Data Sovereignty as an Architectural Principle
Decisions about the cloud are decisions about sovereignty
With every cloud migration, decisions are made regarding the jurisdiction under which data will be processed, the actual scope of certifications, and the extent to which an architecture becomes dependent on a single provider.
Non-European hyperscalers are subject to regulations such as the Cloud Act. This complicates data processing agreements and technical and organizational measures.
Not every C5 audit covers the same scope. The difference between Type 1 and Type 2, as well as between individual services and the entire platform, determines the actual depth of the audit.
Proprietary APIs and formats lock workloads into a single provider. Switching providers later on becomes technically and financially burdensome.
Contractually defined exit scenarios and data export are among the standard requirements of the EVB-IT Cloud in public tenders. Since the enactment of the Data Act, switching providers has also become legally mandatory in some cases.
True Cloud Sovereignty
Our customized cloud solution gives you the freedom and control you need to protect your data and maintain your autonomy. Learn more about true sovereignty in a cloud where data security, operational independence, and technological freedom are not just goals, but a living reality. Your digital infrastructure, operating exclusively according to your rules.
Data Sovereignty
Organisationen müssen sicherstellen, dass ihre Daten stets den rechtlichen Rahmenbedingungen ihres Heimatlandes unterliegen. Dies bedeutet, dass die Speicherung und Verarbeitung von Daten in Übereinstimmung mit der DSGVO und anderen lokalen Gesetzen erfolgen muss. Die Einhaltung dieser Gesetze ist nur garantiert, wenn Daten nicht durch ausländische Gesetzgebung, wie den US CLOUD Act, bedroht werden. Eine souveräne Cloud-Lösung ist daher vollständig in Europa verankert und gewährleistet, dass Daten in europäischen Rechenzentren verarbeitet werden.
Operational Autonomy
Unternehmen und Organisationen müssen jederzeit volle Transparenz und Kontrolle über die betrieblichen Abläufe der genutzten Cloud-Lösung haben. Dies bedeutet, dass Kunden detaillierten Einblick in die Sicherheitsprotokolle, den Betrieb und die Infrastruktur haben und notwendige Änderungen eigenständig initiieren können. Eine Einschränkung dieser Kontrolle durch externe Anbieter oder Drittparteien muss ausgeschlossen sein. Im Vergleich zu US-Lösungen, bei denen der Zugriff oft eingeschränkt ist, bieten souveräne Cloud-Lösungen diese Transparenz und Kontrollmöglichkeiten von Beginn an.
Technological Sovereignty
Eine wirklich souveräne Cloud-Lösung bietet Unternehmen die Möglichkeit, ihre technologische Basis selbst zu verwalten und zu kontrollieren. Dabei sollte die Wahl der genutzten Technologien offen und flexibel sein, sodass Organisationen nicht in Abhängigkeit von bestimmten Anbietern geraten. Offene Standards und Open-Source-Lösungen spielen hier eine zentrale Rolle, da sie sicherstellen, dass Systeme anpassbar und interoperabel bleiben. Dies schützt vor langfristigen Kostenfallen und technischen „Lock-ins“, die bei proprietären Systemen oft auftreten.
Economic Sovereignty
Zertifizierungen & Standards






White Paper: Digital Sovereignty in Germany and Europe
Is an exit strategy required by law?
Since the Data Act (Regulation (EU) 2023/2854, September 2025) took effect, switching providers has become a legal requirement in certain cases. Articles 23 through 31 require cloud providers to remove technical barriers to switching, reduce switching fees to zero by January 2027, and ensure data portability by default. Open interfaces and standardized data formats structurally meet these requirements.
Does GAIA-X guarantee digital sovereignty?
Not without limitations. Leading U.S. hyperscalers such as AWS, Microsoft, and Google are members of the initiative, which structurally limits the original sovereignty goals. GAIA-X remains relevant as a framework for interoperability standards, but it does not guarantee independence from non-European providers. The specific technical and contractual requirements in each individual case are decisive.
Can the EUCS already be used as a reference framework?
No. The European Cybersecurity Certification Scheme for Cloud Services has been under development since 2019 and has not yet entered into force. A binding EUCS is not expected before 2027, and its exact content remains to be determined. Established standards such as BSI C5 and IT-Grundschutz can be relied upon for current procurement decisions.
What is the Germany Stack?
In March 2026, the IT Planning Council formally approved the initiative, thereby establishing the Sovereign Cloud Stack as the technical foundation for a shared digital infrastructure for public administration at the federal and state levels. It combines the open technical SCS standard with a federal implementation mandate.
Does NIS2 also apply to cloud providers?
Yes. The NIS2 Implementation Act has been in effect since December 6, 2025, and expands the scope of organizations subject to the requirements to approximately 30,000 entities across 18 sectors. Cloud providers are explicitly included as part of the ICT supply chain. For proprietary providers that do not offer full infrastructure transparency, it is structurally more difficult to provide the required evidence than it is for auditable open-source solutions.
Does open source alone guarantee sovereignty?
No. Even preconfigured “sovereign” platform stacks can create structural lock-in effects if key components—such as identity management or Kubernetes distributions—are strictly predetermined. What matters most is the actual interchangeability of individual components, the openness of the interfaces, and the ability to continue operations independently of the original provider.
Data Sovereignty for Your Infrastructure
Talk to us about jurisdiction, certification, and the architecture of your cloud environment.
Resources