Skip to Content

The day the American cloud closes: what's left standing in your SMB

Trade war, sanctions clauses and 85% of Canada's cloud with three providers: the shutdown scenario, piece by piece

TL;DR

  • Three American companies hold 85% of Canada's public cloud market (Amazon 42%, Microsoft 31%, Google 12%), against 66% worldwide.
  • The major providers' service terms already allow immediate suspension without notice if serving you would risk breaching US, EU or UK trade law. That clause is not theoretical: Microsoft applied it in Russia in 2024.
  • The Government of Canada writes in its own framework that export controls and sanctions regimes can affect access to software, updates or technical support.
  • Nobody can put a number on the probability of a cut-off, and the decision is not made here. What can be measured is time to restart: how many days before you can invoice, pay and answer clients from something else.
  • Four moves change that answer: an identity directory you run, backups outside the provider, open formats, and an exit clause written into the contract.
  • What goes in their place, layer by layer: Odoo Community (LGPLv3), Nextcloud (AGPLv3), Grist (Apache 2.0), Vaultwarden (AGPLv3), Authentik (MIT). A licence cannot be suspended by a sanctions clause, unlike a subscription.


In this article

In March 2024, thousands of Russian organisations received the same letter from Microsoft: after 20 March, you will no longer be able to access these products or services, or any data stored in them. About fifty cloud products were on the list. It was not an outage, and it was not an unpaid invoice. The reason fit in one line: the European Union's twelfth sanctions package, adopted in December 2023, barred the supply of certain management software, cloud services included, to entities registered in Russia. The date slipped by a few weeks under pressure from the local distributor, and then the cut-off happened: in mid-May 2024, that same distributor announced the shutdowns had begun.

Canada is not Russia. But the decision is not made here: it is made in Washington and in Brussels, and nobody in Montreal or Quebec City controls the timing. Which makes the question the autumn of 2026 raises a fair one: if access closes, what is still standing in your organisation, and how long before you can invoice a client again?

This is a business continuity exercise, not a political one. It is done with a stopwatch and a list, like a disaster recovery plan, except that here the disaster is not a server room fire.


A trade war that has already touched the digital file

Technology is not collateral damage in the tariff fight: it has been a direct lever, and it played out in 48 hours. On 27 June 2025, the White House broke off all trade discussions with Canada over the Canadian digital services tax, a 3% levy aimed in part at Amazon, Google and Meta. On 29 June, Ottawa announced it was rescinding the tax and suspending the payments due the next day, to advance the negotiations. A multibillion-dollar tax file was settled over a weekend, under pressure, and the object of the dispute was the taxation of the tech giants.

Since then the conflict has hardened rather than eased. Negotiations collapsed on 22 August 2026, the United States imposed 50% duties on a range of Canadian products, and Ottawa hit back dollar for dollar: counter-tariffs of 15% to 50% on $27.6 billion of American goods, more than 700 products, in force since 8 September 2026. A threat to double duties on autos and steel is on the calendar for 1 January 2027.

None of this targets the cloud. The point is elsewhere: the trade relationship between the two countries has become a space where sector-wide measures land within days, and where the digital file has already served as a bargaining chip once.


Canada's turn is not a passing phase

One objection comes up as soon as dependency on the American cloud is raised: wait it out, a presidential term always ends. Ottawa does not share that reading, and says so plainly. On 27 March 2025, coming out of an emergency meeting with his ministers, Mark Carney declared that the old relationship with the United States, built on deep economic integration and close security cooperation, was over. Two sentences from that same press conference are worth reading slowly: "there will be no going back", and above all "the next government and all those who follow will have a fundamentally different relationship with the United States". That is not a reaction to one president, it is a forecast spanning several governments.

The rest runs on the same horizon. On 22 October 2025 the government set itself the target of doubling Canadian exports outside the United States by 2035, roughly $300 billion of additional trade. A ten-year target is not a tariff response. On defence, Canada signed a security and defence partnership with the European Union on 23 June 2025, then became the first non-European country to take part in SAFE, the €150 billion loan instrument that finances European weapons purchases. Defence contracts run in decades, and the first ones are already landing: in June 2026 a Montreal company won the first Canadian contract under SAFE, tactical radios for the Polish army.

The numbers are moving alongside the speeches. According to Global Affairs Canada's State of Trade 2026, 72% of Canadian goods exports still went to the United States in 2025, but exports to the US fell 3.7% while exports to the rest of the world surged 11.1%. The non-US share of exports, goods and services combined, reached its highest level since 1981.

