🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

T-Systems

Germany · IaaS/PaaS · https://www.t-systems.com

Sovereignty score78.3%
Global (unweighted)77.2%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty100.0SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty91.6SEAL-4
SOV-3 Data & AI Sovereignty85.0SEAL-3
SOV-4 Operational Sovereignty66.8SEAL-3
SOV-5 Supply Chain Sovereignty60.7SEAL-3
SOV-6 Technology Sovereignty60.0SEAL-3
SOV-7 Security & Compliance Sovereignty78.5SEAL-3
SOV-8 Environmental Sustainability75.1SEAL-3

SOV-1 · Strategic Sovereignty 100.0% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (T-Systems wholly owned by Deutsche Telekom AG, German EU company, no non-EU parent) -> SOV-1.1 opt4. The rated T Cloud Public/Open Sovereign Cloud is operated entirely within the EU. (src: https://www.t-systems.com/de/en/sovereign-cloud/solutions/open-sovereign-cloud)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highDeutsche Telekom is a large German strategic incumbent ~30% anchored by the German state (Federal Republic + KfW); a takeover transferring it to a non-EU sovereign entity is very unlikely.
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumeu_entity controls the roadmap (Deutsche Telekom/T-Systems own R&D on OpenStack-based stack); EU actors have full influence -> SOV-1.3 opt4.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highFunding is EU-based: Deutsche Telekom is self-financing, German-state-anchored and EU-listed, no reliance on non-EU capital.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highT-Systems/Deutsche Telekom is a major EU employer with data centers, R&D and operations concentrated in Germany and the EU.
SOV-1.6Participation in EU strategic programs5. Strategic projects depend on contractor's involvement125/125SEAL-4highDeutsche Telekom is a founding member of Gaia-X and a central actor in European cloud/AI sovereignty programs.
SOV-1.7Alignment with EU industrial strategies4. Bold ambition and dedicated means125/125SEAL-4highDedicated sovereign-cloud line, Chief Sovereignty Officer (2025), Gaia-X leadership and EU sovereign AI factory - bold ambition with dedicated means -> SOV-1.7 opt4.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack (T Cloud Public runs EU-maintained OpenStack/Kubernetes on EU-operated infrastructure in DE/NL; foreign chips residual hardware only) + documented continuity -> SOV-1.8 opt5 'Full autonomy and continuity'.

SOV-2 · Legal & Jurisdictional Sovereignty 91.6% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highThe scoped sovereign offer is operated by a German entity under German/EU law exclusively; contracts and data centers are EU-jurisdiction -> SOV-2.1 opt3. (src: https://www.t-systems.com/de/en/sovereign-cloud/solutions/open-sovereign-cloud)
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity flag (a): pure-EU German entity, no non-EU parent/subsidiary/operational nexus a foreign authority could compel; offer explicitly positioned as CLOUD Act immune (all data incl. metadata processed/stored exclusively in certified EU data centers, access under US legislation such as the CLOUD Act not possible) -> SOV-2.2 opt5 'Verified legal immunity'. (src: https://www.t-systems.com/de/en/sovereign-cloud/solutions/open-sovereign-cloud)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent (German-HQ, no US nexus for the native cloud); immunity; provider states non-EU authority requests cannot be served and would be rejected -> SOV-2.3 opt5 'Requests always rejected'. (src: https://www.t-systems.com/de/en/sovereign-cloud/solutions/open-sovereign-cloud)
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumGerman EU company with EU-majority revenues and EU-operated infrastructure; offer shielded from export-control restrictions toward EU member states and international orgs -> SOV-2.4 opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform IP combines T-Systems engineering with open-source projects (OpenStack, Kubernetes, Terraform); operated/integrated IP is mostly EU-based.
SOV-2.6IP holder jurisdiction4. EU law with exceptions125/167SEAL-4mediumIP holders are predominantly under EU law (Deutsche Telekom and EU-governed open-source foundations), with some internationally-governed upstream exceptions -> SOV-2.6 opt4 'EU law with exceptions'.

SOV-3 · Data & AI Sovereignty 85.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highBYOK/HYOK with own KMS storing keys in HSMs and a zero-access/confidential-computing architecture; customer exclusive control, provider cannot read data -> SOV-3.1 opt5.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumFull customer-controlled visibility into data flows and access logs via console/monitoring, though independent real-time third-party auditability is not clearly evidenced -> SOV-3.2 opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3mediumTenant-controlled deletion on OpenStack with access logs, under C5-audited secure-deletion controls; technically verifiable with logs (no independent cryptographic proof of erasure) -> SOV-3.3 opt4 'Deletion technically verified with access logs' (seal 3).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4mediumeu_exclusive: the scoped EU offer stores and processes exclusively in DE/NL EU data centers strictly protected against third-country access (both regions certified) -> SOV-3.4 opt5 'Exclusively EU'. (src: https://www.open-telekom-cloud.com/en/products-services/core-services/certifications)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumAI is EU-led/operated (sovereign AI on OTC, open frameworks, EU-governed Industrial AI Cloud) but runs on foreign accelerators (NVIDIA GPUs) -> SOV-3.5 opt4 'EU-led AI, foreign accelerators'.

