top of page

Cloud Migration Checklist: 12 Steps for Small Businesses

Nav
11 minutes ago
9 min read

A cloud migration checklist is a step-by-step plan for moving your files, email, apps, and servers to the cloud without losing data or blowing the budget. For a small business it covers seven stages: set goals, inventory everything, choose a path per workload, lock down security, plan the data move, test, then cut over and tune costs.


cloud migration checklist

Here's the uncomfortable truth nobody puts on the cloud provider's homepage. Most cloud migrations that go wrong don't fail on moving day. Moving day usually goes fine. They fail three months later, when the first full invoice lands and it's bigger than the server you just retired, or when someone discovers the one folder that didn't come across was the one accounting needed for the audit.


TL;DR: Use the 12-step cloud migration checklist below. Spend most of your time on inventory and testing, not the move itself. Keep your admin accounts in your company's name. And set a budget alert on day one, because the cloud bills by the minute and it never gets tired.


Clipboard checklist used to plan a small business cloud migration step by step

Why You Need a Cloud Migration Checklist at All


Because the cloud is very good at doing exactly what you told it to, including the wrong thing, at scale.


AWS says it well in its cloud migration checklist for SMBs: "A proper cloud migration checklist helps you plan, prioritize workloads, and use modern tools to scale without disrupting day-to-day operations." The word doing the heavy lifting there is "plan." Nine out of ten messy migrations I've been called in to clean up skipped straight to the "move stuff" part.


A checklist forces the boring questions early. What depends on what? Who needs access on Monday? What happens if we have to roll back? Those questions are cheap on a Tuesday afternoon and very expensive on a Sunday night.


Business owner and IT lead planning cloud migration goals and inventory in a meeting

Phase 1: Plan Before You Move Anything


1. Write down why you're migrating


"Everyone's doing it" is not a goal. Pick one or two you can measure:


  • Retire a server that's hitting end of life (hello, Server 2012 R2 end of life)

  • Let people work from anywhere without a VPN

  • Stop paying for a server closet, its air conditioning, and its UPS batteries

  • Get real backups and disaster recovery without buying a second building


If you can't name the goal, you can't tell if the migration worked.


2. Inventory every app, file share, and dependency


This is the step that decides everything. List:


  • Every server and what runs on it

  • Every file share and who uses it

  • Every line-of-business app, and whether the vendor supports the cloud version

  • Every "little thing": scanners that email to a folder, scheduled scripts, the label printer in shipping


The label printer will be the thing that breaks. It's always the label printer.


3. Choose a path for each workload (the 7 Rs)


Not everything should move the same way. The industry uses the "7 Rs": rehost, relocate, replatform, refactor, repurchase, retire, and retain. For a small business, it usually boils down to four:


  • Repurchase: swap the on-premises app for a SaaS version (on-prem Exchange to Microsoft 365 is the classic).

  • Rehost: lift the server as-is into a cloud virtual machine. Fast, but you're still managing a server.

  • Retire: turn it off. Some of your servers exist out of habit.

  • Retain: keep it on-site. Some things, like certain shop-floor or medical equipment, are fine where they are.


4. Pick the platform and confirm it plays nice


For most of our clients the answer is Microsoft 365 plus Azure, or Google Workspace plus Google Cloud, or AWS for the app workloads. Confirm your core apps support it in writing. "Should be fine" from a sales rep is not writing.


Brass padlock representing MFA and admin account security set up before a cloud migration

Phase 2: Lock Down Security and Access First


5. Set up identity, MFA, and admin accounts before data moves


Security settings are much easier to build into an empty tenant than to bolt onto a full one. Before a single file moves:


  • MFA for everyone, admins first, no exceptions for the CEO (especially the CEO)

  • Separate admin accounts that aren't used for daily email

  • Conditional access so logins from strange places get challenged

  • Least privilege: people get access to what they need, not the whole drive


6. Keep the keys in your company's name


This one isn't on any of the top-ranking checklists, and it should be. Your cloud tenant, your global admin accounts, your domain registrar, and your billing account should belong to your company. Not to your IT provider. Not to the guy who set it up in 2019 and moved to Florida.


