# ISVs on Two Journeys: How Software Vendors Tackle Cloud and AI with One Road.MAP

> How software vendors take their organisation on the cloud journey and the AI journey at once: the three Road.MAP phases for ISVs, each extended for AI.

- URL: https://seiler.it/articles/isv-cloud-ki-road-map/en.html
- Author: Dr. Sven Seiler (https://seiler.it/)
- Type: Article
- Language: en
- Published: 2026-10-11
- Updated: 2026-10-11

**Why the cloud journey is not over for independent software vendors, what the AI journey adds in every phase and why both stand on the same foundation.**

In December 2023 I described how independent software vendors (ISVs) can move to the cloud: from selling licences to becoming a service company, structured in three phases modelled on the AWS Migration Acceleration Program[^1][^2]. For many ISVs this journey is not finished. Since then a second one has been added, and it moves at a much higher pace.

At the end of January 2026, Anthropic released plugins for sales, finance, data and marketing, and legal for its agent Claude Cowork[^3]. In the following week the S&P 500 Software & Services Index with its 140 constituents fell for eight trading sessions in a row, by more than 4 percent on 5 February alone, and was down about 20 percent for the year[^4]. Thomas Shipp, head of equity research at LPL Financial, summed up investors' concern like this:

> “Why do I need to pay for software, the thinking goes, if internal development of these systems now takes developers less time with AI?”[^3]

Whether the stock market is right is open. For ISVs the question is real nonetheless, and in my view it hits them from two sides at once. On the product side, agents take over workflows for which a licence per seat used to be sold. On the development side, competitors build faster with agents, and the customer may well build it themselves.

This does not mean abandoning the cloud journey. An ISV still has to take its organisation along on the cloud journey and, at the same time, on the AI journey. Both succeed with the same Road.MAP, because the cloud building blocks are the foundation of the AI building blocks: without clean tenant isolation, you cannot separate AI context per tenant either. Without a pipeline, you cannot put quality gates in front of an agent.

This article describes the three phases of the Road.MAP for ISVs once more in full, with their contents from 2023, and adds for each phase what the AI journey brings.

## Two journeys, one Road.MAP

The basic idea in 2023 was not to treat ISVs like companies with a data centre. A corporation migrates mainly to lower operating costs. A software vendor migrates to get a different business model: SaaS, short release cycles, operations as part of the product. That is why we adapted the AWS programme in three places. The assessment looks at the ISV's application and business, the Mobilize phase focuses on cultural change through cloud-native services, and the Migrate phase is called Scale & Innovate in our approach.

AI changes nothing about these three phases and their contents. It adds a second layer to each phase (figure 1).

_Figure 1: The three phases of the Road.MAP for ISVs. At the top the building blocks of the cloud journey from the 2023 version[^1], below them the building blocks of the AI journey (graphic in German). Graphic: Storm Reply._

One number shows how big the lever of the AI journey is: Bain puts the share of writing and testing code in the time from idea to launch at about 25 to 35 percent[^5]. Whoever speeds up only this part with AI gains at most this share. An example: if writing becomes twice as fast, at a 30 percent share this saves 15 percent of the total duration (30 × 0.5 = 15). Accordingly, Bain reports productivity gains of around 10 percent from basic code assistants and 25 to 30 percent at companies that rework the entire process[^5]. The gain lies in the whole process, and that is exactly what the Road.MAP organises.

