Cloud migration is a board-level topic today. It’s about agility, compliance, and risk resilience — and about making decisions you can stand behind. According to the Bitkom Cloud Report 20251, 90% of companies with 20+ employees use cloud applications, and 46% plan to invest more than in the previous year. The BSI’s 2024 status report2 calls the threat level “undiminished high” (translated). In my view, regulation and threats are therefore sharpening the demands on governance and security.

The core question is therefore not “Which provider?” but “How do we make a robust, auditable decision that is independent of the vendor logo?”

Michael Wahlers (AWS, Head of Technology) and I developed one approach together in the whitepaper “Sovereign Cloud Strategies for Germany”: a two-layer decision compass with 23 categories in total:

The compass consolidates legal, technical, and operational requirements and helps turn gut feeling into structured governance. For the conceptual frame — why sovereignty is a management topic, not a technology one — see “Digital Sovereignty – More Than Just a Technology Topic”.

The essentials – where decisions stand or fall

The compass names ten essential categories that need to be considered and assessed when selecting a cloud provider. Five examples:

The differentiators – where strategic advantage is decided

The compass names 13 differentiators that help with selecting the right cloud provider. Five examples:

Provider landscape: choice over camp thinking

Options in Germany range from European clouds (e.g. IONOS, STACKIT, Open Telekom Cloud) to international providers with European sovereignty models. One example is the AWS European Sovereign Cloud (ESC): according to AWS4, physically and logically separate infrastructure, operated exclusively by EU-resident personnel with its own corporate structure in Germany; customer-created metadata stays in the EU; IAM, billing, and metering run on their own systems. For decision-makers, this means: sovereignty can be designed with public-cloud providers, too — provided governance, technology, and law interlock. One caveat remains: the ESC belongs to a US parent company — whether and how far the CLOUD Act reaches it is, in my view, not legally settled. Disclosure: Storm Reply, where I am managing director, is an AWS partner.

Practice: turning the compass into a strategy

  1. Check the essentials (sovereignty, compliance, security, availability, cost clarity, isolation).
  2. Prioritize the differentiators (integration, exit capability, partners, industry, sustainability, DX).
  3. Weight and justify (management scorecard, policy-as-code, evidence).
  4. Pilot workloads with IaC and guardrails, plus gate decisions (security/data-protection gate).
  5. Continuous compliance in operation (audits, reviews, evidence management).

Sovereignty isn’t a vendor label — it’s a property of your own operating model.

The next step: interactive instead of abstract

If you’d like to try the compass in practice: anbieter.cloud offers an AI-powered tool. You set priorities (e.g. sovereignty vs. innovation); the tool evaluates against the essentials and differentiators outlined above, explains the weighting, and provides a traceable recommendation — including evidence.

For more depth, the whitepaper “Sovereign Cloud Strategies for Germany” provides background, references (Bitkom, BSI, ZEW, among others), and pragmatic guardrails — from strategy to operations, including the detailed breakdown of all 23 categories.

Sources

  1. Bitkom: “Wirtschaft ruft nach einer deutschen Cloud” (Business calls for a German cloud), press release on the Cloud Report 2025, 11 June 2025. Telephone survey of 604 companies with 20+ employees in Germany (Bitkom Research, calendar weeks 12–19 2025), representative. bitkom.org
  2. Federal Office for Information Security (BSI): “Die Lage der IT-Sicherheit in Deutschland 2024” (“The State of IT Security in Germany 2024”), annual report, November 2024. bsi.bund.de
  3. US Congress: “18 U.S.C. § 2713 – Required preservation and disclosure of communications and records”, added by the CLOUD Act (Pub. L. 115-141, Div. V), 23 March 2018. law.cornell.edu
  4. Amazon Web Services: “AWS Launches AWS European Sovereign Cloud and Announces Expansion Across Europe”, press release, 15 January 2026. General availability, first region in Brandenburg, more than 90 services, operated exclusively by EU residents, customer-created metadata plus IAM, billing and usage metering kept in the EU. press.aboutamazon.com