Government cloud professional services must reconcile public mission, law, procurement, security authorization, records, accessibility, continuity and long-lived operations. A supplier can assess, design, migrate and transfer capability, but the public authority remains accountable for its data, service and risk decision. This plan is jurisdiction-neutral in structure and uses current U.S. federal sources as examples. Agencies must apply their own national, regional and sector requirements.
Use it with the government cloud implementation checklist, the government cloud FAQ and the local government cloud delivery plan. As of July 2026, FedRAMP is transitioning through its 2026 rules and 20x certification paths; teams should verify current official dates and applicability during procurement rather than copying an older authorization template.
Define mission, service and authorization boundaries
Choose a public service or internal mission capability and document users, statutory authority, data, critical transactions, baseline performance, accessibility and continuity. Inventory applications, interfaces, identities, records, suppliers and facilities. Classify data and impact under the applicable scheme. Draw the system and authorization boundary, including provider services, agency configurations and external connections. Broad cloud-first language cannot replace a workload decision or an authorizing official's acceptance of residual risk.
Specify professional-service work packages: discovery, cloud strategy, landing environment, control implementation, authorization evidence, migration, modernization, data transfer, testing, cutover, operations and capability transfer. State deliverables, government inputs, acceptance and decision authority. Separate reusable platform controls from workload controls. A provider authorization package can supply evidence, but the agency must assess its own use, configuration and inherited-control assumptions.
| Work package | Government decision | Supplier evidence |
|---|---|---|
| Assessment | Retain, retire, replace or migrate | Dependency and disposition record |
| Landing foundation | Approved identity, network and policy pattern | Deployed controls and test results |
| Authorization | Residual risk and permission to operate | Current control evidence and gaps |
| Migration | Cutover and rollback authority | Reconciliation, restore and rehearsal |
| Handover | Operating owner and support model | Runbooks, training and access transfer |
Procure control, evidence and exit
Evaluate cloud services against data location, personnel, subcontractors, incident notification, government access, cryptography, vulnerability handling, continuous monitoring, records, accessibility, service levels, price, portability and termination. Require current evidence at the appropriate impact level. In U.S. federal use, FedRAMP authorization is reusable security evidence, not a government-wide authorization to operate for every agency use. Document agency-specific decisions and conditions.
Contract professional services for knowledge transfer, government-owned repositories and accounts, transparent subcontractors, deliverable rights, security duties, staff changes, audit cooperation and termination assistance. Define how provider changes and certification status affect the workload. Avoid proprietary management layers unless their value and export path are tested. Price the exit, including data export, replacement support, record retention and credential removal, before dependency becomes leverage.
Build the landing foundation and shared controls
Establish organization structure, identity federation, privileged access, network patterns, keys, secure configuration, logging, vulnerability management, backup, cost allocation, policy enforcement and deployment automation. CISA's Cloud Security Technical Reference Architecture addresses shared services, migration and cloud security posture management. Tailor architecture to jurisdiction and risk. Protect the control plane and infrastructure pipeline, and separate routine administration from emergency access.
Map each applicable NIST SP 800-53 or local control to provider, platform, workload or organization responsibility and define assessment evidence. Confirm inherited controls are available and current. Automate configuration evidence where reliable, but preserve human review for contextual risk. Continuous monitoring should detect drift and provider change, not merely generate monthly files. Define a plan for gaps and expirations before onboarding workloads.
Model whole-life public cost
Estimate discovery, foundation, provider usage, migration, dual operation, authorization, network, logging, security, data transfer, licenses, accessibility, training, support, modernization, records and exit. Separate one-time and recurring cost and model demand ranges. Include government employee time and enduring oversight. Compare with avoidable current-state cost, not sunk facilities or contracts that remain. Publish assumptions and contingency appropriate to procurement rules.
Create unit cost for the mission service, such as application, case or transaction, alongside reliability and service quality. Allocate shared platform cost transparently. Set budgets and anomaly response with mission-safe escalation; automatic shutdown can harm the public. Review commitments only after stable use is known. Track realized savings after legacy retirement, because a migrated workload running beside its predecessor usually increases total cost.
Migrate in authorized, recoverable waves
Pilot a bounded but representative workload through the real identity, policy, deployment, logging and authorization path. Test accessibility, performance, denial, incident, restore, records export and support. Update the landing pattern from findings. Group later waves by dependency, data and operational risk. Define readiness, freeze, synchronization, reconciliation, traffic shift, observation, rollback and communication for each cutover.

