Digital transformation for public administration, sovereignty makes it possible
Until now, authorities have shied away from the cloud for fear of losing control over citizen services, Fachverfahren and registers. With confidential computing, sovereignty becomes a property of the technology itself: the infrastructure runs with a cloud operator that cannot read the data — the keys remain in public hands, and every claim is cryptographically verifiable. Digitization, cost-effectiveness and resilience no longer exclude one another, neither in procurement nor in the audit.
This isn't a pitch about what would work — it's the architecture behind Germany's GovTech-Platform, running today.

No infrastructure operator holds a readable access path; the keys remain in public hands and are released only against attestation.
Deployment lands with German and European providers or on-premises — and the operator-exclusion architecture holds wherever it runs.
The base architecture is provider-independent by design: changing providers is a migration, not a rebuild — an exit strategy anchored in the architecture, not just in the contract annex.
Remote attestation and evidence packs, verifiable by the authority, the auditor and BSI-certified IT security service providers. Sovereignty is demonstrated by export, not asserted by memo.
What public bodies ask
How is this different from a hyperscaler's "sovereign cloud" offering?
Sovereign-branded regions relocate the problem; they don't remove it — the operator still runs the stack, and trust still rests on contracts and geography. Technical operator exclusion inverts that: the infrastructure operator holds no readable access regardless of who they are, and you can verify it cryptographically.
Do our Fachverfahren need to be rewritten?
No — workloads run inside confidential environments without code changes. That's what made the Elterngeld proof-of-concept migration possible, and it's the property that keeps migration projects inside a legislative period.
We're a municipality, not a federal ministry. Is this within reach?
Yes — the Register-as-a-Service consortium includes an Amt, not just federal actors. Smaller bodies typically enter through their public IT service provider or a shared platform operated at state or federal level, rather than running the infrastructure themselves. Bring your constellation; the deployment model follows it.
Where does the data physically sit?
Where your requirements point: German and European cloud providers, your own datacenter, or a combination — the protection model is identical across them, which is precisely what makes the choice yours rather than the architecture's.
How do we actually procure this?
Three routes, by constellation: through your public IT service provider, through established value-add distribution, or directly. Contract vehicles are structured per procurement — [PLACEHOLDER: confirm EVB-IT Cloud readiness and any framework-agreement or marketplace availability with sales before launch].
How does this map to IT-Grundschutz and NIS2?
Requirement by requirement, on the dedicated pages: BSI IT-Grundschutz (including the supplementary-measures pattern for elevated protection needs) and NIS2, each with a downloadable control mapping — and each honest about what no product can do for you.
And classified environments?
Handled the way they should be — in closed briefings, not on this website. For defense and adjacent programs, see the defense page.
Bring the Fachverfahren, the register, or the tender
Tell us what you're mandated to digitize and what your data protection officer won't sign. We'll show you the architecture already carrying both — in production, in Germany — and give you the version of this story your leadership can repeat.
.png)
