🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

SAP BTP

Germany · PaaS · https://www.sap.com/products/technology-platform.html

Sovereignty score73.4%
Global (unweighted)73.2%
Overall SEAL
SEAL-2 Data Sovereignty
SOV-1 Strategic Sovereignty85.4SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty83.2SEAL-2
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty62.6SEAL-3
SOV-5 Supply Chain Sovereignty60.7SEAL-3
SOV-6 Technology Sovereignty60.0SEAL-3
SOV-7 Security & Compliance Sovereignty78.5SEAL-3
SOV-8 Environmental Sustainability75.1SEAL-3

SOV-1 · Strategic Sovereignty 85.4% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: SAP SE is a German (Walldorf) Societas Europaea incorporated under EU law; the scoped SAP Sovereign Cloud offer is owned and operated entirely within the EU -> opt4. (src: https://news.sap.com/2026/04/sap-cloud-infrastructure-it-grundschutz-certification-data-centers-germany/)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highSAP is a DAX/EURO STOXX 50 constituent with dispersed shareholding and German roots; takeover by a non-EU sovereign entity is very unlikely -> opt5 (kept, all-seal-4 factor).
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumEU-controlled roadmap with own R&D and EU governance participation (DSAG user group, BSI oversight on sovereign offer, Gaia-X) -> opt3 (governance bodies with EU actor participation).
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highSAP is a profitable self-funding listed EU company financed through European capital markets and operating cash flow -> opt5 (kept, all-seal-4 factor).
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4highHQ, majority of R&D and a very large employee base are in Germany/EU, making the EU economic contribution dominant -> opt4 (kept, all-seal-4 factor).
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4mediumStrong participation in EU strategic programs (Gaia-X, Delos sovereign cloud for German administration, EU AI Cloud, EUR 20bn sovereign-cloud commitment) -> opt4 (kept, all-seal-4 factor).
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumDedicated sovereign-cloud governance and published measured investment plans (EUR 20bn over a decade) aligned with EU industrial strategy -> opt3 (kept, all-seal-4 factor).
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: the SAP Sovereign Cloud offer runs on SAP-owned EU data centers on open-source IaaS with SAP-developed core software and a documented continuity plan (SAP publicly states 'no kill switches'); residual foreign chips are hardware-only -> opt5 'Full autonomy and continuity'.

SOV-2 · Legal & Jurisdictional Sovereignty 83.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4mediumThe scoped sovereign offer is contracted under EU/member-state (German) law only, with EU-only data and EU sub-processors -> opt3 'Exclusively EU law'. (src: https://news.sap.com/2026/06/vs-nfd-authorization-sap-cloud-infrastructure/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumimmunity not certified: eu_entity with EU-only ops and structural shielding, but SAP SE has US subsidiaries (operational nexus) and holds no SecNumCloud/EUCS-High, so immunity is structural not verified -> opt4 'Legal structures shielding' (seal-2 ceiling). (src: https://news.sap.com/2026/06/vs-nfd-authorization-sap-cloud-infrastructure/)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumno foreign_parent: the operator is German (SAP SE), not US/PRC controlled, so there is no CLOUD Act/FISA pathway through a foreign parent; the sovereign offer commits to reject/challenge access requests (EU-only data, EU Access, BSI oversight) -> opt5 'Requests always rejected' (same basis as S3NS/STACKIT). (src: https://news.sap.com/2026/06/vs-nfd-authorization-sap-cloud-infrastructure/)
SOV-2.4Export control restrictions4. Part of offer shielded from restrictions towards EU MSs125/167SEAL-3mediumEU-headquartered vendor not subject to export bans toward EU Member States; the sovereign offer is shielded from restrictions toward EU MSs -> opt4.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4highCore BTP IP (HANA, ABAP, CAP, Kyma, Gardener, Cloud Foundry runtime) is SAP-developed originating largely in Germany/EU, with some embedded third-party components -> opt4 'Mostly within the EU' (kept, all-seal-4 factor).
SOV-2.6IP holder jurisdiction4. EU law with exceptions125/167SEAL-4highPrincipal IP holder is SAP SE under German/EU law, with some licensed third-party components under other jurisdictions -> opt4 'EU law with exceptions'.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3mediumSAP Data Custodian and customer-managed-key (BYOK/HYOK) options give customers primary key control, but as operator SAP retains technical ability to read, so not exclusive customer-only -> opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowSovereign offer provides full customer-controlled audit and access logging via trust center/SIEM integration, though not uniformly real-time across all services -> opt4 'Full customer-controlled visibility, not real-time'.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowDeletion is technically performed and evidenced via access logs and retention policy under C5/IT-Grundschutz controls -> opt4 'Deletion technically verified with access logs'.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4mediumeu_exclusive: the SAP Sovereign Cloud option stores and processes data exclusively in SAP-owned EU data centers (Walldorf/St. Leon-Rot) with EU Access restricting sub-processors to EEA, contractually no third-country fallback -> opt5 'Exclusively EU'. (src: https://news.sap.com/2026/04/sap-cloud-infrastructure-it-grundschutz-certification-data-centers-germany/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumSovereign AI offering is EU-led (SAP ABAP model, EU-hosted) running on foreign accelerators; the sovereign-scoped AI keeps models/inference in EU rather than brokering to non-EU APIs -> opt4 'EU-led AI, foreign accelerators'.

