🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

StackIT

Germany · IaaS/PaaS · https://www.stackit.de

Sovereignty score77.6%
Global (unweighted)76.5%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty88.5SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty87.5SEAL-4
SOV-3 Data & AI Sovereignty85.0SEAL-3
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty60.7SEAL-3
SOV-6 Technology Sovereignty60.0SEAL-3
SOV-7 Security & Compliance Sovereignty82.0SEAL-3
SOV-8 Environmental Sustainability68.8SEAL-3

SOV-1 · Strategic Sovereignty 88.5% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: StackIT GmbH & Co. KG is wholly owned by the German Schwarz Group (Schwarz Digits), headquartered in Neckarsulm, with no non-EU parent -> opt4 (entirely within EU). (src: https://schwarz-digits.de/en/product-portfolio/cloud/stackit)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highPrivately held by the Schwarz family group; management has publicly ruled out an IPO to avoid foreign-investor dependencies, making a non-EU takeover very unlikely.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumBuilt on OpenStack/Kubernetes with active upstream contribution and DACH customer focus; EU actors can influence roadmap through community governance and customer channels -> opt3 (governance bodies with EU participation).
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highSelf-financed by the Schwarz Group (Lidl/Kaufland owner); EUR 11bn European investment funded internally with no non-EU capital and explicitly no IPO.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, data centers, staff and parent group are entirely EU-based (Germany/Austria), so economic contribution is fully in the EU.
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4mediumFounding supporter of Gaia-X and a flagship German sovereign-cloud effort with an EUR 11bn digital-sovereignty investment; strong participation in EU strategic programs.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumClear sovereign-cloud strategy with dedicated means (Schwarz Digits division, large DC build-out) and measured execution, aligned with EU industrial/sovereignty goals.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: vertically integrated EU provider running its own open-source-based stack in its own German/Austrian DCs with EU teams and documented continuity; foreign chips are residual hardware only -> opt5 (full autonomy and continuity).

SOV-2 · Legal & Jurisdictional Sovereignty 87.5% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highProvider, management and data centers operate exclusively under German/EU law in Germany and Austria with no foreign legal entity in the chain -> opt3 (exclusively EU law). (src: https://www.stackit.de/en/data-sovereign-cloud/)
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity rule (a): StackIT is a pure-EU (German) entity with no non-EU parent, subsidiary or operational nexus a foreign authority could compel; non-EU laws are genuinely unenforceable against it -> opt5 (verified legal immunity), seal 4.
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent and no non-EU nexus means foreign authorities have no compulsion pathway; as a German company with data centers exclusively in Germany and Austria StackIT is not subject to the US CLOUD Act or FISA 702 and would reject such requests -> opt5 (requests always rejected). (src: https://www.stackit.de/en/data-sovereign-cloud/)
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumFully EU-based provider with EU-sourced software and operations; offering is not subject to non-EU export-control restrictions toward EU Member States or international orgs -> opt5.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumCore platform IP (OpenStack/Kubernetes-based, EU-maintained integrations) is EU-developed, but builds on internationally developed open-source projects, giving a mixed within/outside EU IP origin.
SOV-2.6IP holder jurisdiction4. EU law with exceptions125/167SEAL-4mediumProprietary platform IP is held by the German entity under EU law; underlying open-source components carry permissive licenses, so EU law applies with some external exceptions -> opt4.

SOV-3 · Data & AI Sovereignty 85.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highSTACKIT KMS offers HSM-backed customer-managed keys (FIPS 140-2 Level 3) that never leave the HSM and remain in German DCs, enabling customer-exclusive control so the provider cannot read data -> opt5.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumProvides customer-accessible logging/observability (OTLP, audit logs) with data confined to EU DCs; full real-time independent auditability is not clearly guaranteed -> opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowOperates under C5 Type 2/ISO 27001 deletion controls with audit logs in its own German DCs, giving deletion that is technically verified with access logs -> opt4 (key: technically verified w/ logs).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: all data collection, storage AND processing happen exclusively in Germany (eu01) and Austria (eu02) with no third-country fallback -> opt5. (src: https://docs.stackit.cloud/platform/regions/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumAI Model Serving hosts EU-led, auditable open-source models (Llama, Mistral) in German DCs on foreign accelerators -> opt4 (EU-led AI, foreign accelerators).

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumBuilt on open standards (Kubernetes, S3-compatible APIs, Apache Iceberg, Terraform) preventing lock-in, with documented export methods and formal migration tooling -> opt4.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: entire stack is operated by EU-based (Neckarsulm) teams on EU infrastructure with no non-EU operational dependency for running the service -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering and operations staff are based in Germany (Neckarsulm) serving the DACH region; no evidence of dedicated security-clearance program for choice 5 -> opt4 (all EU staff).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport is delivered by German/EU-based staff for the DACH market; no documented security-clearance requirement to reach choice 5 -> opt4 (all support staff in EU).
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4mediumDocumentation and knowledge resources are EU-maintained (German-led docs and teams), with primary repositories in the EU -> opt4 (EU-only primary repositories).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowOpen-source-based stack on EU-owned DCs means most subcontractor dependencies (e.g., hardware vendors) are replaceable; StackIT could source alternatives or internalize -> opt4.

