Zero-downtime migration is not a product you buy. It is a sequence you rehearse until it is boring.
Replicate continuously, cut over briefly
Get the target in sync and keep it in sync. The cutover window then shrinks from hours of copying to minutes of pointing.
Rehearse the rollback, not just the cutover
Teams rehearse going forward and improvise going back. Execute the rollback at least once in a dry run — the first time you try it should never be at 03:00 with the business waiting.
Cut over in slices
Region by region, store by store, tenant by tenant. A failure then affects one slice, and you learn before it matters.
Define the abort criteria in advance
Write down what "not working" means before the night begins, and who is allowed to call it. Under pressure, nobody wants to be the one deciding.
Keep the old system warm
Decommission a week later, not the same night. The cost of a few extra days is trivial next to the cost of being wrong.