SOV-4 · Operational Sovereignty 62.6% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumBuilt on Kubernetes/Cloud Foundry/Kyma with documented export/migration paths, multi-cloud abstraction (Gardener) and formal SAP migration services -> opt4 'Formal migration services available'.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops: the sovereign offer is operated by SAP in EU-owned data centers by predominantly EU-based, cleared/nationally-approved teams (VS-NfD authorization) -> opt4 'Ops predominantly EU-based teams'.
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3mediumVery large EU engineering base (Germany), with escalation possible abroad in the global org; sovereign offer staffed by approved EU personnel -> opt3 'Majority EU, escalation abroad'.
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3mediumSovereign offer with EU Access keeps support within EEA/Switzerland with cleared personnel; majority EU support with non-EU escalation -> opt3 'Majority in EU, non-EU escalations'.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowEU-primary documentation and knowledge repositories with global English-language fallback; not enforced EU-only end-to-end -> opt3 'EU primary with non-EU fallback'.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumown_stack: the sovereign offer's critical subprocessors are SAP-owned EU facilities, with documented ability to source alternatives or internalise -> opt4 'Ability to source alternatives or internalise'.

SOV-5 · Supply Chain Sovereignty 60.7% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowSAP-owned EU data centers with disclosed hardware provenance under C5/IT-Grundschutz/TSI audits, though residual non-EU chips remain -> opt3 'Transparent with exceptions'.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowHardware is foreign-designed but assembled/integrated in SAP-owned EU data centers with EU audit rights under C5/IT-Grundschutz/TSI -> opt3 'Mixed sourcing, EU audit rights' (same basis as STACKIT/S3NS).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in underlying servers and network gear is supplied by non-EU OEMs with partial provenance transparency -> opt2 (factor is all-seal-4; kept conservative).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3highno foreign_core: the platform core (HANA, ABAP, CAP, integration suite, Kyma, Gardener) is SAP EU IP, designed and maintained substantially by EU teams; not licensed Google/MS tech -> opt4 'Large majority maintained by EU teams'.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowBuild and release of SAP software is controlled and executed by SAP, an EU company, with EU-based engineering control and execution -> opt4 'EU control & execution'.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumIn the sovereign offer the critical infrastructure is SAP-owned EU; remaining non-EU dependencies (chips, some OEM components) are non-critical and documented -> opt4 'Few non-EU in non-critical services, documented'.
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowSAP publishes subprocessor lists and trust-center information and audits suppliers under C5/IT-Grundschutz; most suppliers auditable for the sovereign offer -> opt4 'Most suppliers auditable'.

SOV-6 · Technology Sovereignty 60.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumBTP exposes standards-based interfaces (Kubernetes, OData, REST, Cloud Foundry) and broadly compatible APIs -> opt4 'Standards-based and broadly compatible'.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumOpen-standards policy across most core runtimes (Kubernetes, Istio, OCI containers, OData, OpenAPI, CAP) -> opt4 'Policy for most core services'.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumno foreign_core: core remains SAP-controlled but significant components are genuinely open-sourced (Kyma, Gardener, CAP, UI5) under open governance rather than source-available-only -> opt3 'Open source, centralised governance'.
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumLarge corpus of public documentation (help portal, trust center, discovery center, SAP Community) detailing service architecture -> opt4 'Large corpus of public insight'.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/AI acceleration relies on foreign accelerator stacks hosted in EU data centers -> opt2 'EU-hosted, foreign stack' (seal 3).

SOV-7 · Security & Compliance Sovereignty 78.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumSovereign offer holds C5 Type II + ISO 27001/IT-Grundschutz (BSI) + TSI L3+ + VS-NfD classified-handling authorization, mapping to EAL3-equivalent per the key (C5 + national high-assurance) -> opt4 'EAL3'. (src: https://news.sap.com/2026/06/vs-nfd-authorization-sap-cloud-infrastructure/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highIndependently audited C5 Type II, ISO 27001/IT-Grundschutz, SOC 1/2 Type 2, ISO 22301, TSI L3+ and NIS2/KRITIS alignment -> opt5 'Fully compliant, independently audited' (kept, all-seal-4 factor).
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSovereign offer runs security operations and incident response by EU teams with EU threat intel under BSI oversight -> opt4 'Entire lifecycle by EU teams, EU threat intel'.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get full direct monitoring/audit-log access via portals and SIEM integration with logs stored in EU for the sovereign offer -> opt4 'Full direct access, logs stored in EU'.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumIncident disclosure per GDPR/NIS2/DORA with monitored flow and contractual SLAs -> opt4 'Partial compliance, monitored flow, SLAs'.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowManaged PaaS with maintenance notice and testing windows for customers (except zero-day) -> opt3 'Moderate autonomy'.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: the sovereign offer under BSI oversight plus C5/IT-Grundschutz/VS-NfD tender terms grants full audit rights to the contracting authority and independent EU bodies -> opt5 'Full independent audit by any entity'. (src: https://news.sap.com/2026/06/vs-nfd-authorization-sap-cloud-infrastructure/)

SOV-8 · Environmental Sustainability 75.1% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowSAP-owned EU data centers target low PUE (<1.5) with an efficiency roadmap; no platform-wide PUE<1.3 publicly verified -> opt3 'PUE < 1.5 + roadmap'.
SOV-8.2Hardware reuse & recycling4. Circular economy, EU-aligned188/250SEAL-4lowSAP reports EU-aligned circular-economy hardware lifecycle practices in its sustainability reporting -> opt4 'Circular economy, EU-aligned'.
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3mediumDetailed annual sustainability/integrated reporting with GHG-protocol emissions methodology aligned with EU/ESG requirements -> opt4 'Detailed EU methodology'.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4mediumSAP-owned data centers run on 100% renewable electricity matched with EKOenergy certificates -> opt5 'Only green EU energy supplies' (kept, all-seal-4 factor). (src: https://www.sap.com/about/trust-center/data-center.html)