Sovereign Cloud · Germany & EU
Sovereign Cloud Consulting: Control over Data, Keys and Providers
Insight42 advises public authorities, critical infrastructure (KRITIS) operators and regulated companies on the path to a sovereign cloud: from the Sovereign Cloud Assessment and provider selection (AWS European Sovereign Cloud, Delos Cloud, STACKIT, IONOS, Azure/GCP with EU controls) to a landing zone that meets BSI C5, NIS2 and GDPR from day one.
What “sovereign cloud” really means in 2026
Digital sovereignty is not a data center location. A cloud is sovereign when your organization can answer three questions with “we” at any time: Who can access the data? Who holds the cryptographic keys? Who decides when and where we switch? Data residency in Frankfurt is necessary for this, but not sufficient — otherwise the US CLOUD Act, operations staff outside the EU and proprietary services without an exit path remain unresolved.
The market moved significantly in 2026: the AWS European Sovereign Cloud has been in production in Brandenburg since January 2026 and is operated by an EU company with EU staff. Delos Cloud brings the Microsoft stack under German operational control for the public sector. STACKIT and IONOS offer European-controlled platforms, while the Deutsche Verwaltungscloud (DVC) has become a product of the IT Planning Council. At the same time, the BSI has renewed its criteria catalogue with C5:2026. So the question is no longer “whether”, but “which level of sovereignty for which workload — and at what price”.
This is exactly the decision we structure. Vendor-neutral, with architects who have built the platforms themselves, and with a result you can defend in procurement, audit and board.
Who this consulting is for
Public administration
Federal, state and local government and public IT service providers who want to move to the cloud in line with DVC, BSI C5 and procurement law — without dependency on a single hyperscaler.
KRITIS & regulated companies
Energy, healthcare, finance, water, transport: organizations under NIS2, the KRITIS umbrella act (KRITIS-Dachgesetz), DORA or sector-specific supervision that must use the cloud but owe evidence.
CIO, CISO & enterprise architecture
Decision-makers who need a robust sovereignty strategy — not a slide, but architecture, contracts, key custody and an exit plan.
Typical situations in which clients come to us
- “We use Azure or AWS in Frankfurt and believe that makes us sovereign — the data protection officer and the auditor see it differently.”
- “The tender requires a C5 attestation, DVC conformity and EU operational control. Which provider really meets that, and what does the difference cost?”
- “Our keys are held by the provider. In the event of termination, sanctions or government access, we would have no leverage.”
- “We want to evaluate Delos Cloud, STACKIT or the AWS European Sovereign Cloud, but we have no basis for comparing feature parity, lock-in and migration effort.”
- “We have an exit strategy on paper. Nobody has ever tested it.”
Our sovereign cloud services
1. Sovereign Cloud Assessment (2–4 weeks)
We classify your workloads by protection needs and sovereignty requirements (data residency, operational sovereignty, technical and legal immunity) and assess your current state against BSI C5:2026, NIS2, GDPR/Schrems II and the criteria of the EU Cloud Sovereignty Framework and the Bitkom criteria catalogue.
Result: Sovereignty scorecard per workload, risk register, prioritized action list, decision paper for management or board.
2. Provider selection & target architecture
Structured comparison of the AWS European Sovereign Cloud, Delos Cloud, STACKIT, IONOS, T-Systems/Open Telekom Cloud as well as Azure and Google Cloud with EU controls — by feature parity, operational control, key model (BYOK/HYOK/External Key Manager), attestations, cost model and exit capability.
Result: Decision matrix, target architecture (single, hybrid or multi-cloud), requirements catalogue for procurement/EVB-IT and contract negotiation.
3. Sovereign landing zone & migration
Building the landing zone with identity (Zero Trust, Conditional Access), network (private connectivity, ExpressRoute/Direct Connect), encryption with customer-controlled keys, central logging and policy-as-code — as infrastructure as code, so that C5 and NIS2 controls are provable and reproducible. Then migration in waves following the Cloud Adoption Framework.
Result: Production-ready landing zone, migration plan, control evidence for audit and supervision. Details: cloud migration consulting and our Cloud Adoption Framework approach.
