforms.

Data and application classification

Classify information and workloads by sensitivity, business importance, recovery objectives and relevant location or processing requirements.

Sovereignty and regulatory readiness

Review applicable national, sector and procurement requirements together with relevant European sovereignty criteria. Where useful for planning, we assess the environment against proposed CADA assurance Levels 1–4 and, separately, against European Commission cloud sovereignty procurement criteria — clearly distinguishing current obligations, current procurement and assurance criteria, and emerging regulatory proposals. Proposed CADA requirements are not treated as mandatory law.

Provider dependency and exit effort

Identify technical and commercial dependencies — proprietary APIs, data export limitations, identity dependencies, licensing, contractual commitments, integration redevelopment, operational skills and migration effort — and the major cost drivers behind them. Where the available evidence supports it, we provide indicative effort estimates or cost ranges with clearly stated assumptions rather than exact exit costs.

Target-state architecture options

Develop practical target-state options combining suitable hyperscaler services, European cloud infrastructure, local or private infrastructure and hybrid approaches, with high-level boundaries for data, identity, security, integrations and operations. This is an assessment-level target architecture, not a production-ready detailed implementation design.

Prioritised decision roadmap

For each relevant service or workload we recommend a direction where appropriate — retain, retain with additional controls, isolate, migrate, replace or investigate further — with the reason, dependencies and next decision required.

Portability and recovery validation

Perform a controlled export, backup/restore or portability test for one agreed workload or dataset in a separate target environment, where technically feasible. Document what can be recovered, what remains provider-dependent and which gaps require further work.

What you receive

  • Executive findings brief with recommended decisions.
  • Dependency map and data classification register.
  • Requirements and evidence-gap matrix.
  • Target-state architecture options with provider-selection criteria.
  • Prioritised decision roadmap.
  • Indicative implementation effort and major cost drivers where evidence allows.
  • Portability / recovery validation report.
  • Practical next-step recommendations.

Each recommendation includes its rationale, dependencies and next steps, helping technical and business stakeholders agree on a realistic course of action.

A focused engagement, typically 2–3 weeks

Stage 1

Discover

Agree priorities, review the selected environment and map relevant dependencies.

Stage 2

Evaluate

Assess requirements, identify lock-in, compare target-state options and estimate the effort involved in changing or strengthening the current architecture.

Stage 3

Validate and decide

Complete the agreed portability or recovery test and review findings, trade-offs and the prioritised roadmap with the customer team.

Timing starts once the agreed access, documentation and technical contacts are available. Scope, test feasibility and any third-party costs are confirmed before kickoff. Production migration, detailed solution design and application replacement are scoped separately.

For healthcare organisations

Assess patient-facing applications, appointment workflows, analytics, clinical-support systems and integrations with particular attention to sensitive information, service continuity and operational dependencies.

We work with IT, security and data protection teams to evaluate appropriate hosting and architecture options and document the controls each workflow requires.

Microsoft when it fits the requirement. Sovereign options where the workload calls for them.

Healthcare at Cleverina

Frequently asked questions

Does this require us to leave Microsoft?

No. The assessment may recommend retaining existing Microsoft services, strengthening controls, separating sensitive workloads or moving selected components. Recommendations reflect the organisation's technical, operational and regulatory requirements rather than a preference for any particular provider.

Can Microsoft 365 and SaaS applications be moved like virtual machines?

Not necessarily. Portability varies significantly by service. Exporting data does not recreate application functionality, identity, permissions, workflows or integrations. The assessment identifies these dependencies and the work required to preserve the relevant business process.

Does the assessment certify compliance?

No. It provides a technical assessment, identifies evidence and control gaps, and recommends implementation actions. It does not issue regulatory certification or replace legal advice. Proposed CADA criteria are treated as a planning reference where relevant. Current legal, sector and procurement requirements are considered separately.

How do CADA and cloud sovereignty frameworks fit into the assessment?

Where relevant, we distinguish current requirements and procurement criteria from emerging regulation. Proposed CADA assurance concepts may be used as a planning reference, while existing cloud sovereignty frameworks and applicable national or sector requirements are assessed according to their actual status and relevance to the organisation.

What does the portability or recovery test prove?

It validates the agreed workload or dataset under defined test conditions. The report records what was exported or restored, what was successfully verified, which dependencies remained tied to the original provider, and what additional work would be required.

Will we receive an exact cost to exit our current provider?

The assessment identifies the main technical and commercial cost drivers and can provide indicative ranges or effort estimates where sufficient information is available. A detailed migration quotation may require separate discovery and solution design.

Make your next cloud decision with a clear plan

Tell us which systems matter most and what is driving your review. We will help define an assessment scope around your priorities.

Discuss your assessment