Free whitepaper
Digital sovereignty: what NIS2 changes about it.
Why a server in Frankfurt is not sovereignty on its own, and what the NIS2 Implementation Act now requires you to prove. Seven pages by Andreas Hankel, CTO onehundred, for IT decision-makers, CTOs and cloud leads.
Andreas Hankel
CTO onehundred · Former CTO idealo · CIO of the Year 2014
„Sovereignty is usually negotiated as a question of location: where do the servers sit? In practice it is decided by who can gain access, who operates the platform, and whether you can change your own architecture without a third party’s consent. Since NIS2, you have to be able to prove exactly that, not just claim it.“
- Former CTO idealo: Nearly nine years, 2016 to 2025.
- CIO of the Year 2014: Mid-market category, awarded by IDG, CIO-Magazin and Computerwoche. As VP Technology at ImmobilienScout24 he brought server operations back in-house, built a private cloud and switched the virtualisation platform while in live operation.
- Over 30 years in IT: Since 1990, including 18 years at Fiducia IT, then ImmobilienScout24 and idealo.
„What has been created is exemplary and shows the way for designing the systems of the future.“
Manfred Broy, jury CIO of the Year 2014






Request the whitepaper
You will receive the PDF by email at your business address.
The situation
Around 29,500 instead of 4,500 companies: why sovereignty is now a duty of evidence.
The NIS2 Implementation Act has been in force since 6 December 2025, with no transition period. What is required are not declarations of intent, but documented technical measures. The figures behind that are documented, not asserted.
29,500
Companies in Germany now fall under BSI supervision, up from around 4,500. The registration deadline expired on 6 March 2026, the extension on 31 July 2026.
Quelle: BSI, IDW, BDO
Up to €10m
Fine, or 2 % of global annual turnover. Organisations that have not implemented the measures have been in a sanctionable state since 31 July 2026.
Quelle: BSI
USD 23.1bn
Forecast European sovereign cloud investment (IaaS) in 2027, up from USD 6.7bn in 2025, a tripling in two years according to Gartner. The market is moving, not just the regulation.
Quelle: Gartner
What's inside
Is your sovereignty evidence, or just an intention?
The whitepaper covers three propositions: why data residency and data sovereignty are two different questions, how NIS2 moves sovereignty from intent to evidence, and why sovereignty is decided in operations rather than in the project. Each proposition comes with three questions to place your own position within minutes.
01
Data residency and data sovereignty are two different questions
The US CLOUD Act allows US authorities, under certain conditions, to access data held by US companies, regardless of whether the server sits in Frankfurt, Dublin or Virginia. "Data residency" answers the question of storage location, "data sovereignty" the question of legal jurisdiction. Treating them as the same thing leaves a gap that cannot be closed at short notice once a legal review begins.
02
NIS2 moves sovereignty from intent to evidence
The decisive difference from earlier frameworks is that what is required are not declarations of intent but documented technical measures, from access control through to tested recovery. Organisations that have treated sovereignty as an architectural preference now have to be able to prove it.
03
Sovereignty is decided in operations, not in the project
Building a sovereign architecture is a bounded project. Keeping it sovereign is a permanent task: patches, access rights, supplier changes, new workloads. Where build and run sit with different parties, responsibility shifts at every handover, and with it the question of who has access when it matters.
Further chapters
- Technical detail: sovereignty across all three layers
- Benefits and economics
- What happens if you do nothing
- What onehundred takes on here
- Frequently asked questions
- Conclusion: where do you stand?
- Sources
What onehundred takes on
Consulting, transition, operation.
onehundred covers the full lifecycle of digital sovereignty: infrastructure, platform and software on open standards. One partner instead of a patchwork of consultancy, systems integrator and operator.
Consulting
Position assessment, stack evaluation across all three layers, sovereignty roadmap
Transition
Step-by-step migration into an open, sovereign architecture
Operation
Sovereign operations on an ongoing basis (24/7), including evidence documentation
Clearly out of scope: the legal assessment of whether NIS2 applies to you, ISMS design, governance and reporting processes. That is legal and management consulting. onehundred is accountable for technical delivery and works with specialist partners on the regulatory side, we tell you where that line sits in the first conversation.
Questions
Frequently asked questions.
We missed the registration deadline on 6 March 2026, is it too late?
Does onehundred also handle the legal NIS2 assessment?
Do we have to convert our entire infrastructure at once?
Does digital sovereignty mean we have to leave the cloud?
Conclusion
Where do you stand?
Sovereignty cannot be bought, only built and maintained. The three propositions describe the same movement: from a question of location to a question of law, from intent to evidence, from project to operations. The nine questions in the whitepaper show you, within a few minutes, which of the three carries the greatest urgency for you.
- From a question of location to a question of law
- From intent to evidence
- From project to operations
Why now
Since 31 July 2026 there is no transition phase left. Every week without documented measures is a week in a sanctionable state.
