# Sovereign Cloud Decisions – From Gut Feeling to a Reliable Decision Compass

> A structured decision framework for evaluating cloud providers beyond vendor selection — 23 governance, technical, and operational categories.

- URL: https://seiler.it/articles/souveraene-cloudentscheidungen/en.html
- Author: Dr. Sven Seiler (https://seiler.it/)
- Type: Article
- Language: en
- Published: 2026-03-16
- Updated: 2026-09-24

TL;DR

- Cloud selection is a board-level topic: not “which provider?” but “which robust, auditable decision?”

- The decision compass uses 23 categories at two levels: 10 essentials (compliance, security, scalability, isolation) and 13 differentiators (integration, exit, industry fit, sustainability).

- Data location alone is insufficient — what matters is who has legal access (CLOUD Act, Schrems II).

- Exit capability and open standards (hexagonal architecture, Infrastructure-as-Code) protect freedom of choice over time.

- Sovereignty is not a vendor label — it’s a property of your own operating model.

**Cloud migration is a board-level topic today.** It’s about agility, compliance, and risk resilience — and about making decisions you can stand behind. According to the Bitkom Cloud Report 2025[^1], 90% of companies with 20+ employees use cloud applications, and 46% plan to invest more than in the previous year. The BSI’s 2024 status report[^2] calls the threat level “undiminished high” (translated). In my view, regulation and threats are therefore sharpening the demands on governance and security.

The core question is therefore not “Which provider?” but “How do we make a robust, auditable decision that is independent of the vendor logo?”

Michael Wahlers (AWS, Head of Technology) and I developed one approach together in the whitepaper *“Sovereign Cloud Strategies for Germany”*: a two-layer decision compass with 23 categories in total:

- The essentials: what must fit in every case (sovereignty/compliance, security, scalability, availability, cost and contract clarity, tenant isolation)?

- The differentiators: what creates competitive advantage (integration capability, exit capability & open standards, partner ecosystem & local support, industry fit, sustainability, and developer experience)?

The compass consolidates legal, technical, and operational requirements and helps turn gut feeling into structured governance. For the conceptual frame — why sovereignty is a management topic, not a technology one — see [“Digital Sovereignty – More Than Just a Technology Topic”](/articles/digitale-souveraenitaet/en.html).

## The essentials – where decisions stand or fall

The compass names ten essential categories that need to be considered and assessed when selecting a cloud provider. Five examples:

- Data sovereignty & legal control. Data location alone isn’t enough. What matters is who is legally allowed to access it. In a European context, that means data protection, data residency, operational autonomy, and protection from extraterritorial access (the US CLOUD Act[^3] debate). Sovereignty is designable — through technical, organizational, and legal controls, even with international providers.

- Compliance & evidence. Certifications (e.g. BSI C5, ISO/IEC 27001, SOC 1–3) and auditable evidence are the foundation for audits, especially in regulated industries. What matters is continuity: policy-as-code, audit trails, and regular reviews.

- Security & operational reliability. From encryption at rest and in transit to IAM, DDoS protection, and the SOC: security is not a paper criterion, it’s an operating principle. Availability and resilience (AZ design, DR plans, SLAs) are non-negotiable.

- Scalability & cost transparency. Elastic resources are worthless if the cost model is opaque. What matters is predictability: what do load, traffic, and support cost? Which contract clauses apply when?

- Multi-tenancy & isolation. Strict isolation between tenants, clean identities, per-tenant encryption, and no cross-tenant influence are essential.

## The differentiators – where strategic advantage is decided

The compass names 13 differentiators that help with selecting the right cloud provider. Five examples:

- Exit capability & open standards. Architecture principles (e.g. hexagonal architecture), IaC reproducibility, and open interfaces secure freedom of choice — today and tomorrow. That way, a provider switch stays more than just theoretical.

- Integration & hybrid capability. Seamless coupling to AD/Entra ID, SAP, ITSM, observability stacks (OpenTelemetry), multi-cloud options, or edge concepts — integration saves time, cost, and risk.

