01Assess the current system
Review access and documentation, and define which applications are included.
We assess the agreed system scope from the application through to operation: architecture, database access, interfaces, runtime behaviour and infrastructure use. Existing measurements, failure patterns and operating data help distinguish causes from symptoms. Findings identify which change addresses which bottleneck and how its effect can be checked.
| Area | Review question | Result | Basis |
|---|---|---|---|
| Application design | Which components depend on each other? | Dependency overview | Code and system documentation |
| Performance | Where do delays occur? | Findings for the workflows examined | Measurements and logs |
| Resources | Which capacity is being used? | Options for operating changes | Usage and billing |
| Data and connections | Which dependencies make changes difficult? | Migration prerequisites | Data model and interfaces |
A different cloud or a new server will not address every cause. We examine whether the problem lies in the application, data processing or the operating model.
Keeping the existing system can also be the outcome of the evaluation.
Before migration, applications, data flows, providers and administrative access are inventoried together. For DORA-related work, this can supply technical information for the information register and third-party assessment. The relevant business and control functions identify the evidence needed for the operating decision.
A change must remain manageable in ongoing operation.
The migration plan describes data transfer, dependencies, testing and a workable fallback. Register maintenance and technical migration use the same established system information.
An Azure environment may be an option. We consider existing infrastructure and other operating approaches before deciding on the technical setup.
The recommendation describes the prerequisites and consequences of the selected option.
The assessment produces a prioritised action plan. For a migration, we prepare the target environment, data transfer, interfaces and fallback path; the change then proceeds in agreed stages. After each change, functionality and operation are compared with the baseline. The result determines whether to begin the next wave or adjust the approach.
Review access and documentation, and define which applications are included.
Describe technical causes and prioritise possible changes.
Define work steps and test cases for the selected option.
After an agreed change, repeat the measurements defined for the assessment.
Cost assessment connects resources with actual use: which instances run continuously, how storage and computing capacity are used, and which environments must remain available. This can identify potential changes such as appropriately sized resources, suitable storage classes or scheduled operating hours. Their value is assessed against performance and operational requirements.
A provider change involves more than exporting data. We identify provider-specific databases, interfaces, identity services and operating tools, and the sequence for replacing them. The exit plan describes which data and configuration will move, which replacement components are needed and how the target environment’s functionality can be checked.
Evaluation provides a basis for changes. Whether T-NEX then handles implementation or ongoing operation is defined as a separate scope.
| Question | Evaluation | Hosting |
|---|---|---|
| What is the goal? | Evaluate the current setup and plan changes | Operate an application under the agreed model |
| What is agreed? | Assessment scope and deliverables | Operating services and responsibilities |
Tell us which application is involved and why you need a review. We will agree what should be examined.
DORA since 17 January 2025: scope, ICT risk, incident reporting and third parties, with primary sources and implementation checks.
The DORA register of information: record contracts, identifiers and supply chains using the EU templates and BaFin requirements.
The ninth MaRisk amendment has applied since 30 June 2026. Changes from the previous version and implementation checks for institutions.