What is an exit strategy?
An exit strategy is a documented, tested plan for leaving a software or cloud provider: where the service moves, how the data comes out, who does what and how long it takes, so that leaving is possible without disrupting the business.
Written by Ugo Balducci. Last updated
What an exit strategy means
An exit strategy is the answer, written down in advance, to the question: what do we do if this provider has to go? It names the fallback, whether another provider, an in-house team or open-source software you run yourself. It sets out how the data is exported and in which formats, the steps and owners for the switch-over, the trigger that starts it and the time it should take.
A good exit strategy is tested. Exporting data once and restoring it into the fallback shows what the document missed. A plan nobody has exercised is an assumption.
Why it matters when choosing where software runs
Regulators now ask for exit strategies. The EU Digital Operational Resilience Act (DORA), applicable to EU financial entities since 17 January 2025, requires exit strategies for ICT services that support critical or important functions. FINMA’s outsourcing circular, published with its other circulars, expects Swiss banks and insurers to be able to bring an outsourced function back in house or move it to another provider. Outside finance, public procurement rules and client contracts often ask the same question.
The easiest exit is the one designed in from the start. Software with open data formats and a licence that lets someone else run it reduces vendor lock-in before the contract is signed.
How Pilae handles it
Every Pilae plan includes a written exit plan for Pilae itself. The apps we run are open source or source-available, so another operator or your own team can take over the same apps without rebuilding them. At the end of the contract you receive your data, configuration and runbooks in open formats, with help moving to another operator or back in-house, and then written confirmation that your data has been deleted.
For your other providers, our exit plan service builds a documented fallback for each critical SaaS or cloud dependency, with scheduled exports, a runbook and a dated test record. It supports the requirements described on the NIS2 and DORA and FINMA pages. When the decision is to leave, migration moves the service.