Plan continuity for provider, network, identity and agency dependency failures. Set recovery objectives from public impact and run timed restore or failover exercises. Keep protected backups and necessary offline or manual procedures. Coordinate incident roles and reporting with providers before release. NIST SP 800-144 emphasizes deliberate security and privacy planning; migration urgency does not reduce the need to understand outsourced risk.
| Acceptance area | Proof | Unacceptable shortcut |
|---|---|---|
| Security | Configured and assessed control evidence | Provider logo alone |
| Continuity | Timed restore and dependency exercise | Backup success email |
| Records | Searchable export with retention metadata | Unstructured final archive |
| Accessibility | Representative user and standards testing | Automated scan only |
| Operations | Government-led incident and deployment rehearsal | Supplier presentation |
Transfer operations and preserve public accountability
Have government staff lead deployment, access review, incident triage, restore, cost review and supplier escalation before acceptance. Transfer source, infrastructure definitions, control mappings, evidence, configuration, asset records, runbooks, contracts, licenses and known risks. Remove unnecessary supplier access and time-bound continuing support. Establish change, vulnerability, provider review and reauthorization triggers. A successful migration leaves an accountable public operator, not permanent dependence on project specialists.
Measure mission outcome, accessibility, reliability, security, recovery, cost, staff capability and user burden. Review public complaints and service failures, not only infrastructure health. Retire legacy systems and permissions through controlled records disposition. Keep exit evidence current and periodically test export or replacement assumptions. Government platforms may outlive contracts and leadership terms, so decision records and durable ownership matter.
A ten-step government cloud work package
Use one integrated work package per migration wave, signed by mission, technology, security, records, accessibility, procurement and operations owners. The sequence should reference the current jurisdictional authorization process and contract. Reusable provider evidence can accelerate review, but every step still needs evidence about the agency's actual configuration and use.
- Approve mission outcome, service owner, impact classification, data categories, records duties, accessibility and continuity baseline.
- Inventory workload components, interfaces, identities, providers, licenses, facilities, operators and dependencies inside the proposed boundary.
- Choose disposition and target service model, documenting retained legacy dependencies and why cloud is appropriate for this workload.
- Procure provider and professional services with current assurance evidence, transparent subcontractors, change duties, price and tested exit terms.
- Build the landing foundation through government-owned identity, account, network, key, policy, logging, backup and deployment patterns.
- Map provider, platform, workload and organizational controls; assess inherited evidence, agency configuration and unresolved plans of action.
- Forecast migration, dual operation, authorization, government labor, recurring usage, support, records and retirement under demand ranges.
- Pilot through the production authorization path and test access denial, accessibility, load, incident, restore, export and billing allocation.
- Cut over with freeze, synchronization, reconciliation, traffic shift, observation, communication and named rollback authority.
- Have government staff lead operation and recovery, retire legacy access and infrastructure, and maintain continuous monitoring and exit evidence.
Close the wave only after the asset and authorization records match production, supplier access is reviewed, records can be retrieved, continuity objectives are proven and old spend has an approved retirement date. Feed control gaps and support findings into the shared landing pattern before the next workload repeats them.
Key takeaways
- Scope professional services around a named public mission and authorization boundary.
- Treat provider certifications as reusable evidence, not a universal agency risk decision.
- Build shared controls and map every remaining responsibility explicitly.
- Include authorization, dual running, government labor and exit in whole-life cost.
- Require government-led operational rehearsals before handover acceptance.
Frequently asked questions
Does FedRAMP authorization give an agency an ATO?
No. It supplies reusable assessment evidence and a federal authorization designation. The agency still makes and documents its authorization decision for the specific system and use.
Does in-country hosting guarantee sovereignty?
No. Consider legal control, operators, support access, encryption keys, subcontractors, dependencies, export and the authority to continue or terminate service.
When should the legacy system be retired?
After reconciliation, observation, continuity acceptance, records disposition and rollback decision are complete. Set the retirement criteria before migration so parallel operation does not become indefinite.
Plan records and public-information obligations at architecture time. Identify official records, retention schedules, legal holds, search, export, metadata and disposition authority across provider logs, collaboration tools, databases and backups. A cloud deletion control must not destroy records still subject to retention, while indefinite backups should not defeat lawful disposal. Test retrieval with records personnel before accepting the service.
Accessibility applies to the migrated public service and internal administrative tools. Preserve accessible authentication, forms, documents, support and status communication during cutover and degraded operation. Include disabled users and staff in representative tests. A technically successful migration can still reduce public access when identity, CAPTCHA, mobile-only features or outage notices create new barriers. Track accessibility defects with the same ownership and release discipline as security findings.
Govern supplier concentration at portfolio level. Map common provider, identity, network, key, monitoring and skills dependencies across agencies or departments. A workload may appear recoverable while many services share one control-plane failure. Use coordinated incident exercises, capacity scenarios, current contacts and tested export for material concentration. Multicloud branding alone does not resolve shared software, personnel or contractual dependencies.
Conclusion
Government cloud professional services are valuable when they leave a public body with a secure, authorized, recoverable and governable mission service. Define the boundary, procure evidence and exit, build shared controls, migrate in rehearsed waves and transfer operating capability. Public accountability remains with government even when infrastructure and delivery expertise are supplied by others.