The digital file moves with it. On 3 September 2026, Ottawa launched Digital Transformation Canada, a federal organisation that names digital sovereignty in its mandate and turns federal procurement into a strategic anchor customer for Canadian technology firms. It is the logic of trade diversification, applied to software suppliers.

None of this says what will happen to your Microsoft 365 tenant. What it does say is that both governments describe a structurally changed relationship, with dated commitments that run past any single election. For an SMB the practical consequence is short: "let's wait for things to settle" is not a plan, it is the absence of one.


85% of Canada's cloud sits with three companies

On 2 June 2026, the Canadian Anti-Monopoly Project published Parting Clouds, an analysis of the Canadian cloud market. The headline figure: Amazon 42%, Microsoft 31%, Alphabet 12%, meaning 85% of Canada's public cloud market sits with three American companies. The same three hold 66% globally. Canada is therefore markedly more concentrated than the world average, and the report names the consequence plainly: a country locked into a small number of providers has no meaningful choice, whether the threat is coercion by a foreign government or rent extraction by an uncontested monopolist.

Public sector figures follow the same shape. The federal government spent more than $156 million on cloud services in 2022-23 alone, most of it with Microsoft and Amazon, and close to $1.3 billion with American providers since 2021.

On the private side, Statistics Canada measures the exposure: in 2023, cloud computing was the most widely used technology among Canadian businesses with five or more employees, at 48% adoption, up three points from 2021. Put another way, one Canadian business in two hands part of its operations to infrastructure it does not run, in a market where three foreign providers share 85% of the supply.

Shares of the Canadian public cloud market A hundred percent stacked bar: Amazon 42%, Microsoft 31%, Google 12%, all other providers combined 15%. The three American giants total 85% in Canada, against 66% worldwide. Source: Canadian Anti-Monopoly Project, June 2026. Global average for the three: 66% Amazon Web Services: 42% of the Canadian market Microsoft: 31% of the Canadian market Google: 12% of the Canadian market All other providers combined: 15% of the Canadian market 42% 31% 12% 15% 85% for the three, in Canada Amazon Microsoft Google All others Source: Canadian Anti-Monopoly Project, "Parting Clouds", 2 June 2026.
The Canadian public cloud market by provider. The dashed line marks the global average for the same three companies.


The off switch is already written into your contract

The most useful part of this discussion is not in a speech or a report: it is in the terms you accepted by ticking a box.

Microsoft's product terms for online services provide that the company may suspend or terminate the agreement immediately and without notice to the extent it reasonably believes that performance would cause it to violate trade laws or put it at risk of becoming subject to sanctions. Those trade laws are named in the contract: the trade laws of the US, the EU and the UK, including the US Export Administration Regulations, the sanctions administered by the Office of Foreign Assets Control, and the EU Dual Use Regulation. The clause requires neither proof of a breach nor a court decision, only a reasonable belief on the provider's part. And the European route is not theoretical: the 2024 Russian cut-off came out of Brussels, not Washington.

The Amazon Web Services customer agreement, in its 14 August 2026 version, is built the same way: immediate suspension under section 4.1, immediate termination where the law requires it, and a 30-day window after the termination date to retrieve your content, on condition that all amounts due have been paid.

Even in the ordinary case of a subscription that simply expires, Microsoft 365's documented timeline leaves little room: 30 days of expired status where everyone still works normally, then 90 days of disabled status where users lose their apps and only administrators can still reach the data, then deletion. Four months in total, and that is the favourable scenario. The letter sent in Russia described the other one.

If you have never put a number on what leaving costs, our article on the exit cost of 2,596 services gives the method, and it applies here unchanged.


Cut-offs that have already happened elsewhere

The clause is not dormant. It has been exercised more than once, and not only against states.

In October 2019, Adobe deactivated every Venezuelan account under presidential executive order 13884, initially without refunds, before partly walking the position back. In July 2019, GitHub restricted accounts held by users in Iran, Syria and Crimea, including private repositories belonging to developers with no connection to any weapons programme. In March 2022, Amazon, Microsoft and Google stopped accepting new cloud customers in Russia, two years before the shutdown already mentioned.