## Assess: a business case for the service company

The Assess phase lays the foundation, because it evaluates the ISV's current application, infrastructure and strategy before anything moves. Unlike the AWS programme, which looks more at the total cost of ownership (TCO) at company level, the Road.MAP puts the ISV's business requirements at the centre. The phase covers five points:

- Application-centric assessment to define the target architecture for the migration

- Modernisation needs of the application, determined with the AWS Well-Architected SaaS Lens[^6]

- Migration Readiness Assessment for ISVs, tailored to the challenges of software vendors

- Briefings and workshops, aligned with the ISV's customers and its own strategy

- Adapted business case that prioritises SaaS commercialisation and value KPIs such as future time to market, release cycles and operational excellence

The building blocks are called SaaS Check, SaaS Business Plan, Leadership Alignments, Migration Readiness Assessment for ISV, Briefings & Workshops, App-Mod & SaaS Patterns and Accelerators. In 2023 the outcome of the phase read “Create a case for change to modern application patterns and becoming a service company”. With the AI journey it becomes: becoming a service company and an AI-capable company.

**On top: the AI journey.** Two questions extend the assessment. The first concerns the product: which part of it is a workflow that an agent at the customer will handle by itself in future? Two imagined extremes show the range. In the simple case it hits a reporting module that collects data and sends it as a PDF; an agent at the customer can do this directly from the database, and the module loses its price. In the extreme case it hits the core product, if its value lies mainly in the data entry form and hardly in the business logic behind it. Then the licence model as a whole is in question. In my view the answer is usually a shift of value towards data, business logic, integrations and liability, because no agent takes over the certification, the industry rules and the responsibility for the product.

The second question concerns the organisation: how far along is the company in using AI overall? That is what we built the Road.MAP for AI for, a maturity model with eight dimensions and five levels[^7]. The dimensions are Governance & Legal, Cost & Steering, Infrastructure & Permissions, Security & Risk, Knowledge & Data, Organization & Enablement, Culture & Change, and Use Cases & Value Contribution. The levels range from 1 Experiment to 5 Agentic Organization[^8]. For an ISV this assessment belongs in the Assess phase, because it shows whether the organisation can carry the product decision at all.

## Mobilize: readiness through experience

In the Mobilize phase the ISV builds readiness through hands-on experience, with particular attention to the cultural change that cloud-native services trigger. It prepares the technical migration and aligns the organisation with modern cloud practices. The phase covers eight points:

- Application-centric modernisation, starting from the application's target architecture

- Business case for future SaaS sales channels and monetisation models

- Early joint prototyping aiming at evolutionary MVPs (minimum viable products)

- Tracking of SaaS usage to manage costs and consumption

- Cultural knowledge transfer that fosters a culture of innovation and speed

- Automation of tenant isolation, data partitioning and observability

- Pipelines for a fast, agile and secure development cycle

- Operating models for fast deployment cycles with little overhead

The building blocks are grouped into four areas: Portfolio (Discovery & Planning, Migration Plan, Business Case), Migrate (Migration & Modernization Experience, SaaS Prototyping), People (Skills and Center of Excellence, DevOps culture) and Platform (Landing Zone, Software Development Lifecycle, Deployment & Operating Model, Security & Compliance). In this phase we work closely with the ISV's development teams and add to them where needed, so that the transformation gets room to breathe. In 2023 the outcome read “Build readiness through experience focusing a cultural change driven by cloud native services”. The AI journey adds: and through agents that help develop safely.

**On top: the AI journey.** The Software Development Lifecycle already stood at the centre of this phase in 2023, and that is where the AI journey starts. According to the 2025 DORA report, 90 percent of the nearly 5,000 technology professionals surveyed use AI at work. There, AI adoption is positively related to software delivery throughput, but still negatively related to its stability[^9]. More code is therefore not automatically more software. For an ISV whose customers pay for a stable product, that is the decisive sentence.

That is why Agentic Engineering joins the DevOps culture: teams learn to lead agents, that is, to write requirements precisely enough for an agent to implement them, to check results and to set rules for what an agent may and may not do. In our own development this shifts developers' work towards specifying and reviewing, and that takes practice, even for experienced people.

