:quality(50))
What Has Changed with the New Act
Sovereignty is now an explicitly recognized award criterion. Section 58(2) VgV lists the qualitative characteristics used to determine the most economically advantageous tender: quality, personnel, and customer service. Since July, the provision has included a fourth category: “aspects of digital sovereignty.” The explanatory memorandum is unusually explicit, and such aspects, including the use of interoperable and open IT systems, can constitute “relevant and decisive quality characteristics.”
The key word is “decisive.” An award criterion is weighted, and that weighting must be disclosed. This puts sovereignty on an equal footing with price.
Sovereignty can be contractually safeguarded. Germany’s Act against Restraints of Competition (GWB) now expressly allows contracting authorities to make digital sovereignty considerations specific conditions for contract performance. Sovereignty therefore determines not only whether a contract is awarded, but also how the services are delivered, with contractual penalties and termination rights enforcing compliance. What a provider promises in its bid remains enforceable throughout the contract term.
In exceptional cases, procurement law may not apply at all. If a service involves aspects of cybersecurity or digital sovereignty and also requires a particularly high degree of confidentiality, data availability, or integrity, essential security interests may be affected, and public procurement provisions under competition law may not apply. This is not automatic; the explanatory memorandum requires assessing and justifying the conditions on a case-by-case basis. The underlying logic is nevertheless noteworthy, with lawmakers placing digital sovereignty on the same level as key security-industry technologies and encryption.
The Real Work: Making Sovereignty Measurable
The legal question of whether sovereignty can be considered has now been resolved. The practical question of how remains. In its newsletter on the reform, public procurement law firm Redeker Sellner Dahs identifies exactly the two challenges procurement authorities now face: defining sovereignty aspects in a way that complies with procurement law, and then actually measuring and evaluating them.
Robust frameworks for both are now available.
The European Commission’s Cloud Sovereignty Framework defines eight sovereignty objectives, ranging from strategic and legal sovereignty to data and AI sovereignty, supply chain transparency, and technological openness. Each objective is assessed on a scale from 0 to 4 and consolidated into a weighted Sovereignty Score. The framework operates on two levels: Assurance Levels establish minimum requirements, while the score serves as an award criterion. In the future, it could also provide contracting authorities in EU member states with a standardized toolkit for developing specifications and evaluation matrices.
The BSI’s C3A criteria translate this approach into German procurement practice. They are based on the EU framework, translate its factors into verifiable criteria, and require providers to meet the C5 criteria. The catalog follows a risk-based approach and offers different options, including localization requirements such as data center location and the origin of operations personnel. Depending on the criticality of the use case, contracting authorities can decide whether to require localization in Germany or within the EU. Providers can demonstrate compliance through audits. Guidance on the audit process has been announced and is expected to follow the established C5 attestation process.
How to Identify a Truly Sovereign Provider
In practice, four questions separate marketing claims from demonstrable sovereignty:
Does the same software run in every operating environment? The data center's location does not determine sovereignty; the ability to switch does. Only if a solution can run on-premises, in a private cloud, and with established hyperscalers using the same codebase and offering the same functionality does switching remain a realistic option rather than a theoretical one.
Who can access the data, and under which jurisdiction? Public debate often focuses on where data is stored. What matters is who can access it, and under what conditions. Access means control.
Is there evidence rather than self-declaration? Certifications such as ISO 27001, C5 attestations, or, in the future, C3A compliance are verifiable. Claims about a “sovereign cloud” are not.
Are dependencies transparent? Vendor lock-in usually becomes visible only when you try to leave, when licensing models change, prices rise, and negotiations go nowhere. That is why procurement processes should require transparency about subcontractors, third-party components, and exit paths from the outset.
Beta Systems: What This Means in Practice
For more than four decades, Beta Systems has developed software for business-critical IT automation and hybrid infrastructure orchestration as an independent software provider headquartered in Berlin, with development operations in Germany and Europe. For public authorities, data centers, and municipal IT service providers, this means:
You decide the operating model, not us. Our solutions run on-premises, in a private cloud, or with hyperscalers, with a consistent codebase and the same functionality. Your infrastructure decision remains reversible. That's the difference between an offering that meets sovereignty criteria and one that merely addresses them.
Verifiable evidence rather than assurances. With ISO 27001 and ISO 9001 certifications, Beta Systems can provide the evidence procurement authorities will increasingly require: no backdoors, no kill switches, clearly defined access models, and high auditability.
Making heterogeneous environments manageable. ANOW!® Automate orchestrates processes across mainframe, on-premises, and cloud environments—without locking you into a single platform. In complex, long-established public-sector IT environments, this is essential to ensuring individual components can be replaced without risking operations.
Keeping data processing transparent and traceable. The explanatory memorandum explicitly identifies the traceability and control of data-processing operations as an aspect of sovereignty. This is where end-to-end automation comes into play: organizations that can centrally control, log, and analyze every processing step can provide information to regulators and audit authorities and identify dependencies before they become a problem.
For us, digital sovereignty is a product reality, and our “Made in Europe” software has no hidden dependencies, so you remain in control.
Conclusion
The reform ends a situation in which the lowest price had a structural advantage over independence. Digital sovereignty is no longer a legal risk to weigh, but a quality criterion you can use with legal certainty.
What matters now is implementation. A criterion that isn't weighted effectively doesn't exist in the procurement process.
Note: This article is intended for general informational purposes and reflects the state of affairs at the time of publication. It does not constitute legal advice and is not a substitute for an assessment of the individual case. We make no warranty as to the accuracy, completeness, or timeliness of the information.
Are you looking for a digital sovereignty vendor for your next project?
Talk to us about the technical side, including the evidence, certifications, and architectural characteristics our solutions provide, and how they can fit your requirements.
:quality(50))
:quality(50))
:quality(50))