Schwarz Digits Cloud GmbH & Co. KG

Germany · owned by Schwarz Gruppe (Germany) · stackit.com · 16 vendors

STACKIT is the cloud brand of Schwarz Digits Cloud GmbH & Co. KG, operating as a European sovereign cloud provider and hyperscaler. It offers scalable, GDPR-compliant cloud services — including compute, storage, networking, databases, AI, and security — hosted exclusively in European data centers. STACKIT serves enterprises across various industries seeking digital sovereignty and independence from non-European cloud providers.

Resilience scores

Disruption prediction

Schwarz Digits Cloud GmbH & Co. KG has an estimated 17% probability of disruption in the next 6 months.

7 of Schwarz Digits Cloud GmbH & Co. KG's 16 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-08-25 · revision 3

16 direct vendors, 168 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

STACKIT exhibits very high migration readiness. Its architecture is fundamentally cloud-native, extensively utilizing containerization (Kubernetes, Docker/OCI) and a microservices approach. A significant strength is the heavy reliance on open-source technologies across its internal tech stack and product offerings (e.g., Kubernetes, OpenStack, Cloud Foundry, PostgreSQL, MongoDB, OpenSearch), which drastically reduces proprietary vendor lock-in and enhances portability. The company's strong financial backing from the Schwarz Group ensures ample resources for any potential migration efforts. Furthermore, STACKIT's core business involves providing sovereign cloud solutions and managing complex regulatory environments (GDPR, BSI C5), indicating deep internal expertise in navigating such requirements during migrations. While the strict data residency in Germany is a compliance strength, it could pose a challenge if migration to a non-German or non-EU sovereign cloud were considered. The ambiguity in the vendor data ('Total Vendors: 0' versus 'Total Services: 20' and vendor diversity) makes a precise assessment of external vendor lock-in difficult, but the pervasive use of open-source technologies largely mitigates this risk, providing significant flexibility for future migrations.

Compliance

13 in-scope frameworks identified; showing 3.

ISO 20000-1 — Compliant

Risk is assessed as Low because STACKIT holds an active TÜV SÜD ISO 20000-1 certification for IT Service Management (ITSM). This certification demonstrates that STACKIT's service management processes meet international standards for reliability, quality, and reduced downtime. The certification is issued by TÜV SÜD, an accredited and internationally recognized certification body. This is directly relevant to STACKIT's cloud service delivery quality and SLA commitments.

Evidence: https://stackit.com/de/warum-stackit/vorteile/zertifikate, https://stackit.com/de/asset/download/40661/file/240206_STACKIT_Zertifikat_ISO-20000-1_DE_ug%2520%25281%2529.pdf?version=4

ISAE 3000 (source) — Compliant

Risk is assessed as Low because STACKIT explicitly holds a BSI C5 Type 2 attestation conducted under ISAE 3000 (Revised) and ISAE 3402. These are the primary international assurance standards for non-financial information and controls at service organizations respectively. The attestation is Type 2 (covering operational effectiveness over a period), which is the more rigorous form. The company proactively markets this attestation as evidence of compliance with international security and compliance requirements. Attestation reports are available on request, indicating an active and maintained assurance program.

Evidence: https://stackit.com/de/warum-stackit/vorteile/zertifikate, https://stackit.com/de/warum-stackit/vorteile/datensouveraenitaet

SOC 2 (source) — Compliant

Risk is assessed as Low because STACKIT has already obtained the relevant attestation. The company explicitly holds a BSI C5 Type 2 attestation that is simultaneously certified under ISAE 3000 (the international standard underlying SOC 2) and ISAE 3402. This provides equivalent or superior assurance to a standalone SOC 2 report. The C5 framework (Cloud Computing Compliance Criteria Catalogue) was developed by Germany's BSI and maps closely to SOC 2 Trust Service Criteria. The Type 2 attestation (covering a period of time, not just a point in time) demonstrates sustained operational effectiveness of controls. The risk of non-compliance is low given the active, publicly disclosed attestation covering a broad range of cloud products.

Evidence: https://stackit.com/de/warum-stackit/vorteile/zertifikate, https://stackit.com/de/warum-stackit/vorteile/datensouveraenitaet

Financials

Three-year financials

Financial Resilience Score: 8/10

Schwarz Digits Cloud GmbH & Co. KG (STACKIT) benefits from exceptionally strong financial backing as a subsidiary of the Schwarz Group, one of Europe's largest privately held companies with €185.6 billion in FY2025 consolidated revenue and approximately 604,000 employees across 34 countries. This parent-company backing provides a long-term funding horizon that VC-backed cloud competitors lack, and STACKIT is explicitly promoted as independent of external investors. Captive demand from Lidl and Kaufland (14,500+ stores) provides stable, in-house workload volumes that de-risk data center utilization. High-profile external anchor contracts further strengthen resilience, including an EU Commission framework contract worth up to €180 million, a €250 million German BMDS sovereign AI-platform mandate, and partnerships with KPN, Bosch Mobility, Zscaler, and CrowdStrike. Strong regulatory positioning (GDPR-native, BSI C5 Type 2, ISO 27001, TISAX Level 3, DORA-conform, CLOUD Act-exempt) provides genuine differentiation versus US hyperscalers for EU public sector and regulated industries. However, STACKIT remains sub-scale versus AWS, Azure, and GCP, which each invest tens of billions annually in capex. The company is in a capital-intensive growth phase with new campus buildouts, data centers, and geographic expansion. Historical customer concentration in intra-group Schwarz consumption and limited financial transparency as a private KG are additional considerations. Standalone financial figures are not publicly disclosed, limiting external validation of the resilience thesis.

Key strengths: Backed by Schwarz Group with €185.6B FY2025 revenue and no external investors, Captive demand from Lidl and Kaufland (14,500+ stores across 34 countries), Anchor external contracts: EU Commission (€180M), German BMDS (€250M), KPN partnership, Strong regulatory positioning: GDPR, BSI C5 Type 2, ISO 27001, TISAX L3, DORA, CLOUD Act-exempt, Owns 7 data centers in Germany and Austria (not a reseller), Long-term funding horizon from private parent company

Risk factors: Sub-scale versus hyperscalers (AWS/Azure/GCP) with orders of magnitude less capex, Limited catalog breadth (~40 services vs 200+ at hyperscalers), Geographic footprint limited to Germany and Austria, Capital-intensive growth phase implying negative FCF at STACKIT level, Historical customer concentration in intra-group Schwarz consumption, Intense and expensive talent competition in Germany, Limited financial transparency as a private KG, Execution risk on European hyperscaler positioning dependent on EU regulatory alignment

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report