- Partner ecosystem & local support. Sovereignty is built in projects. Relevant DACH expertise, vetted partners, German-language 24/7 support, and clear escalation paths are real accelerators.

- Industry fit & certification roadmaps. Sector blueprints (e.g. BaFin, KRITIS, MDR) and proven reference architectures reduce rollout risk.

- Sustainability & transparency. Measurable CO₂ footprints, PUE values, and verified ESG targets, in my view, increasingly count among public-sector procurement criteria and are a differentiator in tenders.

## Provider landscape: choice over camp thinking

Options in Germany range from European clouds (e.g. IONOS, STACKIT, Open Telekom Cloud) to international providers with European sovereignty models. One example is the **AWS European Sovereign Cloud (ESC)**: according to AWS[^4], physically and logically separate infrastructure, operated exclusively by EU-resident personnel with its own corporate structure in Germany; customer-created metadata stays in the EU; IAM, billing, and metering run on their own systems. For decision-makers, this means: sovereignty can be designed with public-cloud providers, too — provided governance, technology, and law interlock. One caveat remains: the ESC belongs to a US parent company — whether and how far the CLOUD Act reaches it is, in my view, not legally settled. *Disclosure: Storm Reply, where I am managing director, is an AWS partner.*

## Practice: turning the compass into a strategy

1. Check the essentials (sovereignty, compliance, security, availability, cost clarity, isolation).

1. Prioritize the differentiators (integration, exit capability, partners, industry, sustainability, DX).

1. Weight and justify (management scorecard, policy-as-code, evidence).

1. Pilot workloads with IaC and guardrails, plus gate decisions (security/data-protection gate).

1. Continuous compliance in operation (audits, reviews, evidence management).

> Sovereignty isn’t a vendor label — it’s a property of your own operating model.

## The next step: interactive instead of abstract

If you’d like to try the compass in practice: [anbieter.cloud](https://anbieter.cloud/) offers an AI-powered tool. You set priorities (e.g. sovereignty vs. innovation); the tool evaluates against the essentials and differentiators outlined above, explains the weighting, and provides a traceable recommendation — including evidence.

For more depth, the whitepaper *“Sovereign Cloud Strategies for Germany”* provides background, references (Bitkom, BSI, ZEW, among others), and pragmatic guardrails — from strategy to operations, including the detailed breakdown of all 23 categories.

## Sources

[^1]: Bitkom: “Wirtschaft ruft nach einer deutschen Cloud” (Business calls for a German cloud), press release on the Cloud Report 2025, 11 June 2025. Telephone survey of 604 companies with 20+ employees in Germany (Bitkom Research, calendar weeks 12–19 2025), representative. [bitkom.org](https://www.bitkom.org/Presse/Presseinformation/Wirtschaft-ruft-nach-deutscher-Cloud)

[^2]: Federal Office for Information Security (BSI): “Die Lage der IT-Sicherheit in Deutschland 2024” (“The State of IT Security in Germany 2024”), annual report, November 2024. [bsi.bund.de](https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Lageberichte/Lagebericht2024.pdf)

[^3]: US Congress: “18 U.S.C. § 2713 – Required preservation and disclosure of communications and records”, added by the CLOUD Act (Pub. L. 115-141, Div. V), 23 March 2018. [law.cornell.edu](https://www.law.cornell.edu/uscode/text/18/2713)

[^4]: Amazon Web Services: “AWS Launches AWS European Sovereign Cloud and Announces Expansion Across Europe”, press release, 15 January 2026. General availability, first region in Brandenburg, more than 90 services, operated exclusively by EU residents, customer-created metadata plus IAM, billing and usage metering kept in the EU. [press.aboutamazon.com](https://press.aboutamazon.com/aws/2026/1/aws-launches-aws-european-sovereign-cloud-and-announces-expansion-across-europe)
