
Why Public Authorities Need a Cloud Strategy Now
The digital transformation of public administration is at a turning point. A cloud-first approach is no longer an option; it is a necessity. German authorities must act, and time is of the essence — the Deutsche Verwaltungscloud has become a product, sovereign offerings from AWS, Delos, STACKIT and IONOS are live, and BSI C5:2026 sets the new bar.
A well-designed Cloud Migration Roadmap provides the foundation. It connects technical requirements with regulatory mandates, placing BSI C5 compliance at the core. The ultimate goal is to achieve digital sovereignty in the cloud.

Understanding the Challenge
Public institutions face unique hurdles. A Data Protection Impact Assessment (DPIA) for the cloud is mandatory. IT-Grundschutz must be involved from the start. The procurement of cloud service providers follows strict regulations.
A multi-cloud strategy offers flexibility: Azure and GCP migrations can proceed in parallel, the Cloud Adoption Framework for Azure provides proven methodology, and sovereign platforms complete the ecosystem for workloads with the highest protection needs.
The 5-Phase Approach to Cloud Migration
Phase 1: Assessment and Analysis — Every successful migration begins with an inventory. What workloads exist? What are the dependencies? What protection needs does each carry?
Phase 2: Strategy and Architecture — This is where the actual roadmap is developed. Azure Landing Zone or GCP Landing Zone? Often, the answer is both. Multi-cloud enables freedom of choice.
Phase 3: Compliance and Security — BSI C5 requirements are defined. A BSI-compliant cloud security concept is created. ISO 27001 based on IT-Grundschutz forms the basis.
Phase 4: Migration and Implementation — The datacenter migration is performed step-by-step in waves. VMware-to-Azure migrations use proven tooling. A fixed-price migration offer provides planning security.
Phase 5: Operations and Optimisation — Managed services take over routine operations and ensure availability. Continuous improvement becomes the standard.
Quick Checklist: Cloud Migration Roadmap
| Step | Action | Timeline |
|---|---|---|
| 1 | Create Workload Inventory | Week 1-2 |
| 2 | Document Compliance Requirements | Week 2-3 |
| 3 | Evaluate Cloud Providers | Week 3-4 |
| 4 | Plan Landing Zone | Week 4-6 |
| 5 | Launch Pilot Project | Week 6-8 |
| 6 | Finalise Rollout Plan | Week 8-10 |
To-Do List for Decision-Makers
- Today: Appoint an internal cloud champion.
- This Week: Initiate an IT landscape assessment.
- This Month: Commission an independent cloud readiness assessment.
- Quarter 1: Conduct a BSI C5 gap analysis.
- Quarter 2: Prepare the cloud migration tender.
Why Multi-Cloud Makes Sense for Public Authorities
A single sovereign cloud alone is often not enough. Specialised services require flexibility. The Deutsche Verwaltungscloud can be combined with Azure, GCP, the AWS European Sovereign Cloud or STACKIT — per workload, by protection need.
The advantages are clear: no vendor lock-in and the best solution for every use case. A cloud framework agreement enables rapid procurement, and comparable offers keep migration costs predictable. We go deeper in Multi-Cloud Strategy for the Federal Administration.
The Next Step
A professional Cloud Migration Roadmap is complex. It requires expertise in technology, compliance and procurement law. Insight42 supports public authorities on this journey, from the initial analysis to ongoing operations — with BSI C5, IT-Grundschutz and NIS2 built into the architecture.
Ready for the first step? See Cloud Migration Beratung (German) or contact us for a non-binding initial consultation.