The image illustrates how the new German stack anchors the areas of zero trust, BYOK and open source in the IT tech stack of regulated industries (AI-generated).

250 million euros for the federal government's AI cloud: The Deutschland-Stack goes live

Written By SecureCloud
August 19, 2026

The federal government has awarded the 250 million euro contract for the sovereign AI cloud to T-Systems/SAP and SVA/Schwarz Digits/Codesphere. What zero trust, BYOK and open source now mean for IT managers in regulated industries.

At the end of May, the federal government awarded the 250 million euro contract for the sovereign AI cloud - to the consortia T-Systems/SAP and SVA/Schwarz Digits/Codesphere. With zero-trust architecture, Bring Your Own Key and a strict commitment to open source, the German stack is now operational for the first time. Why the award is more than just a PaaS project for the administration - and what four levers it unlocks for regulated industries.

What was awarded - and to whom

On May 21, 2026, the German government awarded the contract for a platform-as-a-service infrastructure (PaaS) with a volume of around 250 million euros (heise, 21.05.2026) .

The award is split between two consortia with clearly separated roles:

T-Systems and SAP will take the lead role and deliver the PaaS services for AI applications on a secure, sovereign cloud platform.

SVA, Schwarz Digits and Codesphere form the second team. SVA is responsible for architecture and integration, Schwarz Digits provides the BSI-certified Stackit cloud as the infrastructure layer, Codesphere provides the platform layer including cold-start technology, which, according to the provider, saves up to 90 percent on compute costs.

The constellation is remarkable: none of the lots awarded go to a US hyperscaler. For the first time, a nationwide AI cloud is being built on a stack whose operator, infrastructure, key management and platform software are fully anchored in the EU.

Three technical specifications that make the difference

Behind the political buzzword "sovereign AI cloud" are three concrete specifications that are binding in the tender - and which serve as a benchmark for every other cloud buyer in the country.

Zero-trust architecture with continuous authentication. Every access is checked individually, regardless of whether it comes from the internal or external network. Experience has shown that this principle is the most effective lever against lateral movement after initial access.

Bring Your Own Key (BYOK). The user authorities retain cryptographic control over their own keys. This means that in practice, what C3A demands in theory as a sovereignty criterion applies: no data or key domination by the platform operator.

Open standards and open source without vendor lock-in. The platform must be explicitly based on open interfaces and allow open source components. This rules out the possibility of migration to another sovereign environment becoming technically impossible at a later date.

The compliance framework is ISO/IEC 27001 and the BSI criteria catalog C5:2020. The next stage is already on the table with the C5:2026 published in April 2026 and the new sovereignty catalog C3A. We have outlined here how these catalogs interlock and which three questions they answer: "Germany stack and C3A: Digital sovereignty finally gets concrete".

Kipitz: The first litmus test for meaningful AI in administration

The first productive application on the new cloud is Kipitz, the federal government's own AI assistant. It supports document processing, knowledge management, translation and the acceleration of planning processes. SVA already operates Kipitz at the Federal Information Technology Center (ITZBund), so the transfer to the new cloud environment will be seamless.

Experience has shown that AI projects in regulated areas do not fail because of the models, but because of three issues: the data space, the identity of the users and the reproducibility of results. Kipitz addresses precisely these points - with BYOK encryption of inputs, EUDI wallet-enabled authentication and a documented model pipeline. This creates the first reliable reference model that AI workflows in SMEs can use as a guide.

Why the award accelerates the sovereignty conversation in the private sector

Up to this point, procurement has formally only affected public administration. For the private sector, however, it has a double effect: as a procurement standard and as a market signal.

As a procurement standard: every future cloud and AI tender will have to be measured against Zero Trust, BYOK and open source components - this applies to hospitals under state sponsorship as well as to savings banks, insurance companies and large law firms.

As a market signal: if the federal government operates its administrative AI on a purely European stack, arguments such as "AI is not scalable without hyperscalers" lose their foundation. The CISPE alliance and the 25 European cloud CEOs, who called for clear procurement rules in March, have thus achieved their first measurable success (heise, 18.03.2026).

Four steps that IT managers can take now

Define Zero Trust as a minimum standard in your own cloud profile. Anyone still using network perimeter logic today has a model that is now considered inadequate in federal tenders. Experience has shown that one hour with IT management is enough to identify gaps.

Check Bring Your Own Key in existing cloud contracts. Anyone who does not hold their own keys does not have key control. Background on the legal situation: "Data protection in the cloud - US laws versus GDPR".

Hardening AI workflows along the three weak points. Data space, identity, reproducibility - these are precisely the points that Kipitz addresses. If you are planning your own AI use case, it is best to organize it along the same three axes.

Measuring cloud providers against C3A-compliant building blocks. BSI-certified stackit cloud, key management in the EU, open source components and disconnect capability are the new hygiene factors. How we classify this: "BSI makes cloud sovereignty measurable - an overview of the C3A criteria".

Sovereign infrastructure as a foundation - why SecureCloud actively welcomes this award

SecureCloud operates its platform 100 percent in Germany on its own hardware at noris network AG, BSI C5 and ISO 27001 certified, without a US parent company and without third-country access. SecureShare, SecureWork, SecureSign and SecureMail are designed precisely for the use cases that are now becoming the nationwide standard with Zero-Trust, BYOK and Open Standards: Law firms, tax consultancies, clinics, banks and financial service providers, public authorities and industry.

For us, the 250 million award is the long overdue confirmation that sovereign AI and cloud solutions in Germany are not only possible, but also economically viable. The standard that now applies to the public sector will inevitably spread to all regulated sectors in the coming quarters.

Conclusion: a promise becomes a project

With the 250 million award, the federal government has for the first time not talked about digital sovereignty, but built it. Zero trust, bring your own key and open source are no longer buzzwords, but contractual terms. Anyone responsible for cloud and AI strategy today now has a reference stack against which any future procurement can be measured - and a clear lever to turn their own architecture in the same direction.


Interessiert Sie die souveräne Cloud?

Hier geht's zur kostenlosen Testphase

Picture of SecureCloud

SecureCloud

SecureCloud is a German cloud platform for encrypted data rooms, secure data exchange, and digital signatures. Its headquarters and all data centers are located entirely in Germany. SecureCloud is ISO 27001-certified, holds a BSI C5 certificate, and complies with the requirements of the GDPR. Since 2014, SecureCloud has supported more than 6,000 customers in the private and public sectors, including critical sectors such as healthcare, the legal system, public administration, and the financial sector.

Related Articles

News & Trends

The Cyber Resilience Act (CRA) makes no exceptions—security is the key to entering the supply chain

The Cyber Resilience Act applies to all organizations, regardless of size. What the CRA requires, when it takes effect, why it makes...

News & Trends

The EU-US data protection framework following ‘Trump v Slaughter’

On June 29, 2026, the U.S. Supreme Court dealt a structural blow to the EU-U.S. Data Privacy Framework. Safe Harbor, Privacy...

News & Trends

White Paper “Confident in 30 Days”: The Easy Transition to Digital Independence

White Paper “Self-Sufficient in 30 Days”: €660,000 in risk due to dependence on U.S. cloud services, a 3-year cost comparison, and a...