Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Preserve your data and customer continuity before access ends, then replace or retire the dependency with a controlled migration.
Capture before evidence disappears
- Save shutdown notices, dates, contract, export formats, APIs, invoices, data locations, subprocessors, retention, deletion, and support commitments.
- Inventory every workflow, integration, credential, domain, webhook, embedded link, customer promise, and unique vendor-held record.
- Run full exports with counts, hashes, relationships, attachments, timestamps, and documentation needed to interpret them.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Migrate, self-host, or retire? | Business value, replacement fit, data portability, security, time, and cost are compared. | Choose one owner and cutoff; avoid parallel systems without a reconciliation plan. |
| Freeze changes? | The final export cannot safely merge later vendor updates. | Announce a read-only or cutoff window, take the final export, and reconcile deltas. |
Proof that recovery worked
- Record counts, totals, files, relationships, and sample workflows match between vendor export and destination.
- Domains, webhooks, automations, credentials, links, and customer documentation point to the replacement.
- The vendor confirms deletion or contractual retention outcome after your verified archive exists.
Controls to put in place
- Maintain periodic usable exports and test them outside the vendor.
- Track critical vendors, exit time, data ownership, alternatives, and contract renewal dates.
- Avoid opaque identifiers and workflows that cannot be reconstructed elsewhere.
Export a representative vendor dataset, import it into a blank alternative, reconcile counts and attachments, rotate a webhook, and run one complete customer workflow.
Use counsel and privacy specialists when the vendor cannot return or delete data, enters insolvency, changes subprocessors, or ends service before contractual obligations are met.
What this means
This is a migration under a deadline, not a normal outage. Access, exports, APIs, support, and documentation may disappear before the final service date.
Secure your data and proof of ownership first. Then map behavior, dependencies, and customer commitments before choosing a replacement.
Warning signs
- A shutdown, end-of-life, acquisition, or account-termination notice arrives.
- Support slows down and key staff or documentation disappear.
- Export tools, APIs, billing, or renewals change unexpectedly.
- The provider stops accepting new customers or publishes a migration deadline.
- Your contract provides little notice or data-return help.
Recover now
First hour
- Verify the notice through an official channel. Record final service, export, billing, and support dates.
- Export immediately. Save raw data, files, contacts, consent, configuration, templates, logs, invoices, and account metadata.
- Preserve access. Confirm owners, 2FA, recovery methods, API keys, and payment status. Do not cancel early.
- Map dependencies. List every workflow, webhook, domain, customer promise, and automation that uses the vendor.
- Name the migration owner and decision date. Separate must-have behavior from convenient features.
This week
- Validate exports by opening files and counting important records.
- Ask the provider for deletion timing, export limits, redirects, forwarding, and migration assistance.
- Test replacement services with a copy of real-shaped, non-sensitive data.
- Plan the cutover, rollback window, customer communication, and old-data retention.
- Run both systems only when you can reconcile changes between them.
- Remove old integrations and credentials after the replacement is verified.
Verify recovery
- Required data, files, configuration, and consent records exist outside the vendor.
- The replacement performs every critical workflow.
- Record counts and financial totals reconcile.
- Domains, webhooks, automations, and customer links point to the replacement.
- Old billing and renewal are canceled only after cutover.
- The vendor confirms data deletion or retention according to the contract and law.
Prepare now
Portability
- Critical vendor data is exported on a schedule.
- Export files are tested and include metadata, status, and consent where needed.
- Templates, configuration, and automation logic exist outside the provider.
- Open formats and standard protocols are preferred for critical workflows.
Dependency
- Every critical vendor has a documented owner, contract, renewal, and exit path.
- The business knows the maximum acceptable migration deadline.
- A shortlist of alternatives exists for single-source services.
- Contracts address notice, data return, deletion, and transition support.
Practice
- A sample export has been imported into a different tool or local test system.
Common mistakes
- Waiting for a polished migration tool. Export access may degrade first.
- Canceling before the final export. Billing access can be tied to account access.
- Saving only the obvious data. Configuration, consent, suppression, logs, and identifiers matter.
- Choosing a replacement from feature lists. Test the critical workflow and data model.
- Running two systems without reconciliation. Both copies drift.
Sources
- CISA: Reducing ICT supply-chain risk in small businesses
- CISA: Resilient supply-chain plan for SMBs
- NIST: Contingency planning