Cloud adoption in the public sector: moving carefully, not slowly
South Africa’s National Policy on Data and Cloud has set the direction for government cloud adoption. The harder question for most departments and entities is pace — and what ‘careful’ actually looks like in practice.
The National Policy on Data and Cloud sets a cloud-first direction for government, requires that data centre infrastructure used by government entities be located within the country, and puts the State Information Technology Agency (SITA) at the centre of sourcing and certifying cloud services for national and provincial departments. That’s a meaningful shift from an earlier draft that leaned toward a single, government-owned data centre model, and it opens the door to private-sector cloud providers working alongside SITA rather than being routed around entirely.
Why ‘slowly’ and ‘carefully’ get confused
Procurement cycles, security sign-off and budget approval in the public sector all move on their own timelines, and it’s tempting to read a long timeline as the safe option. In practice, the entities that stall the longest often end up with the least defensible position — ageing on-premises infrastructure, no consistent security baseline across departments, and eventually a forced, rushed migration when something breaks. Careful and slow are not the same thing; a well-scoped, phased migration can be both fast enough to matter and safe enough to defend.
What a realistic pace looks like
Start with lower-risk workloads — email, collaboration tools, internal document storage — before migrating systems tied to sensitive citizen data or critical service delivery. Confirm SITA certification requirements early for national and provincial departments, since procurement can stall badly when this is left until after a vendor is already selected. Build POPIA, the Cybersecurity Policy Framework and the Cybercrimes Act into the migration plan from day one — the Policy reinforces these rather than replacing them, so existing compliance obligations don’t disappear just because the infrastructure changes. Treat data residency as a design constraint, not an afterthought, given the Policy’s requirement that government data centre infrastructure sit within the country.
Where private-sector partners fit
The Policy explicitly acknowledges the expertise and resources available in the private sector to support scalability and efficiency, rather than requiring every department to build cloud capability from scratch internally. For municipalities and public entities not compelled to route everything through SITA, that opens room for a managed, phased approach with an experienced partner — provided the security and compliance groundwork is done properly rather than assumed.