Six documented cut-offs, from 2019 to 2025 A timeline. July 2019: GitHub restricts accounts in Iran, Syria and Crimea, private repositories included. October 2019: Adobe deactivates every Venezuelan account under presidential executive order 13884. March 2022: Amazon, Microsoft and Google stop accepting new cloud customers in Russia. May 2024: Microsoft cuts about fifty cloud services to Russian businesses under the European Union's twelfth sanctions package. February 2025: a US executive order sanctions the International Criminal Court and its prosecutor. October 2025: the Court replaces Microsoft 365 with openDesk, an open source suite. July 2019 October 2019 March 2022 May 2024 February 2025 October 2025 GitHub restricts accounts in Iran, Syriaand Crimea, private repositories included Adobe deactivates every Venezuelanaccount, executive order 13884 Amazon, Microsoft and Google stop takingnew cloud customers in Russia Microsoft cuts about fifty cloud servicesto Russian businesses, EU sanctions A US executive order sanctions theInternational Criminal Court The Court replaces Microsoft 365 withopenDesk, an open source suite July 2019, GitHub October 2019, Adobe in Venezuela March 2022, the three providers in Russia May 2024, Microsoft cuts cloud access in Russia February 2025, sanctions against the International Criminal Court October 2025, the Court leaves Microsoft 365
Six documented decisions where access was restricted or cut by the provider, under a sanctions regime.

The most instructive case for a civilian organisation is the International Criminal Court. After the US executive order of 6 February 2025 sanctioning the Court, the Associated Press reported in May that its prosecutor Karim Khan could no longer reach his Microsoft account and had moved to a Swiss provider. Microsoft disputed that reading, its president Brad Smith stating that the company had at no point ceased or suspended its services to the Court. In February 2026, however, it went back to the UK Parliament to have the testimony of one of its own executives corrected, after he said the decision to cut the account came from the Court rather than from Microsoft: the company called that version inaccurate, while maintaining that it never cut services to the Court itself. The distinction is about one account, not the organisation. What is not disputed is what followed: on 31 October 2025, the Court confirmed it was replacing Microsoft 365 with openDesk, an open source suite backed by the German agency ZenDiS, across its entire digital workplace.

An institution does not move its whole office suite on an impression. It does it because it concluded that its daily working tools depended on a decision it does not control.


What breaks first, layer by layer

The instinct is to think "my files". That is not where it starts. In a moderately equipped SMB, the first piece to fall is identity, and it takes everything else with it, including applications that do not belong to the provider being cut.

Layer What stops What saves you
Identity No one signs in anywhere, including third-party software wired to single sign-on against the same directory A directory you run, plus local break-glass accounts on critical equipment
Email Mailboxes unreachable, history included, and the addresses stop receiving A domain whose DNS records you hold, and a copy of the mailboxes outside the provider
Files Sync stops, share links die, documents opened in the browser no longer open at all Real local copies rather than placeholders, in open formats readable without the vendor's editor
ERP, payroll, invoicing The hosted software becomes unreachable, so invoicing and payroll stop the same day A recent data export, and an instance you can restart somewhere else
Workstations Provisioning and management policies freeze, activation blocks on new devices A local install image, and a build procedure that does not depend on the cloud
Backups If they live in the same tenant as the data, they leave with it The 3-2-1 rule, with at least one copy at a different provider or on your own premises

That last row is the one that surprises people most in a workshop. Plenty of organisations do have a Microsoft 365 or Google Workspace backup, but it is stored inside the very ecosystem it protects. That is exactly the subject of our article on backing up Google Workspace and Microsoft 365 data, and it is the cheapest fix on this whole list.


What governments put in writing

You can find the scenario overblown. Public administrations have put it in writing.

The federal digital sovereignty framework published in the autumn of 2025 starts by stating the dependency: most of the digital products and services used by the Government of Canada are supplied by a small number of major global technology companies. It then names the risk, in a sentence that works just as well for a twenty-person SMB: global conditions, including export controls, sanction regimes and other regulatory measures, can also affect access to software, updates or technical support.

The federal white paper on data sovereignty and public cloud goes further on legal access: the primary risk it identifies is the US government's ability to compel an organisation subject to US law to hand over data under its control, regardless of where that data sits and without notifying Canada. That is why the same document requires the government to keep exclusive control of encryption keys, and limits public cloud to data classified up to Protected B.

In Quebec, the policy statement on digital sovereignty and IT procurement, tabled in February 2026 by the Ministry of Cybersecurity and Digital Technology, acknowledges that the government still relies on foreign technology providers for part of its infrastructure. It sets eight orientations, among them sovereign hosting in the Quebec Government Cloud, data control through data centres under Quebec jurisdiction, wider use of open source software, and strategic clauses added to supplier contracts.

That statement targets the public administration, not your business. But it signals what public buyers will be asking of their suppliers in the tenders of the coming years, and the contractual clause is the named mechanism. If you sell to the state, it will eventually show up in your tender documents.

