Germany’s Stack Goes Live: 250 Million Euros for the Federal AI Cloud
Germany's sovereign AI cloud: €250 million, T-Systems, SAP, StackIT, no US hyperscalers. What the Germany stack means for private operators.
€250 million, two consortia, not a single US hyperscaler. With the award on 21 May 2026, Germany’s Federal Ministry of Digital Affairs and Public Administration has taken the largest-ever federal decision on AI infrastructure, and the announcement reads like an architecture blueprint rather than a press release. The federal government is not buying a platform website. It is purchasing a sovereign cloud architecture delivered as Platform-as-a-Service, built via consortia of German and European providers, and embedding Zero-Trust, key sovereignty and open-source requirements into the contract terms. For private cloud operators, the tender text is therefore required reading: it shows in detail what sovereign cloud operations look like.
Key Takeaways
- €250 million, two lots: The consortium led by T-Systems and SAP commands 70 %, while the group comprising SVA, Schwarz Digits and Codesphere holds 30 %. No lot is awarded to a US hyperscaler.
- Sovereignty is in the contract, not the marketing: Zero-Trust, Bring Your Own Key and open-source components are mandatory tender conditions, not optional extras. Operator, infrastructure and key management must remain anchored inside the EU.
- The lesson for private operators: If you want to sell sovereignty, you must deliver key sovereignty, open interfaces and verifiable compliance, not just claim it. The federal government has just defined what the specification sheet must look like.
Related:Frontier model offline by ministerial decree / Cleanly separating NIS2 and DORA compliance clusters in Kubernetes
1. Sovereignty is now a tender criterion, not a buzzword
“Digital sovereignty” long sounded like a keynote platitude. In this tender, the term becomes a contractual acceptance condition with explicit evaluation criteria. The federal government demands that the operator, infrastructure, key management and platform software all remain fully anchored within the EU. For the first time, a federal AI cloud is being built on a stack in which not a single lot is awarded to an American hyperscaler.
Concretely, this translates into two operational imperatives. First, Zero-Trust: every access request is individually verified, whether it originates from inside or outside the network. Second, Bring Your Own Key: the using authorities retain cryptographic control over their own keys; the platform operator is not granted access to plaintext data. This is the technical definition of control, not the legal one.
For private operators, the message is uncomfortable. Sovereignty without key sovereignty is merely a label. If you want to serve the public sector or regulated industries, you will henceforth be measured against exactly these two points.
2. Open-source has become a contractual obligation
The platform must explicitly be built on open interfaces and allow open-source components. This reads like a commitment but acts as a lock-in brake. The German government has learned from the past: a cloud whose interfaces belong to a single provider is not a sovereign cloud, but a dependency with a German data center.
The strategic effect is clear. Open interfaces reduce switching costs and keep competition alive in the stack. This same logic is driving private operators who want to get a grip on their multi-cloud costs, as the cloud-broker model demonstrates. Where open standards take hold, negotiating power shifts back to the customer.
The acid test is the exit. A platform is only truly open when switching to another operator doesn’t trigger a migration project lasting months. Open-source components and documented interfaces turn a theoretical switching option into a practical one. For operators, this means: if you build openly, you must actively test the exit, not just promise it. A data export that takes three weeks of manual labor in an emergency has no place in the federal government’s requirements as proof of sovereignty.
The award in figures
70 / 30 Lot distribution: T-Systems and SAP lead, followed by SVA with Schwarz Digits and Codesphere.
0 Lots awarded to US hyperscalers.
ISO 27001, BSI C5 Compliance baseline, with the C3A sovereignty catalog slated as the next tier.
3. PaaS means: the federal government rents the platform, not the responsibility
The cloud is explicitly being procured as a Platform-as-a-Service, not raw infrastructure. The consortium led by T-Systems and SAP delivers the PaaS services, SVA owns architecture and integration, Schwarz Digits provides the infrastructure via its BSI-certified StackIT Cloud, and Codesphere supplies the platform layer. Responsibilities are cleanly separated, but accountability remains with the federal government.
