{"id":38712,"date":"2026-04-28T09:54:48","date_gmt":"2026-04-28T07:54:48","guid":{"rendered":"https:\/\/www.cloudmagazin.com\/2026\/04\/29\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-2\/"},"modified":"2026-08-03T15:45:37","modified_gmt":"2026-08-03T13:45:37","slug":"architecture-drives-compliance-costs","status":"publish","type":"post","link":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/","title":{"rendered":"Architecture Drives Compliance Costs: How to Cut Them"},"content":{"rendered":"<p style=\"color:#6190a9;font-size:0.9em;margin:0 0 16px;padding:0;\">8 min read<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>By 2026, BSI-KRITIS, NIS2 and C5 will no longer sit side-by-side but stack vertically. Organisations embedding cloud services into critical infrastructure must satisfy all three frameworks simultaneously\u2014without letting compliance become a box-ticking exercise that delivers no real protection. This practical audit reveals where the frameworks actually collide and how a multi-cloud setup can still pass inspection.<\/strong><\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Bottom line: compliance hinges on the interplay of service selection, tenant configuration, evidence collection and incident-reporting workflows. The provider supplies only one piece of the puzzle.<\/p>\n<h2>Key Takeaways<\/h2>\n<div style=\"background:#f8fbfd;border:1px solid rgba(11,183,253,0.28);border-radius:8px;padding:22px 26px;margin:16px 0 32px 0;\">\n<ul style=\"color:#1a2733\">\n<li><strong>The regulated circle keeps expanding:<\/strong> With NIS2 transposed via the NIS2UmsuCG and the KRITIS umbrella law, far more companies now face cybersecurity and resilience obligations. Not every organisation will qualify as a KRITIS operator in the strict sense, yet NIS2\/BSIG duties and KRITIS-style audit chains now reach deeper into the market than before.<\/li>\n<li><strong>C5 is a proof framework, not a finish line:<\/strong> The auditor\u2019s attestation folder covers the provider. Tenant configuration, key management, access control and logging must still be demonstrable by the operator.<\/li>\n<li><strong>Multi-cloud creates multiple audit trails per workload:<\/strong> Provider attestation, tenant evidence, supply-chain and sub-processor proofs sit in separate silos unless a central evidence layer ties them together. The compliance workload rises sharply.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related<\/span><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/22\/byod-in-german-enterprises-2026-what-market-data-reveal\/\" style=\"color:#333;text-decoration:underline;\">BYOD in the German Enterprise 2026<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/03\/19\/sap-sovereign-cloud-france-what-march-19-2026-means\/\" style=\"color:#333;text-decoration:underline;\">SAP Sovereign Cloud France<\/a><\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What\u2019s really new in 2026<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>What is BSI-KRITIS compliance for cloud usage?<\/strong> Operators of critical infrastructures are now required to demonstrate, for every cloud service used in production, the data class, location, provider attestation (typically BSI C5 Type 2), their own tenant configuration evidence, and a documented incident reporting chain including 24-hour early-warning under NIS2. Generic provider attestations are no longer sufficient as of 2026.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The debate around KRITIS and cloud has been ongoing for years, but 2026 marks a turning point. The second ordinance amending the BSI-Kritisverordnung lowers thresholds in several sectors. At the same time, the draft KRITIS umbrella law for the first time links physical and digital resilience. In parallel, the NIS2 implementation in the NIS2UmsuCG significantly expands the circle of entities subject to obligations. Any company that previously hovered just below the KRITIS threshold is now inside\u2014or perilously close.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">For accurate classification, remember: for cloud setups, NIS2\/BSIG is the more immediate cybersecurity lever. The KRITIS umbrella law adds further pressure on resilience and evidence requirements for operators of critical assets, though some details still need to be fleshed out in subordinate regulations. Keeping the regimes separate helps plan more precisely.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The impact on cloud strategies is anything but subtle. Every cloud service used in production must be evidenced individually: category, data class, location, provider attestation, and your own tenant configuration evidence. What three years ago passed as a blanket \u201cwe have C5\u201d statement will be dismantled in a 2026 KRITIS audit. Auditors now demand service-level granularity, not just a hyperscaler-wide snapshot.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">C5 remains an important attestation framework for cloud providers. For operators, however, it is only one piece of the puzzle: tenant configuration, access control, key management, and logging must each be verifiable. This separation was long glossed over and now lands squarely on the operator\u2019s desk during audit.<\/p>\n<div style=\"background:#004a59;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#0bb7fd;letter-spacing:-0.03em;line-height:1;\">29,700<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">Estimated number of entities in Germany that could fall under the NIS2 implementation\u2014including existing KRITIS operators.