What this needs technically, we call an AI Software Factory. It means the environment in which agents may work safely. It builds on the landing zone, pipelines and operating model from the cloud journey and replaces none of these building blocks. We build it in seven layers (figure 2):

- Context: rules, architecture decisions and domain knowledge, machine-readable in the repository

- Workflow: tickets as a queue for agents, from the draft specification to the pull request

- Agent runtime: isolated, disposable environments with a separate identity per agent

- Quality and gates: tests, evaluations, a second model in the review and human approval

- Operations and learning loop: incidents from operations become new tickets

- Cost: cost per ticket instead of one lump bill

- People and roles: who maintains context, who grants autonomy, who is liable

_Figure 2: The seven layers of the AI Software Factory as we build it (graphic in German). Graphic: Storm Reply._

What this looks like in practice is shown by a run from our own development: a new feature was built across seven packages, from the first sentence in the chat to the working function in just under four hours, with twelve commits, a review agent that found a bug, and a human who approved at the end. I describe this run step by step in the article “[AI Software Factory: How a Sentence in a Chat Becomes a Shipped Feature](/articles/ai-software-factory/en.html)”.

**What matters:** the factory is an operating state that you build layer by layer on the cloud platform. It cannot be installed.

## Scale & Innovate: transformation at scale

The third phase corresponds to the Migrate phase of the AWS programme and is called Scale & Innovate in the Road.MAP, because besides the move it is about modernisation and competitive advantage through customer-related activities. Existing applications and workloads are moved to the cloud systematically and modernised along the way. The phase covers five activities:

- Optimising the applications to use the cloud's auto scaling, load balancing and resilience

- Developing new features with cloud services, so that innovations reach customers faster

- Customer-related innovation, aligned with the needs of the ISV's own customers

- Scaling the infrastructure, which grows with demand without losing performance

- Continuous optimisation, also after the migration

The building blocks are called Migrate (in waves), Operate & Optimize, Next-Gen MSP (managed service provider) and Innovate. In 2023 the outcome read “Accelerate transformation at scale and focus on competitive advantages through customer related activities”. The AI journey adds: also with AI features that run securely and affordably per tenant.

**On top: the AI journey.** Two points from the Mobilize phase become much harder when scaling with AI: tenant isolation and the tracking of usage and costs. A SaaS product with AI features must separate not only databases and storage per tenant, but also the context a model sees. An agent writing a summary for customer A must not have a document from customer B in its context. It is the same task as in the cloud journey, just with one more component that does not work deterministically.

The difference is even bigger for costs. Gartner expects the cost of AI for coding to exceed the average developer salary by 2028[^10]. According to Gartner, 23 percent of technology leaders already spend 200 to 500 US dollars per developer per month on tokens, and 6 percent of organisations more than 2,000 US dollars[^11]. Let us take the upper value for an ISV team with 30 developers: 30 × 2,000 US dollars is 60,000 US dollars a month, or 720,000 US dollars a year. The same logic applies inside the product when AI features consume tokens per tenant. Whoever prices per seat and does not know the cost per request sells every additional use at a loss in the worst case.

Then there is regulation, and it hits ISVs directly as manufacturers. Since 11 September 2026 the Cyber Resilience Act has required manufacturers to report actively exploited vulnerabilities: an early warning within 24 hours, a full notification within 72 hours[^12]. The main obligations apply from 11 December 2027[^13]. My reading of the text is that these obligations do not distinguish whether a line of code comes from a human or an agent. An ISV must therefore be able to show who initiated, reviewed and approved a change. In a software factory this is a by-product of the process, because every agent has its own identity and every approval is logged. In a development where everyone runs their agent on their own laptop, it is an after-the-fact reconstruction.

## Summary

The Road.MAP for ISVs carries two journeys. The cloud journey remains with all its contents from 2023: the application- and business-oriented assessment, the Mobilize phase with landing zone, pipelines, operating model and cultural change, and Scale & Innovate with migration in waves, operations and customer-related innovation. The AI journey is added in every phase. Assess adds AI maturity according to the Road.MAP for AI and the question of which part of the product an agent can replace. Mobilize adds Agentic Engineering and the AI Software Factory, which sits on the cloud platform. Scale & Innovate extends tenant isolation, cost control and traceability to models and tokens.