SOV-4 · Operational Sovereignty 66.8% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4highBuilt on open standards (OpenStack, Kubernetes, Terraform/OpenTofu) with documented export and formal migration services -> SOV-4.1 opt4.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: the native T Cloud Public stack is managed end-to-end by EU-based T-Systems teams -> SOV-4.2 opt5 'Entire stack managed by fully EU-based team'.
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3mediumLarge EU/German cloud workforce; majority-EU skills with possible escalation abroad in the wider group -> SOV-4.3 opt3 'Majority EU, escalation abroad'.
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3high24/7 support for the native cloud provided in Europe (German +49 phone, email, chat); non-EU escalation cannot be fully excluded -> SOV-4.4 opt3 'Majority in EU, non-EU escalations'.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation is EU-primary for the sovereign offering with non-EU fallback from the global Deutsche Telekom group -> SOV-4.5 opt3 'EU primary with non-EU fallback' (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumCritical operations rest on EU-operated infrastructure and EU subcontractors; T-Systems can source alternatives or internalise, hardware/GPU suppliers non-EU -> SOV-4.6 opt4.

SOV-5 · Supply Chain Sovereignty 60.7% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3mediumComponent sourcing (servers, NVIDIA GPUs) is foreign but documented and auditable within the C5/ISO supplier-management framework with EU audit rights -> SOV-5.1 opt3 'Transparent with exceptions' (seal 3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumServer/GPU hardware manufactured abroad on foreign design but sourced under EU audit rights and documented supplier management (not a black box) -> SOV-5.2 opt3 'Mixed sourcing, EU audit rights' (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in servers and accelerators supplied by foreign vendors with only partial disclosure -> SOV-5.3 opt2 (seal 4 by rubric).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: platform software is open-source (OpenStack, Kubernetes, Terraform) maintained/integrated by a large majority of EU teams at T-Systems -> SOV-5.4 opt4 'Large majority maintained by EU teams'.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowSoftware integration, build and release for the native cloud are controlled and executed by EU-based T-Systems teams -> SOV-5.5 opt4 'EU control & execution'.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumConsistency with the own-stack German cohort (STACKIT anchor): the core platform is EU-operated open source (OpenStack/Kubernetes) and the only non-EU dependency is substitutable commodity silicon/GPUs as non-critical hardware inputs, documented -> SOV-5.6 opt4 (few non-EU in non-critical, documented).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowConsistency with the own-stack German cohort: under T-Systems' ISO 27001/C5 supplier-management framework with EU audit rights, most suppliers are auditable beyond just the critical ones -> SOV-5.7 opt4 (most suppliers auditable). (src: https://www.open-telekom-cloud.com/en/products-services/core-services/certifications)

SOV-6 · Technology Sovereignty 60.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highOpen-by-default architecture on OpenStack, Kubernetes and interoperable APIs with explicit portability commitments -> SOV-6.1 opt5.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3highOpen standards (OpenStack, Kubernetes, Terraform/OpenTofu, standard APIs) are policy across most core services -> SOV-6.2 opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumCore platform built on open-source projects under centralised foundation governance; T-Systems' own service layer not fully open-sourced (no foreign_core) -> SOV-6.3 opt3 'Open source, centralised governance' (seal 3).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumSubstantial public insight into the architecture (open-source basis, docs, certifications); deep customer co-design limited -> SOV-6.4 opt3 'Some public insight'.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/AI is EU-hosted (DE/NL data centers, Industrial AI Cloud) but runs on a foreign stack of imported NVIDIA accelerators -> SOV-6.5 opt2 'EU-hosted, foreign stack' (seal 3).

SOV-7 · Security & Compliance Sovereignty 78.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumCerts held: BSI C5 Type 2 + ISO 27001/27017/27018 + SOC 1/2/3 + TISAX. Per the answer-key cert->EAL map, BSI C5 is a high-assurance EU/national cloud certification mapping to EAL3 (opt4 'EAL3', seal 3); applied identically to the German cohort (STACKIT anchor scored opt4 on BSI C5) -> SOV-7.1 opt4. (src: https://www.open-telekom-cloud.com/en/products-services/core-services/certifications)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highFully compliant and independently audited against GDPR, with BSI C5:2020 Type 2, ISO 27001/27017/27018/27701, SOC 1/2/3, TISAX and DORA alignment -> SOV-7.2 opt5.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumEU-based SOC and incident handling with EU threat intelligence (Telekom Security); full lifecycle by EU teams -> SOV-7.3 opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers have full direct access to monitoring/logging via the console with logs stored in EU data centers; tamper-proof immutability not explicitly guaranteed -> SOV-7.4 opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumIncident disclosure follows GDPR/NIS2-aligned processes with monitored flow and SLAs; full real-time CSIRT sharing not explicitly evidenced -> SOV-7.5 opt4.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowCustomers can deploy/test patches with maintenance windows and notice for the IaaS/PaaS layer (except emergency zero-day) -> SOV-7.6 opt3 (seal 4 by rubric).
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: DPA grants the controller contractual full audit rights of processing activities plus C5/ISO independent certification audits -> SOV-7.7 opt5 'Full independent audit by any entity'.

SOV-8 · Environmental Sustainability 75.1% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4highPublished PUE ~1.25-1.32 (Amsterdam) and ~1.3 (Biere), i.e. around/below 1.3, with the Biere DC holding the EU Code of Conduct energy-efficiency award -> SOV-8.1 opt4 'PUE < 1.3'. (src: https://www.open-telekom-cloud.com/en/benefits/sustainability)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDeutsche Telekom has documented circular-economy and hardware-recycling programs; no EU-certified lifecycle confirmed -> SOV-8.2 opt3 'Documented program' (seal 3).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3mediumDeutsche Telekom publishes detailed sustainability reporting following EU methodologies as a listed company, climate-neutral-by-2040 targets -> SOV-8.3 opt4 'Detailed EU methodology'.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highSince 2021 Deutsche Telekom sources 100% renewable electricity group-wide; the EU data centers (e.g. Biere) run entirely on green energy -> SOV-8.4 opt5. (src: https://www.open-telekom-cloud.com/en/benefits/sustainability)