Industry · Public sector

Digital transformation for public administration, sovereignty makes it possible

Until now, authorities have shied away from the cloud for fear of losing control over citizen services, Fachverfahren and registers. With confidential computing, sovereignty becomes a property of the technology itself: the infrastructure runs with a cloud operator that cannot read the data — the keys remain in public hands, and every claim is cryptographically verifiable. Digitization, cost-effectiveness and resilience no longer exclude one another, neither in procurement nor in the audit.

This isn't a pitch about what would work — it's the architecture behind Germany's GovTech-Platform, running today.

Confidential computing layer of Germany's GovTech-Platform
L-BANK ELTERNGELD PROCESS SUCCESSFULLY MIGRATED (PROOF OF CONCEPT)
Mappings for BSI IT-Grundschutz and NIS2
THE PUBLIC-SECTOR TRILEMMA
Three forces act at once.
 Digitization is mandatory
,
sovereignty is scrutinized
in every tender, and
the rulebook is tightening
: NIS2 now designates public administration a regulated sector.
Conventional answers satisfy one pressure by sacrificing another. Confidential computing dissolves the trade —
cloud scale with the operator technically excluded
, keys under public control, and every claim verifiable by the authority itself.
THE MANDATE
Delivered on cloud timelines, not legacy ones.
THE TENDER
Survived without a sovereignty concession — and without the controversy.
THE AUDIT
Answered with evidence, not explanations.
WHAT AGENCIES BUILD ON IT
Fachverfahren into the cloud — without rewrites
+
Registers and citizen data, sealed
+
Health and social data platforms
+
Inter-agency collaboration without data pooling
+
Sovereign cloud that survives the tender
+
Elevated protection needs, answered concretely
+
For public IT service providers: operate sovereignty as a service
+
BUILT FOR THE tender, NOT JUST THE WORKLOAD
Who can access the data?

No infrastructure operator holds a readable access path; the keys remain in public hands and are released only against attestation.

Which jurisdiction governs it?

Deployment lands with German and European providers or on-premises — and the operator-exclusion architecture holds wherever it runs.

What happens at exit?

The base architecture is provider-independent by design: changing providers is a migration, not a rebuild — an exit strategy anchored in the architecture, not just in the contract annex.

How is any of it proven?

Remote attestation and evidence packs, verifiable by the authority, the auditor and BSI-certified IT security service providers. Sovereignty is demonstrated by export, not asserted by memo.

FAQ

What public bodies ask

Q·01

How is this different from a hyperscaler's "sovereign cloud" offering?

Sovereign-branded regions relocate the problem; they don't remove it — the operator still runs the stack, and trust still rests on contracts and geography. Technical operator exclusion inverts that: the infrastructure operator holds no readable access regardless of who they are, and you can verify it cryptographically.

Q·02

Do our Fachverfahren need to be rewritten?

No — workloads run inside confidential environments without code changes. That's what made the Elterngeld proof-of-concept migration possible, and it's the property that keeps migration projects inside a legislative period.

+
Q·03

We're a municipality, not a federal ministry. Is this within reach?

Yes — the Register-as-a-Service consortium includes an Amt, not just federal actors. Smaller bodies typically enter through their public IT service provider or a shared platform operated at state or federal level, rather than running the infrastructure themselves. Bring your constellation; the deployment model follows it.

+
Q·04

Where does the data physically sit?

Where your requirements point: German and European cloud providers, your own datacenter, or a combination — the protection model is identical across them, which is precisely what makes the choice yours rather than the architecture's.

+
Q·05

How do we actually procure this?

Three routes, by constellation: through your public IT service provider, through established value-add distribution, or directly. Contract vehicles are structured per procurement — [PLACEHOLDER: confirm EVB-IT Cloud readiness and any framework-agreement or marketplace availability with sales before launch].

+
Q·06

How does this map to IT-Grundschutz and NIS2?

Requirement by requirement, on the dedicated pages: BSI IT-Grundschutz (including the supplementary-measures pattern for elevated protection needs) and NIS2, each with a downloadable control mapping — and each honest about what no product can do for you.

+
Q·07

And classified environments?

Handled the way they should be — in closed briefings, not on this website. For defense and adjacent programs, see the defense page.

+
Get started

Bring the Fachverfahren, the register, or the tender

Tell us what you're mandated to digitize and what your data protection officer won't sign. We'll show you the architecture already carrying both — in production, in Germany — and give you the version of this story your leadership can repeat.

Certifications & security
Certified ISO/IEC 27001
IT Security made in Germany — TeleTrusT