Skip to content
Hosting8 min readupdated 11/08/2026

Detect vendor lock-in and consciously manage dependencies

By Kevin Kröger, Geschäftsführer, Software und Plattformbetrieb

Verkabelte Server-Racks in einem Rechenzentrum
Header image: Unsplash
THE SHORT ANSWER

Vendor lock-in does not arise from simply using a provider, but rather from data formats, interfaces, identities, operating processes, contracts and a lack of in-house knowledge that are difficult to replace. Dependency can be chosen consciously if the benefits, path to change and follow-up costs are documented.

Where is the dependency hiding?

Don’t just check data exports. Relevant ties are also created through proprietary APIs, event services, role models, key management, monitoring, deployment, billing, and trained teams. Exporting as a file is not enough if relationships, history or permissions are lost. Therefore, for each critical service, note which data and functions can be transferred and what would have to be rebuilt when changing.

What questions belong in contract and architecture?

Contracts should clearly regulate termination, transition period, export scope, formats, support and costs. Technically, documented interfaces, separate business logic, automated data exports and a tested restart help. The EU Data Act requires information on switching procedures, porting methods, formats and known technical limitations for covered data processing services. The exact legal classification belongs in expert hands.

Does any specific platform feature need to be avoided?

No. A managed service can significantly improve security, availability and speed of development. What is crucial is a conscious calculation: What measurable advantage does the function bring, what alternative exists and how expensive would a later change be? Particularly critical data should be regularly backed up in a usable format and the exit should be tested using a realistic scenario.

Next steps

From the answer to implementation

Sources and basis

The central statements in this article were reviewed against the following primary sources.

Frequently asked questions

Is open source automatically free of vendor lock-in?
No. Operations, extensions, data models and lack of knowledge can also create strong bonds. Open source code can make switching easier, but does not guarantee it.
Do we need a full second provider for every service?
Not necessarily. The effort should match the risk. For critical services, documented exports, restarts, deadlines and a realistic exit plan are often the first sensible step.
Continue reading

More specialist articles about Hosting

Hosting

What would this look like in your organisation?

We apply the specialist assessment to your situation and clarify a concrete next step.

Request a meeting