
Most cloud migration business cases fail the same way: they compare this year’s infrastructure bill with next year’s cloud bill, declare victory or defeat, and ignore everything that actually moves the number — risk, resilience, the operating model, and what it costs to leave. Then reality arrives, the case does not survive contact with the CFO, and the migration stalls at 30%.
Here is the business-case structure we use with enterprises and public-sector organizations in Germany: six components, one defensible three-year number, and the assumptions written down where finance can challenge them.
Key takeaways
- A credible migration ROI is a three-year total-cost delta, not a monthly-bill comparison.
- Six components belong in the model: current TCO, migration cost, target operating model, risk reduction, resilience value, and exit cost.
- The two most-ignored components — risk and exit — are precisely the ones regulated buyers and auditors ask about.
- Wave-based migration keeps the business case honest: each wave has its own costs, savings and proof.
The six components of a defensible business case

1. Current TCO — the honest baseline
Hardware refresh cycles, licenses, data-center contracts, power, and the engineering hours spent keeping it all alive. Most baselines undercount people time and overcount sunk costs. Rule: count what you would actually stop paying.
2. Migration cost — priced per wave
Assessment, landing zone, per-workload migration effort, parallel running, and training. Pricing this per migration wave — rather than as one heroic estimate — is what keeps the number believable. Our approach to wave planning follows the Cloud Adoption Framework, adapted for regulated environments.
3. Operating model — where the recurring savings live
The savings are not in the servers; they are in what your team stops doing: patching hypervisors, capacity planning, weekend failovers. If the target operating model is not designed (platform team, automation, managed services), the business case silently assumes the old one — and the savings never materialize.
4. Risk reduction — the line auditors read first
Unpatched end-of-life systems, single points of failure, key-person dependencies: each has an expected cost, and migration changes it. Quantify even roughly — likelihood × impact, stated openly — and the CFO conversation changes tone. For DSGVO- and BSI-C5-relevant workloads this is also where security architecture enters the case as value, not cost.
5. Resilience — priced downtime
What does an hour of outage cost in your order flow, production line or citizen services? Multi-zone architectures and tested restores change that expected loss. Resilience is the component business stakeholders understand fastest — use their numbers, not IT’s.
6. Exit cost — the sovereignty line
What would it cost to leave the platform you are migrating to? Egress, re-platforming, contractual lock-in. European regulators increasingly expect an answer (think DORA and NIS2 supply-chain thinking), and executives should demand one. A business case that prices exit is a business case that survives its third year.
Worked example: the shape of the number
A typical mid-size estate (150 workloads, one aging data center): baseline TCO €2.1M/year; migration cost €1.4M across four waves; target run cost €1.5M/year with a leaner operating model; quantified risk and resilience value €300k/year; exit provision €200k. Three-year result: roughly €1.3M net positive — before counting a single new capability. The point is not these numbers; it is that every one of them has an owner and an assumption you can challenge.
Business-case checklist
- Baseline TCO includes people time and excludes sunk costs
- Migration priced per wave, with wave 1 scoped in detail
- Target operating model designed and costed
- Top 5 risks quantified (likelihood × impact) before/after
- Downtime cost stated by the business, not IT
- Exit cost estimated and provisioned
- Three-year horizon, assumptions on one page
Get a business case your CFO will sign
Insight42 builds migration business cases and then delivers them — assessment, landing zones, migration waves and the operating model, with GDPR, EU data residency and BSI C5 built in from the start. Explore our cloud adoption & migration services or request a Cloud Migration Assessment.