On September 2, 2026, Switzerland's Federal Chancellery announced the launch of a program to build a sovereign workplace environment that would run in parallel with Microsoft 365. The federal administration had finished rolling out the new Office suite to roughly 54,000 seats only in mid-December 2025—barely eight and a half months before this announcement. The first phase targets about 3,000 employees, carries an estimated cost of CHF 9 million, and is set to go live starting at the end of 2027. Whether to switch entirely to open-source software will be decided later. What has been decided is not a migration plan, but rather the advance preparation of a second working environment—for a limited number of people—that would activate if Microsoft 365 became unusable.
A Second Plan Launched Eight and a Half Months After Filling 54,000 Seats
The Federal Chancellery has stated two goals: strengthening digital sovereignty and ensuring the administration can keep functioning during a crisis. The first-phase estimate is CHF 9 million, covering roughly 3,000 employees.
The timeline requires careful reading. The original announcement uses the phrase "Ab Ende 2027" (from the end of 2027), which does not mark a completion deadline—it marks the start of operations. The cost of full rollout and ongoing operation will be calculated later, based on lessons learned from this first phase.
The federal administration began its phased Microsoft 365 rollout in October 2024, signed a three-year licensing agreement with Microsoft at the end of 2024, and completed deployment to about 54,000 seats by mid-December 2025. During that same period, it also finalized a policy of keeping documents labeled as sensitive out of the cloud and on federal data centers instead. In other words, the Swiss federal administration launched a program to find an exit from Microsoft 365 roughly eight and a half months after finishing its government-wide rollout of the same platform.
The roughly 3,000 people who will begin using the sovereign workplace environment starting at the end of 2027 represent just over 5% of the roughly 54,000 seats that completed the Microsoft 365 rollout in December 2025. However, the numerator (about 3,000) counts employees, while the denominator (about 54,000) counts workplaces/devices (Arbeitsplätze)—there is no primary source establishing a one-to-one correspondence between the two. The English-language outlet It's FOSS described the same figure of about 3,000 as "7% of federal employees," using the roughly 43,500 total federal employee count as its denominator; using seat count as the denominator instead yields a figure in the 5% range. The percentage itself matters less than confirming what the denominator actually represents.
Behind this program lies a feasibility study that had just been completed. Known as "PoC BOSS"—formally, Büroautomation mit Open-Source-Software (Office Automation with Open-Source Software)—its final report is dated the same day, September 2, 2026. Its stated objectives included not only strengthening digital sovereignty but also explicitly testing whether an exit strategy from Microsoft 365 was actually viable.
In this study, which involved 172 participants across multiple government departments, document editing, file storage, collaboration, email, and calendar functions were all rated favorably, while large-scale video conferencing showed remaining limitations. The evaluation included individual tools such as Nextcloud and Collabora Online, alongside openDesk as an integrated overall solution. However, the Federal Chancellery's announcement only describes the destination as a "sovereign Swiss open-source platform" without naming specific products. This result has shaped the scale of the first phase.
What CHF 9 Million Is Actually Buying—And It's Not Migration
At the end of 2024, the federal administration paid Microsoft roughly CHF 140 million to secure three years of access to Microsoft 365. No competitive tender was held. The award decision explained that procuring this service remained essential. Swiss public broadcaster SRF has referred to this contract as a "golden cage."
The CHF 9 million estimate for the first phase of building a sovereign workplace environment is an order of magnitude smaller than the roughly CHF 140 million, three-year licensing contract the same federal administration signed with Microsoft at the end of 2024. Converting at CHF 1 = ¥193 (the prevailing rate as of September 8, 2026, per XE.com and similar sources), the former amounts to roughly ¥1.7 billion, and the latter to roughly ¥27 billion.
That said, these two figures aren't directly comparable in nature. The CHF 9 million is merely the first-phase estimate—not the total cost of exiting Microsoft 365. The contracts have different starting points, and they cover different scales: roughly 54,000 seats versus roughly 3,000 employees.
