A regulatory map for infrastructure buyers

Gaia-X · NIS2 · IT-SiG 2.0 · DSGVO · BSI IT-Grundschutz — what they actually require.

Buyers of sovereign infrastructure navigate an overlapping set of European and German frameworks. They are not the same thing — some are law, some are standards, some are labels — but they converge on one requirement: demonstrable, auditable control over your own systems.

This page is an educational overview to orient a procurement or security team. It is not legal advice, and it does not assert any certification status for this platform. For what a specific regulation requires of your programme, involve your compliance and legal functions.

The frameworks, in plain terms

DSGVO / GDPR

The EU General Data Protection Regulation (Datenschutz-Grundverordnung) governs personal-data processing. For infrastructure, the relevant pressure is on international transfers and processor control: personal data flowing to a provider under foreign jurisdiction (e.g. the US CLOUD Act) is a transfer-risk problem that residency claims alone do not resolve.

NIS2

The EU NIS2 Directive raises cybersecurity obligations for essential and important entities — risk management, supply-chain security, incident reporting, and accountability at management level. It pushes operators toward infrastructure they can secure, monitor, and account for end to end, including their software supply chain.

IT-SiG 2.0 (Germany)

The second IT Security Act expands the duties of operators of critical infrastructure (KRITIS) in Germany, including attack-detection requirements and stronger BSI oversight. It reinforces the need for auditable, controllable platforms rather than opaque managed services.

BSI IT-Grundschutz

The German Federal Office for Information Security (BSI) publishes IT-Grundschutz — a comprehensive baseline-protection methodology and control catalogue. It is the practical yardstick many German public-sector programmes align to. Open, self-hosted infrastructure is straightforward to map to Grundschutz modules because you control — and can evidence — the whole stack.

Alignment vs. certification. "Maps cleanly to Grundschutz modules" is a design property. A formal BSI certification or C5 attestation is a separate, audited status. We describe alignment where it is true and never imply a certification we do not hold.

Gaia-X

Gaia-X is not a law but a European initiative defining a framework and labels for sovereign, interoperable data infrastructure. Its criteria emphasise transparency, portability, and provider independence — properties that open, self-hostable platforms satisfy structurally.

The common thread

Read together, these frameworks are not asking “is the datacenter in-country?” They are asking:

  • Can you see what your infrastructure does? (auditability)
  • Can you secure and monitor it end to end? (control)
  • Can you evidence all of the above to a regulator? (accountability)
  • Are you free of foreign compulsion over the system? (jurisdiction)

That is the same definition of sovereignty arrived at from a legal direction: open, self-hosted, controllable, with no foreign root access.

What to ask a platform vendor

  • Can you evidence the full software supply chain (SBOMs, reproducible builds)?
  • Can the platform run air-gapped for the most sensitive workloads?
  • Does the architecture map to BSI IT-Grundschutz modules, and where are the gaps?
  • What foreign jurisdiction, if any, touches the operator or control plane?

Bring those questions to your compliance team early — the answers shape which frameworks you can satisfy and how much evidence you will have to produce.

← All sovereignty articles Talk to an expert