Digital Sovereignty Is Now an Award Criterion - What This Means for Public Contracting Authorities

Blog Article·6 min
betasystems_portraits-leon-stamm.jpg
Leon Stamm
VP of Marketing, Beta Systems
Follow me for more content

Key Takeaways

  • Since July 1, 2026, Germany’s Public Procurement Ordinance (VgV) has explicitly listed “aspects of digital sovereignty” as an award criterion. This settles the long-debated question of whether such criteria are permissible.

  • Sovereignty requirements can also be incorporated into contracts as performance conditions and enforced through contractual penalties and termination rights.

  • The German Federal Office for Information Security’s (BSI) C3A criteria and the European Commission’s Cloud Sovereignty Framework provide, for the first time, a robust toolkit to define and measure digital sovereignty.

  • Procurement authorities can now require evidence rather than self-declarations and assess providers based on whether their architecture actually enables customers to switch.

For years, public procurement authorities faced the same dilemma when purchasing IT: technological independence, data sovereignty, and the ability to exit were clearly relevant from a technical perspective, but difficult to address under procurement law. Authorities that made them procurement criteria risked challenges based on discrimination or insufficient connection to the contract's subject matter. As a result, the system favored the lowest price.

With the Procurement Acceleration Act, which took effect on July 1, 2026, lawmakers have resolved this dilemma.

IT and dora security icon lock

What Has Changed with the New Act

Sovereignty is now an explicitly recognized award criterion. Section 58(2) VgV lists the qualitative characteristics used to determine the most economically advantageous tender: quality, personnel, and customer service. Since July, the provision has included a fourth category: “aspects of digital sovereignty.” The explanatory memorandum is unusually explicit, and such aspects, including the use of interoperable and open IT systems, can constitute “relevant and decisive quality characteristics.”

The key word is “decisive.” An award criterion is weighted, and that weighting must be disclosed. This puts sovereignty on an equal footing with price.

Sovereignty can be contractually safeguarded. Germany’s Act against Restraints of Competition (GWB) now expressly allows contracting authorities to make digital sovereignty considerations specific conditions for contract performance. Sovereignty therefore determines not only whether a contract is awarded, but also how the services are delivered, with contractual penalties and termination rights enforcing compliance. What a provider promises in its bid remains enforceable throughout the contract term.

In exceptional cases, procurement law may not apply at all. If a service involves aspects of cybersecurity or digital sovereignty and also requires a particularly high degree of confidentiality, data availability, or integrity, essential security interests may be affected, and public procurement provisions under competition law may not apply. This is not automatic; the explanatory memorandum requires assessing and justifying the conditions on a case-by-case basis. The underlying logic is nevertheless noteworthy, with lawmakers placing digital sovereignty on the same level as key security-industry technologies and encryption.

The Real Work: Making Sovereignty Measurable

The legal question of whether sovereignty can be considered has now been resolved. The practical question of how remains. In its newsletter on the reform, public procurement law firm Redeker Sellner Dahs identifies exactly the two challenges procurement authorities now face: defining sovereignty aspects in a way that complies with procurement law, and then actually measuring and evaluating them.

Robust frameworks for both are now available.

The European Commission’s Cloud Sovereignty Framework defines eight sovereignty objectives, ranging from strategic and legal sovereignty to data and AI sovereignty, supply chain transparency, and technological openness. Each objective is assessed on a scale from 0 to 4 and consolidated into a weighted Sovereignty Score. The framework operates on two levels: Assurance Levels establish minimum requirements, while the score serves as an award criterion. In the future, it could also provide contracting authorities in EU member states with a standardized toolkit for developing specifications and evaluation matrices.

The BSI’s C3A criteria translate this approach into German procurement practice. They are based on the EU framework, translate its factors into verifiable criteria, and require providers to meet the C5 criteria. The catalog follows a risk-based approach and offers different options, including localization requirements such as data center location and the origin of operations personnel. Depending on the criticality of the use case, contracting authorities can decide whether to require localization in Germany or within the EU. Providers can demonstrate compliance through audits. Guidance on the audit process has been announced and is expected to follow the established C5 attestation process.

How to Identify a Truly Sovereign Provider

In practice, four questions separate marketing claims from demonstrable sovereignty:

  1. Does the same software run in every operating environment? The data center's location does not determine sovereignty; the ability to switch does. Only if a solution can run on-premises, in a private cloud, and with established hyperscalers using the same codebase and offering the same functionality does switching remain a realistic option rather than a theoretical one.

  2. Who can access the data, and under which jurisdiction? Public debate often focuses on where data is stored. What matters is who can access it, and under what conditions. Access means control.

