ONEHUNDRED

Free whitepaper

Digital sovereignty: what NIS2 changes about it.

Why a server in Frankfurt is not sovereignty on its own, and what the NIS2 Implementation Act now requires you to prove. Seven pages by Andreas Hankel, CTO onehundred, for IT decision-makers, CTOs and cloud leads.

Andreas Hankel, CTO onehundred

Andreas Hankel

CTO onehundred · Former CTO idealo · CIO of the Year 2014

„Sovereignty is usually negotiated as a question of location: where do the servers sit? In practice it is decided by who can gain access, who operates the platform, and whether you can change your own architecture without a third party’s consent. Since NIS2, you have to be able to prove exactly that, not just claim it.“

Andreas Hankel, Autor des Whitepapers
  • Former CTO idealo: Nearly nine years, 2016 to 2025.
  • CIO of the Year 2014: Mid-market category, awarded by IDG, CIO-Magazin and Computerwoche. As VP Technology at ImmobilienScout24 he brought server operations back in-house, built a private cloud and switched the virtualisation platform while in live operation.
  • Over 30 years in IT: Since 1990, including 18 years at Fiducia IT, then ImmobilienScout24 and idealo.

„What has been created is exemplary and shows the way for designing the systems of the future.“

Manfred Broy, jury CIO of the Year 2014

Request the whitepaper

You will receive the PDF by email at your business address.

Why now

In your inbox within minutes. With the nine questions you will know today whether your sovereignty is evidence or just an intention.

The situation

Around 29,500 instead of 4,500 companies: why sovereignty is now a duty of evidence.

The NIS2 Implementation Act has been in force since 6 December 2025, with no transition period. What is required are not declarations of intent, but documented technical measures. The figures behind that are documented, not asserted.

29,500

Companies in Germany now fall under BSI supervision, up from around 4,500. The registration deadline expired on 6 March 2026, the extension on 31 July 2026.

Quelle: BSI, IDW, BDO

Up to €10m

Fine, or 2 % of global annual turnover. Organisations that have not implemented the measures have been in a sanctionable state since 31 July 2026.

Quelle: BSI

USD 23.1bn

Forecast European sovereign cloud investment (IaaS) in 2027, up from USD 6.7bn in 2025, a tripling in two years according to Gartner. The market is moving, not just the regulation.

Quelle: Gartner

What's inside

Is your sovereignty evidence, or just an intention?

The whitepaper covers three propositions: why data residency and data sovereignty are two different questions, how NIS2 moves sovereignty from intent to evidence, and why sovereignty is decided in operations rather than in the project. Each proposition comes with three questions to place your own position within minutes.

01

Data residency and data sovereignty are two different questions

The US CLOUD Act allows US authorities, under certain conditions, to access data held by US companies, regardless of whether the server sits in Frankfurt, Dublin or Virginia. "Data residency" answers the question of storage location, "data sovereignty" the question of legal jurisdiction. Treating them as the same thing leaves a gap that cannot be closed at short notice once a legal review begins.

02

NIS2 moves sovereignty from intent to evidence

The decisive difference from earlier frameworks is that what is required are not declarations of intent but documented technical measures, from access control through to tested recovery. Organisations that have treated sovereignty as an architectural preference now have to be able to prove it.

03

Sovereignty is decided in operations, not in the project

Building a sovereign architecture is a bounded project. Keeping it sovereign is a permanent task: patches, access rights, supplier changes, new workloads. Where build and run sit with different parties, responsibility shifts at every handover, and with it the question of who has access when it matters.

Further chapters

  • Technical detail: sovereignty across all three layers
  • Benefits and economics
  • What happens if you do nothing
  • What onehundred takes on here
  • Frequently asked questions
  • Conclusion: where do you stand?
  • Sources

What onehundred takes on

Consulting, transition, operation.

onehundred covers the full lifecycle of digital sovereignty: infrastructure, platform and software on open standards. One partner instead of a patchwork of consultancy, systems integrator and operator.

Consulting

Position assessment, stack evaluation across all three layers, sovereignty roadmap

Transition

Step-by-step migration into an open, sovereign architecture

Operation

Sovereign operations on an ongoing basis (24/7), including evidence documentation

Clearly out of scope: the legal assessment of whether NIS2 applies to you, ISMS design, governance and reporting processes. That is legal and management consulting. onehundred is accountable for technical delivery and works with specialist partners on the regulatory side, we tell you where that line sits in the first conversation.

Questions

Frequently asked questions.

We missed the registration deadline on 6 March 2026, is it too late?
Too late for registration within the deadline, not too late to act. Both the original date (6 March 2026) and the BSI extension (31 July 2026) have passed. The obligation itself is unaffected: registration should be completed without delay, and the implementation status of the technical measures documented in parallel, so that you can demonstrate you are able to act if inspected.
Does onehundred also handle the legal NIS2 assessment?
No. We are fully accountable for the technical sovereignty basis. For the legal classification, whether you are in scope, which reporting duties apply, we work with specialist partners, because these are distinct disciplines that we do not artificially merge.
Do we have to convert our entire infrastructure at once?
No. Transition is deliberately incremental and follows business criticality: less critical systems migrate first, critical core systems follow with greater care and test coverage.
Does digital sovereignty mean we have to leave the cloud?
Not necessarily. It means your architecture does not tie you to a single provider, which can include public cloud, private cloud, edge or on-premise in any sensible combination.

Conclusion

Where do you stand?

Sovereignty cannot be bought, only built and maintained. The three propositions describe the same movement: from a question of location to a question of law, from intent to evidence, from project to operations. The nine questions in the whitepaper show you, within a few minutes, which of the three carries the greatest urgency for you.

  1. From a question of location to a question of law
  2. From intent to evidence
  3. From project to operations
Get the whitepaper

Why now

Since 31 July 2026 there is no transition phase left. Every week without documented measures is a week in a sanctionable state.