In comparison to the four major US hyperscale cloud services there are dozens of EU regional cloud services. STACKIT is one of these and at its Cloud X Summit, STACKIT demonstrated how it is expanding from a European infrastructure cloud into a broader ecosystem encompassing enterprise applications, cybersecurity, data, AI, development tools, and cloud adoption services.
In my previous blogs on this I described the risks related to who operates their cloud, who controls the technology, the laws that the service is subject to, whether critical services can continue operating if a supplier becomes unavailable, and whether workloads can realistically be moved elsewhere.
STACKIT has a strong answer to these questions. However, it also illustrates an important reality: sovereign infrastructure does not automatically make a cloud service sovereign.
From German Cloud to European Ecosystem
STACKIT is part of Schwarz Digits, the IT and digital division of Germany's Schwarz Group, best known for its Lidl and Kaufland retail businesses. This gives STACKIT an unusual position among European cloud providers, it developed from the requirements of one of Europe's largest retail organizations.
Schwarz Group remains an important "customer zero." STACKIT supports the applications used by the retail arm ranging from enterprise software to large-scale AI workloads. For example, every night it uses the service to generate more than two billion retail forecasts. In addition, it uses the platforms for AI based computer vision, SAP, ServiceNow, and software development.
This provides STACKIT with both financial backing and a large environment in which to prove its technology. But the requirements of Schwarz Group are not necessarily the requirements of every European enterprise or public-sector organization. STACKIT has used this experience in collaboration with partners to create standardized services that are more widely usable.
Building Out the Ecosystem
One of the clearest messages from Cloud X Summit was that infrastructure sovereignty alone is not sufficient. Customers need applications, data platforms, cybersecurity products, and AI services to operate and grow their businesses.
To support this, STACKIT is expanding its ecosystem through relationships with other enterprise technology providers. These include SAP, ServiceNow, Snowflake and Zscaler alongside European and international AI providers to offer sovereign, open-standard enterprise data analytics, and Generative AI in Europe. This is strategically important to compete in a market where customers continue to depend upon non-EU clouds for higher-level services.
STACKIT is also strengthening its own data and AI capabilities, MLOps, developer services and confidential computing. Hardware-backed confidential computing provides additional protection against access by the cloud service provider to the customer data.
However, STACKIT is not trying to reproduce AWS, Microsoft Azure, or Google Cloud service for service. STACKIT says it wants to maintain a comparatively lean portfolio, and it estimates that this currently addresses around 80% of workloads. However, it acknowledges that individual services do not yet generally match the feature richness of the hyperscalers.
There is merit in simplicity, but it also creates a challenge where many organizations have become highly dependent upon specific hyperscaler capabilities.
Sovereignty and Software as a Service
Organizations want solutions, not just IT infrastructure. This raises a sovereignty challenge when software from a non-European supplier runs on sovereign European infrastructure.
For example, in the case of ServiceNow, STACKIT installs, configures, and runs the software on the STACKIT infrastructure. This potentially provides greater data and operational sovereignty than consuming the same application as a non-EU SaaS service.
But it does not eliminate dependency on ServiceNow. The original vendor still develops the software and supplies future releases, security updates and patches. Locally operating the service can therefore reduce operational dependency, but it cannot eliminate the underlying software supply-chain dependency.
This is not a weakness unique to STACKIT. It illustrates the multi-dimensional nature of sovereignty that is captured by the EU Cloud Sovereignty Framework.
Cloud Migration and Cloud Exit
Another important announcement was the STACKIT Cloud Adoption Framework. Rather than being another collection of cloud documentation, this framework is intended to bring together guidance, reusable assets, tools, training, and partner expertise that help organizations adopt STACKIT and move workloads onto the platform.
This addresses an important but sometimes neglected element of sovereignty: practical portability. It is easy to state that an organization should avoid cloud lock-in.
The hyperscale clouds have well developed tools to support inbound workload migration. Another alternative often proposed is to “modernize” the workload for example by recoding it to use containers. Either option introduces risks and organizations need reassurance that the benefits of the move are worthwhile.
The Cloud Adoption Framework could therefore become an important part of STACKIT's proposition if it makes migration easier. But organizations also need to ask another question: how easily could we subsequently move away from STACKIT?
A sovereign European cloud should not merely replace dependency on a US provider with dependency on a European one. Open technologies, portable architecture, documented interfaces and credible exit plans remain important regardless of who owns the cloud.
From German Strength to European Scale
STACKIT has particularly strong credentials in Germany, but becoming a European sovereign cloud requires more than exporting a German model.
However, public sector sovereignty requirements differ between European markets. Some German public-sector organizations have requirements for data to remain in Germany or even within a particular federal state. The same is also true around the EU where for example, Franch public services have requirements for SecNumCloud certification.
STACKIT is responding through partners and procurement frameworks rather than attempting to build a direct services organization in every country. This appears sensible, but success will depend on establishing trusted local ecosystems and demonstrating that its definition of sovereignty matches national requirements rather than assuming there is a single European model.
A European Choice
The Cloud X Summit demonstrated how far STACKIT has moved beyond providing basic IaaS. The Schwarz Group provides scale and a demanding customer-zero environment; the service portfolio is expanding; major enterprise software providers are joining the ecosystem; and STACKIT is investing in data, AI, security, confidential computing, and practical cloud adoption.
The EU is an enormous and growing market for IT services and exploitation of AI. STACKIT provides European organizations with an increasingly credible sovereign cloud option. It will not eliminate every technology or supply-chain dependency, nor does it yet match the breadth of the hyperscalers. But sovereignty does not require complete technological isolation. The important question for European organizations is which dependencies they are prepared to accept, which they need to control, and how much they value having a European alternative.