Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

BSI Defines Cloud Sovereignty: New Criteria for Secure IT Infrastructures

With the C3A criteria, the BSI has presented concrete standards for sovereign cloud services. Critical infrastructure operators and security authorities in particular benefit from the new requirements.

BSI presents concrete standards for sovereign cloud services

With the "Criteria Enabling Cloud Computing Autonomy" (C3A), the German Federal Office for Information Security (BSI) has for the first time defined concrete standards for when cloud services can be considered sovereign. The new criteria are intended to create clarity, particularly for security-critical applications in public administration and for operators of critical infrastructure.

Until now there has often been uncertainty about which cloud solutions can actually be operated independently of non-European providers such as AWS, Azure, Alibaba or Huawei Cloud. "We are concerned with technically viable solutions that formulate concrete conditions," explains Thomas Caspers, Vice President of the BSI.

Practical experience feeds into the new standards

In developing the C3A, the BSI draws on extensive practical experience with various degrees of dependency. Several sovereign cloud approaches have already been tested in Germany, including:

  • The SAP-Microsoft cooperation DelosCloud
  • Stackit from Schwarz Digits
  • The T-Systems Sovereign Cloud in cooperation with Google
  • Amazon's European Sovereign Cloud offering

In parallel, the French IT security agency ANSSI tested similar approaches, always involving French companies, such as defence group Thales with S3NS, which is certified to SecNumCloud requirements.

"Using the example of the AWS European Sovereign Cloud, among others, we saw how many mechanisms play a role in keeping a cloud operational," Caspers explains. "But such offerings cannot be operated completely decoupled for years on end."

Concrete criteria for emergencies

The C3A standards define precise requirements for various scenarios. One central criterion is SOV-4-09-C, which sets out the requirements in the event of a "disconnect" - the decoupling from the non-European operator cloud:

  • Operations must continue without any loss of availability, integrity, authenticity and confidentiality
  • A documented process for the decoupling must be in place
  • The operator must test and document this at least once a year

For staffing requirements, the BSI distinguishes between different security levels. Criterion SOV-4-01-C1 requires all employees with access to operating resources to hold EU citizenship and have EU residence. For high-security applications such as security authorities or the Bundeswehr, SOV-4-01-C2 applies: here, all employees must be resident within the Federal Republic of Germany.

For a state of defence as regulated by the Basic Law, the requirements are particularly strict: cloud service providers must be able to hand over operations, including the necessary equipment and personnel, to the federal authorities.

Implications for critical infrastructure and security technology

The new standards are not legally binding for the time being, but they can be declared minimum requirements in legislation or public tenders. "The C3A can become the benchmark for the federal administration," says Caspers.

This becomes particularly relevant through the link to existing requirements: federal bodies are obliged to implement the BSI's IT-Grundschutz. When using external cloud services, they must fulfil module OPS 2.2 and the minimum standard for the use of external cloud services (MST-NCD). The C3A supplement these security criteria with aspects of digital sovereignty.

For operators of critical infrastructure, who are already subject to strict security requirements, the new standards mean additional planning certainty. Companies from sectors such as energy, water, health or telecommunications can now specifically select cloud solutions that meet both security and sovereignty requirements.

European dimension and future prospects

The publication of the C3A criteria comes strategically ahead of the European Commission's planned presentation of the Cloud and AI Development Act (CADA) on 27 May. Observers expect Executive Vice-President of the Commission Henna Virkkunen to set out clearer criteria for cloud sovereignty with the CADA.

Should similar criteria find their way into the annexes of IT security legislation such as NIS2 or the Cybersecurity Act, this would have significant effects across Europe. The German proposal could then become the standard for sovereign cloud services throughout the EU.

For the security technology industry, these developments mean new planning certainty when selecting cloud services for critical applications. Whether large hyperscalers can meet the strict requirements will depend on the respective requirement profile of customers and on the regulatory pressure to choose sovereign solutions.