The short answer
A working exit plan starts at signature, not at termination: that is when you secure data export rights, transition assistance, timelines, and deletion terms. Decide what you can actually take in a usable form, return and wipe hardware, plan parallel running with a cutover point and rollback, and hold a tested stressed-exit scenario with evidence for every material supplier so operations never gap.
Key takeaways
- The best time to negotiate exit terms is while the contract is being priced: portability, notice periods, and transition help are nearly impossible to add after signing.
- Data can be exportable without being portable — metadata, permissions, approval history, and attachments often stay behind in the old system.
- The EU Data Act obliges cloud providers to maintain an exit plan and support portability; it took effect in January 2024 and applies from 12 September 2025.
- Every piece of vendor hardware needs a decision: return, sanitize and redeploy, or dispose with a certified chain of custody.
- Migration is a project with a parallel-running window, a defined cutover, and a rollback plan, not a one-time switch.
- Material suppliers need an exit plan even when you have no intent to leave, because a sudden failure forces a stressed exit in days.
- Governance requires a dependency register, named owners, clear exit triggers, and test evidence that reviewers and boards can inspect.
Start at Signature, Not at Termination
An exit plan is not a contingency document you write when a relationship fails; it is a negotiation lever you use while the contract is still being priced. Lock-in is built at signing, not discovered at exit. Termination windows, data export rights, transition assistance, and notice periods are almost impossible to add once the agreement is signed and your leverage is gone.
Treat the exit plan as a required schedule in the contract template and finalize it during negotiation. A useful readiness test: can you describe the exit on a single page — what you would lose, what it would cost, and how long it would take? If you cannot, you are not ready to negotiate. During the pilot, ask the vendor to export a sample of your data and check whether it is usable, not merely downloadable.
- Who created the dependency: the vendor through bundling and terms, or you through custom workflows and weak integration?
- What you would lose, what leaving would cost, and how long it would take
- Where export rights, formats, and timelines are written down
Data: What You Take and in What Form
Portability rarely reduces to a single export button. Structured records may come out cleanly, but metadata, user permissions, workflow settings, custom fields, attachments, and audit history often stay behind or arrive as a flat file that cannot be reconstructed in the next system. Define in the contract what you can take, in which format, on what schedule, and whether you can export without vendor involvement.
Prefer configuration over custom code, because custom code is what traps you, and keep definitions, scripts, and credentials outside any single provider. Regulation is pushing exit rights toward standard practice. The EU Data Act took effect in January 2024 and applies from 12 September 2025; it requires cloud service providers to maintain an exit plan, communicate portability options clearly, and apply security measures while customers retrieve their data. Deletion obligations for personal data under laws such as GDPR are separate from commercial terms, so the contract should still set the deletion window, written certification, and deletion at subprocessors and in backups.
- Export formats and the right to self-service export at any time
- Delivery timelines and limits on volume or bandwidth charges
- Fee caps on data extraction and vendor-assisted migration
- Deletion window, written confirmation, and flow-down to subprocessors and backups
Hardware: Return, Sanitize, Redeploy
Hardware is the part of an exit people forget because it carries no glamour, yet it concentrates financial and security risk. Map every asset the vendor supplied or that holds vendor data: laptops, servers, network gear, and media. For each, decide whether it will be returned, sanitized and redeployed, or disposed of.
Data-bearing media that leave your control must be wiped to an accepted standard and, where retention rules require, accompanied by a certificate of destruction with a chain of custody. Separate the financial from the physical: leased equipment is returned on schedule and in the agreed condition to avoid fees, while purchased equipment that will not be reused goes through a certified disposal channel. Track serial numbers and locations in the same register you use for data so no device is left connected to old credentials after exit.
- Lease returns on schedule and in the agreed condition
- Media wiped to standard with a certificate of destruction where needed
- Redeployment or disposal through a documented, auditable process
Migration and Cutover: Timeline, Parallel Run, Rollback
Migration is a project with its own timeline, not a switch to be flipped. It starts with a target design, a data inventory, and a decision about what moves first. Begin with the least critical workloads to rehearse the process, then move the revenue-critical ones once the route is proven. Negotiate a transition or assistance period and a parallel-running window so the old and new services overlap instead of gap.
Define cutover and rollback before you begin. Cutover is the moment traffic and users move; rollback is the plan to reverse if validation fails. Keep the old environment available until data is reconciled, access is recreated, and users confirm the new system. Egress and data-access fees are a known cost — some vendors treat extraction as a paid professional-services engagement — so cap those charges and volume-based egress in the original terms.
