Exit strategy
In shortA clause in a contract is a guess. A completed export is proof.
Almost every large cloud contract contains an exit clause. Almost none has ever been used. That is the heart of the problem: a clause describes what should happen. It says nothing about what actually happens.
What a credible exit strategy contains
A full export, performed. Not requested, not promised — pulled, loaded into a different tool, and checked. Write down what is missing. That list is the real inventory.
A named destination. "We would take something else then" is not a strategy. A specific product, a rough effort estimate, a contact.
A timeline. Realistically, how long does the switch take, from decision to switching the old system off? If nobody can answer, that is the answer.
A trigger. When would you actually go through with it? A price rise above X per cent, the loss of the adequacy decision, an outage over Y hours. Without a trigger, nothing happens until it is too late.
What the law now requires
For financial firms, DORA has required documented exit plans for critical ICT providers since January 2025 — with testing. The EU Data Act obliges cloud providers to support a switch and has abolished switching charges. See EU Data Act.
Anyone in a regulated sector has to do this anyway. Everyone else should, because it is the cheapest insurance in this entire field.
The side effect nobody mentions
A rehearsed exit changes the next contract negotiation more than any argument. Not because you threaten anything. Because both sides know it would be possible.