Buyers of sovereign infrastructure navigate an overlapping set of European and German frameworks. They are not the same thing — some are law, some are standards, some are labels — but they converge on one requirement: demonstrable, auditable control over your own systems.
This page is an educational overview to orient a procurement or security team. It is not legal advice, and it does not assert any certification status for this platform. For what a specific regulation requires of your programme, involve your compliance and legal functions.
The frameworks, in plain terms
DSGVO / GDPR
The EU General Data Protection Regulation (Datenschutz-Grundverordnung) governs personal-data processing. For infrastructure, the relevant pressure is on international transfers and processor control: personal data flowing to a provider under foreign jurisdiction (e.g. the US CLOUD Act) is a transfer-risk problem that residency claims alone do not resolve.
NIS2
The EU NIS2 Directive raises cybersecurity obligations for essential and important entities — risk management, supply-chain security, incident reporting, and accountability at management level. It pushes operators toward infrastructure they can secure, monitor, and account for end to end, including their software supply chain.
IT-SiG 2.0 (Germany)
The second IT Security Act expands the duties of operators of critical infrastructure (KRITIS) in Germany, including attack-detection requirements and stronger BSI oversight. It reinforces the need for auditable, controllable platforms rather than opaque managed services.
BSI IT-Grundschutz
The German Federal Office for Information Security (BSI) publishes IT-Grundschutz — a comprehensive baseline-protection methodology and control catalogue. It is the practical yardstick many German public-sector programmes align to. Open, self-hosted infrastructure is straightforward to map to Grundschutz modules because you control — and can evidence — the whole stack.
Alignment vs. certification. "Maps cleanly to Grundschutz modules" is a design property. A formal BSI certification or C5 attestation is a separate, audited status. We describe alignment where it is true and never imply a certification we do not hold.
Gaia-X
Gaia-X is not a law but a European initiative defining a framework and labels for sovereign, interoperable data infrastructure. Its criteria emphasise transparency, portability, and provider independence — properties that open, self-hostable platforms satisfy structurally.
The common thread
Read together, these frameworks are not asking “is the datacenter in-country?” They are asking:
- Can you see what your infrastructure does? (auditability)
- Can you secure and monitor it end to end? (control)
- Can you evidence all of the above to a regulator? (accountability)
- Are you free of foreign compulsion over the system? (jurisdiction)
That is the same definition of sovereignty arrived at from a legal direction: open, self-hosted, controllable, with no foreign root access.
What to ask a platform vendor
- Can you evidence the full software supply chain (SBOMs, reproducible builds)?
- Can the platform run air-gapped for the most sensitive workloads?
- Does the architecture map to BSI IT-Grundschutz modules, and where are the gaps?
- What foreign jurisdiction, if any, touches the operator or control plane?
Bring those questions to your compliance team early — the answers shape which frameworks you can satisfy and how much evidence you will have to produce.
