CORELYNK

Connecting Business and Technology...

Guide

Cloud Migration Checklist for SMBs

A practical, engineer-written checklist for small and mid-sized businesses planning a move to the cloud — from assessment and planning through cutover and post-migration support.

Cloud migration goes wrong for predictable reasons: an incomplete inventory, an undefined budget, unclear downtime expectations, and identity or backup gaps discovered after go-live. None of these are technical surprises — they are planning gaps.

Use the checklist below to work through each phase in order. The first two phases (assessment and planning) determine most of the outcome, so treat them as real work rather than paperwork.

1. Assessment — know what you actually run

Most failed migrations fail here. Before a single workload moves, inventory everything and grade it for cloud readiness.

  • List every server, application, and database, with owners and business criticality
  • Document current licensing (Windows Server, SQL, line-of-business apps) and renewal dates
  • Map application dependencies — what talks to what, and on which ports
  • Baseline performance: CPU, RAM, storage IOPS, and peak usage windows
  • Measure internet bandwidth and identify sites that need a circuit upgrade first
  • Flag legacy apps that cannot move as-is and need replacement or re-hosting

2. Planning — goals, budget, and success criteria

A migration without a written definition of success turns into an open-ended project. Fix the scope early.

  • Write the business driver: cost, resilience, remote work, compliance, or an aging server refresh
  • Set a target monthly cloud spend and compare it against current hardware + maintenance costs
  • Agree on acceptable downtime per workload (RTO) and acceptable data loss (RPO)
  • Prioritize workloads: start with low-risk, high-value systems such as file shares and email
  • Assign an internal decision maker and a technical point of contact
  • Build a rollback plan for every phase before scheduling it

3. Choose the migration approach per workload

Not everything belongs in the same bucket. Grade each application against these five options.

  • Rehost (lift and shift) — fastest path for stable servers with no code changes
  • Replatform — move to managed databases or app services to cut admin overhead
  • Repurchase — swap a legacy app for a SaaS equivalent (accounting, CRM, ticketing)
  • Refactor — rebuild only when the business case clearly justifies the spend
  • Retire or retain — decommission unused systems and keep anything blocked by compliance on-premises

4. Security, identity, and compliance

Cloud is not secure by default. Identity and backup are the two areas SMBs most often get wrong.

  • Enforce multi-factor authentication on every administrative and user account
  • Apply least-privilege roles — no shared global admin accounts
  • Encrypt data at rest and in transit, and document where regulated data lives
  • Configure independent, tested backups — cloud replication is not a backup
  • Enable centralized logging, alerting, and endpoint protection from day one
  • Confirm HIPAA, PCI, or contractual requirements are met before go-live, not after

5. Migration runbook and cutover

Run the move like a project with a timed script, not an all-nighter improvised on a weekend.

  • Pilot with a small user group and a non-critical workload first
  • Pre-seed large data sets ahead of the cutover window to shorten downtime
  • Write a minute-by-minute cutover runbook with owners and go/no-go checkpoints
  • Schedule cutovers outside business hours and notify users in advance
  • Validate DNS, email routing, printing, VPN, and line-of-business app access immediately after cutover
  • Keep the source environment intact until validation is signed off

6. Post-migration — optimize and support

The first 90 days determine whether the migration saves money or quietly inflates your bill.

  • Right-size instances and storage tiers after two to four weeks of real usage
  • Set budget alerts and review cloud spend monthly
  • Decommission on-premises hardware and stop paying for unused licenses
  • Run a restore test from backup to prove recovery works
  • Document the new environment and train staff on changed workflows
  • Move to proactive monitoring and managed support so issues surface before users report them

Common mistakes to avoid

  • Moving everything at once instead of phasing by risk
  • Assuming the cloud provider backs up your data — most do not, by default
  • Skipping bandwidth checks and discovering the office circuit is the bottleneck
  • Leaving legacy admin accounts and old VPN rules in place after cutover
  • Never right-sizing after go-live, then paying twice what you budgeted

Want this checklist run for your business?

CoreLynk engineers handle the assessment and planning phases with you — no call center, direct access to the people doing the work.