For this reason, it's more appropriate to view this as a difference of magnitude rather than to compare the figures as a strict ratio. Given the scale of the gap, this clearly isn't a budget for wholesale replacement. No procurement officer would believe that roughly ¥1.7 billion could rebuild office environments for 54,000 seats.
The Federal Chancellery itself does not deny the current state of dependency. In comments to SRF, the office acknowledged that, as a matter of fact, the federal administration today depends on Office products. The new environment will not replace Microsoft 365—it will run alongside it. Whether to fully shift to open source remains a decision for later.
Taking the two conditions—parallel operation and a decision deferred to later—at face value, what the CHF 9 million is buying is not migration itself. It is the standing readiness of a fallback: a state in which employees can keep working if Microsoft 365 goes down.
The Military Moved First; Zurich Decided to Wait
Outside the federal administration, the same judgment has already been put into action. Switzerland's Cyber Command (Kommando Cyber) will migrate all of its personnel to openDesk by October 2026. Its commander, Simon Müller, stated: "As long as companies remain subject to laws like the US CLOUD Act, they can no longer be used in certain military contexts." The reason for exclusion wasn't technical inferiority—it was which country's laws the company answered to.
The CLOUD Act, enacted in the United States on March 23, 2018, applies to providers of electronic communication services and remote computing services subject to US jurisdiction. It stipulates that data in a provider's possession, custody, or control can be compelled through lawful process even if stored outside the United States. It is not a blanket rule applying uniformly to all data held by any American company. However, the only executive agreements the US Department of Justice has published under the Act cover just two countries: the United Kingdom (effective October 3, 2019) and Australia (effective December 15, 2021). Negotiations with Canada began March 22, 2022, and talks with the EU resumed March 3, 2023. No agreement or even the start of negotiations with Japan has been confirmed.
Meanwhile, at least one municipality reached the opposite conclusion. The City of Zurich's Organisation und Informatik (OIZ), working jointly with the Bern University of Applied Sciences, evaluated openDesk and, on May 21, 2026, concluded that replacing Microsoft 365 with openDesk or a similar sovereign solution was not yet feasible for the city. What's missing: the lack of a mobile app (only a browser version exists), a device management foundation, telephony, and comprehensive cybersecurity services. OIZ says it will conduct field trials of openDesk within the same year while continuing to use Microsoft 365 until a viable alternative is found. The Federal Chancellery's decision to start with a small group of just 3,000 people becomes easier to understand when set alongside this assessment.
There is also institutional groundwork in place. Article 9 of the federal EMBAG law requires that source code for software developed or commissioned by federal authorities be published so that anyone can use, modify, and redistribute it free of charge (with exceptions for third-party rights or security reasons). Matthias Stürmer, who researches government digitalization, estimates that 80% of Swiss companies and government bodies use Microsoft. Microsoft, for its part, has responded to this trend with capital of its own: on June 2, 2025, it announced $400 million for Swiss cloud and AI infrastructure, and on April 3, 2026, it announced $10 billion over four years for Japan. Those trying to reduce dependency and those trying to localize the appearance of that dependency are moving at the same time.
Does Japan Have an Alternative to Switch To?

The structure facing Japan's government closely resembles Switzerland's. On March 27, 2026, the Digital Agency selected five services for the fiscal 2026 government cloud: Amazon Web Services, Google Cloud, Microsoft Azure, Oracle Cloud Infrastructure, and Sakura Cloud. Four of these five providers are US-based.
The environment employees use day-to-day follows the same pattern. The Government Solution Service (GSS), Japan's shared office environment, is built around Microsoft 365, Teams, Copilot, SharePoint, and OneDrive. According to Microsoft's own customer case study page, as of late November 2025 the rollout had reached roughly 46,400 users at agencies where deployment was complete, plus roughly 150,600 users at agencies still preparing for or in the process of deployment. These figures come from vendor-published material; they have not been independently confirmed against a primary government source.