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: BSI \/ BMI, key-points paper on NIS2 implementation<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">The Three Frameworks and Where They Clash<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Treating KRITIS, NIS2 and C5 as separate tracks creates three parallel audit universes. That\u2019s expensive and unnecessary. In practice, about two-thirds of the requirements overlap. It\u2019s the remaining thirty percent that must be understood\u2014otherwise, you\u2019ll face findings.<\/p>\n<div style=\"overflow-x:auto;margin:32px 0;\">\n<table style=\"width:100%;border-collapse:collapse;font-size:0.95em;\">\n<thead>\n<tr style=\"background:#004a59;color:#fff;\">\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #004a59;color:#fff;\">Aspect<\/th>\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #004a59;color:#fff;\">BSI-KRITIS<\/th>\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #004a59;color:#fff;\">NIS2 (national)<\/th>\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #004a59;color:#fff;\">BSI C5<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>Target audience<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Operators of critical infrastructure<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Essential and important entities<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#004a59;font-weight:600;\">Cloud providers<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>Evidence<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Audit every two years<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Self-declaration plus oversight<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#004a59;font-weight:600;\">Type 1 or Type 2 attestation<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>Incident reporting<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">To BSI, deadline varies by sector<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">24-hour early warning<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">To provider\u2019s customers<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>Cloud relevance<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Indirect via outsourcing<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Supply-chain obligations directly<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#004a59;font-weight:600;\">Direct<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"font-size:0.8em;color:#888;margin-top:8px;\">Source: BSI-Kritisverordnung, NIS2UmsuCG draft, BSI C5 2020.<\/p>\n<\/div>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The most critical conflict in practice: NIS2 demands a 24-hour early warning for reportable incidents. KRITIS sector rules are sometimes stricter, sometimes looser. C5, in turn, obliges the provider to inform its customers. The customer must handle escalation to the BSI themselves. If the interface isn\u2019t set up, they receive an incident alert from the hyperscaler but can\u2019t process it organizationally.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Important clarification on the deadline: the 24-hour clock starts as soon as the obligated entity becomes aware of a significant security incident and must trigger the reporting path. Provider alerts are just one possible trigger, not the only one. If you haven\u2019t established an internal assessment and escalation path, you\u2019ll burn most of those 24 hours on organizational clarification.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Second conflict: supplier security. NIS2 places supply-chain protection at the center. In a multi-cloud reality, every hyperscaler and every SaaS tier-2 provider is part of that chain. C5 only covers the first cloud provider, not its sub-processors. Running SaaS on Hyperscaler X means you have two supplier levels with different evidence obligations.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">From Framework to Setup: A Four-Week Path<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The following approach is distilled from compliance projects in utilities, KRITIS-adjacent industries, and insurers. The timeline fits an existing multi-cloud setup with two to three hyperscalers and a handful of SaaS tools with customer data access.<\/p>\n<div style=\"margin:28px 0;border:1px solid #e5e5e5;border-radius:6px;overflow:hidden;\">\n<div style=\"background:#004a59;color:#fff;padding:12px 18px;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;\">KRITIS Cloud Inventory in Four Weeks<\/div>\n<div style=\"padding:8px 0;\">\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:140px;font-weight:700;color:#0bb7fd;\">Week 1<\/div>\n<div style=\"color:#333;line-height:1.55;\">Cloud service inventory per asset: which service, which data class, which provider, which attestation, which location. One line per service, not per provider.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:140px;font-weight:700;color:#0bb7fd;\">Week 2<\/div>\n<div style=\"color:#333;line-height:1.55;\">Mapping to protection goals: per service, confidentiality, integrity, availability according to BSI protection requirement assessment. This is where SaaS tools holding data classes no one had on their radar become apparent.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:140px;font-weight:700;color:#0bb7fd;\">Week 3<\/div>\n<div style=\"color:#333;line-height:1.55;\">Establish evidence layer: central log sink for configuration drift, identity events, encryption status per service. Cloud Security Posture Management or custom-built via provider APIs\u2014either way, the key is one repository.