Zum Inhalt springen
Unabhängig verifiziert · Quartalsweises Re-Audit
EU VETTED

STACKIT

VERIFIZIERT
Cloud & Hosting · Germany
Founded 2019 · stackit.com ↗

German sovereign cloud built by Schwarz Digits (Lidl/Kaufland parent), 4 EU DCs, EU Cloud III €180M winner with SEAL-3 highest rating.

Warum diese Bewertung?

STACKIT (Bad Friedrichshall, German Schwarz Digits — the IT arm of privately-held Schwarz Group, parent of Lidl and Kaufland) is built explicitly as a sovereign-cloud alternative to AWS/Azure/GCP — ISO 27001 + BSI C5 + EUCS-aligned + DORA-ready, four EU data centres (Neckarsulm DC01, Ellhofen DC08, Ostermiething Austria DC10, fifth Lübbenau under construction), winner of the European Commission's €180M Cloud III tender (April 2026, SEAL-3 highest sovereignty rating) and the Dutch Ministry of Justice & Security SLM Rijk framework; full 5/5 with no CLOUD Act exposure.

SCORE
5.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About STACKIT

STACKIT is the sovereign cloud built by Schwarz Digits — the IT and digital division of the privately-held Schwarz Group, parent of the European discount-retail giants Lidl and Kaufland. Headquartered in Bad Friedrichshall, Germany (Am Campus 1, 74177), STACKIT runs four European data centres at Neckarsulm (DC01, Schwarz Group HQ campus), Ellhofen (DC08, Heilbronn region), Ostermiething (DC10, Salzburg, Austria), and a fifth facility under construction in Lübbenau, Germany. The Schwarz Group has invested approximately €11B in STACKIT, making it one of the most heavily-capitalised European cloud-sovereignty bets and a structurally different proposition from VC-funded EU cloud upstarts: the parent retailer is a private German Stiftung-controlled group with €146B annual turnover, with no PE or US-VC exposure on the cap table at any layer. Sovereignty positioning is the entire product thesis. STACKIT markets itself as "100% European DNA" with the trio "Skalierbar. Sicher. Souverän" — scalable, secure, sovereign. The compliance footprint covers ISO 27001, BSI **C5**, **EUCS** (European Cybersecurity Certification Scheme for cloud services, ENISA), DORA-ready ICT-third-party status for regulated financial services, GDPR, and the Schwarz Group's own **ES³ (European Sovereign Stack Standard)** internal sovereignty measurement framework. The procurement validation came in two moves during 2026: (1) selection as one of four winners of the European Commission's €180M Cloud III sovereign-cloud framework (April 2026), with the highest **SEAL-3** rating signifying engineering against supply-chain disruptions originating outside the EU; and (2) selection by the Dutch Ministry of Justice and Security under the SLM Rijk framework as a sovereign cloud alternative. The product surface spans 11+ categories — infrastructure (compute, block/object storage, networking), managed databases, managed Kubernetes, AI workloads, and colocation. Pricing is via a configurable STACKIT Calculator; specific entry-tier figures were not captured at audit but the product is positioned mid-market to enterprise rather than indie/SMB. Best fit: EU public-sector procurement (post-Cloud III tender), DORA-regulated financial services, large EU corporates needing a non-VC-funded sovereign cloud, and any organisation aligning with Gaia-X or the EU Tech Sovereignty Package. Together with Hetzner, OVHcloud, and Scaleway, STACKIT forms the four-pillar EU hyperscaler-alternative stack on this directory.
SUB-PROCESSORS

Unterauftragsverarbeiter-Karte · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Rahmenwerke & Zertifizierungen

ISO/IEC 27001
ACTIVE
C5
ACTIVE
EUCS
ACTIVE
FEATURES

Funktionsmatrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Preise & Tarife

KOSTENPFLICHTIG
Individuelle Preise

Kontaktieren Sie den Anbieter für Staffel- oder Mengenpreise.

Preisseite ansehen ↗
PUBLIC DOCUMENTS

Öffentliche Dokumente

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    www.stackit.de/wp-content…
    Open ↗
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternativen in dieser Kategorie