Exit
Vendor exit: bringing back data, access and operational capability in a controlled way
An exit does not begin with the termination notice. Critical relationships need return, migration and transition scenarios defined early.
9 minute read · Content as of 21.07.2026
Plan for orderly and unplanned exit
Contract end, service failure, a security incident, insolvency or geopolitical change can come with different lead times. For critical services, data export, substitute operation, knowledge transfer and a maximum transition period are prepared.
Offboarding ends with verifiable evidence
Access and keys are revoked, data is transferred and deleted according to agreed rules. Open incidents, retention obligations, subcontractors and remaining dependencies are explicitly closed out.
- data format, export time and completeness check
- accounts, tokens, certificates and remote access
- deletion and return evidence
- knowledge transfer, remaining obligations and final sign-off
Sources used
- ISO/IEC 27036-2:2022 – Requirements · ISO · 2022
- BSI Standard 200-4 Business Continuity Management · BSI · 2023
- Vendor, due diligence and exit patterns · KaitoSec