  3. Is there evidence rather than self-declaration? Certifications such as ISO 27001, C5 attestations, or, in the future, C3A compliance are verifiable. Claims about a “sovereign cloud” are not.

  4. Are dependencies transparent? Vendor lock-in usually becomes visible only when you try to leave, when licensing models change, prices rise, and negotiations go nowhere. That is why procurement processes should require transparency about subcontractors, third-party components, and exit paths from the outset.

Beta Systems: What This Means in Practice

For more than four decades, Beta Systems has developed software for business-critical IT automation and hybrid infrastructure orchestration as an independent software provider headquartered in Berlin, with development operations in Germany and Europe. For public authorities, data centers, and municipal IT service providers, this means:

You decide the operating model, not us. Our solutions run on-premises, in a private cloud, or with hyperscalers, with a consistent codebase and the same functionality. Your infrastructure decision remains reversible. That's the difference between an offering that meets sovereignty criteria and one that merely addresses them.

Verifiable evidence rather than assurances. With ISO 27001 and ISO 9001 certifications, Beta Systems can provide the evidence procurement authorities will increasingly require: no backdoors, no kill switches, clearly defined access models, and high auditability.

Making heterogeneous environments manageable. ANOW!® Automate orchestrates processes across mainframe, on-premises, and cloud environments—without locking you into a single platform. In complex, long-established public-sector IT environments, this is essential to ensuring individual components can be replaced without risking operations.

Keeping data processing transparent and traceable. The explanatory memorandum explicitly identifies the traceability and control of data-processing operations as an aspect of sovereignty. This is where end-to-end automation comes into play: organizations that can centrally control, log, and analyze every processing step can provide information to regulators and audit authorities and identify dependencies before they become a problem.

For us, digital sovereignty is a product reality, and our “Made in Europe” software has no hidden dependencies, so you remain in control.

Conclusion

  • The reform ends a situation in which the lowest price had a structural advantage over independence. Digital sovereignty is no longer a legal risk to weigh, but a quality criterion you can use with legal certainty.

  • What matters now is implementation. A criterion that isn't weighted effectively doesn't exist in the procurement process.

Are you looking for a digital sovereignty vendor for your next project?

Talk to us about the technical side, including the evidence, certifications, and architectural characteristics our solutions provide, and how they can fit your requirements.

Note: This article is intended for general informational purposes and reflects the state of affairs at the time of publication. It does not constitute legal advice and is not a substitute for an assessment of the individual case. We make no warranty as to the accuracy, completeness, or timeliness of the information.

Author

betasystems_portraits-leon-stamm.jpg
Leon Stamm
VP of Marketing, Beta Systems

Further Resources

Blog Article

Digital Sovereignty in German Public Administration: Why Independent IT is Crucial

Public administration in Germany is facing a crucial challenge: How can it regain its digital sovereignty and make itself less dependent on IT providers from outside Europe? In this article, we examine the risks of so-called lock-in effects, show strategies for strengthening digital independence and explain why Beta Systems is a reliable partner for the public sector striving for digital sovereignty.
Blog Article

7 Best Broadcom Automic Alternatives & Competitors for Enterprise IT in 2026

Are you evaluating a Broadcom alternative for enterprise workload automation? You’re likely already dealing with rising license costs, unpredictable renewal terms, or a scheduler that hasn't kept pace with your hybrid cloud strategy. You're not alone. Gartner’s 2026 Magic Quadrant for Service Orchestration and Automation Platforms (SOAP) notes that Broadcom customers have reported friction around contract renewal pricing and a lack of self-service migration tooling, both of which are common triggers for a vendor switch. This guide covers the 7 best Broadcom alternatives for enterprise IT in 2026 so you can shortlist with confidence before you start a formal evaluation.
Blog Article

Where Enterprise Automation Is Heading: Insights from the 2026 Gartner® Magic Quadrant™ for SOAP

The move from traditional workload automation to intelligent, end-to-end orchestration is accelerating. This change is one of the clearest signals we've seen from the 2026 Gartner® Magic Quadrant™ for Service Orchestration and Automation Platforms (SOAP), and it comes at an important moment for Beta Systems. For the second year in a row, Beta Systems has been positioned as a Leader in the Gartner Magic Quadrant for SOAP. But beyond vendor positioning, the 2026 report provides an important view into where enterprise automation is heading. The evolution is not simply from job scheduling to more sophisticated workload automation. SOAPs are increasingly becoming the operational layer connecting applications, infrastructure, data pipelines, cloud services, and now AI agents. Here are our key takeaways from the 2026 research.