A small-business CRM migration should move the minimum viable customer record—contacts, companies, deals, activities, owners, notes, essential custom fields, consent/suppression, and required integrations—through a short, reversible cutover. A small team needs fewer objects and stronger evidence, not an enterprise program copied at half scale.
This page owns the constraints of a small team with few admins and no dedicated data engineer. Use the broader CRM data migration checklist for complex/custom-object programs and the small-business CRM guide for product selection.
Keep the small-business migration deliberately small
Default to five core objects: people/contacts, companies/accounts, deals/opportunities, activities/tasks, and users/owners. Add products/line items, tickets, subscriptions or custom objects only when an active workflow, reporting, legal, service or finance requirement depends on them. Archive unused fields and workflows instead of reproducing clutter.
For each included object define what moves, what stays as encrypted reference, what is reconstructed, and what is retired. Include notes and selected attachments only when necessary and supported. Email/calendar history may remain in the provider or arrive through a new integration; do not duplicate it simply because it is visible in the old CRM.
Write success in observable terms: every active contact belongs to the correct company where expected; every open deal has owner, stage, amount, close date and associations; every required note/activity is readable and attributed; suppression survives; and the team can resume work without parallel editing.
Assign owners, evidence, and status
A tiny team still needs role separation. Migration owner prepares exports, mappings, imports and reconciliation. Business approver owns fields, stages, dedupe and acceptance. Privacy/security reviewer approves personal-data handling, consent, retention and deletion; this may be the founder with qualified advice. Each system/integration has a named owner.
| Task | Owner | Evidence | Status |
|---|---|---|---|
| Source export | Migration owner | Files, counts, timestamp, checksum | Not started / blocked / ready / accepted |
| Field/owner map | Business approver | Mapping sheet + decisions | Draft / approved |
| Consent/suppression | Privacy owner | Policy, source, edge tests | Blocked until accepted |
| Import/reconciliation | Migration owner | Job logs, counts, exception list | Test / canary / final |
| Cutover/rollback | Approver | Go/no-go and rehearsal record | Open / closed |
Keep this register in one controlled document. Store exports separately with least privilege. FTC guidance recommends knowing what personal information exists, limiting access/retention, securing it, and disposing of what is no longer needed; see Protecting Personal Information.
Build the source-to-target map
Map one source field to one target field and one authority. Capture source object/field/type, business meaning, requiredness, example/nulls, target object/field/type, transformation, default, owner, permission, stable old ID, relationship key, validation and retirement. Map stages and enumerations by meaning rather than label alone.
Preserve source record IDs in hidden/legacy-ID fields where the target permits; also create a crosswalk of source ID → target ID. Load in dependency order: active users/owners, companies, contacts, deals, then activities/notes and join/association records. A contact email or company domain is not always a unique key; shared inboxes, subsidiaries and changed domains require explicit handling.
Official tools vary. HubSpot documents export options including properties and associations for supported objects. Salesforce’s Data Import Wizard supports specified objects/CSV and recommends a small test. Close says JSON is needed to export all activities and offers additional account exports. These examples do not prove universal portability or cross-CRM equivalence.
Dedupe without destroying relationships
Dedupe from an approved candidate list, never by blind merge. Generate candidates using normalized email, phone, domain, source ID, CRM ID and company/name context. Decide survivor, field precedence, ownership, consent/suppression precedence, deal/activity/note reparenting and old-to-new ID mapping. Keep the most restrictive approved suppression state when evidence conflicts.
Pipedrive’s official guidance describes spreadsheet mapping and import permissions, while its duplicate documentation explains matching/merging behavior. Test the exact target: automated matching can join two people who share a value or fail to join aliases. Revert options can also be conditional; a vendor “revert” control is not your full rollback plan.
Perform dedupe before the final import when safe, but preserve immutable source and merge ledger. Never delete one side until every child deal, activity, note, owner and integration reference is accounted for. Run CRM data-quality checks without turning migration into an endless cleanup project.
Stage representative records and edge cases
Stage a small but representative corpus, not merely ten clean contacts. Include active/inactive owner, contact with/without company, multiple contacts at one company, shared email/domain, duplicate candidates, open/won/lost deals, multiple currencies, null and custom fields, long/Unicode note, past/future task, email/call/meeting history, deleted source record, suppressed contact and missing relationship.
Zoho’s CRM-to-CRM documentation shows data files, notes and attachment mappings plus unmapped-field reporting. It is a bounded Zoho path, not proof another source or target moves the same artifacts. Test each candidate vendor’s current import, edition, permissions, association format and limits from official docs and the actual tenant.
Use least-privilege import credentials. Salesforce documents that import permissions vary by object and tool. Confirm owners exist and can view/edit the target records; an import that succeeds under a super-admin can still leave reps unable to work.
Freeze briefly and capture the final delta
Use a short freeze only after staging passes. Announce exactly what users must stop editing: contacts, companies, deals, activities, notes, custom fields, ownership, stages, consent and integration configuration. Pause source automations and downstream writes; capture queued/error states.