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;\">\n<div style=\"min-width:140px;font-weight:700;color:#0bb7fd;\">Week 4<\/div>\n<div style=\"color:#333;line-height:1.55;\">Interface drill: walk through a 24-hour reporting path from provider alert to BSI confirmation of receipt. The first run reveals organizational gaps, not technical ones.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The urge to tackle everything in parallel is understandable, but inefficient. Without a clean inventory, every posture tool is redundant. Without protection requirement assessment, no one knows which configuration evidence is truly critical. This sequence has proven most reliable in practice.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">If you already operate a central cloud platform for inventory and drift detection, Week 3 can be shortened. If you\u2019re still tracking assets in Excel sheets per department, extend Week 1 instead of cutting corners. An incomplete inventory surfaces on page one of a KRITIS audit. Then the correction cycle begins under time pressure.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What holds up, what breaks: Multi-cloud under scrutiny<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">In the clash between architectural idealism and audit reality, it\u2019s decided whether a setup survives scrutiny. The patterns below have frequently led to findings\u2014or just as often, avoided them\u2014over the past two years.<\/p>\n<div style=\"display:grid;grid-template-columns:repeat(auto-fit,minmax(280px,1fr));gap:16px;margin:28px 0;\">\n<div style=\"background:#fdf3f3;padding:24px 28px;border-radius:8px;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#c0392b;\">What breaks<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Broad claims like \u201cwe use C5-certified providers\u201d without a service list<\/li>\n<li style=\"margin-bottom:6px;\">SaaS tools with customer data access that don\u2019t appear in any outsourcing inventory<\/li>\n<li style=\"margin-bottom:6px;\">Identity stack lacking a central audit trail across all tenants<\/li>\n<li style=\"margin-bottom:6px;\">Encryption keys managed by the provider, with no operator documentation of rotation or access<\/li>\n<li>Incident reporting path limited to email, without an escalation runbook or substitute rules<\/li>\n<\/ul><\/div>\n<div style=\"background:#f1f7f0;padding:24px 28px;border-radius:8px;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#2d7a3e;\">What holds up<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Service-level inventory with data classification, location, and attestation evidence for each entry<\/li>\n<li style=\"margin-bottom:6px;\">Customer-managed encryption keys for data classified as \u201chigh,\u201d at minimum for critical infrastructure assets<\/li>\n<li style=\"margin-bottom:6px;\">Centralized cloud security posture management across all hyperscalers, with drift alerts on configuration<\/li>\n<li style=\"margin-bottom:6px;\">Outsourcing contracts listing sub-processors and change notices<\/li>\n<li>Drill-tested 24-hour reporting path with defined roles and backup communication channels<\/li>\n<\/ul><\/div>\n<\/div>\n<p style=\"line-height:1.8;margin-bottom:20px;\">More often than not, failure stems not from technology but from organization. Cloud architectures at most critical-infrastructure operators are technically sound. What\u2019s missing are documented interfaces between IT security, compliance, and line-of-business teams. If you haven\u2019t walked through your reporting path once a quarter, you don\u2019t truly know it.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">A second common stumbling block is the SaaS shadow layer. Marketing tools, HR systems, legal platforms\u2014all eventually creep into the critical-infrastructure orbit because they process data from critical assets or hold identities of operations staff. Any inventory gap here is an audit gap waiting to happen.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Architecture decisions with compliance leverage<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Three architectural building blocks have an outsized impact. They\u2019re not new, but by 2026 they\u2019re no longer optional.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>First: Identity federation with a central audit backbone.<\/strong> If you run Hyperscaler X, Y and three SaaS vendors with separate identity stacks, you have five audit logs. If you centralize on one identity provider with consistent federation, you have one. The audit effort doesn\u2019t drop linearly\u2014it falls off a cliff\u2014because incident forensics follows a single path.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>Second: Customer-managed keys, at minimum for data classes \u201chigh\u201d and \u201cvery high.\u201d<\/strong> Provider-managed keys are convenient and sufficient for \u201cnormal.\u201d When KRITIS-relevant data classes are involved, the discussion about key sovereignty is one the auditor reads and scores. An in-house key infrastructure\u2014whether external key manager or dedicated HSM attachment\u2014earns points in the report and buys maneuvering room during an incident.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>Third: Configuration evidence as a first-class citizen.<\/strong> Provider attestations are point-in-time snapshots. A live cloud changes daily. Without a drift detector that alerts on deviations from the desired state, you cannot prove control effectiveness between audit dates. The auditor\u2019s question \u201cwhen did you know?\u201d can only be answered with a log entry, not an assumption.