Defense Capabilities Require Their Own Infrastructure
In Everyday Operations
Defense Capability Is Evident in the Details, Not in the Situation Report
Cloud infrastructure in the defense sector proves its worth not in theory, but in concrete aspects of the day-to-day operations of the armed forces and the defense industry, which is subject to security clearance requirements.
Members of the armed forces need secure access to administrative and logistical systems from various locations, sometimes under harsh operational conditions. secunet.cloud ensures that the unclassified systems behind these operations are available at all times, tailored to the SINA ecosystem for higher classification levels.

A defense contractor processes bid documents and technical data up to the VS-NfD classification level in collaboration with government agencies and the client. This collaboration must be conducted in accordance with VSA standards, without any data discontinuities between the organizations.
Navigation, reconnaissance, and communication are increasingly reliant on space-based infrastructure. The cyber and information space surrounding these systems must be secured just as robustly as traditional IT networks.

Regulatory Context
Requirements Applicable to the Public Sector
The defense sector is subject to the highest classification levels. VS-NfD, GEHEIM, NATO SECRET, and SECRET UE/EU SECRET govern the handling of classified data, while the Classification Directive (VSA) defines the procedures for doing so. For the defense-related industrial sector, the security regulations for the commercial sector under the Security Clearance Act also apply. BSI C5 remains the assessment catalog for the cloud level, while NIS2 sets minimum standards for network and information security, including in the defense sector. Cloud services cover only data up to the VS-NfD classification level; higher classifications are reserved for the dedicated SINA ecosystem.
Sovereignty
Alliance-capable while remaining independent
NATO and EU interoperability require open standards. National security requires control over one’s own infrastructure. Both must apply simultaneously; they should not be a compromise.
Open Standards as a Foundation
secunet cloud is based on Kubernetes and OpenStack. Open standards instead of proprietary black boxes—transparent and auditable.
No dependence on a single manufacturer
Runs on standard hardware without being tied to a single vendor. Procurement decisions remain independent of any single supply chain.
Independence as a prerequisite, not as an option
A migration path back to one's own infrastructure or to another provider is part of the concept from the very beginning. In the defense sector, this is not just a nice-to-have.
Can be operated directly from the command post
The same cloud stack also runs on the barracks grounds or in the command post when an external connection is not an option.
Operations in Germany
If secunet takes over operations, this is done exclusively in certified data centers within Germany.
From procurement logistics to classified information: four levels of security requirements

For administrative, logistics, and procurement systems that do not handle classified information. Fully scalable for use in Germany.

Cloud platform for classified information up to VS-NfD. For GEHEIM, NATO SECRET, and higher classifications, the dedicated SINA ecosystem is used, not the cloud.

A self-sufficient infrastructure for AI models and AI-related business processes, without sharing data with external providers.
Zertifizierungen & Standards




Discuss cloud strategies for the military or industry
Whether it’s administrative systems, VS-NfD classification, or integration with the SINA ecosystem: We’ll work with you to assess your needs.
Resources