Then there is the obligation that already applies: since September 2023, before disclosing personal information outside Quebec or entrusting its processing or storage outside Quebec, a business must conduct a privacy impact assessment and enter into a written agreement. The law says "outside Quebec", not "outside Canada". Our review of Law 25 four years on sets out where SMBs actually stand on this.


What the providers' promises are worth

The providers saw the question coming, and they answered. On 30 April 2025, Microsoft made five digital commitments to Europe, including a pledge to promptly and vigorously contest, through every legal avenue available, any government order to suspend its European cloud operations, with a code deposit in Switzerland as the continuity plan should the challenge fail.

Canada got its version on 9 December 2025, alongside an announced investment of CAD 19 billion between 2023 and 2027: a threat intelligence centre in Ottawa, local processing of certain interactions, confidential computing and external key management through Azure Key Vault in the Canadian regions, a partnership with Cohere, and a commitment to pursue every legal and diplomatic avenue, litigation included, to protect access to critical infrastructure.

These commitments are real and they carry weight. They also have three limits worth naming honestly. They are unilateral: a company can change them, unlike a statute. They promise to contest an order, not to win. And the suspension clause for sanctions risk was not removed from the service terms in the meantime.

There is one arena where the balance of power already operates without any sanction at all: price. On 4 December 2025, Microsoft announced a worldwide pricing update effective 1 July 2026. Microsoft 365 Business Basic goes from US$6 to US$7 per user, Business Standard from US$12.50 to US$14, Office 365 E3 from US$23 to US$26, Microsoft 365 E5 from US$57 to US$60. For a 40-person team on Business Standard that is US$720 more per year, decided elsewhere, without negotiation. Our honest five-year comparison of M365 against a libre stack puts numbers on the gap over time.


The blind spots of sovereignty

An article that stopped here would be selling an illusion. The rest of the answer is in what follows.

First, probability, and this is where it pays to be blunt: it cannot be calculated. Canada is not a sanctioned jurisdiction today, and the mechanisms used against Russia, Venezuela or Iran are not aimed at it. But those mechanisms exist, they have been triggered several times since 2019, and the decisions behind them are taken within days, abroad, without consultation. The June 2025 breakdown in trade talks fitted into one social media post. Anyone quoting you a percentage is making it up. So a continuity plan is built on impact and on time to restart, the way a fire extinguisher is bought without estimating the odds of a fire.

Second, open source is not a sealed bubble. A server you run still depends on code repositories and container images often hosted in the United States, on a certificate authority, on a domain name service, on operating system updates, and on hardware designed elsewhere. What open source changes is not the absence of dependency, it is its nature: a copy of the code and of your data lets you restart somewhere else, where a closed tenant leaves you no recovery at all. The difference is reversibility, not independence.

Third, cost. Migrating a full office suite is a project, not a weekend. Schleswig-Holstein has moved close to 80% of its administration's workstations to LibreOffice and expects more than €15 million in licence savings in 2026, but it is spending €9 million of one-off investment that same year, and the operation spans several years. Denmark's digital ministry made the same choice in the summer of 2025. France is rolling out its own Visio conferencing tool across the state civil service by 2027 in place of Teams and Zoom, with roughly 200,000 civil servants in scope after a one-year pilot with 40,000. Those trajectories are credible precisely because they are slow and budgeted. And they say the opposite of what is often assumed: this is not unrealistic, it is plannable. A twenty-person organisation does not have 30,000 workstations to move, it has twenty, and it can start with a single layer this year without breaking anything.


Where to start without tearing everything out

The right opening question is not "am I leaving Microsoft". It is: how many days would I need to invoice a client if my main provider closed tomorrow morning? That number can be measured, and it comes down in stages, with no big bang.

Four moves, in decreasing order of return:

  1. Get your backups out of the tenant. A copy of your mailboxes, your files and your accounting database at another provider or on your own premises. It is the cheapest move and the one that changes the answer most.
  2. Take back the domain and the DNS records. Your domain name and its DNS zone should live with a registrar separate from your email provider. Without that, you cannot even point your addresses somewhere else.
  3. Test your formats. Open your ten most critical documents in an editor that is not the vendor's. Anything that does not open properly is a dependency, not a file.
  4. Write the exit into the contract. Retrieval window, export format, egress fees. The moment to negotiate those three lines is at renewal, not during the crisis.

