Why exit plans are now tested
For years, an exit strategy was a clause in the contract and a paragraph in the vendor file. Regulators now ask for more. DORA requires EU financial entities to hold exit strategies for ICT services that support critical or important functions, and to test them. In Switzerland, FINMA expects supervised institutions that outsource significant functions to stay able to bring them back or move them elsewhere.
The question behind both is the same: if this provider stopped tomorrow, what would you run instead, and how long would it take? Outside finance, the same question comes up after a price rise, a change of terms or a new foreign law.
A fallback that exists
A plan only works if the fallback is real. For each critical service, we name an app you control, open source or source-available: Nextcloud for file storage, Open WebUI for an AI assistant, Keycloak for identity, n8n for automation, Mattermost for chat, Garage for S3 object storage, vLLM for a model API, Forgejo for code hosting. We run it on your premises or in Pilae Cloud, from a warm standby to a documented cold start, depending on the recovery time you need.
Data leaves the provider on a schedule, in open formats, and is stored in your chosen country with the same backup regime as the rest of your estate.
Proof for your register
Each exercise leaves a dated record: what ran, how long it took, what failed and what was fixed. That record goes into your ICT third-party register and in front of your auditors. When you decide to leave a provider for good, the plan becomes the project; see leaving a SaaS. To start, book a call.