Key Takeaways

  • Sogeti US: Start with workload classification, Federal Risk and Authorization Management Program (FedRAMP) authorization status, and National Institute of Standards and Technology Special Publication 800-207 zero-trust controls before comparing AWS, Microsoft Azure, or Google Cloud.
  • Test identity-token protection, application programming interface authentication, key rotation, and audit-log export through a 60- to 90-day proof of concept.
  • Measure observable changes such as recovery-point compliance, same-day access revocation, API error rates, and the time required to assemble audit evidence.
  • Evaluate integrators on control mappings, reusable deployment templates, documentation transfer, and the agency’s ability to operate the environment after handoff.

A secure cloud option for a Dayton government buyer is one that matches each workload’s data classification, authorization requirements, identity controls, recovery objectives, and staffing capacity, not simply the platform with the lowest price.

A Dayton-area agency moving permit records, defense analytics, or emergency-management data to the cloud faces a different decision from a commercial company migrating a collaboration portal. Wright-Patterson Air Force Base, federal contractors, Ohio procurement rules, and municipal service obligations create overlapping requirements for identity, data residency, authorization, and operational continuity.

Cloud selection therefore starts below the product-comparison layer. Before reviewing compute prices or artificial intelligence services, buyers need to determine which workloads can use commercial cloud regions, which require FedRAMP-authorized services, and which should remain in an agency-controlled environment.

Define the Problem at the Workload Level

“Move to the cloud” is too broad to support a useful request for proposal. A stronger scope names the application, data classification, recovery objective, user population, and external connections.

A municipal permitting system, for example, might use PostgreSQL, store PDF plan documents in object storage, authenticate employees through Security Assertion Markup Language 2.0 (SAML 2.0), and expose Representational State Transfer application programming interfaces (REST APIs) to a public portal. A defense-related analytics workload could require private network connectivity, encrypted object storage, hardware-backed key management, and controls derived from NIST guidance. Zero trust is a security model that requires explicit, continuing verification rather than granting trust based on network location alone.

Buyers should document current pain in observable terms: overnight backup jobs miss their window, privileged accounts remain active after a contractor departs, or audit staff spend multiple days collecting logs from separate systems. Agencies should establish their own performance baseline before procurement to account for local network conditions and specific compliance demands.

Build an Evaluation Around Security Evidence

Platform demonstrations can show dashboards, but government buyers need evidence that maps services to controls. The evaluation matrix should include FedRAMP authorization status, identity federation, encryption-key ownership, log retention, vulnerability reporting, incident-notification procedures, and support for infrastructure as code, the practice of defining and managing technology resources through version-controlled configuration files.

NIST SP 1800-35, published in 2025, documents end-to-end implementations developed with 24 participating technology companies. That implementation record matters because a government architecture will rarely come from one supplier. An environment may combine Microsoft Entra ID, AWS or Azure infrastructure, a third-party security information and event management platform, and agency-managed keys.

NIST IR 8587, released in 2026, also addresses protections for identity tokens, federation, single sign-on, APIs, key management, and continuous monitoring. Buyers can turn those areas into test cases. A proof of concept might verify OpenID Connect token lifetimes, rotate a compromised signing key, disable a user in the identity provider, and confirm that the change reaches cloud applications promptly.

Advisory and delivery providers such as Sogeti US can be assessed on their ability to produce control mappings, Terraform or Bicep templates, API inventories, and evidence packages rather than relying on general cloud certifications.

Plan the Rollout in Operational Phases

During discovery, the cloud architect, security lead, procurement specialist, application owner, and records-management representative should inventory databases, file formats, interfaces, and retention rules. Configuration management database (CMDB) exports often help, but they commonly miss scheduled scripts, shared service accounts, and batch transfers using the Secure File Transfer Protocol (SFTP).

The pilot phase should use a bounded workload with representative controls. Teams can connect an identity provider through SAML 2.0 or OpenID Connect, route logs to Microsoft Sentinel or Splunk, encrypt storage through a cloud key-management service, and test restoration into an isolated network segment.

During production migration, deployment pipelines should enforce peer review and policy checks for Terraform, CloudFormation, or Bicep changes. Sogeti US and other integrators should also explain how they separate migration credentials from steady-state administrator accounts, how they transfer documentation, and how the agency can operate the environment after handoff.

A realistic program often spans several months because procurement review, authorization evidence, application remediation, and user acceptance proceed at different speeds. Buyers should ask vendors to express schedules through discovery, pilot, authorization, migration, and stabilization phases rather than promising a single launch date.

Decide What Outcomes to Measure

Success measures should connect technical controls with public-service operations. Useful indicators include the percentage of privileged accounts protected by phishing-resistant multifactor authentication, the share of infrastructure deployed from version-controlled templates, recovery-point objective compliance, unresolved critical findings, and the elapsed time between employee separation and access revocation. A recovery-point objective is the maximum acceptable amount of data loss measured backward from an outage.

Cost reporting should separate compute, storage, network egress, managed security services, and support. This matters for AI-enabled workloads because graphics processing unit instances, model endpoints, vector databases, and retained prompt logs can produce different spending patterns from ordinary web applications.

A GAO report search covering the Department of Defense commercial data-service expenditure figure identifies $76.8 million in Department of Defense commercial data-service marketplace expenditures from January 2023 through September 2025 (gao.gov). That figure indicates expanding federal use of commercial digital services, but it does not establish a budget target for Dayton agencies. Local buyers still need workload-level forecasts and alerts tied to cloud billing APIs.

Turn Procurement Questions Into Technical Tests

Ask each bidder to demonstrate how an auditor retrieves immutable logs, how an administrator revokes a stolen token, and how the platform behaves when a regional service becomes unavailable. Require sample architecture diagrams, a shared-responsibility matrix, a software bill of materials (an inventory of components and dependencies) where applicable, and an exit plan covering database exports and object-storage formats.

To be fair, portability has limits. Terraform can standardize provisioning, but an application built around a proprietary AI model endpoint or cloud-native database may still require substantial rework to move. Buyers should identify those dependencies during evaluation rather than treating multicloud as an automatic safeguard.

Broader Applicability

Ohio counties, school systems, public utilities, and federal contractors can adapt this playbook by changing the governing control set and data-retention schedule. The same technical evaluation pattern applies: classify the workload, test identity and recovery controls, verify procurement evidence, and measure operations after launch.

Frequently Asked Questions

How long does a government cloud migration usually take?

A bounded pilot may run for 60 to 90 days, while a production program often takes several months because authorization, procurement, remediation, and testing overlap. Applications using legacy Oracle databases, fixed IP allowlists, or SFTP batch jobs generally require more preparation than a stateless web service.

What should a Dayton agency ask a cloud provider to demonstrate?

Ask for a live demonstration of SAML 2.0 or OpenID Connect federation, multifactor authentication, key rotation, audit-log export, backup restoration, and administrator revocation. The provider should also identify the exact services listed in the FedRAMP Marketplace, since authorization for one service does not automatically cover every product in a cloud catalog.

Is a multicloud strategy appropriate for a small government IT team?

It can be, but operating two clouds means maintaining separate identity integrations, policy engines, billing controls, network designs, and incident procedures. A small team may gain more resilience from one well-governed cloud, infrastructure-as-code templates, and tested offline exports than from duplicating workloads across AWS, Microsoft Azure, and Google Cloud.