Wednesday, August 19, 2026 · Week 34 DE · EN · FR · ES Dark
Logistics & Supply Chain

Reshoring Over Offshore: German SMEs Rewire Cloud Supply Chains

Practice Report 2026: Which workloads German SMEs are moving back from US regions to EU data centers, which certifications (C5, BSI‑KRITIS, Gaia‑X) truly drive them, and where the sovereignty narrative collapses against …

By Benedikt Langer April 13, 2026 10 min read
Reshoring Over Offshore: German SMEs Rewire Cloud Supply Chains

6 min read

By 2026, reshoring won’t be a marketing label—it’ll be a line item in the budget. German mid-sized companies are moving specific workloads from US hyperscaler regions back to EU data centres—some entirely, many in hybrid setups. The drivers aren’t just sovereignty debates. It’s audit questions from BSI-KRITIS assessments, customer C5 certifications, and KRITIS-Dachgesetz obligations kicking in from October 2025 that are forcing operational changes.

Key takeaways

  • Workload triage, not cloud exit. Companies are bringing back KRITIS workloads, personal data analytics, and backups with retention requirements. The rest stays hybrid or pragmatically with the hyperscaler.
  • Audits are the real drivers. C5 Type 2 certifications, BSI-KRITIS assessments, and the KRITIS-Dachgesetz are forcing decisions—not sovereignty debates or Gaia-X narratives.
  • Failure isn’t about infrastructure. STACKIT, OVHcloud, IONOS, and Open Telekom Cloud can handle the workloads—the projects fail due to SaaS dependencies and missing managed services like BigQuery or DynamoDB.

RelatedCloud Repatriation 2026: The TCO Model  /  Broadcom-VMware Channel: The Provider Landscape 2026

This isn’t a mass exodus—it’s workload triage. What must stay in the EU? What can run hybrid? What can pragmatically remain in AWS us-east-1 or Azure East US? This article explores what’s actually happening in projects since early 2026—and where the narrative clashes with hyperscaler-scale reality.

Which workloads are being repatriated

Three clear clusters are driving mid-sized companies to migrate in 2026. First: KRITIS-relevant workloads. Since the KRITIS-Dachgesetz and Germany’s NIS2 implementation, operators of critical infrastructure must provide evidence on data processing location, access, and control. Energy providers, water utilities, and hospital groups are pulling patient and control data back—often to Open Telekom Cloud or IONOS.

Second: personal data analytics and CRM data with Schrems II risks. Companies that relied on AWS SCCs and the EU-US Data Privacy Framework in 2024/25 are facing audit pushback. Analytics pipelines are moving to EU-native providers or AWS Frankfurt (eu-central-1) with explicit region-lock policies.

Third: backups and long-term archives with legal retention requirements (commercial and tax law, §257 HGB, §147 AO). Cold data is shifting from US S3 to S3-compatible EU providers or OVHcloud Object Storage. The migration effort is manageable, but the compliance argument is strong.

2.3 bn
Combined EU cloud revenue for STACKIT, OVHcloud, IONOS, and Open Telekom Cloud in 2024 (IDC, Synergy Research)
~72%
DACH market share of the three US hyperscalers in the IaaS segment (Synergy Research Q4/2024)
Oct. 2025
Planned effective date of the KRITIS-Dachgesetz after Bundestag approval

What these certifications really drive

Three frameworks dominate the debate, each carrying different weight. The BSI’s C5 (Cloud Computing Compliance Criteria Catalogue) is the most practically significant lever. Major clients and public-sector buyers demand C5 Type 2 as a contractual baseline. AWS, Azure, and Google Cloud hold C5 attestations for their EU regions, but the additional criteria (DEU C5:2020) on data localisation force explicit region configuration. Anyone who’s deployed globally until now will need to re-architect.

BSI-KRITIS isn’t a certificate—it’s a mandatory regime for operators of critical infrastructure. The obligation under §8a of the BSI Act requires proof of adequate protective measures every two years. In practice, that means cloud outsourcing must be documented, data processing agreements must be watertight, and exit strategies must be robust. Hyperscalers’ standard DPAs often no longer cut it.

Gaia-X provides an architecture and labelling framework (Gaia-X Labels Level 1 to 3) that guarantees data sovereignty. Productive workloads on Gaia-X-certified services remain rare. Gaia-X primarily serves as a tender criterion in the public sector and as a template for internal governance. Anyone expecting Gaia-X to deliver a ready-made cloud will be disappointed.

Where the narrative clashes with hyperscaler reality

The sovereignty story sounds clean: out of US clouds, into EU providers. In real-world projects, the narrative fractures at three key points.

