Does sovereignty end at the border

Does sovereignty end at the border? Why Germany's BSI C3A level deserves a closer look

Does sovereignty end at the border? Why Germany’s BSI C3A level deserves a closer look

06.08.26

First off: C3A is a real asset.

With the “Criteria Enabling Cloud Computing Autonomy”, the BSI has achieved something this market has long been waiting for. Since April 27, 2026, sovereignty is no longer just a claim, but a verifiable requirements profile. Anyone who reads the catalog quickly realizes: practitioners have been at work here. Six dimensions, basic criteria, additional criteria, risk-based selection. This is how you turn a political buzzword into a practical tool.

And yet, two points give me pause.

The first: The catalog specifies two levels of localization: EU and Germany. Depending on the criticality of their operations, cloud customers can require that data centers be located in Germany and that operations staff reside in Germany. Not in Europe. In Germany. The second point concerns the operations staff themselves – more on that later.

I understand where this comes from. There are use cases in which the state has special protection needs: classified information, defense, core sovereign functions. It is undisputed that such cases justify special requirements.

However, this does not require a separate level in the catalog. Anyone with such protection needs can include them as an additional criterion in the respective request for proposals. That is exactly what public procurement law is for.

Incidentally, the BSI itself sees it this way: the catalog explicitly states that restrictions should be justified on the basis of German law and must be permissible under public procurement law, for example for reasons of public safety. The justified exception is therefore already included in the catalog.

And let’s be honest: These cases should account for only a small percentage of all use cases. And that’s exactly when the question arises: why a separate “Germany” level needs to be so prominently featured in the catalog. If half the government classifies its workloads as core sovereign tasks, we have a completely different problem.

On top of that, there’s an asymmetry that really concerns me. In many of these cases, American providers have been at least partially accepted so far. Microsoft is still widely used in the German public sector today, and for particularly sensitive scenarios, Delos has even established a dedicated operating structure to ensure this remains the case. We go through all this trouble for non-European technology.

Why don’t we place at least the same level of trust in European companies? A provider from Helsinki, Vienna, or Milan is subject to the same GDPR, the same NIS2, and the same European legal framework as one from Stuttgart. If that isn’t enough to ensure sovereignty, it says less about these providers than about our trust in Europe.

My question is therefore: What happens if the German level becomes the norm rather than a justified exception?

Regulation is European. Should sovereignty be a national matter?

Let’s take a look at what actually regulates our industry:

The GDPR is European.
NIS2 is European.
DORA is European.
eIDAS 2.0 and the EUDI Wallet are European.

Even the C3A explicitly aligns its structure and objectives with the European Cloud Sovereignty Framework. The entire legal architecture within which we operate is built on a single market.

But if we define sovereignty at the national level, we’re drawing new boundaries right within that very market. France has long since charted its own national path with SecNumCloud. If the German level is adopted as the procurement benchmark, and other member states follow suit, a European provider will soon face a patchwork quilt: one certification per country, one operating model per country, one staffing concept per country.

Who can afford that? Not the European scale-up. Rather, the corporation with the large compliance department. The irony is bitter: A tool intended to reduce dependence on non-European providers could ultimately exacerbate the very fragmentation that has been holding back Europe’s digital economy for decades.

The American provider has a home market of nearly 350 million people. The European provider will have 27 home markets – if we’re not careful.

Sovereignty requires scale

Digital sovereignty does not arise from isolation, but from alternatives.

Europe will only become more independent if European providers grow large enough to be genuine alternatives. You grow large in a market of 450 million people, not in one of 84 million. Any special national requirement that is not absolutely necessary for security policy works against this goal.

Therefore, here is my proposal for interpreting the C3A, in case the BSI does not make corrections here:
The EU level is the standard. The German level is the justified exception for state security needs, not the default setting for every tender that wants to appear sovereign.

Any procurement officer who demands the German level should be able to answer the question of what specific risk it addresses that the EU level does not cover. In most cases, the honest answer will be: none.

And to the standard-setters, in Bonn as well as in Brussels: The harmonization of national catalogs under the European framework should not be a long-term goal, but rather the next step. One criterion, one audit, 27 markets. That would be sovereignty that strengthens Europe.

A passport is not a security concept

This brings me to the second point that’s been bothering me.

The C3A requires, for operational sovereignty, that all persons with access to the operational infrastructure be EU citizens with their primary residence in the EU.

At the German level, this requirement is even stricter: EU citizenship plus primary residence in Germany. This is where my two points of criticism intersect.

The residency requirement makes sense to me: Anyone living in the EU is subject to European law. But citizenship? The engineer who has lived in Berlin for fifteen years, pays taxes here, and sends her children to school here is not allowed to operate a sovereign cloud because she has the “wrong” passport. Her neighbor, who has an EU passport and has not undergone any security screening, is allowed to do so.

At the national level in Germany, it gets even more absurd: The Portuguese engineer in Freiburg is allowed to do so, but her colleague with the same passport – who lives ten kilometers away in Alsace and commutes daily – is not.

Trust is built through vetting, not through a birth certificate. Security clearances, dual-control principles, and logged accesses: these are the tools that truly address insider risks.

A eligibility criterion primarily addresses one thing: the shortage of skilled workers – but in the wrong way. Europe’s cloud providers compete globally for talent. Narrowing the talent pool through a list of criteria does not make European providers more competitive, but rather slows them down.

Where we stand

We have built cidaas as a European platform: a German company, governed by German law, operating in Europe.

We meet German requirements, and we’re happy to do so. But our benchmark is the European market, because only it is large enough to sustain digital sovereignty economically.

Sovereignty does not end at national borders. Properly understood, it begins there.

More related content

Learn more about digital sovereignty: Digital Sovereignty – we love the term, but what do we actually mean?