<\/p>\n<blockquote style=\"background:#f0fafe;padding:24px 28px;margin:32px 0;font-style:italic;font-size:1.08em;color:#004a59;border-radius:8px;\">\n<p> A C5 attestation in the folder does not replace the audit trail inside the tenant. That\u2019s the lesson from every serious KRITIS report of the last two years. <\/p>\n<\/blockquote>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Supply chains and the sub-processor knot<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">NIS2 moved supply-chain security from the appendix to the front page. For multi-cloud setups this means: every sub-processor becomes visible. Hyperscaler X uses sub-processor A for logging, sub-processor B for threat intelligence, sub-processor C for hardware maintenance. That list must exist, stay current, and any change must be contractually notified.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">In a multi-cloud setup the numbers multiply. Three hyperscalers with twelve to twenty sub-processors each add up to roughly fifty supply-chain entries. Without a central outsourcing register that maintains the list and timestamps every change, the NIS2 question on supply-chain risk management cannot be answered.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Practical step: keep the outsourcing register as CSV or database table, reconcile monthly with provider sub-processor lists, write a change-notice into the contract, and name a reviewer. Sounds bureaucratic, but it\u2019s the prerequisite for a NIS2 audit without obvious findings.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What auditors will really look for in 2026<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">From conversations with auditors\u2014without revealing details of individual reports\u2014a pattern emerges. Three areas receive disproportionate attention in 2026.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The first area is the completeness of the inventory. If you inventory cloud services by provider instead of by service, you\u2019re immediately flagged. Auditors ask for the asset list, inspect the service roster, and compare it with network telemetry. Any SaaS tool surfacing in traffic that isn\u2019t on the list is a direct finding.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The second area is the effectiveness of the incident reporting chain. NIS2 demands 24-hour early warning. Auditors don\u2019t ask for the process; they ask for the last exercise. A quarterly drill with substitute rules and fallback communication usually suffices.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The third area is the consistency of key and identity sovereignty across every cloud tenant. Here multi-cloud complexity hits hardest. A single view of rotated keys and critical identity events over the last 90 days is the bare minimum. Without it, an audit problem is guaranteed.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Frequently Asked Questions<\/h2>\n<details>\n<summary><strong>Is a C5 Type 2 attestation sufficient for KRITIS compliance?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. A C5 Type 2 attestation documents provider controls over a defined period, but it does not replace the operator\u2019s own risk assessment or the tenant-level audit trail. The operator must independently document its cloud configuration, key management, and access controls.<\/p>\n<\/details>\n<details>\n<summary><strong>How do you demonstrate uniform compliance in a multi-cloud setup?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">With a centralized evidence layer. Cloud Security Posture Management\u2014or a custom build using provider APIs\u2014aggregates configuration, identity, and encryption events from all hyperscalers into a single source. Auditors examine this single source, not three separate dashboards.<\/p>\n<\/details>\n<details>\n<summary><strong>Which cloud services fall under the NIS2 supply-chain obligations?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">All services that are material to the operation of essential services. In practice: every cloud service that processes data or identities of the obligated entity. This includes SaaS tools even if they are not directly in the production path, but merely hold identities or configuration data.<\/p>\n<\/details>\n<details>\n<summary><strong>What does the 24-hour deadline mean across multiple cloud providers in concrete terms?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The clock starts when the obligated entity becomes aware of the incident, not when the provider does. Providers notify their customers, the customer evaluates and then submits the report to the BSI. Organizations without an internal escalation path can burn most of the 24 hours on internal clarifications.<\/p>\n<\/details>\n<details>\n<summary><strong>Is an external key manager worth it for KRITIS workloads?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">For data classified as \u201chigh\u201d in most cases, yes. Customer-managed keys with an external key manager give the operator full control over keys and an independent audit trail. In the audit report and in an actual incident, this makes a clear difference compared to provider-managed keys.