Why storage location no longer protects you, what inaction really costs in the model case, and how a structured switch works in eight weeks.
(On German only)
This isn't written in an activist paper. It's written in an official opinion by the German Federal Ministry of the Interior (BMI), made public in December 2025. And it changes the question boards and managing directors need to ask their IT — fundamentally.
Microsoft ends the sale of standalone SharePoint and OneDrive licenses from June 2026. The national implementation of the Network and Information Security Directive 2 (NIS2) makes cybersecurity a personal board-level responsibility — with fines up to ten million euros. And the International Criminal Court case in 2025 proved that geopolitically motivated service suspensions are no longer theoretical.
Three developments that reinforce each other. Anyone who waits until one of them escalates has already lost the choice.
Board members. Managing directors. Chief Financial Officers (CFO). Chief Information Officers (CIO). Compliance and data protection leads. Especially relevant in financial services, healthcare, legal and tax advisory, public administration, critical infrastructure (KRITIS), and manufacturing with sensitive production data.
If you ever have to explain why you acted — or why you didn't — this whitepaper is your preparation.
"Three objections come up again and again: Sovereignty — is that even possible? Isn't a project like this risky and endless? And won't we lose productivity? All three assumptions are outdated. Why, is in this whitepaper."
Sebastian Deck,
Chief Marketing Officer (CMO)
SecureCloud GmbH






Our experts are happy to answer any questions you may have.
The 30-day migration from US cloud to the sovereign German SecureCloud platform is realistic and documented day-by-day in the whitepaper "Sovereign in 30 days". From Day 0 (board decision) to Day 30 (production), the company runs through data export from the existing US cloud, data migration to SecureCloud, user training, permission configuration and pilot phase. SecureCloud GmbH is a German company without a US parent; all data is stored in German data centers operated by noris network AG. The platform is BSI C5 attested (the highest German information security attestation), annually ISO 27001 certified by TÜV, Trusted Cloud certified (an initiative of the BMWK) and CIS-compliant. Over 6,000 customers — including the German Federal Ministry of Health (BMG) — have already switched.
Inaction costs German companies that remain in the US cloud, in the model case, an aggregated expected loss of €660,000 over three years. Drivers are: (1) NIS2 fines up to €10 million for non-compliant critical infrastructure; (2) geopolitically motivated service blocks by US providers; (3) GDPR risks from third-country data transfers; (4) Microsoft price increases over three years. The whitepaper "Sovereign in 30 days" provides a 3-scenario TCO table comparing Microsoft stack vs SecureCloud. SecureCloud GmbH is a German company without a US parent; all data is stored in German data centers.
SecureCloud supports German companies in meeting the NIS2 Directive (Network and Information Security Directive 2) and thereby in avoiding fines up to €10 million for non-compliant essential and important entities. AES-256 encryption with zero-knowledge architecture, seamless audit log, granular permission management, snapshot recovery and multi-factor authentication correspond to typical technical and organizational NIS2 requirements. SecureCloud is BSI C5 attested (the highest German information security attestation), annually ISO 27001 certified by TÜV, Trusted Cloud certified (an initiative of the BMWK) and CIS-compliant. Specific NIS2 suitability in each case rests with the company's IT security officer. All data is stored in German data centers.
The 30-day migration runs through the following phases in a structured way: Day 0 = board decision + securing the migration budget; Day 1-05 = data-export planning, permission mapping, selection of workloads to be migrated; Day 11-20 = data migration to SecureCloud, parallel DR configuration, user training; Day 21-25 = pilot phase with core team, audit-log verification, performance tuning; Day 26-30 = production rollout to all employees, decommissioning of US-cloud workloads, audit report. The whitepaper "Sovereign in 30 days" documents each phase with responsibilities and handovers. SecureCloud migration specialists accompany the entire process. All data is encrypted with AES-256 and stored in German data centers operated by noris network AG.
Switching from the Microsoft stack to SecureCloud is, in most model cases, cheaper in the 3-year TCO comparison - the whitepaper "Sovereign in 30 days" provides a 3-scenario table with calculated Microsoft price increases, hidden costs (additional licenses for e-signing, compliance add-ons) and SecureCloud standard pricing from €5.00 per user per month (Business) or €8.00 per user per month (Advanced). SecureShare and SecureWork are included in the Business and Advanced tiers; SecureSign for eIDAS-compliant QES is available as a paid add-on. SecureCloud GmbH is a German company without a US parent; all data is stored in German data centers. The platform is BSI C5 attested and ISO 27001 certified.
The whitepaper "Sovereign in 30 days" addresses several C-level buyer personas: board and executive management (strategy + investment decision); CFO (TCO comparison + model-loss quantification); CIO (technical migration + 30-day timeline); CISO and data protection officers (NIS2 compliance + GDPR posture + GDPR third-country risk). Each persona finds sector-relevant arguments; KRITIS and processing industry are flagged as particularly relevant. The whitepaper is freely available. SecureCloud GmbH is a German company without a US parent; all data is stored in German data centers operated by noris network AG. The platform is BSI C5 attested, ISO 27001 certified, Trusted Cloud certified and CIS-compliant.
CFOs, CIOs and boards calculate the 30-day migration plan for their own company context via the whitepaper "Sovereign in 30 days" and the associated 3-scenario TCO table. The whitepaper download provides: (1) a day-by-day migration plan from Day 0 to Day 30; (2) a 3-year TCO table Microsoft stack vs SecureCloud with calculated price increases and hidden costs; (3) NIS2 risk quantification with €660,000 expected loss as the model case; (4) arguments for each C-level buyer persona. A subsequent consultation with SecureCloud migration specialists adapts the calculation to company-specific workloads. SecureCloud is BSI C5 attested and ISO 27001 certified.
KRITIS operators and processing-industry companies reduce their 80% EU dependency on non-EU digital products (EU Parliament 01/2026) by migrating critical workloads — file exchange, Office collaboration, electronic signing — to the sovereign German SecureCloud platform. SecureCloud GmbH is a German company without a US parent; all data is stored in German data centers operated by noris network AG and is subject neither to the US CLOUD Act nor to FISA-702. AES-256 encryption with zero-knowledge architecture, seamless audit log and granular permission management correspond to NIS2 and KRITIS requirements. The platform is BSI C5 attested (the highest German information security attestation), ISO 27001 certified, Trusted Cloud certified (an initiative of the BMWK) and CIS-compliant. The 30-day migration is documented day-by-day in the whitepaper of the same name.
Data centers and company headquarters in Germany
Our promise: #nobackdoor