Skip to content
AEGRYN
← Terug naar Blog

Strategie

Cloud Migration and SaaS Architecture: The Operational Guide for Leaders

Migrating to the cloud or refactoring a SaaS architecture is not just an IT project. This operational guide covers critical decisions: hyperscaler selection, migration strategy (lift-and-shift vs. refactoring), data sovereignty, NIS2/GDPR compliance, technical debt management, and the impact on company valuation.

10 juli 2025 11 min leestijd

Cloud migration has become a rite of passage for European tech companies looking to scale, modernise their stack, or prepare for a transaction. But between the cloud-native imperative and the operational realities of a migration, there are many decisions to make — with direct consequences for the company's transferable value.

Lift-and-shift or refactoring: choosing the right strategy

Lift-and-shift (or rehosting) moves the existing application to cloud infrastructure without modifying its architecture. It is the fastest route, the least risky in the short term, and the one that delivers the fewest operational gains. It suits companies that need to exit an on-premise data centre quickly or whose application is stable and cheap to operate. Refactoring (or re-architecting) revisits the application architecture to adapt it to cloud constraints and advantages: stateless services, microservices, event-driven architecture, auto-scaling. This approach maximises long-term gains — cost-at-usage, resilience, time-to-market — but requires significant investment in engineering time and change management. A third path, often underestimated, is replatforming: migrating the application by adapting certain components (replacing a managed database with RDS/Cloud SQL, moving from an application server to a PaaS service) without rethinking the complete architecture. This is often the best cost/value trade-off for growth-stage tech SMEs.

Hyperscaler or sovereign cloud: the data sovereignty challenge

The European cloud market is dominated by three American hyperscalers: AWS, Microsoft Azure and Google Cloud Platform. They offer mature services, global reach and an unmatched tool ecosystem. But for companies processing personal data, health data, government data or data subject to strict sectoral obligations, their use creates growing regulatory risks. The US Cloud Act (2018) authorises American authorities to demand access to data stored by American providers, even when that data is physically in Europe. This contradiction with the GDPR fuels an unresolved legal debate since the Schrems I and II rulings. Sovereign alternatives exist: OVHcloud, Scaleway and Outscale (a Dassault Systèmes subsidiary) in France, with ANSSI's SecNumCloud qualification as the reference; IONOS and Hetzner in Germany (BSI C5 certification); Exoscale in Switzerland. For companies seeking to certify NIS2 compliance or qualify their data in the context of a transaction or public investment, the choice of cloud infrastructure has become a strategic rather than merely technical decision.

SaaS architecture: the patterns that define value

A well-designed SaaS architecture stands out not just for its technical performance — but for its transferability, its marginal cost of operation, and its ability to evolve without accumulated technical debt. Here are the patterns that directly impact valuation: **Native multi-tenancy vs. isolation-based multi-tenancy.** A native multi-tenant architecture (shared database with schema-level or row-level security isolation) reduces per-customer operational cost and improves margins. A silo architecture (dedicated instance per customer) offers more isolation and suits high-value enterprise clients, but generates higher fixed costs. The choice directly impacts LTV/CAC ratio and valuation multiples. **API-first.** An API-first architecture decouples frontend from backend, facilitates third-party integration, and opens the path to data monetisation via partner APIs. It is also the prerequisite for a microservices architecture or a transition to a platform model. **Observability and SLOs.** The ability to measure performance, define Service Level Objectives and produce uptime reports has become a due diligence criterion for acquirers and investors. A platform without structured monitoring (Datadog, New Relic, OpenTelemetry) is perceived as an operational risk.

NIS2 and GDPR compliance: infrastructure under regulatory constraint

The NIS2 directive, transposed into European national laws since October 2024, imposes new obligations on essential and important entities: cybersecurity risk management, incident notification within 24 hours, supply chain security, and personal liability for executives in case of non-compliance. For SaaS publishers, this translates into concrete infrastructure requirements: encryption at rest and in transit, access management (IAM, MFA, least-privilege principle), logging of access and operations, regular penetration testing, and a documented and tested business continuity plan (BCP). These requirements are not just compliance constraints — they constitute a commercial differentiator vis-à-vis large accounts and the public sector, and a qualification criterion in M&A due diligence processes. A SaaS publisher that can demonstrate NIS2 compliance significantly reduces the perceived risk for an acquirer.

Managing technical debt in a migration

A cloud migration is often an opportunity to surface accumulated technical debt — and sometimes to make it worse if poorly managed. The main sources of debt in migration projects are: dependencies on undocumented legacy systems, hardcoded infrastructure configurations (hardcoded credentials, magic numbers), the absence of IaC (Infrastructure as Code with Terraform, Pulumi or CDK), and non-auditable manual deployment processes. A successful migration integrates from the outset a comprehensive dependency inventory, an IaC strategy that versions infrastructure as code, and a CI/CD pipeline that automates tests and deployments. These practices reduce operational risk, facilitate the onboarding of new engineers, and constitute a strong signal of technical maturity for acquirers. Within the CIFSO 5000 certification framework, the Integrity dimension evaluates precisely this level of maturity: presence of IaC, test coverage, architecture documentation, and the ability to deploy and rollback in an audited manner.

Cloud migration and transferability: what acquirers see

From an acquirer's or investor's perspective, the quality of cloud infrastructure is a direct indicator of the company's organisational quality. Positive signals include: infrastructure fully managed in IaC, clearly separated development, staging and production environments, proactive monitoring with alerts, tested backups, and up-to-date architecture documentation. Negative signals are equally telling: unrevoked personal cloud accesses from former employees, cloud billing that balloons without cost allocation tracking, default security configurations that have not been hardened, or a critical dependency on a single engineer who holds the accesses. A well-documented and well-conducted cloud migration is therefore doubly strategic: it improves operations and resilience in the short term, and it increases the transferable value and defensibility of that value in the medium term. This is exactly the objective that CIFSO 5000 Certification allows to materialise and make verifiable.

IA

Dit artikel is geschreven met behulp van kunstmatige intelligentie en beoordeeld onder de redactionele verantwoordelijkheid van Aegryn. Overeenkomstig artikel 50 van de EU AI Act nemen wij de redactionele verantwoordelijkheid voor deze inhoud op ons.

Insights Aegryn

Recevez chaque semaine les analyses Aegryn — M&A, valorisation, tech, CIFSO.

Klaar om uw actief in te dienen of de catalogus te raadplegen?