4. Key custody & exit readiness
Design and implementation of BYOK/HYOK with HSM, key lifecycle processes and emergency access. Plus a tested exit plan: data export, portability, restart at an alternative provider — rehearsed, not just documented.
Result: Key concept, exit runbook, exercise report. More on this: encryption & key management.
5. Compliance support: C5, NIS2, IT-Grundschutz
Mapping the customer-side C5 criteria, NIS2 risk management measures and IT-Grundschutz modules to your cloud architecture; preparation for audits. See BSI C5 consulting and NIS2 consulting.
How we work
- Scoping workshop (1 day): Goals, regulatory framework, workload inventory, stakeholders. A clear definition of what “sovereign” means for you in concrete terms.
- Assessment (2–4 weeks): Protection needs analysis, gap analysis against C5:2026/NIS2/GDPR, provider shortlist, cost model.
- Decision: Target architecture and provider selection with a decision paper — defensible to management, data protection, internal audit and the procurement office.
- Implementation: Landing zone as code, key custody, migration in waves, control evidence.
- Operations & evidence: Optional managed services with continuous compliance monitoring, exit exercises and an annual reassessment.
Technologies & regulations we work with
Platforms
AWS European Sovereign Cloud, Delos Cloud, STACKIT, IONOS Cloud, Open Telekom Cloud, Microsoft Azure (incl. Cloud for Sovereignty), Google Cloud (Sovereign Controls), OpenStack/Kubernetes on-prem and hybrid.
Security & keys
HSM, Azure Key Vault Managed HSM, AWS KMS External Key Store, Google Cloud EKM, HashiCorp Vault, Confidential Computing, Zero Trust identity (Entra ID, Keycloak).
Regulation
BSI C5:2020/C5:2026, IT-Grundschutz, ISO 27001, NIS2 (NIS2UmsuCG, in force since 6 December 2025), KRITIS umbrella act, GDPR/Schrems II, DORA, EU AI Act, German Administration Cloud strategy, EU Cloud Sovereignty Framework.
Why Insight42
- Vendor-neutral. We do not sell cloud capacity. Our recommendation follows your protection needs, not partner commissions.
- Engineers, not slide consultants. The architects who write the assessment then build the landing zone — as code, with evidence.
- Regulation from practice. Experience with BSI C5 and IT-Grundschutz in public-sector projects; GDPR and EU data residency as an architecture principle, not an afterthought.
- German company, based in Ingolstadt. German contract basis, German- and English-speaking contacts, European standards.
Frequently asked questions about sovereign cloud
Is a data center in Germany enough for digital sovereignty?
No. Data residency does not protect against access by the operator or by third-country law such as the US CLOUD Act. Sovereignty only arises from the combination of residency, customer-controlled keys, EU operational control and real exit capability.
AWS European Sovereign Cloud, Delos Cloud or STACKIT — which is “the most sovereign”?
That depends on the workload. The offerings differ in operating model, range of services, key model and price. We evaluate them in a decision matrix against your specific requirements instead of making blanket judgments.
Do we as a cloud customer need our own C5 attestation?
Usually not — the attestation concerns the provider. However, you must fulfil and be able to prove the corresponding customer-side criteria. This is exactly where our BSI C5 consulting helps.
How long does a Sovereign Cloud Assessment take?
Two to four weeks, depending on the number of workloads. You receive a scorecard, a risk register and a decision paper — with no obligation to implement with us.
Further reading
How sovereign is your cloud really?
In a 30-minute initial call we clarify your protection needs, the regulatory framework and whether a Sovereign Cloud Assessment makes sense for you.
Why Insight42
- Regulated-market focus: we work with enterprises and public-sector organizations in Germany and Europe, and design architectures aligned with BSI C5, NIS2 and GDPR.
- End-to-end delivery: assessment, architecture, implementation and operations from one team — founded and led by Martin-Peter Lambert in Ingolstadt.
- Engineers who ship: we build and operate our own products — Secretary42, Unimatrix-OI and InheritanceVault — and bring the same production discipline to client work.
- Sovereignty by design: data residency, key custody (BYOK/HYOK) and a documented exit strategy are design inputs from day one.