KuppingerCole’s Buyer’s Guide on Hybrid Cloud Services is positioned as a structured starting point for selecting Infrastructure as a Service (IaaS) vendors in a hybrid IT delivery model, not as a complete procurement methodology. It directs organizations to begin by identifying primary use cases, then evaluate vendors against weighted functional and non-functional criteria, request and score vendor information, ask targeted follow-up questions, and narrow to a shortlist for deeper RFIs and proof-of-concept testing. The guide emphasizes ensuring technical and organizational prerequisites are in place so hybrid IaaS becomes part of a consistent architecture with aligned governance and management processes.
The report frames IaaS as a common, comparable layer across vendors that enables migrating existing workloads with minimal change while leaving customers responsible for operating systems, middleware, applications, access control, and regulatory compliance. Hybrid IT is presented as a response to security and compliance concerns in multi-cloud reality: sensitive data and critical systems can remain on-premises or in private cloud resources, improving control but increasing management complexity. Security and compliance are explicitly shared responsibilities: the provider secures the infrastructure, while the customer secures what runs on it and must still meet legal obligations.
Five leading IaaS use cases are highlighted—DevOps, disaster recovery, external-facing applications, hybrid workloads/data, and analytics/machine learning—each implying different priority weights across selection criteria. Functional criteria span deployment models, compute (including specialized GPU and bare metal), networking (including TLS and hybrid connectivity), storage types, continuity/failover, DevOps tooling, containers/Kubernetes, virtualization support, migration tooling, and serverless options. Non-functional criteria stress vendor viability, geographic jurisdiction, partner ecosystem, portal/management integration, access management, data security, cyber resilience, and independent compliance certifications, reinforced by a vendor-question set focused on real-world SLA performance, breach handling, responsibility boundaries, and integration capabilities.
See All Locations
See All Locations