Your MSP gets its own named admin accounts with MFA. If you ever part ways, you disable theirs and keep working. If a provider insists on owning your tenant, call that what it is: a leash.


7. Map your compliance requirements


If you handle patient data, defense contract data, or card payments, HIPAA, CMMC, or PCI comes along for the ride. Pick cloud services and regions that support your framework, sign any required agreements (like a HIPAA business associate agreement), and turn on audit logging from day one. Retrofitting logs after an incident is like installing the security camera after the burglary.


External hard drive backup taken before migrating company data to the cloud

Phase 3: Move the Data Without Losing Any


8. Clean up and back up before you migrate


AWS again, and it's the best single line in their guide: "Clean, standardize, and back up your data before you move it."


In practice:


  • Delete or archive the "New Folder (7)" graveyard nobody has opened since 2017

  • Fix broken permissions now, or you'll migrate them

  • Take a full backup and test a restore before migration starts


Moving junk to the cloud doesn't make it less junk. It just makes it junk you pay for by the gigabyte.


9. Test with a pilot group


Move one department or one small workload first. Pick friendly users who will actually report problems instead of quietly emailing files to themselves. Test:


  • Can they open, edit, and share files?

  • Do the apps work, including printing?

  • Is performance OK from home and from the office?

  • Can you restore a deleted file?


Fix what breaks, then scale up.


10. Plan the cutover and the rollback


Schedule the big move for a Friday evening or weekend. Freeze changes on the old system. Update DNS and mapped drives. Keep the old server powered off but intact for at least a week. If Die Hard taught us anything, it's that you don't take the whole building offline without a way back out.


IT engineer monitoring cloud performance and costs after a migration

Phase 4: After the Move (Where Most Budgets Leak)


11. Monitor performance and fix the stragglers


The first two weeks after cutover are when the weird stuff shows up. Someone's Excel macro pointed at a server that no longer exists. The scanner is emailing into the void. Keep someone on point to catch these fast. Our help desk answers critical issues in under 15 minutes, and migration week is exactly when that matters.


12. Control costs from day one


Set budget alerts. Right-size virtual machines. Turn off test servers you forgot about. Review the bill monthly for the first six months.


This isn't paranoia. Flexera's 2025 State of the Cloud report found that "84% of respondents believe that managing cloud spend is the top cloud challenge for organizations today," and the report puts wasted cloud spend at 27%. Jay Litkey, Flexera's SVP of Cloud and FinOps, put it plainly: "To stay on budget and accurately forecast for future needs, organizations need to fine-tune how to track and manage their cloud spend."


Employee checking email after a Microsoft 365 email and file cloud migration

Email and Files: The Cloud Migration Most Small Businesses Actually Do


The top-ranking checklists are written for companies moving hundreds of apps. That's fine for them. For most businesses with 10 to 100 people, the real migration is smaller and more personal: email, shared drives, and maybe one line-of-business app.


Here's the short cloud migration checklist for that job:


  • Email. Move mailboxes, calendars, and contacts to Microsoft 365 or Google Workspace. Lower the DNS record TTLs a few days before cutover so mail flow switches fast. Set up SPF, DKIM, and DMARC on day one so your mail doesn't land in spam.

  • Shared drives. Map each old share to a SharePoint site, Teams channel, or shared drive. Rebuild permissions on purpose instead of copying 15 years of "just give everyone access."

  • Personal files. Redirect Desktop and Documents to OneDrive so laptops stop being the only copy of anything.

  • Shared mailboxes and distribution lists. Easy to forget. Painful when info@ stops receiving mail.

  • Mobile devices. Tell people ahead of time that their phone will ask them to sign in again. Otherwise your help desk gets 40 calls before 9am.


One more thing: Microsoft and Google both keep your data safe from their own outages. Neither one promises to save you from your own deleted folder or a ransomware sync. Add a third-party backup for the tenant. It's cheap, and it's the difference between "restored in ten minutes" and "gone."