- Sequencing from pilot workloads to critical systems
- An agreed parallel-running period and transition support window
- Success criteria for cutover and a written rollback plan
- Caps on egress and data-extraction charges
Operational Continuity and the Stressed Exit
Continuity is the reason exit planning exists. When a supplier fails abruptly, you face a stressed exit — an accelerated move measured in days or weeks rather than months. Business continuity and disaster recovery teams should therefore hold an exit plan for every material and high-impact supplier, not only the ones you intend to leave. The plan must cover interim arrangements, how long the transition takes, and the fallback if the replacement is not ready.
Regulated sectors increasingly expect proof, not policy. Reviewers and boards want evidence that the dependency can be replaced, that critical data can be recovered, that service can continue during the exit, and that named owners can execute runbooks. Run exit tests such as restoring a backup in another environment or exporting a real dataset, and keep the evidence.
- Exit plans for material suppliers even without an intent to leave
- Interim arrangements and transition duration estimates
- A tested backup-restore exercise outside the primary environment
- Named runbook owners and a recent record of checks
Governance, Communication and Documentation
Governance gives the plan owners. Assign roles with a RACI so legal, procurement, IT, security, compliance, and the business each know what they own. Define triggers that open an exit review: performance failure, renewal, acquisition, a price change, or a new regulatory obligation.
Keep a short register of dependencies and exit owners for each workload, with the last test date and known blockers. Notify the vendor professionally, state your reasons, and agree on the due diligence each side will perform. Keep records of decisions and communications throughout the exit. After the move, document lessons learned so the next transition is faster.
Put it into practice
Exit-Readiness Audit: One Sheet per Critical Supplier
Score every material vendor against this list. A missing answer or unproven claim means the dependency is not ready for a critical decision.
- I can describe the exit on one page: what we lose, what it costs, and how long it takes
- Export formats, self-service export rights, and delivery timelines are in the contract
- A sample export was tested and proved usable, not just downloadable
- Metadata, permissions, approval history, and attachments are included in the move
- Fees for data extraction and volume-based egress are capped
- Deletion window, written certification, and flow-down to subprocessors and backups are agreed
- A hardware map exists with a return, sanitize, or redeploy decision for every asset
- Data-bearing media are wiped to standard with chain of custody on disposal
- There is a migration schedule, parallel-running window, cutover point, and rollback plan
- A backup-restore or real-data export test has been executed and evidenced
- Named owners and RACI roles are set, with clear exit triggers
- Decision and communication records are kept and retained after completion
Questions people ask
What is the difference between data that is exportable and data that is portable?
Data can download as a file yet fail to transfer into the new system in a usable state. Exports usually deliver structured records, while metadata, user permissions, workflow settings, custom fields, attachments, and audit history remain behind or arrive as a flat file that cannot be reconstructed. Before signing, ask the vendor to export a sample and verify that the history and object relationships move, not just isolated records.
When should I start negotiating an exit plan?
At signature, while you still have leverage over price and terms. Termination windows, data export rights, transition help, and notice periods are nearly impossible to add later. Make the exit plan a required schedule in the contract template and refine it during negotiation; during the pilot, test whether the vendor can export a usable sample of your data.
What does the EU Data Act require for cloud exit and portability?
The EU Data Act is a European regulation that eases switching between cloud providers and data-processing services. It took effect in January 2024 and applies from 12 September 2025. It obliges service providers to maintain an exit plan, clearly communicate portability options and the steps customers must take, and apply security measures while customers retrieve their data. This is general regulatory information; consult a lawyer familiar with your jurisdiction for your specific situation.
How should hardware and media be handled during an exit?
Map every vendor asset — laptops, servers, network gear, and media — and decide for each whether it is returned, sanitized for redeployment, or disposed of. Return leased equipment on schedule and in the agreed condition to avoid fees. Wipe data-bearing media to an accepted standard and, where required, obtain a certificate of destruction with chain of custody. Keep serial numbers and locations in the same register you use for data.
What is a stressed exit and how do I prepare for one?
A stressed exit is an accelerated move caused by a supplier's complete failure or prolonged disruption, leaving days or weeks rather than months. Material suppliers need a prepared exit plan even when there is no intent to leave. It includes interim arrangements, an estimate of transition duration, and a fallback if the replacement is not ready. Readiness is proven through tests such as restoring a backup in another environment, exporting a real dataset, and runbooks that named owners can execute.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Vendor Lock-In: A Beginners GuideITAM Review
- Terminating with a Vendor: Governance, Changes and Best PracticesFuture of Sourcing Digital Publication
- EU Data ActAtlassian
- Build a Cloud Exit Plan Without Limiting InnovationCygnet
- What You Need to Know Before Exiting a Vendor ContractClear Guidance Partners
- Launch of The CMORG Third Party Exit Plan TemplateCross Market Operational Resilience Group (CMORG)