EU-sovereign (STACKIT, OVHcloud, IONOS, Open Telekom Cloud)

  • C5 Type 2, BSI-KRITIS-compliant architectures out of the box
  • German/European jurisdiction, no US parent company
  • Direct contacts, often bilingual, support SLAs without timezone hassles
  • Compute and storage pricing competitive with hyperscaler EU regions
Hyperscaler scale (AWS, Azure, GCP)

  • Managed-service depth: Bedrock, SageMaker, BigQuery, Synapse—no 1:1 EU equivalent
  • Global failover topologies that national providers can’t replicate
  • Ecosystem of ISVs and integrations that drive developer productivity
  • ML/AI stack with current GPU generations available in EU regions

First fracture point: Managed Services. Teams running production workloads on Amazon Aurora, DynamoDB, or Azure Cosmos DB won’t find equivalent managed services with EU providers. Migration often means switching to self-managed PostgreSQL or smaller service catalogues—doable, but costly in engineering time.

Second fracture point: SaaS dependencies. Microsoft 365, Salesforce, and ServiceNow all sit on US-owned platforms. Even Microsoft’s EU Data Boundary offerings can’t fully escape the CLOUD Act. If you’re serious about blocking US access, you’ll need to start at the SaaS layer, not IaaS.

Third fracture point: AI stack. EU providers are investing (STACKIT has an AI platform, OVHcloud offers GPU instances), but the gap with Bedrock or Vertex AI remains wide. Teams building LLM-based products often stay with US hyperscalers for inference, at least. Reshoring here means keeping data in the EU while running model inference where the models live.

Practical Steps for a Reshoring Project

If you’re launching a reshoring project, follow this sequence:

  1. Workload triage (weeks 1-3): Classify all workloads by three criteria—KRITIS relevance, personal data, and retention obligations. Only migrate workloads with a genuine compliance driver. Leave the rest where they are for now. Result: a prioritised list covering no more than 15 to 20 percent of your portfolio.
  2. Define target architecture (weeks 3-6): Select one provider per workload cluster. Database workloads go to Open Telekom Cloud or IONOS, object storage to OVHcloud, Kubernetes base to STACKIT. Avoid a multi-provider strategy within a single cluster—it adds operational complexity without boosting sovereignty.
  3. Proof-of-migration with one workload (months 2-3): Migrate a single, non-business-critical application. Measure runtime behaviour, support quality, and costs in real terms. Only then scale up. Companies that migrate five workloads in parallel create operational risks without gaining any insights.
  4. Establish exit-ready operational processes (months 3-5): Implement Infrastructure as Code (Terraform, Pulumi), portable containers, and standardised data export formats from the outset. If you end up locked into an EU provider, you’ve only relocated the original problem.
  5. Reporting and certificate mapping (months 4-6): Integrate providers’ C5 attestations into your audit documentation, update KRITIS evidence, and adjust BSI reporting channels. This is the part that makes the project’s value visible to the board and supervisory bodies.

Reshoring in 2026 isn’t a political statement—it’s an engineering project with a compliance driver. The cleanest approach is unglamorous: prioritise workloads, rigorously test one provider, and build in exit readiness. Do this methodically, and you’ll gain data sovereignty without the scaling setbacks the narrative often downplays. Those planning reshoring as a total exit from US clouds quickly land in SaaS debates the IaaS team can’t resolve.

Ultimately, the deciding question is: what do you need the audit stamp for? For KRITIS obligations and public tenders, EU providers are often non-negotiable. For productive AI and data platforms, the hybrid reality persists: EU regions with hyperscalers, strict region locks, plus an EU-native provider for components requiring C5 Type 2. This two-layer architecture may lack glamour, but it will survive the next audit cycles.

How Gaia-X and EuroStack Fit Into the Reshoring Debate

In operational architecture work for 2026, Gaia-X rarely appears as a standalone requirement—but it frequently surfaces in public sector tenders and regulated industries. What matters in practice are the self-description schemas and the label system: a provider with Gaia-X Label Level 2 or 3 signals that specific sovereignty criteria (data processing location, access rights, jurisdiction) are contractually guaranteed. For a KRITIS company needing to explain to auditors why a workload remains in a US cloud, the label provides a usable argument. Without it, the discussion drags on.

EuroStack is newer, politically charged, and currently more of a roadmap debate. The vision of a seamless European infrastructure stack—from silicon to compute to platform services—isn’t yet a foundation for mid-market architecture decisions in 2026. However, it appears in funding calls and influences which EU providers remain strategically relevant for the next five years. If you’re planning reshoring today, check which providers are actively involved in EuroStack projects. It’s not a buying criterion, but it signals long-term investment commitment.

In practice, this means: make Gaia-X Label a must-have in tenders, and EuroStack participation a bonus. Communicate both internally without fanfare. Overhype Gaia-X as a marketing topic, and you’ll lose the compliance team; ignore it, and you’ll lose public tenders.

