NorthC Deutschland GmbH
Germany · www.northcdatacenters.de · 25 vendors
Resilience scores
- Digital Sovereignty: 28
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Hewlett Packard Enterprise — Technology — United States
- Host Europe GmbH — Germany
- and 22 more
Services catalogue
2 services in catalogue across 1 category; runs on 25 sub-vendors.
- NorthC Hosting
- Web Hosting / Data Center Services
Insights
Last updated 2026-08-19 · revision 2
25 direct vendors, 218 subvendors
Direct vendors by controlling owner country (sample)
- United States: 14
- Netherlands: 1
- Germany: 4
Subvendors by controlling owner country (sample)
- Switzerland: 1
- United States: 153
- Australia: 3
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
NorthC Deutschland GmbH exhibits a medium level of migration readiness, primarily supported by its customer-facing cloud offerings and strong data sovereignty stance, but hindered by significant regulatory uncertainties and a lack of transparency regarding internal migration capabilities. The company actively facilitates customer migrations by offering 'Cloud Connect' services to major public cloud platforms (Microsoft Azure, AWS, Google Cloud, IBM Cloud) via partners, demonstrating experience with hybrid and multi-cloud architectures. NorthC also provides its own Public and Private Cloud solutions with flexible virtual infrastructure and a self-service portal, indicating internal capabilities in cloud service delivery. A key strength is NorthC's explicit focus on 'Datensouveränität' and European data residency, which simplifies compliance for customers with strict data localization requirements (e.g., healthcare, government, financial services in Germany) when migrating within the EU/DACH region. Existing certifications like ISO 27001 and ISO 20000-1 suggest structured IT service management processes that would aid in managing complex migrations. Vendor geographic diversity across 7 countries could also offer flexibility in sourcing migration-related services. However, the regulatory environment presents significant challenges and uncertainties for migration readiness. The 'Assessment Required' status for the EU Data Act (Medium risk) is particularly relevant, as this regulation introduces obligations around switching rights, interoperability, and data portability that directly impact the ease and cost of migrating data and services between providers. Similarly, DORA (Medium risk) will impose mandatory contractual provisions for financial sector customers, including requirements for exit strategies and audit rights, which could complicate migrations for these critical clients. The high-risk 'Assessment Required' status for NIS2 and KRITIS could also introduce complex regulatory hurdles for customers migrating critical systems to or from NorthC's infrastructure. While NorthC's internal tech stack includes a proprietary customer portal and DCIM, the use of WordPress for its public website suggests that its own internal systems may not be fully cloud-native or microservices-oriented, potentially indicating internal migration challenges. The 'Vendor Lock-in Risk: Unknown' and the missing financial data (revenue concentration, growth history) also limit the ability to fully assess the company's capacity to fund or support large-scale internal or customer migrations.
Compliance
15 in-scope frameworks identified; showing 3.
BDSG — Partially Compliant
The BDSG supplements GDPR with German-specific requirements and is mandatory for all companies operating in Germany. NorthC Deutschland GmbH's privacy policy explicitly references §26 BDSG (employee data processing) and §25 TDDDG (cookie/tracking consent), demonstrating awareness of German-specific data protection law. Risk is Medium because: (1) BDSG compliance cannot be fully verified externally without access to internal policies and procedures; (2) the BDSG includes specific requirements for employee data (§26), works council involvement in data processing decisions, and enhanced rights for data subjects that go beyond GDPR; (3) Germany has one of the most active data protection enforcement environments in the EU, with multiple state-level DPAs (NorthC falls under BayLDA for its Nürnberg HQ). The company's DPO appointment and GDPR compliance infrastructure provide a strong foundation.
Evidence: https://www.northcdatacenters.com/de/datenschutzerklaerung/, https://www.gesetze-im-internet.de/bdsg_2018/, https://www.lda.bayern.de/
ISO 9001 — Compliant
ISO 9001 certification is confirmed for NorthC's München and Nürnberg locations. This is a voluntary standard but demonstrates commitment to quality management and continuous improvement. Risk is Low as this is a market-differentiating certification rather than a regulatory requirement, and active certification is confirmed.
Evidence: https://www.northcdatacenters.com/de/ueber-uns/zertifizierungen/
DIN EN 50600 — Compliant
DIN EN 50600 CAT. III certification by TÜV Rheinland is confirmed for München and Nürnberg locations. This is the European standard for data center infrastructure reliability and is the German/European equivalent of the Uptime Institute Tier classification. CAT. III (equivalent to Tier III) ensures concurrent maintainability and N+1 redundancy. Risk is Low as TÜV Rheinland certification is a rigorous third-party assessment.
Evidence: https://www.northcdatacenters.com/de/ueber-uns/zertifizierungen/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
NorthC Deutschland GmbH benefits from strong structural tailwinds in the European data center sector, driven by cloud adoption, AI workloads, and data sovereignty regulations (GDPR, NIS2, KRITIS). The company is backed by DWS Infrastructure (Deutsche Bank asset-management arm), providing deep institutional capital support for capex-heavy expansion and refinancing capacity. Its diversified footprint across 11 German data centers in major metros (Frankfurt, Berlin, Munich, Hamburg, Düsseldorf, Nuremberg) reduces single-site concentration risk, and its focus on regulated end-customers in healthcare, government, and KRITIS-relevant sectors creates sticky, long-duration contracts. However, the business faces significant risks typical of PE-owned data-center platforms: high capital intensity requiring large upfront capex (particularly in Frankfurt), elevated German power prices and grid connection constraints, and regulatory compliance burdens from the German Energy Efficiency Act (EnEfG) mandating strict PUE and waste-heat requirements from 2024/2027. Rapid M&A-driven growth (maincubes acquisition in 2023) introduces integration and goodwill risk, while interest-rate sensitivity on variable-rate infrastructure financing remains a concern. As a private GmbH, verified statutory financials were not retrievable in this session, limiting quantitative resilience assessment.
Key strengths: PE sponsor backing from DWS Infrastructure providing deep capital support, Strong sector tailwinds from cloud, AI, and data sovereignty regulation, Diversified 11-site German footprint across all major metros, Sticky long-duration contracts with regulated end-customers (healthcare, government, KRITIS), Strategic connectivity/interconnection position (DE-CIX)
Risk factors: High capital intensity of data center construction and expansion, Elevated German power prices and grid connection constraints, Regulatory compliance capex risk under EnEfG (PUE and waste-heat requirements), Competitive pressure from hyperscale operators (Equinix, Digital Realty, NTT, Vantage, STACK), M&A integration and goodwill risk from rapid roll-up strategy, Interest-rate sensitivity on PE-typical leveraged financing structure
Revenue by product/service
- Colocation: 78%
- Connectivity and Cloud Connect: 12%
- Managed Services and Cloud Solutions: 10%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.