If you’re evaluating data sovereignty, DORA / NIS2 compliance, cloud repatriation, sovereign AI, or a self-service platform for your developers — this is the engagement that turns the question into a written plan with numbers, owners, and a timeline.
Pairs with: all three Ænix platforms — the assessment names which one fits your scope, or says none of them does.
When the Platform Readiness Assessment fits
Buyers reach us with one of four pressures. The assessment addresses them as a single program.
Regulator and sovereignty pressure DORA (in force January 2025), NIS2, GDPR, sectoral data residency. Output: compliance-by-design map for your stack.
AI and analytics on sensitive data GenAI / inference workloads where data cannot leave the perimeter. Output: private-AI architecture options scoped to your model and data class.
Cloud repatriation and cost control Public-cloud bill outpacing predictability, FinOps mandate, repatriation in roadmap. Output: cost trajectory with caps and timeline.
Developer self-service and time-to-environment Environments that take weeks to provision, IAM/network/monitoring done by hand, multiple tools nobody owns. Output: time-to-environment baseline → target with a delivery plan.
What 14 days cover — four workstreams, one report
The assessment runs in parallel across four workstreams. Each has a named owner on our side, a defined deliverable, and a fixed window.
| # | Workstream | What we inspect | Deliverable |
|---|---|---|---|
| 1 | Inventory and platform maturity | Workloads (VMs / containers / databases), environments (dev / staging / prod), provisioning velocity, IaC coverage, GitOps maturity, CI/CD ownership | Current-state architecture map + maturity score across 8 dimensions |
| 2 | Sovereignty and regulator gap | DORA / NIS2 / GDPR / sectoral applicability, data residency mapping, encryption posture, supplier-risk concentration, audit trail | Compliance-by-design map: controls met, gaps, prioritized remediation |
| 3 | Cost and cloud-spend posture | Public cloud bill (last 12 months), commitment / reservation utilization, egress cost, repatriation feasibility per workload, FinOps maturity | Cost trajectory: current spend → 12-month target with caps, repatriation candidates ranked |
| 4 | Developer self-service and platform engineering | Time-to-environment (current SLA), provisioning friction points, golden-path coverage, internal documentation, platform-team capacity | Time-to-environment baseline + target metric, golden-path proposal, platform-team RACI |
Each workstream produces a 3-5 page section in the final report. The full report lands at the end of week 2 (or week 4 for the deeper variant).
Three outcomes you walk away with
1. Time-to-environment metric
Current: how long from “team needs an environment” to “environment is reachable, monitored, and secure”. Target: what it takes to bring that to hours, not weeks. Plan: the platform-engineering work that closes the gap, with effort estimates and a sequence.
2. Compliance-by-design map
A control-level map for the regulatory frameworks you operate under — DORA, NIS2, GDPR, sectoral. For each control: where you stand, what’s missing, what an architecture-level fix looks like, and which workloads it touches.
3. Cost and control trajectory
A 12-month spending plan with caps and a clear path between current public-cloud spend and a controllable hybrid or private-cloud posture. Repatriation candidates ranked by ROI. FinOps owner identified.
Who this is for — and who it’s not
Strong fit — at least four of these are true:
- You have your own product or platform engineering teams (not just an IT department)
- You handle sensitive data under regulator pressure (banks, insurance, public sector, telco, critical enterprise)
- You run multiple environments and internal teams that all need infrastructure
- You have a hybrid setup — on-prem + public cloud + legacy
- You have AI / ML use cases that can’t simply be lifted to a hyperscaler
- Your public-cloud bill or FinOps situation is a board-level concern
- You are actively hiring platform / SRE / DevOps / cloud architect roles
- You operate 24/7 critical systems
Not a fit:
- Small IT team running one or two systems
- No internal platform-engineering function and no plan to build one
- Goal is purely “save on licenses” — not faster delivery, not sovereignty, not control
If you’re not sure which side you’re on — the discovery call answers that for free before you commit to a paid engagement.
How the engagement runs
Day 0 — Discovery call (30 min, free) Confirm fit, narrow scope, identify executive sponsor and four workstream owners.
Day 1 — Kickoff workshop (90 min) Mutually-agreed objectives, access to artifacts (architecture docs, GitHub orgs, billing read-only, regulator scope).
Days 2-9 — Parallel workstream analysis Four engineers run the four workstreams. Daily async updates to your sponsor. Three short interviews per workstream with named owners on your side.
Day 10 — Findings checkpoint (60 min) Walk through preliminary findings; you correct or sharpen. We adjust before the final report.
Days 11-13 — Report drafting Written report assembled. All four workstreams, three outcomes, prioritized remediation, executive summary.
Day 14 — Executive readout (60-90 min) Final report handed over. Q&A with sponsor and selected stakeholders. Roadmap discussion: what would Phase 2 look like.
The 4-week variant adds: vendor-shortlisting workshops (where applicable), proof-of-concept scoping for repatriation candidates, and stakeholder interviews across two more business units.
Who actually does the work
The engagement is run by Ænix platform engineers — the team that builds and operates Cozystack in production for service providers, banks, and sovereign-cloud projects. Not seconded management consultants. Not a partner network handing the project off after the sale.
That matters because:
- We’ve made these architectural decisions on real production systems, not slides.
- Our recommendations come with implementation effort estimates we have actually paid.
- If you decide to engage us for Phase 2 implementation, the same engineers continue.
Ænix is the company behind Cozystack, an open-source CNCF Project. The Cozystack stack is the foundation we typically recommend — but the assessment is not a sales engagement for Cozystack. If your context fits a different stack, the report says so.
Pricing and engagement scope
14-day (focused)
Single workstream emphasis (sovereignty, OR cost, OR developer experience). Single business unit / domain. Written report and executive readout. On request
28-day (full)
All four workstreams in depth. Multi-BU stakeholder interviews. Vendor shortlisting for relevant components. PoC scoping. Written report, executive readout, and a Phase 2 implementation roadmap. On request
Fixed-price. Single invoice. Mutual NDA at kickoff. No additional travel or expenses unless specifically scoped.
If a Phase 2 engagement follows, the assessment cost is credited against the implementation engagement (subject to scope).
What we’ve assessed and built
We’ve run platform readiness assessments for service providers, regional cloud providers, financial-services organizations, telecom operators, and sovereign-cloud initiatives across the EU and Central Asia.
Named references and the protected versions of NDA-covered engagements are shared on the discovery call. Customer stories →
More questions? See the methodology deep-dive on our blog or talk to us.
Start with a 30-minute discovery call
Free. No prep needed. We confirm fit, agree on a focused scope, and tell you whether the 14-day or the 28-day variant matches your situation. If neither fits, we say so.
Or read more:
- Cloud readiness assessment — 14-day methodology in detail
- Solutions overview — by trigger
- Cozystack — the platform we typically recommend
Ænix is the company behind Cozystack — a CNCF Project, Kubernetes Certified Distribution, OpenSSF Best Practices. We run platform readiness assessments and platform engineering programs for service providers, banks, and sovereign-cloud projects across the EU and Central Asia.