Printed one-page cloud migration checklist on a desk

The One-Page Cloud Migration Checklist


If you want the whole thing on one screen, here it is. Print it, tape it to the server rack, and cross things off.


  1. Goals written down and agreed

  2. Full inventory of apps, shares, and dependencies

  3. A path chosen for each workload (repurchase, rehost, retire, retain)

  4. Platform confirmed with every app vendor

  5. MFA, admin accounts, and conditional access set up in the new tenant

  6. Tenant, domain, and billing owned in the company's name

  7. Compliance needs mapped, agreements signed, logging on

  8. Data cleaned, backed up, and a restore tested

  9. Pilot group moved and signed off

  10. Cutover scheduled, with a rollback plan and the old system kept intact

  11. Two weeks of close monitoring after cutover

  12. Budget alerts on, monthly cost review booked


If a line on that list makes you nervous, that's the line to spend more time on.


Paid and due bills next to a calculator, representing a surprise cloud bill after migration

The Surprise Bill Problem Nobody Warns You About


The single most common reason a new client calls us is a bill that's different every month. Usually it's their last MSP's invoice. Lately, it's their cloud invoice.


Here's my one strong opinion on this. Variable, surprise pricing is the biggest problem in how IT gets billed. A CFO can't forecast a number that moves every month based on usage nobody's watching. A careless cloud migration takes a fixed cost (a server you already paid for) and turns it into a meter that runs 24 hours a day. With 27% of cloud spend going to waste, that meter is often running on nothing at all.


The fix: decide up front what "normal" costs, alert on anything above it, and make it somebody's job to look.


That's how we run managed IT services: one flat monthly rate for our work, and a monthly look at your cloud bill so it doesn't grow a personality.


Founder of a small all-cloud business who may not need a cloud migration partner

When You Don't Need Us for This


I'd rather talk you out of a project than sell you one you don't need. Skip the MSP if:


  • You're under 10 people and already on Microsoft 365 or Google Workspace. You're basically migrated. Turn on MFA and a backup for the tenant, and you're in good shape.

  • You only need to move a small file share. A tech-comfortable person can move it to SharePoint or Google Drive over a weekend. Check the permissions afterward.

  • Your software vendor offers a hosted version and will migrate you for free. Take the deal and let them do it.


Bring in help when there's a server running Active Directory, a database, a line-of-business app, or compliance requirements. That's where a missed dependency costs real money.


Business owner thinking through common cloud migration questions

Straight Answers About Cloud Migration


What are the steps in a cloud migration checklist?


Set goals, inventory your apps and data, choose a migration path for each workload, set up security and admin accounts, plan compliance, clean and back up data, pilot test, cut over with a rollback plan, then monitor and control costs.


How long does a cloud migration take for a small business?


A simple email and file migration for a 20 to 50 person office often takes two to six weeks, most of it planning and testing. Server and app migrations take longer, depending on how many dependencies turn up in the inventory.


What are the 7 Rs of cloud migration?


Rehost, relocate, replatform, refactor, repurchase, retire, and retain. They're options for how to handle each workload, from moving it as-is to replacing it with a SaaS product or shutting it off.


What is the biggest risk in cloud migration?


For small businesses, it's usually missed dependencies and cost overruns, not the cloud itself. Flexera's 2025 report found 84% of organizations call managing cloud spend their top cloud challenge.


Do I need to back up data before migrating to the cloud?


Yes. Take a full backup, test a restore before you start, and keep the old system intact for at least a week after cutover in case you need to roll back.


Is the cloud more secure than an on-premises server?


It can be, if you set it up right: MFA, separate admin accounts, conditional access, logging, and backups. A cloud tenant with weak passwords and no MFA is less secure than a patched server in a locked closet.


IT support engineer on a headset helping a company plan its cloud migration

Still Stuck? Give Us A Call


If you're staring at a server closet and wondering what should move, what should retire, and what it'll cost every month afterward, give us a call at 410-703-3857 or send us a note. We'll run the inventory, map the dependencies, and give you a flat price for the project before anything moves.


And yes, we'll find the label printer before it finds you.


Comments


bottom of page