- What is the Government Private Cloud, in plain terms?
- Servers, storage and networking made available to public authorities and institutions in state data centres, instead of a machine kept on your own premises or at a commercial hosting provider. ADR is the beneficiary and contracting authority, STS is beneficiary and partner, and SRI is security partner through its National Cyberint Centre. It is funded through the National Recovery and Resilience Plan, Component 7, and provides IaaS, PaaS and SaaS services: you are allocated capacity, you do not buy hardware.
- Can we just move our current server there?
- Almost never. You do not move the server, you move the application. The infrastructure has entry requirements: components that still receive security updates, an application that can be started automatically, complete source code, defined authentication, tested backups. An application that fails those is refused regardless of available capacity — which is why the readiness audit comes before any migration.
- Who decides whether our application is accepted?
- The administrator of the target infrastructure. We do not represent ADR, STS, SRI or DNSC and we have no privileged access to what they administer. What we can do is bring the application to the state where the technical requirements are met, and hand over the documentation that shows it.
- Our institution is not in the national programme. What now?
- The programme’s published targets concern institutions of central public administration, migrated through centrally contracted suppliers. Most local authorities are not in those lots, so preparing the application and choosing a supplier are theirs to handle — which is exactly the work described on this page, and it can be contracted directly under Law no. 98/2016.
- Can you intervene if we have already received a vulnerability report or notification?
- Yes. We start by taking controlled ownership of the infrastructure and making an initial backup, so the data is preserved before anything changes. We then assess the critical vulnerabilities, isolate the affected components and set out a remediation plan. We commit to rapid mobilization and assessment — not to a fixed resolution deadline decided before the analysis.
- How long until we receive an offer?
- We reply within the same business day with a preliminary assessment, the recommended service and the steps required for procurement. The technical and financial offer follows once we understand the access available and the actual state of the application.
- What if the original supplier no longer responds, or the source code is incomplete?
- This is one of the most common situations. We start from what actually exists: the running application, the database, the server configuration. We rebuild the technical inventory, document the dependencies and establish what can be recovered, what has to be rebuilt and what can be retired.
- Can the application be moved directly into government infrastructure?
- Rarely directly. An application with outdated components, dependencies that cannot be updated, or no automated deployment can be rejected on entry into the new infrastructure. The migration readiness audit establishes exactly what has to be modernized before the move.
- Do we need Kubernetes?
- Not for every application. For simple sites and portals we recommend an architecture proportional to the requirement. Kubernetes is justified when availability, scaling and operational complexity genuinely call for it.
- We have backups. Is that enough?
- An untested backup is not a recovery strategy. We test the actual restore, measure how long it takes and document the procedure, so the institution knows the real recovery time before an incident rather than during one.
- Can these services be contracted through direct acquisition?
- The services are defined with an object, deliverables, a timeframe and terms of provision, so they can be acquired directly under Law no. 98/2016. The decision on the procedure belongs to the contracting authority, based on the estimated value of the entire requirement.
- Can you publish the service in the SEAP electronic catalogue?
- Yes. On request we send the technical datasheet, the matching CPV code and the item in the SEAP electronic catalogue, together with the technical and financial offer.
- Can the content and history of the current website be preserved?
- Yes. Taking over and structuring the content, together with migrating the public archive, are part of the modernization package. Preserving the public archive is usually a requirement, not an option.
- What happens after the migration?
- We can take over operations as a monthly subscription or annual contract: monitoring, updates, backup, restore testing, certificate management, security reviews, reporting and incident management.