Take a timestamped full snapshot, then a final delta containing created/updated/deleted/merged records since the snapshot. Record source, filters, timezone, file/row counts, bytes, schema and checksums. If the source cannot export a delta, compare two full exports using stable IDs and modified timestamps, and document uncertainty.
Keep downtime bounded by preparation, not optimism: target schema, users, mappings, integrations-off, staging, scripts/sheets, rollback and communication must be ready first. The appropriate freeze length depends on volume, tools, team, history and failures; there is no universal number of hours.
Reconcile records, fields, owners, relationships, and history
Reconcile five layers independently. Counts compare source expected, imported, failed, skipped, merged and accepted by object/status/owner. Fields compare exact values, nulls, enums, amounts/currencies, timestamps, custom fields, consent and suppression. Relationships verify contact-company, deal-company/contact, activity/note-record and owner edges.
Owner reconciliation verifies active/deactivated users, reassignment and permissions. History reconciliation checks earliest/latest activities, order, author, type, timestamps, notes and legacy IDs. Reconcile both directions: every expected source item has one target/disposition, and every target item traces to one source or approved new-system record.
Manually inspect all failures and a random sample of successes. A matching contact total can conceal wrong companies; a matching deal total can conceal wrong owner or stage. Record missing, duplicate, orphaned, truncated, transformed and unknown cases. Hard gates include missing suppression, wrong owner on open deal, broken critical relation, unauthorized exposure and unrecoverable rollback.
Cut over reversibly and prove rollback
Cut over in reversible layers. Import users and core records, reconcile, then history/notes, reconcile, then enable integrations one at a time. Start target automations read-only/draft-only or on internal records. Only one CRM may own each integration and write path; disable source sync before enabling target for that scope.
The kill switch stops target imports, automations and integrations while keeping logs. Rollback disables target writers, restores source access/integrations where still contractually possible, uses crosswalk and import batch IDs to remove/reverse target changes, corrects downstream systems and replays only proven missing updates. Test rollback on staging/canary before final cutover.
Follow CRM integration controls for retries, duplicate writes, permissions and field authority. Keep the source read-only for the approved rollback window rather than asking reps to update two CRMs.
Record the accepted owners, training, launch support, and post-cutover controls in your CRM implementation checklist; migration acceptance is the handoff into operating governance, not the end of it.
Decommission and delete only after acceptance
Decommission after business acceptance, integration proof and rollback expiry. Disable users/service accounts, SSO/OAuth/API keys, email/calendar/phone/marketing/accounting/support integrations, webhooks, forms, automations, scheduled exports and billing. Rotate secrets; update website forms, bookmarks, documentation, inventories and incident contacts.
Request deletion/return evidence under the executed agreement and applicable policy. Record scope, timing, permitted retention, backups/subprocessors and confirmation. Maintain only the approved encrypted archive for its retention period, then dispose securely. Deletion is not proof that every object was portable, and export does not authorize indefinite retention.
Apply the worked example and calculate TCO
Synthetic example—not a vendor result: the small CRM has 1,000 contacts, 300 companies, 200 deals, 3,000 activities/notes and 10 users: 4,510 records. Target accepts 4,470, merges 20 approved duplicates, archives 10, and leaves 10 unresolved. Accounted rate is 4,500/4,510 = 99.8%, but one unresolved suppressed-contact record blocks go-live.
The manifest expects 2,400 relationships; 2,380 pass, 15 are approved absent and five are wrong. Accepted relationship rate is 2,380/2,400 = 99.2%. Do not treat that as a universal threshold: correct all critical open-deal/consent edges and have the owner accept bounded historic gaps.
TCO = source export/support + target licenses + temporary admin/help + cleanup/dedupe + mapping/import + integrations + secure storage + privacy/security/legal + testing/reconciliation + overlap + user training + incidents/rollback + decommission/exit − retired costs. Model low/base/high manual cleanup and overlap. A cheaper CRM can cost more if history or associations require reconstruction.
Print the owner-evidence-status checklist
☐ Scope core objects only — Owner: ___ Evidence: ___ Status: ___
☐ Export and checksum source — Owner: ___ Evidence: ___ Status: ___
☐ Approve field/stage/owner map — Owner: ___ Evidence: ___ Status: ___
☐ Preserve old IDs and relationship crosswalk — Owner: ___ Evidence: ___ Status: ___
☐ Review dedupe/merge candidates — Owner: ___ Evidence: ___ Status: ___
☐ Stage edge-case corpus and permissions — Owner: ___ Evidence: ___ Status: ___
☐ Freeze, pause writes, capture final delta — Owner: ___ Evidence: ___ Status: ___
☐ Reconcile counts/fields/owners/edges/history — Owner: ___ Evidence: ___ Status: ___
☐ Prove kill switch and rollback — Owner: ___ Evidence: ___ Status: ___
☐ Enable one integration at a time — Owner: ___ Evidence: ___ Status: ___
☐ Revoke/decommission/delete and record TCO — Owner: ___ Evidence: ___ Status: ___
The best small-business migration is not the fastest claim. It is the smallest defensible scope that preserves the customer record, gives the team one place to work, and remains reversible until evidence supports closure.