GDPR, Schrems II, and the Question of Jurisdiction

The legal core of the reshoring wave isn’t in Berlin—it’s in Luxembourg. Since the 2020 Schrems II ruling and the subsequent debates around the EU-US Data Privacy Framework, transferring personal data to the US has only been permissible with additional technical and organisational measures. The 2023 Data Privacy Framework formally stabilised the situation, but it remains under constant scrutiny. Several EU data protection authorities have signalled they would re-examine it if the framework faces political or legal challenges.

For architecture, this means: companies running productive systems with personal data in US regions today carry a residual risk—one that can be mitigated by EU region locks, but never fully eliminated. The CLOUD Act allows US authorities to access data held by US companies under certain conditions, regardless of where the data is physically stored. For most mid-sized businesses, this isn’t an operational issue, but it *is* an auditable item—and those always end up in the risk register sooner or later.

The cleanest architectural response in 2026 isn’t total withdrawal, but segmentation by data class: highly sensitive personal data (health records, employee information, communications) with EU-native providers, while operational data without personal ties can stay with hyperscalers. Hybrid cases require individual assessment. It’s more administrative work, but it significantly reduces legal exposure—and it’s exactly the approach GDPR regulators want to see.

What Reshoring Doesn’t Solve

Two misconceptions persist. First: reshoring doesn’t break dependence on US software stacks. Storing data in an EU data centre while processing it with Microsoft 365, Salesforce, or ServiceNow means you haven’t truly left US jurisdiction. The SaaS question is a separate project—one that demands its own solutions, like European alternatives such as Nextcloud, Open-Xchange, or specialised vertical SaaS from the DACH region.

What reshoring solves

  • Data location proof for KRITIS and customer audits
  • Jurisdictional exposure to Schrems II concerns
  • Egress cost structures for EU-proximate analytics pipelines
  • C5 Type 2 verifiability via European provider chains

What reshoring does NOT solve

  • SaaS dependencies (Salesforce, M365, ServiceNow, HubSpot)
  • Lack of managed services (BigQuery, DynamoDB, Lambda equivalents)
  • Shared responsibility for ISV software with US master agreements
  • Staffing needs for in-house platform operations and lifecycle management

Second: reshoring isn’t a cost-cutting project. In most price comparisons, EU-native providers are more expensive than hyperscalers, especially for elastic workloads. Be upfront about this with your CFO—or the project will collapse in the first budget review. The business case hinges on audit resilience, not infrastructure savings. Flip that logic, and you’ll build a reshoring initiative that gets unwound after two years because the promised cost reductions never materialised.

Frequently Asked Questions

When does it make sense to even consider reshoring as a project?

At the latest when KRITIS obligations, C5 attestations, or BSI requirements land on your desk during the next audit cycle—and your auditor explicitly raises the jurisdiction question. Below that threshold, a well-documented region lock within a hyperscaler’s EU zone often suffices. It’s less effort and meets most mid-market needs.

Do I need to completely exit US cloud services for reshoring?

No. Most projects in 2026 take a hybrid approach: critical workloads, classified by data sensitivity, move to EU-native providers, while the rest stay with AWS, Azure, or Google Cloud—just locked to EU regions. Total-exit rhetoric works for Sunday speeches, rarely for actual roadmaps.

Which certifications actually matter in the reshoring discussion?

In practice: BSI’s C5 Type 2 as the baseline, ISO 27001 as the foundation, and Gaia-X Label Level 2+ for public tenders. KRITIS proofs (B3S) are sector-specific add-ons. Everything else is marketing fluff—useful, but not a dealbreaker.

How do I avoid swapping US lock-in for EU lock-in?

From day one, bet on portable tech: Kubernetes over proprietary orchestration, Terraform instead of vendor-specific consoles, open data formats instead of managed-service quirks. Don’t wait to draft exit plans until you’re ready to switch—make them a contractual part of onboarding with your new provider.

What does reshoring mean for your company’s SaaS landscape?

Little to nothing, as long as the focus stays on IaaS. The SaaS debate is its own beast—driven by different factors and often far more politically charged. If you handle reshoring cleanly during an IaaS migration and sidestep the SaaS question, you’ve given an honest answer. No one’s ditching Microsoft 365 as a side project in an infrastructure overhaul.

Read more on cloudmagazin

Editor’s Picks

Source image: Pexels / Sergei Starostin (px:6466141)

Also available in

FrançaisEspañolDeutsch
MBF Media Newsletter

The monthly briefing for decision-makers

Once a month, the MBF Media Newsletter gathers what matters from cloudmagazin, MyBusinessFuture, Digital Chiefs and SecurityToday, curated by the editorial team.

25,000 IT and business decision-makers read this newsletter. Read along.

Subscribe for free
MBF Media Newsletter, aktuelle Ausgabe auf dem iPhone
A magazine by Evernine Media GmbH