The Migration Isn’t Expensive. The Migration Nobody Planned Is Expensive.
The typical failure pattern: a workload is lifted and shifted to the cloud with its on-premises sizing intact, nobody revisits that sizing after go-live, and the invoice six months later reflects paying cloud prices for on-premises assumptions. Flexera’s 2026 State of the Cloud Report found organizations waste an average of 29% of cloud spend — the highest figure in five years — driven in large part by workloads provisioned without an optimization pass.
Compliance makes the miscalculation worse. Data-residency and processing-location requirements under HIPAA and CMMC/DFARS 252.204-7012 constrain which regions, services, and even which specific cloud configurations are usable — a decision that has to be made during assessment, not discovered during a compliance audit after the migration is done.
Armorstack’s migration methodology treats assessment as an engineering deliverable, not a sales formality — because the decisions made in week one determine whether a migration finishes on budget or turns into a multi-quarter cost-optimization project.
Four Phases. A Sign-Off Gate at Each One.
Assessment
Workload dependency mapping, data-gravity analysis (which datasets are too large, too latency-sensitive, or too regulated to move casually), and a data-residency review against HIPAA and CMMC/DFARS requirements — before a single workload is scheduled.
Pilot
One low-risk, high-visibility workload moves first — typically file services, email, or a non-production environment — to validate the runbook, the rollback plan, and the performance assumptions before committing the rest of the environment.
Migrate
Workloads move in dependency order, with a defined cutover window, a tested rollback procedure, and a freeze on unrelated changes during the migration window.
Optimize
Instance right-sizing, reserved-capacity or savings-plan commitments, and storage-tier review happen 30-60-90 days after cutover — the phase most migrations skip, and where most wasted spend actually gets recovered.
Why Sequencing Matters
Skipping the pilot phase is the single most common cause of migration overruns we’re brought in to fix — an assumption that held for a test workload breaks at scale, and the fix costs more mid-migration than it would have cost in week one.
What Migrates First — and What Waits
File & Collaboration Workloads
Usually the lowest-risk, highest-visibility first move — validates identity, networking, and access patterns before anything with a compliance obligation moves.
Email & Messaging
A well-understood migration path with mature tooling; a common second wave once identity and networking are proven in the pilot.
Non-Production / Dev-Test
Low business risk, high learning value — a second proving ground for automation and infrastructure-as-code before production workloads are scheduled.
Line-of-Business Applications
Migrated in dependency order once their data stores, integrations, and compliance posture are mapped — rarely a “just lift it” candidate.
Regulated Data Stores (PHI / CUI)
Migrated last, and only after data-residency, encryption, and access-control requirements are validated against HIPAA or CMMC/DFARS 252.204-7012. Moving these first without that validation is the most common compliance mistake we see.
Legacy / VMware Workloads
Where a workload can’t move cleanly, Armorstack runs it in parallel through our VMware modernization track rather than forcing a risky rip-and-replace on a deadline.
Data Residency Isn’t Optional for Regulated Workloads
HIPAA doesn’t mandate that ePHI stay within a specific geography, but it does require a signed Business Associate Agreement with the cloud provider and documented safeguards wherever the data lives — an assessment step migrations frequently skip. CMMC 2.0 and DFARS 252.204-7012 are stricter: Controlled Unclassified Information may only be stored, processed, or transmitted in cloud environments that meet security requirements equivalent to the FedRAMP Moderate baseline, which rules out a meaningful share of default cloud configurations.
Armorstack’s assessment phase identifies which workloads carry these constraints before migration scheduling — not after. See our HIPAA Compliance and CMMC 2.0 Compliance pages for how this maps to your framework.
Optimization Doesn’t End at Cutover
The 30-60-90 day Optimize phase is where Armorstack applies FinOps discipline — instance right-sizing against actual utilization, committed-use pricing where usage patterns justify it, and storage-tier review. For a deeper look at where cloud spend actually leaks after migration, see our guide, The Hidden Costs of Cloud: A FinOps Guide for Enterprises.
Frequently Asked Questions
Ready to Migrate Without the Budget Surprise?
Assessment first. Pilot second. A committed timeline before a single workload moves.
Armorstack operates infrastructure for regulated industries: healthcare, financial services, manufacturing, and defense contractors. One contract. 24/7.