This is where many sovereignty debates fall short. PaaS shifts operations, not liability. Whoever rents the platform still needs to know how keys rotate, how incidents escalate, and who picks up the phone at 03:40 a.m. in a crisis. The operator question doesn’t disappear; it’s merely delegated to contracts.
For private providers, it’s worth examining the underlying math. When a sovereign stack becomes financially viable hinges on utilization, staffing, and make-or-buy decisions, an issue Digital Chiefs dissects using concrete cost models.
4. Compliance requirements are rising measurably
ISO/IEC 27001 and BSI C5 serve as the baseline. The tender explicitly names the C3A sovereignty catalogue as the next hurdle, tightening the proof-of-sovereignty requirement. This is more than a simple tick in the specification sheet. It sets a moving target: whoever delivers today must be able to demonstrate tomorrow that they meet the stricter catalogue.
This is where ambition diverges from operations. Sovereignty, zero-trust and auditable key management must work in unison; otherwise “security by incident” replaces “security by design.” The difference can cost you a sleepless week and a supervisory question, as the parallel debate around NIS2 and DORA in Kubernetes clusters shows.
A shifting compliance target also rewrites contract logic. Selling a certificate as a snapshot will fail the moment the next catalogue kicks in. A better operating model schedules audits as recurring beats: key rotation, logging and evidence collection run continuously, not just for the audit. For private operators, this is the uncomfortable takeaway from the award. The bar is not fixed, so the security concept cannot be either.
5. What private cloud operators can learn from the federal award
One detail barely made the headlines: the contract was only awarded after the losing bidders Google and Adesso withdrew their procurement appeals. Sovereignty is enforced in two ways here, technically in the stack and politically against the legal objections of the large providers. Anyone who wants to offer sovereign services now has a reference case that private customers can also invoke.
Three lessons transfer directly. First: sovereignty becomes purchasable when it is written into the specification, not merely promised as a value statement. Second: open source and open interfaces are the most effective tools against lock-in, even in private agreements. Third: the vendor that combines key sovereignty with verifiable compliance wins regulated customers, not the one with the largest marketing budget.
The Germany stack is therefore more than a government project. It is the first large-scale test of whether sovereign cloud can actually work in Germany. If it does, the federal specification will become the benchmark for anyone aiming to sell sovereign cloud in the DACH region.
Frequently Asked Questions
What is the Deutschland-Stack?
The Deutschland-Stack is the planned sovereign IT foundation of the German federal government. Its first operational component is an AI cloud operated as a Platform-as-a-Service, where operator, infrastructure, and key management are fully anchored within the EU.
Who won the €250 million contract?
The award is shared by two consortia: T-Systems and SAP lead with 70 percent, while the consortium comprising SVA, Schwarz Digits, and Codesphere holds 30 percent. No lot went to a US hyperscaler.
What does Bring Your Own Key mean in this context?
User agencies retain cryptographic control over their own keys. The platform operator is not granted access to plaintext data. This is the technical foundation for true data sovereignty.
Why is open source a tender requirement?
Open interfaces and open-source components reduce switching costs and prevent the platform from being locked into a single vendor. They are the most effective safeguard against technical lock-in.
What can private cloud operators learn from this?
That sovereign cloud will henceforth be measured by key sovereignty, open interfaces, and verifiable compliance, not by marketing. The federal government has set the specification for sovereign offerings across the DACH region.
Further Reading
cloudmagazin800-Volt DC in the Data Center: NVIDIA’s Pivot for Cloud CapacitycloudmagazinCloud Backup with IaC: Resilience Over Restore RiskcloudmagazinDisaggregated Inference: Why AWS and Cerebras Are Detaching the GPUCover image: AI-generated (June 2026)
Images in article: AI-generated (May 2026)
Image source: AI-generated (Juli 2026)