Those four points cost almost nothing and require no migration. They turn a hypothetical cut-off into a manageable interruption. The rest, moving one layer at a time to tools you can restart elsewhere, is a programme planned over years, exactly like the administrations that have started down that road.


What replaces what, and under which licence

The word "open source" is vague. What matters in this file sits in one precise document: the licence. An LGPL, an AGPL, an Apache 2.0 or an MIT hands you a usable copy of the code, the right to run it wherever you want, and the right to hand it to someone else to run on your behalf. That right cannot be withdrawn by a trade compliance clause, because it is not a subscription. A subscription can be suspended.

Here are the substitutions that come up most often in SMBs and non-profits, with each licence and the honest catch that comes with it.

Layer What it replaces The replacement The catch to know about
Identity and single sign-on Microsoft Entra ID, Okta, Google sign-in Authentik (MIT) or Keycloak Authentik's enterprise edition is paid and proprietary. The MIT core is more than enough for an SMB. See our guide to SSO with Authentik or Keycloak
Files, calendars, contacts, sharing OneDrive, SharePoint, Google Drive Nextcloud (AGPLv3) The Enterprise offer sells support and guidance, not a different codebase. Details in our article on Nextcloud for SMBs
ERP, invoicing, CRM, projects, timesheets Dynamics 365, Salesforce, QuickBooks, Sage 50, Acomba Odoo Community (LGPLv3) Several apps stay in the Enterprise edition. The exact split is in Community vs Enterprise and in the comparison with Sage, Acomba and QuickBooks
Shared spreadsheets and small databases Excel on SharePoint, Airtable, Google Sheets Grist (Apache 2.0) Since 2026, single sign-on through OIDC or SAML is no longer part of grist-core. A textbook case of an open core tightening. Our article on Grist lays out the split
Passwords and team secrets 1Password, LastPass, Dashlane Vaultwarden (AGPLv3) It is an independent server compatible with the official Bitwarden clients, with no connection to Bitwarden Inc. Setup in our Vaultwarden article
Team messaging Teams, Slack Matrix and Element (Apache 2.0 and AGPLv3) Deployment is easy, it is carrying the history over that costs. The procedure is in Really replacing Slack and Teams
Email Exchange Online, Gmail An IMAP mailbox at an independent host, managed from Symbifox Symbifox Taking the whole thing in house stays thankless, and our article on self-hosting your own email says so plainly. The route we recommend keeps the protocol open: the mailbox stays on IMAP, so it is portable to any client and any host, and it is the management layer that plugs into your ERP, mobile included. That management layer is our own module, under a proprietary licence: reversibility rests on the protocol, not on it

The order that works

Nobody moves seven layers in one year. This order holds because each step makes the next one easier rather than riskier.

  1. The password vault. Self-contained, independent of everything else, immediate value. And it unlocks the rest: as long as credentials live in someone's head or in a file, no migration can be planned.
  2. Files. Nextcloud sits beside what you already have, with no cut-over. You sync, you move one department at a time, you keep the old one readable for as long as needed.
  3. The business core. The ERP, because it is what decides whether you can invoice on Monday morning. It is the longest piece, and the only one whose downtime costs money by the hour.
  4. Identity, last. A directory does not move on its own: you put it in once there are two or three applications to unify behind it. Coming from Active Directory, the switch is described in our article on migrating to Authentik.

At the end of that road, what you hold is not a contract: it is a copy of the code, your data in documented formats, and the right to run the whole thing somewhere else. The host goes back to being what it should always have been, a supplier you can replace, rather than a switch you depend on.


At Blue Fox

We deploy that exact stack by default, hosted in Quebec, under the client's control: Odoo Community for the business core, Nextcloud for files and collaboration, Grist for shared spreadsheets, Vaultwarden for passwords, Authentik for identity. The price covers hosting and support, never the right to use the software, and an organisation that wants to leave walks away with its database, its code and its data in readable formats.

That does not mean leaving everything behind. Plenty of organisations keep Microsoft 365 for office work and first move what hurts most in a shutdown: invoicing, client files, backups. It is a continuum, not a switch.

If you want to see what a full stack you can restart elsewhere looks like, we assembled and documented one: Symbifox, the all-inclusive ERP from Blue Fox, with Nextcloud for document management alongside it.

Let's talk about your exposure to the American cloud: an hour is enough to measure your time to restart and pinpoint the two or three pieces to move first.


Sources

Hiring in Odoo with the interview book: the scorecard, the blind panel and a file the candidate can read
What Odoo Community's recruitment app does very well, the exact point where it stops, and the nine modules we wrote for what comes next.