It is only fair to say where this model is not clear-cut. The boundary between Mobilize and Scale & Innovate blurs, because a factory keeps growing in operation and is not finished on a set date. A small ISV with five developers does not need all seven layers at once; for them, context rules in the repository, an automated review and cost per ticket are a realistic start. And no factory answers the question of which product should be built. Whoever protects the wrong parts of their product in the assessment only builds them faster with agents.

The recommendation is clear nonetheless: take the organisation along on both journeys and treat the cloud platform as the common foundation. An ISV that can build its own software safely with agents on this platform will then also understand what agents will replace at its customers.

## Not a product, but an approach

The AI Software Factory is not a product we sell. At Storm Reply we work with it ourselves, and the Agent Hub is our implementation of it. What we offer ISVs is the approach: walking the cloud journey and the AI journey in their own company and establishing a software factory, with their own repositories, their own rules and the models that fit their own compliance. Where customers allow us to, we also develop their products ourselves in our factory.

If you want to know where your company stands on these two journeys, get in touch.

## Sources

[^1]: Seiler, Sven: “ISVs auf dem Pfad der agilen Transformation” (German), Medium (Storm Reply), 20 December 2023. [medium.com](https://medium.com/storm-reply/zukunftswege-der-cloud-isvs-auf-dem-pfad-der-agilen-transformation-c2c982d7bf59)

[^2]: AWS: “AWS Migration Acceleration Program (MAP)”, programme page. [aws.amazon.com](https://aws.amazon.com/migration-acceleration-program/)

[^3]: CNN: “Anthropic’s new AI tool sends shudders through software stocks”, 4 February 2026. [cnn.com](https://www.cnn.com/2026/02/04/investing/us-stocks-anthropic-software)

[^4]: CNBC: “AI fears pummel software stocks: Is it ‘illogical’ panic or a SaaS apocalypse?”, 6 February 2026. [cnbc.com](https://www.cnbc.com/2026/02/06/ai-anthropic-tools-saas-software-stocks-selloff.html)

[^5]: Bain & Company: “From Pilots to Payoff: Generative AI in Software Development”, Technology Report 2025, 23 September 2025. [bain.com](https://www.bain.com/insights/from-pilots-to-payoff-generative-ai-in-software-development-technology-report-2025/)

[^6]: AWS: “SaaS Lens – AWS Well-Architected Framework”, documentation. [docs.aws.amazon.com](https://docs.aws.amazon.com/wellarchitected/latest/saas-lens/saas-lens.html)

[^7]: Storm Reply: “KI etablieren – Road.MAP for AI” (German), website. [ki-etablieren.de](https://ki-etablieren.de)

[^8]: Storm Reply: Road.MAP for AI, maturity model with eight dimensions and five levels (German). [ki-etablieren.de](https://ki-etablieren.de/reifegradmodell.html)

[^9]: Google Cloud / DORA: “2025 DORA Report: State of AI-Assisted Software Development”, study, 23 September 2025. Nearly 5,000 technology professionals worldwide, plus over 100 hours of qualitative data. [cloud.google.com](https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report)

[^10]: Gartner: “Gartner Predicts AI Coding Costs Will Surpass Average Developer’s Salary by 2028 as Token Consumption Surges”, press release, 24 June 2026. [gartner.com](https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges)

[^11]: Computer Weekly: “Gartner: AI coding agents will cost more than real developers”, 2026. [computerweekly.com](https://www.computerweekly.com/news/366645054/Gartner-AI-coding-agents-will-cost-more-than-real-developers)

[^12]: European Commission: “Cyber Resilience Act – Reporting obligations”, information page. [digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting)

[^13]: European Commission: “Cyber Resilience Act”, information page. [digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)