<\/p>\n<\/details>\n<div style=\"margin:40px 0 24px 0;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/22\/byod-in-german-enterprises-2026-what-market-data-reveal\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">BYOD in the German Enterprise 2026: Market data on security, costs and compliance<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/franco-german-ai-dialogue-17-april-2026-mittelstand-operationalisierung-gaia-x\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Franco-German AI Report: Three homework assignments for DACH SMEs<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/ai-governance-2026-system-level-vorstand-trust-plattform-eu-ai-act\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">AI Governance 2026: System-level instead of Excel compliance<\/a><\/p>\n<\/div>\n<\/div>\n<p style=\"text-align:right;\"><em>Photo: Eckhard Henkel \/ Wikimedia Commons (CC BY-SA 3.0 DE)<\/em><\/p>\n<p style=\"text-align:right;color:#868e96;font-size:0.85em;margin-top:48px;font-style:italic;\"><em>Image source: AI-generated (May 2026), C2PA certificate embedded in image<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"BSI-KRITIS, NIS2, and C5 will align in 2026. This is how a multi-cloud setup passes the audit: inventory, evidence layer, 24-hour reporting path.","protected":false},"author":31,"featured_media":41397,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/04\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/04\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"pre_headline":"","bildquelle":"","teasertext":"","language":"de","_evm_slot_owner":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-2"],"footnotes":""},"categories":[921,930,926],"tags":[],"industry":[],"class_list":["post-38712","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-reboot-germany","category-sustainability"],"evm_reading_time_minutes":13,"wpml_language":"en","wpml_translation_of":38659,"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Architecture Drives Compliance Costs: How to Cut Them<\/title>\n<meta name=\"description\" content=\"Reduce compliance costs by aligning cloud architecture with NIS2, BSI-KRITIS, and C5 requirements\u2014early design decisions save up to 40% in remediation spend.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Architecture Drives Compliance Costs: How to Cut Them\" \/>\n<meta property=\"og:description\" content=\"Reduce compliance costs by aligning cloud architecture with NIS2, BSI-KRITIS, and C5 requirements\u2014early design decisions save up to 40% in remediation spend.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/\" \/>\n<meta property=\"og:site_name\" content=\"cloudmagazin\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cloudmagazincom\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-28T07:54:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-03T13:45:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/04\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero.jpg\" \/>\n<meta name=\"author\" content=\"Alec Chizhik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/04\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero.jpg\" \/>\n<meta name=\"twitter:creator\" content=\"@cloudmagazin\" \/>\n<meta name=\"twitter:site\" content=\"@cloudmagazin\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alec Chizhik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/\"},\"author\":{\"name\":\"Alec Chizhik\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#\\\/schema\\\/person\\\/ce38baaa19a580268aedce096597eb3c\"},\"headline\":\"Architecture Drives Compliance Costs: How to Cut Them\",\"datePublished\":\"2026-04-28T07:54:48+00:00\",\"dateModified\":\"2026-08-03T13:45:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/\"},\"wordCount\":2230,\"publisher\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero-c2pa-260521.jpg\",\"articleSection\":[\"News\",\"Reboot Germany\",\"Sustainability\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/\",\"name\":\"Architecture Drives Compliance Costs: How to Cut Them\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero-c2pa-260521.jpg\",\"datePublished\":\"2026-04-28T07:54:48+00:00\",\"dateModified\":\"2026-08-03T13:45:37+00:00\",\"description\":\"Reduce compliance costs by aligning cloud architecture with NIS2, BSI-KRITIS, and C5 requirements\u2014early design decisions save up to 40% in remediation spend.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero-c2pa-260521.jpg\",\"contentUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero-c2pa-260521.jpg\",\"width\":1792,\"height\":1024,\"caption\":\"KI-generiertes Titelbild. C2PA-Zertifikat im Bild hinterlegt.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/2026\\\/04\\\/28\\\/architecture-drives-compliance-costs\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/home\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Architecture Drives Compliance Costs: How to Cut Them\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/\",\"name\":\"cloudmagazin\",\"description\":\"Inspiration f\u00fcr Businessentscheider\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#organization\",\"name\":\"cloudmagazin\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/cloudmagazin-logo-klein_menu.jpg\",\"contentUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/cloudmagazin-logo-klein_menu.jpg\",\"width\":150,\"height\":150,\"caption\":\"cloudmagazin\"},\"image\":{\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/cloudmagazincom\\\/\",\"https:\\\/\\\/x.com\\\/cloudmagazin\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/cloudmagazin\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/#\\\/schema\\\/person\\\/ce38baaa19a580268aedce096597eb3c\",\"name\":\"Alec Chizhik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/alec-chizhik.jpg\",\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/alec-chizhik.jpg\",\"contentUrl\":\"https:\\\/\\\/www.cloudmagazin.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/alec-chizhik.jpg\",\"caption\":\"Alec Chizhik\"},\"description\":\"Alec is the Chief Digital Officer at Evernine and writes about cloud architectures, IT security, and digital operations practices.