SOV-5 · Supply Chain Sovereignty 60.7% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowStandard x86 servers use disclosed foreign-origin components (Intel/AMD CPUs, NVIDIA GPUs); sourcing is transparent with exceptions -> opt3 (key: transparent sourcing).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowHardware is mixed-sourced from foreign OEMs/ODMs but deployed and operated in StackIT's own EU DCs under C5 audit rights -> opt3 (key: mixed sourcing, EU audit rights).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode on CPUs, GPUs and NICs is foreign-supplied (Intel/AMD/NVIDIA) with only partial provenance disclosure -> opt2 (all-seal-4 factor).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: platform is open-source (OpenStack/Kubernetes), with a large majority of the stack integrated and maintained by EU (German) teams who contribute upstream -> opt4 (large majority maintained by EU teams).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware is controlled and built by EU-based teams in Germany; EU control and EU execution of the build/release pipeline -> opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3lowFew non-EU dependencies; foreign chips/GPUs are non-critical-substitutable hardware inputs documented at a high level, with EU-controlled software and DCs -> opt4 (few non-EU in non-critical services, documented).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowRunning its own EU DCs with C5 Type 2/ISO 27001 supplier audits, most suppliers are auditable, beyond just the critical ones -> opt4 (most suppliers auditable).

SOV-6 · Technology Sovereignty 60.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3highStandards-based and broadly compatible: Kubernetes, S3-compatible APIs, Apache Iceberg, OpenStack APIs and Terraform provider enable portability -> opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumOpen standards (S3, Kubernetes, OTLP, Iceberg, OpenStack) are adopted as policy across most core services -> opt4.
SOV-6.3Open source availability4. Open source, significant EU contributions, restricted governance150/200SEAL-4mediumNo foreign_core: platform is open-source-based (OpenStack/Kubernetes) with significant EU upstream contributions; governance of those projects is community-led rather than fully EU-controlled -> opt4 (open source, significant EU contributions, restricted governance).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumProvides substantial public documentation, source-accessible technology and published architecture insight via docs and the OpenInfra community -> opt3 (some public insight).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowHPC/GPU capacity (e.g., the Luebbenau GPU build) is EU-hosted but runs on a foreign hardware/software stack (NVIDIA accelerators) -> opt2 (EU-hosted, foreign stack), seal 3.

SOV-7 · Security & Compliance Sovereignty 82.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumBSI C5 Type 2 (one of the highest German cloud security standards) plus ISO 27001 and ISAE 3000 (SOC 2); mapped as high-assurance EU cloud cert / EAL3-equivalent per the answer key for an awarded SEAL-3 sovereign offer -> opt4 (EAL3), seal 3. (src: https://schwarz-digits.de/en/presse/archive/2024/c5-type-2-certificate-stackit-receives-confirmation-of-the-highest-security-standards-for-cloud-services)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highGDPR-compliant by design, BSI C5 Type 2, ISO 27001, ISAE 3000 (SOC 2) and ISAE 3402, all independently audited; positioned for NIS2/DORA in the EU -> opt5.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident handling are run by EU-based teams in Germany over the full lifecycle; no explicit ENISA/CSIRT real-time sharing for choice 5 -> opt4 (entire lifecycle by EU teams).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get direct access to monitoring/logging (OTLP, audit logs) with logs stored in EU (German) DCs; tamper-proof immutability not explicitly documented -> opt4 (full direct access, logs in EU).
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumIncident disclosure aligned with GDPR/NIS2 with monitored notification flows and SLAs as an EU provider; real-time CSIRT sharing not explicitly evidenced -> opt4.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumAs operator of its own open-source-based stack in its own DCs, StackIT has high autonomy to schedule and deploy maintenance independently -> opt4.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: as an awarded Cloud III SEAL-3 sovereign offer, the tender-grade terms provide full audit rights for the contracting authority and independent EU bodies -> opt5 (full independent audit by any entity).

SOV-8 · Environmental Sustainability 68.8% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4highPublished DC PUE values of 1.5, 1.3 and 1.2 (Ostermiething as low as 1.1) with an efficiency roadmap; best sites are below 1.5 with a clear improvement program -> opt3 (PUE < 1.5 + roadmap). (src: https://stackit.com/en/learn/knowledge/cloud/sustainability)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowSustainability messaging covers efficient operations and waste-heat reuse; a documented hardware reuse/recycling program -> opt3 (documented program).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3lowSchwarz Group publishes detailed sustainability reporting under EU methodology (energy, efficiency, renewable sourcing) covering StackIT DCs -> opt4 (detailed EU methodology).
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highAll data centers are operated with certified green electricity in the EU (Germany/Austria), including on-site PV and renewable-only operation at new sites -> opt5. (src: https://stackit.com/en/learn/knowledge/cloud/sustainability)