Data Sovereignty as an Architectural Principle

secunet cloud operates its infrastructure exclusively in German data centers certified to BSI C5, IT-Grundschutz, and the Sovereign Cloud Stack—providing a solid foundation for sound decision-making.
syseleven.de has become secunet.cloud. You are already on our new website. The platform, services and contacts remain the same.

Decisions about the cloud are decisions about sovereignty

With every cloud migration, decisions are made regarding the jurisdiction under which data will be processed, the actual scope of certifications, and the extent to which an architecture becomes dependent on a single provider.

Non-European hyperscalers are subject to regulations such as the Cloud Act. This complicates data processing agreements and technical and organizational measures.

Not every C5 audit covers the same scope. The difference between Type 1 and Type 2, as well as between individual services and the entire platform, determines the actual depth of the audit.

Proprietary APIs and formats lock workloads into a single provider. Switching providers later on becomes technically and financially burdensome.

Contractually defined exit scenarios and data export are among the standard requirements of the EVB-IT Cloud in public tenders. Since the enactment of the Data Act, switching providers has also become legally mandatory in some cases.

True Cloud Sovereignty

Our customized cloud solution gives you the freedom and control you need to protect your data and maintain your autonomy. Learn more about true sovereignty in a cloud where data security, operational independence, and technological freedom are not just goals, but a living reality. Your digital infrastructure, operating exclusively according to your rules.

Organisationen müssen sicherstellen, dass ihre Daten stets den rechtlichen Rahmenbedingungen ihres Heimatlandes unterliegen. Dies bedeutet, dass die Speicherung und Verarbeitung von Daten in Übereinstimmung mit der DSGVO und anderen lokalen Gesetzen erfolgen muss. Die Einhaltung dieser Gesetze ist nur garantiert, wenn Daten nicht durch ausländische Gesetzgebung, wie den US CLOUD Act, bedroht werden. Eine souveräne Cloud-Lösung ist daher vollständig in Europa verankert und gewährleistet, dass Daten in europäischen Rechenzentren verarbeitet werden.


Unternehmen und Organisationen müssen jederzeit volle Transparenz und Kontrolle über die betrieblichen Abläufe der genutzten Cloud-Lösung haben. Dies bedeutet, dass Kunden detaillierten Einblick in die Sicherheitsprotokolle, den Betrieb und die Infrastruktur haben und notwendige Änderungen eigenständig initiieren können. Eine Einschränkung dieser Kontrolle durch externe Anbieter oder Drittparteien muss ausgeschlossen sein. Im Vergleich zu US-Lösungen, bei denen der Zugriff oft eingeschränkt ist, bieten souveräne Cloud-Lösungen diese Transparenz und Kontrollmöglichkeiten von Beginn an.


Eine wirklich souveräne Cloud-Lösung bietet Unternehmen die Möglichkeit, ihre technologische Basis selbst zu verwalten und zu kontrollieren. Dabei sollte die Wahl der genutzten Technologien offen und flexibel sein, sodass Organisationen nicht in Abhängigkeit von bestimmten Anbietern geraten. Offene Standards und Open-Source-Lösungen spielen hier eine zentrale Rolle, da sie sicherstellen, dass Systeme anpassbar und interoperabel bleiben. Dies schützt vor langfristigen Kostenfallen und technischen „Lock-ins“, die bei proprietären Systemen oft auftreten.



Zertifizierungen & Standards

IT-Grundschutz
ISO 27001
ISO 27017
ISO 27018
BSI C5 Type 2

White Paper: Digital Sovereignty in Germany and Europe

Placing Jurisdiction, Certification, and Open Stack within the Broader Regulatory Context: C3A, Deutschland-Stack, and EuroStack as Frameworks for Sovereign Cloud Architectures.
Download the white paper
FAQ
Frequently Asked Questions About Data Sovereignty

Since the Data Act (Regulation (EU) 2023/2854, September 2025) took effect, switching providers has become a legal requirement in certain cases. Articles 23 through 31 require cloud providers to remove technical barriers to switching, reduce switching fees to zero by January 2027, and ensure data portability by default. Open interfaces and standardized data formats structurally meet these requirements.


Not without limitations. Leading U.S. hyperscalers such as AWS, Microsoft, and Google are members of the initiative, which structurally limits the original sovereignty goals. GAIA-X remains relevant as a framework for interoperability standards, but it does not guarantee independence from non-European providers. The specific technical and contractual requirements in each individual case are decisive.


No. The European Cybersecurity Certification Scheme for Cloud Services has been under development since 2019 and has not yet entered into force. A binding EUCS is not expected before 2027, and its exact content remains to be determined. Established standards such as BSI C5 and IT-Grundschutz can be relied upon for current procurement decisions.


In March 2026, the IT Planning Council formally approved the initiative, thereby establishing the Sovereign Cloud Stack as the technical foundation for a shared digital infrastructure for public administration at the federal and state levels. It combines the open technical SCS standard with a federal implementation mandate.


Yes. The NIS2 Implementation Act has been in effect since December 6, 2025, and expands the scope of organizations subject to the requirements to approximately 30,000 entities across 18 sectors. Cloud providers are explicitly included as part of the ICT supply chain. For proprietary providers that do not offer full infrastructure transparency, it is structurally more difficult to provide the required evidence than it is for auditable open-source solutions.


No. Even preconfigured “sovereign” platform stacks can create structural lock-in effects if key components—such as identity management or Kubernetes distributions—are strictly predetermined. What matters most is the actual interchangeability of individual components, the openness of the interfaces, and the ability to continue operations independently of the original provider.


Contact request

Data Sovereignty for Your Infrastructure

Talk to us about jurisdiction, certification, and the architecture of your cloud environment.

I acknowledge that I have the right to object to the processing of my data at any time, with effect for the future. Further information on the processing of your personal data can be found at: https://www.secunet.cloud/en/privacy-policy.