For years, cloud sovereignty was treated as a niche topic for government agencies and especially security-conscious industries. Today, it’s a core factor in a company’s ability to act. Many organizations in the DACH region face the challenge of using modern cloud technologies without losing control over their data, processes, and regulatory obligations. The topic has long reached the C-suite — not just the IT department.

In its 2024 status report1, Germany’s federal cybersecurity agency BSI calls the state of IT security in Germany “tense” and the threat level “undiminished high” (translated). That is why I see robust governance and security controls as a baseline. At the same time, the Bitkom Cloud Report 20252 shows that 90% of German companies with 20+ employees already use cloud applications (2024: 81%). The question is no longer if, but how sovereign cloud use can be designed.

Sovereignty starts in management, not in the data center

Digital sovereignty is far more than mere data localization. It describes the ability to control IT resources, data flows, and dependencies on your own terms — while upholding all legal and organizational requirements. That makes it a management responsibility, not a technical detail.

Real sovereignty only emerges when business and IT develop a cloud strategy together. In my view, companies that establish a coordinated governance model early reduce risk, decide faster, and avoid siloed solutions.

A typical scenario: a manufacturer launches isolated predictive maintenance projects close to the shop floor and discovers that a lack of strategic alignment leads to extra effort and incompatibilities. Only a shared cloud roadmap makes it possible to integrate production data, MES, and ERP — and to account for regulatory requirements (such as quality and compliance rules).

Sovereignty doesn’t emerge from technology — it emerges from structure. Clear roles, controlled decision-making, and transparent cloud governance.

Between idealism and pragmatism

The topic is debated controversially in Germany. On one side are calls for legally secure use without foreign government access, full switching capability, and technological control. BSI president Claudia Plattner counters that some of the major firms, especially from the U.S., “already have a ten-year head start” — and that it is unrealistic to expect “that we will be able to do all of this ourselves in the short term” (heise online, August 20253, translated).

Practice moves between these poles: German companies and institutions want to be independent without giving up global pace of innovation, scalability, and breadth of services.

The Bitkom Cloud Report 20252 shows this balancing act: 78% of companies consider Germany too dependent on US cloud providers, while 46% plan to invest more in cloud than in the previous year. The path to digital sovereignty doesn’t require isolation — it requires smart governance, balancing control and openness.

Sovereignty as a strategic process

Developing a sovereign cloud strategy follows a clear management approach. First, evaluate requirements and risks:

On that basis, a target architecture takes shape, with a defined landing zone, policy set, and role model. Established frameworks like BSI C5, ISO/IEC 27001, or SOC 1–3 support this structure. The key is that governance, compliance, and technology are integrated from day one. Sovereignty isn’t a state — it’s a continuous process lived through regular reviews, policy-as-code, and automated compliance.

New options for Europe’s cloud strategy

In my view, Germany’s cloud landscape is becoming more differentiated: alongside national providers like IONOS, STACKIT, or Open Telekom Cloud, international providers are also rolling out specific European models. One example is the AWS European Sovereign Cloud (ESC) — a cloud operated entirely within the EU, physically and logically separate from the other AWS Regions, with its own corporate structure in Germany.

The AWS ESC launched4 on 15 January 2026 with more than 90 services — a subset of the global AWS portfolio — and relies on European control and governance mechanisms. Operations are handled exclusively by EU-resident personnel; the partition uses its own certificates and root authorities5; customer-created metadata (roles, permissions, labels, configurations) stays in the EU; and identity, billing, and metering run on their own systems. In its own words, AWS6 aims to help customers “meet their evolving sovereignty needs, including stringent data residency, operational autonomy, and resiliency requirements.”

One caveat remains: the ESC belongs to a US parent company — whether and how far the CLOUD Act reaches it is, in my view, not legally settled. For IT decision-makers, the takeaway is: digital sovereignty can be designed with global cloud providers, too — provided technical, legal, and organizational controls interlock — but each organization has to assess the legal question for its own workloads.

Disclosure: Storm Reply, where I am managing director, is an AWS partner.

The path to a sovereign cloud organization

Sovereignty doesn’t come from choosing a provider — it comes from a clear roadmap. Companies typically begin with a sovereignty assessment (readiness check and regulatory mapping), then design a target architecture and run pilot workloads in the chosen cloud. Infrastructure-as-code ensures reproducibility; policy-as-code ensures auditability. That way sovereignty becomes an operational principle rather than a marketing slogan.

Conclusion

Digital sovereignty doesn’t mean isolation — it means informed freedom of choice. Organizations in Germany can use international cloud technologies and at the same time guarantee data control, security, and compliance. Depending on their priorities, different paths are open: European providers for local control, international clouds for global innovation, or hybrid models that combine the best of both worlds.

Those who start now to build a sovereign cloud strategy benefit twice over: in the short term through the trust of customers and regulators thanks to transparent governance, and in the long term through the ability to choose from a wide range of offerings and adapt quickly.

For more depth: the whitepaper “Sovereign Cloud Strategies for Germany” describes 23 categories for cloud provider selection that companies should consider when establishing their cloud strategy. Complementing this, anbieter.cloud offers an AI-powered tool for sovereignty strategy and provider selection.

Related read: for the practical translation of those 23 categories into an auditable provider decision, see “Sovereign Cloud Decisions – From Gut Feeling to a Reliable Decision Compass”.

Sources

  1. Federal Office for Information Security (BSI): “Die Lage der IT-Sicherheit in Deutschland 2024” (“The State of IT Security in Germany 2024”), annual report, November 2024. bsi.bund.de
  2. Bitkom: “Wirtschaft ruft nach einer deutschen Cloud” (Business calls for a German cloud), press release on the Cloud Report 2025, 11 June 2025. Telephone survey of 604 companies with 20+ employees in Germany (Bitkom Research, calendar weeks 12–19 2025), representative. bitkom.org
  3. heise online: “BSI-Präsidentin: Digitale Souveränität für Deutschland vorerst unerreichbar” (“BSI president: digital sovereignty out of reach for Germany for now”), news article, 12 August 2025. Quotes by Claudia Plattner. heise.de
  4. Amazon Web Services: “AWS Launches AWS European Sovereign Cloud and Announces Expansion Across Europe”, press release, 15 January 2026. General availability, first region in Brandenburg, more than 90 services, operated exclusively by EU residents, customer-created metadata plus IAM, billing and usage metering kept in the EU. press.aboutamazon.com
  5. Colm MacCárthaigh, AWS Security Blog: “Establishing a European trust service provider for the AWS European Sovereign Cloud”, blog post, 10 July 2025 (updated 4 August 2025). aws.amazon.com
  6. Amazon Web Services: “European Digital Sovereignty”, product page, retrieved 27 September 2026. aws.amazon.com