So what safeguards exist for the case where foreign law becomes an issue? The Digital Agency's standard guideline DS-310 establishes that, in principle, data centers used by government cloud systems should be located domestically. The provision requiring encryption key management for data stored overseas—meaning measures by which the cloud provider or a supervising government authority is prevented from reading data except through keys held by the user—is a conditional requirement that applies depending on the sensitivity of user data; it is not a uniform mandate applying to all overseas storage. The guideline further requires that, where availability risk is foreseeable due to data-localization obligations under foreign law, that risk be avoided or reduced—for example, by keeping backups in a country not subject to that foreign law.
Looking category by category at what is and isn't covered, one gap stands out.
| Category | Swiss Federal Administration | Japan's Published Documents |
|---|---|---|
| Data location | Documents labeled sensitive are kept out of the cloud and retained on federal data centers | DS-310 establishes domestic data center location as the default principle |
| Encryption keys | No mention found in the materials reviewed for this article | Conditional rule requiring user-held keys to render data unreadable, depending on data sensitivity |
| Availability risk from foreign law | No mention found in the materials reviewed for this article | Requires measures such as maintaining backups in countries not subject to the foreign law in question |
| Replacement of the office environment itself | CHF 9 million allocated to build a parallel second environment | No such provision found in the documents reviewed |
In other words, Japan's government procurement documents include provisions addressing foreign-law risk with respect to data location and encryption keys, but within the range of materials reviewed, no provision was found for a fallback office environment to switch to during a crisis. What is protected is the data—not the environment used to create documents from that data, hold meetings, and process approvals. That said, this does not necessarily mean individual ministries and agencies lack alternative arrangements in their own business continuity plans. What has been reviewed here is limited to DS-310 and published materials; individual BCPs have not been traced.
There are signs of movement, too. Japan's growth strategy, approved by the Cabinet on July 21, 2026, states that the country will advance the introduction of a "High-Confidentiality Sovereign Cloud (tentative name)" for handling highly sensitive information, and that a conclusion on procurement, contracting, and operational methods will be reached sometime in 2026. However, neither the scope nor the timing has been finalized, and what is under discussion here is cloud infrastructure as a platform—whether the office environments employees use daily for document creation and video conferencing fall under the same framework cannot be determined from published materials.
What Japan Can Verify Before the End of 2027
What Japan can take from Switzerland's design is less a debate over whether to abandon Microsoft and more a lesson in how to phase the process. The Federal Chancellery did not first decide whether a full migration was feasible. Instead, it chose a sequence: activate the second environment for only about 3,000 people, then calculate the cost of full deployment and ongoing operation later, based on that experience. What gets settled first here isn't a technical verdict—it's a matter of fact: how much it costs, at what scale, and by when a fallback can be established.
There are three things IT officials in government and at companies running their operations on Microsoft 365 can check right now. First, whether business continuity plans include an alternative office environment. Many plans anticipate data center outages or network failures, but few distinguish the case where a service becomes unusable for legal or policy reasons tied to the provider itself. Second, in what format and within what time frame documents and email could be extracted once a contract ends. Third, where in daily operations hard-to-replace functions—like large-scale video conferencing—are deeply embedded.
That third point was the one place Switzerland's PoC stumbled: even at the small scale of 172 participants, limitations remained. No one has yet identified the threshold at which this becomes a problem when scaled up to 3,000 people, let alone 54,000 seats.
The timing for verification is approaching. Switzerland's Cyber Command has stated it will complete its migration to openDesk by October 2026, meaning results from real-world operation—including large-scale video conferencing—will emerge first. In Japan, a conclusion on procurement and operational methods for the high-confidentiality sovereign cloud is expected sometime in 2026; whether that conclusion covers only cloud infrastructure or extends to the office environment employees actually use will reveal whether Japan is building a fallback as a matter of institutional policy. And at the end of 2027, roughly 3,000 people in Switzerland will begin using their second environment.
Whether to abandon Microsoft 365 is not, for now, a realistic question for any government—Zurich's own assessment makes that clear. The realistic question is how many hours it would take to restore operations on the day Microsoft 365 becomes unusable. Answering that requires an investment on the scale of CHF 9 million and hands-on experience across roughly 3,000 people. Whether Japan's government and companies are currently in a position to produce that same estimate cannot be determined from what has been published so far.