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/alecchizhik\\\/\"],\"url\":\"https:\\\/\\\/www.cloudmagazin.com\\\/en\\\/author\\\/alec\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Architecture Drives Compliance Costs: How to Cut Them","description":"Reduce compliance costs by aligning cloud architecture with NIS2, BSI-KRITIS, and C5 requirements\u2014early design decisions save up to 40% in remediation spend.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/","og_locale":"en_US","og_type":"article","og_title":"Architecture Drives Compliance Costs: How to Cut Them","og_description":"Reduce compliance costs by aligning cloud architecture with NIS2, BSI-KRITIS, and C5 requirements\u2014early design decisions save up to 40% in remediation spend.","og_url":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/","og_site_name":"cloudmagazin","article_publisher":"https:\/\/www.facebook.com\/cloudmagazincom\/","article_published_time":"2026-04-28T07:54:48+00:00","article_modified_time":"2026-08-03T13:45:37+00:00","og_image":[{"url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/04\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero.jpg","type":"","width":"","height":""}],"author":"Alec Chizhik","twitter_card":"summary_large_image","twitter_image":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/04\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero.jpg","twitter_creator":"@cloudmagazin","twitter_site":"@cloudmagazin","twitter_misc":{"Written by":"Alec Chizhik","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/#article","isPartOf":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/"},"author":{"name":"Alec Chizhik","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/ce38baaa19a580268aedce096597eb3c"},"headline":"Architecture Drives Compliance Costs: How to Cut Them","datePublished":"2026-04-28T07:54:48+00:00","dateModified":"2026-08-03T13:45:37+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/"},"wordCount":2230,"publisher":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#organization"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero-c2pa-260521.jpg","articleSection":["News","Reboot Germany","Sustainability"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/","url":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/","name":"Architecture Drives Compliance Costs: How to Cut Them","isPartOf":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/#primaryimage"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero-c2pa-260521.jpg","datePublished":"2026-04-28T07:54:48+00:00","dateModified":"2026-08-03T13:45:37+00:00","description":"Reduce compliance costs by aligning cloud architecture with NIS2, BSI-KRITIS, and C5 requirements\u2014early design decisions save up to 40% in remediation spend.","breadcrumb":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/#primaryimage","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero-c2pa-260521.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026-cover-hero-c2pa-260521.jpg","width":1792,"height":1024,"caption":"KI-generiertes Titelbild. C2PA-Zertifikat im Bild hinterlegt."},{"@type":"BreadcrumbList","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cloudmagazin.com\/en\/home\/"},{"@type":"ListItem","position":2,"name":"Architecture Drives Compliance Costs: How to Cut Them"}]},{"@type":"WebSite","@id":"https:\/\/www.cloudmagazin.com\/en\/#website","url":"https:\/\/www.cloudmagazin.com\/en\/","name":"cloudmagazin","description":"Inspiration f\u00fcr Businessentscheider","publisher":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cloudmagazin.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cloudmagazin.com\/en\/#organization","name":"cloudmagazin","url":"https:\/\/www.cloudmagazin.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2020\/04\/cloudmagazin-logo-klein_menu.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2020\/04\/cloudmagazin-logo-klein_menu.jpg","width":150,"height":150,"caption":"cloudmagazin"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/cloudmagazincom\/","https:\/\/x.com\/cloudmagazin","https:\/\/www.linkedin.com\/showcase\/cloudmagazin\/"]},{"@type":"Person","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/ce38baaa19a580268aedce096597eb3c","name":"Alec Chizhik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/alec-chizhik.jpg","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/alec-chizhik.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/alec-chizhik.jpg","caption":"Alec Chizhik"},"description":"Alec is the Chief Digital Officer at Evernine and writes about cloud architectures, IT security, and digital operations practices.","sameAs":["https:\/\/www.linkedin.com\/in\/alecchizhik\/"],"url":"https:\/\/www.cloudmagazin.com\/en\/author\/alec\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts\/38712","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/comments?post=38712"}],"version-history":[{"count":5,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts\/38712\/revisions"}],"predecessor-version":[{"id":50425,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts\/38712\/revisions\/50425"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/media\/41397"}],"wp:attachment":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/media?parent=38712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/categories?post=38712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/tags?post=38712"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/industry?post=38712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}