What is the aim of Sovereign Cloud Stack?
Definition of the Sovereign Cloud Stack Open, verifiable standards and building blocks for cloud infrastructures, so that organisations can build and operate independent platforms without vendor lock-in.
The focus is on Interoperability, transparency, technological independence and certifiable sovereignty.
Organisations should be able to:
- their cloud infrastructure to shape and control it yourself
- Switching providers flexibly
- Avoiding dependencies in the long term
- To develop systems in a sustainable manner
This is not just a matter of compliance or location-related issues, but of the Structural manageability of cloud architectures.
Why is digital sovereignty important?
Digital sovereignty is a key prerequisite for Capacity to act, security and capacity for innovation.
Cloud infrastructures form the foundation of modern IT. At the same time, their use gives rise to new dependencies:
- from individual providers
- from proprietary platforms
- due to legal frameworks beyond one’s control
These dependencies can give rise to strategic risks – for example, through limited options for switching suppliers, a lack of transparency or limited influence over technological developments.
Digital sovereignty addresses precisely these challenges. It describes the ability of digital systems to:
- to use and shape it independently
- to operate or relocate independently
- to be able to monitor and further develop in the long term
This is explicitly about more than just legal compliance. Data protection and regulation are important foundations, but they are not sufficient on their own to ensure sustainable control over digital infrastructures.
What is crucial, rather, is the Systems Architecture:
- Are the interfaces open and standardised?
- Can workloads be moved between providers?
- Is the process transparent and reproducible?
- Does knowledge remain accessible, or is it tied to individual providers?
Digital sovereignty thus becomes a specific design issues relating to cloud architectures – not merely a compliance issue.
For organisations, this means:
- more strategic autonomy
- higher Resilience in the face of disruptions and geopolitical risks
- better Control over data and processes
- long-term Avoiding lock-in effects
For the market, this means:
- more competition
- more innovation
- greater transparency
What is the basis of digital sovereignty?
- Legal dimension
Digital sovereignty encompasses the ability to define and enforce rules for digital solutions. One example of this is the EU's General Data Protection Regulation (GDPR), which aims to ensure transparency and control over personal data. However, challenges such as the Schrems II ruling and dependencies on non-European cloud providers show how important it is to go beyond mere legal compliance.
Franchise agreements with local operators attempt to solve these problems, but often fail to ensure genuine self-determination and transparency. - freedom of choice
Technological dependencies often arise from proprietary interfaces and platforms. This makes it difficult to switch providers, as the costs of switching are often prohibitively high. Open standards and open-source software can reduce such dependencies, as they enable interoperability and flexibility. - Technological dimension
Proprietary licences and vendor lock-ins restrict technological self-determination. Open-source software provides a basis for technological sovereignty through transparency, peer review and adaptability. However, this requires active communities and expertise in order to be used sustainably. - competence dimension
Software alone is not enough – skills are needed to operate it securely and to a high standard. Building and sharing knowledge is therefore crucial. As with the open-source movement, operational knowledge must also be shared more openly in order to strengthen resilience and achieve true digital sovereignty.
Is Sovereign Cloud Stack only available in Germany?
No. Sovereign Cloud Stack is not a national project, but a An open, internationally applicable approach to sovereign cloud infrastructures.
Although SCS originated in the German context and specifically addresses requirements such as digital sovereignty, data protection and regulatory frameworks, the underlying principles are, however, universally applicable:
- open standards
- Open-source software
- Interoperability
- transparent operating models
These characteristics are relevant regardless of geographical boundaries – wherever organisations are developing their digital infrastructure monitor, understand and operate flexibly want to.
SCS is therefore aimed at:
- Cloud providers
- public authorities
- Company
- Integrators and operators
worldwide.
At the same time, SCS helps to create a a more decentralised and diverse cloud ecosystem to promote. Rather than a few dominant platforms, this enables collaboration between many providers who build on common standards whilst remaining independent.