The honest version of what an eQMS migration involves — what moves, what runs in parallel, and where the risk actually lives.
Replacing a quality system is not a software purchase, it is a records project. The subscription is the easy number. The cost that surprises teams is the effort of deciding what comes across, proving it came across intact, and keeping the old system available long enough that nobody has to guess.
Three things drive that effort, and you can estimate all of them before you sign anything.
Retention is set by your frameworks, not your vendor. Blood establishments hold records for ten years under 21 CFR 606; device manufacturers keep design history for the life of the device plus two years; CLIA laboratories hold most records two years and some considerably longer. Decide the retention obligation per record type before you scope migration — it is the single biggest lever on effort, because it determines whether you move a decade of closed CAPAs or reference them in place.
Most systems will export records. Fewer will export the audit trail attached to them, and that is the part an inspector asks about. Request a sample export from your incumbent early — not at termination, when goodwill is thin. If the audit trail does not come with the record, the defensible approach is to keep the legacy system readable for the retention period and migrate forward-looking data only. That is a normal, inspectable decision when it is documented as one.
Someone has to confirm that what arrived matches what left. That work is yours regardless of vendor, but its size depends on whether the migration is scripted and verifiable or hand-assembled. Ask any vendor for their reconciliation approach and the evidence it produces. If the answer is a spreadsheet of counts, your quality team owns the proof.
The sequence is not arbitrary. Controlled documents are the spine — training assignments, deviations, and CAPAs all reference them, so moving documents first means everything after it lands with its references intact. Training follows immediately, because a document revision without its training assignments is the most common finding in the first inspection after any system change.
Open quality events move last, and only the open ones. A CAPA mid-investigation has to move with its full chain — the deviation that triggered it, the root cause, the actions, the owners, the dates. Closed events from prior years usually do not need to move at all; they need to remain retrievable, which is a different and much cheaper requirement.
Equipment and supplier records sit between the two. They are self-contained enough to move early, but they carry schedules — calibration intervals, requalification windows — that have to land with the correct next-due dates or the first month in the new system generates a wave of false overdues.
For a short window, live work runs in both the old system and Kintavo. It feels redundant; it is the cheapest insurance in the project. The parallel run catches the workflow gap no rehearsal finds, proves the migrated data against reality, and gives your team confidence with real records before the cutover decision.
Cutover itself happens under change control — assessed, approved, dated — so the migration is itself an audit-ready record. The old system goes read-only, retained per your records policy, and every record after the effectivity date lives in one place.
IQ/OQ execute against your configured Kintavo instance, and PQ runs your processes with your people — the same 6–8-week validation path as any new implementation, with documentation delivered signed as each phase completes. Migrated records are verified as part of PQ, so historical data is covered by the same package.
What you should not accept from any vendor, us included: a migration plan without a record-count reconciliation, or a validation package that ignores migrated data.
The comfortable sequence: demo and gap assessment while the incumbent contract is still running, migration and parallel run in the final 60 days, cutover before renewal so you never pay for two systems longer than the parallel window. If your renewal is closer than that, say so in the demo request — compressed timelines are workable when we know upfront.
The reason for the ninety days is leverage, not logistics. Starting with a live contract behind you means you are choosing an alternative rather than negotiating against a deadline — and teams who start thirty days out almost always auto-renew for another year.