You are on a procurement committee at a German Landesbehörde, evaluating sovereign-cloud options for a 2,400-user migration off Microsoft 365. Last Friday, Schwarz Digits announced the European Sovereign Stack Standard (ES³) at Hannover Messe: a maturity model in four levels, more than a hundred criteria, independently verified by BDO AG. Your CIO forwarded the announcement with one sentence: can we use this in the next tender as a hard award criterion?

The honest answer is not yet, and probably not in the form Schwarz Digits is offering it. The reason has nothing to do with whether the methodology is well-engineered — by the available public material, it is. The reason has to do with who wrote it and what they sell.

Schwarz Digits writes the European Sovereign Stack Standard. The same Schwarz Digits operates StackIT, a sovereign-cloud provider that competes for the procurement decisions ES³ is designed to influence. The standard’s writer is a market participant in the market the standard scores. That is not, by itself, disqualifying — ISO, IEEE and IETF standards routinely originate at vendors with skin in the game. It is, however, the structural fact that has to be acknowledged before the standard can be used as a procurement instrument rather than as a procurement signal.

This article is the audit of what ES³ actually verifies, what it leaves unverified, what its conflict of interest does and does not affect, and the question your committee has to answer before you cite ES³ in a tender.

What ES³ actually is

The launch on Friday, 17 April 2026, three days before Hannover Messe opened, had Rolf Schumann and Christian Müller, co-CEOs of Schwarz Digits, presenting the structure: four maturity levels — Basic, Initial, Advanced, Future-Proof — applied across more than a hundred criteria spanning jurisdiction, ownership, operational control, supply chain and key custody. BDO AG verified the methodology. Parwäz Rafiqpoor, Management Board Chairman of BDO Germany, signed the attestation.

The first level, Basic, covers minimum data-residency claims. Initial requires operational independence from non-EU control. Advanced requires full architectural separation from non-EU dependencies. Future-Proof claims verifiable continuity under hostile geopolitical conditions. The level definitions track the existing European discussion — they correspond roughly to what a sovereign-cloud buyer would intuitively expect. The criteria catalogue, by the public summary, is the standard’s contribution. The catalogue itself is not yet public in full.

BDO’s verification statement is specific in scope: it confirms the methodology, not individual product assessments. This is the right framing for an audit firm to use, and it is the framing that any procurement committee referencing ES³ has to understand. A verified methodology means BDO has examined how the four levels and hundred criteria are constructed and judged the construction defensible. It does not mean BDO has rated any specific cloud provider against the levels. The rating is a separate exercise — one that, on the structure announced, Schwarz Digits will perform on its own products and offer as a service for others.

The launch positions ES³ as Europe’s measure of digital sovereignty. The audit verifies the measure. The provider of the measure is also the provider of the offering being measured.

The conflict at the centre

Schwarz Digits is the IT and digital arm of the Schwarz Gruppe — the parent company that owns Lidl and Kaufland — and it operates StackIT, a sovereign-cloud provider competing directly with AWS Europe, Azure Sovereign Cloud and Google Cloud Sovereign for European public-sector tenders. Bernd Wagner, the Schwarz Digits CSO who introduced the technical detail at the Hannover Messe stand, runs a security architecture that is engineered against criteria the parent company has now also written. Schwarz Digits is not a neutral standards body. It is a market participant defining the rules of its own market.

This is structurally identical to two scenarios any European procurement officer would recognise as suspect. Microsoft writing the standard against which Microsoft Sovereign Cloud is evaluated. AWS publishing the criteria for European Sovereign Cloud certification. In both cases, the proper procurement response would be sceptical scrutiny of the criteria-selection, not adoption of the standard as award criterion. ES³ deserves the same scrutiny.

The two defences routinely offered for ES³ both fall short on a careful read.

The first defence: someone had to do this, and the market would not wait for a neutral body. This is genuinely true. European formal standards work — CEN-CENELEC, ETSI — moves on timescales of years to decades. A workable vendor-led standard now is plausibly more useful than a slow neutral one in 2032. The argument concedes the conflict and rests on urgency. Urgency is a reason to use ES³ as input, not as output. A standard adopted because the alternative was slower than the political timetable is still a standard with a conflict at its core, and the conflict shapes the criteria.

The second defence: BDO’s verification mitigates the conflict. Partially. Rafiqpoor’s attestation language is specific — it confirms the methodology, not the criteria selection. A vendor-written methodology that audits well is still a vendor-written methodology. The conflict of interest is in which criteria were chosen to be in the catalogue and which were chosen to be out, not in whether the chosen criteria are internally consistent. BDO can verify the second without addressing the first.

The cui-bono pass simplifies. Schwarz Digits and StackIT benefit if ES³ becomes the default sovereignty score-sheet, because their offering is engineered against criteria they wrote. BDO benefits from being the verification authority for what could become a widely cited European standard. The German-speaking sovereign-cloud ecosystem broadly benefits if German-flavoured criteria become the de facto European default. French sovereign-cloud vendors — Outscale, OVHcloud, Atos, Linagora — have not co-shaped the criteria; they lose marginally if ES³ is widely adopted in German public procurement.

What the four levels actually verify, and what they leave unverified

The catalogue covers jurisdiction, ownership, operational control, supply chain and key custody by the public summary. Three architectural layers are conspicuously absent from any reporting on the standard.

Update channels for the underlying open-source components. Most sovereign-cloud stacks depend on hundreds of upstream OSS dependencies whose primary distribution endpoints are on GitHub — Microsoft-owned. A sovereignty standard that does not address this layer leaves the same gap that the Euro-Office launch made visible elsewhere. The runtime can be European; the supply chain rarely is.

Cryptographic root trust. Which certificate authorities sit in the verification chain, which DNS root servers the resolver depends on, which signing infrastructure the platform’s package distribution uses — all are sovereignty-relevant and all are absent from the ES³ summary.

Continuity guarantees under sanctions designation of the audit firm itself. BDO is a globally-operating professional services firm with US business exposure. If BDO were sanctioned for verifying European sovereignty, the verification chain that ES³ depends on collapses. ES³’s own continuity assumption is that its audit infrastructure remains operational, which is the same assumption M365 customers were making in 2020.

The Future-Proof level claims to address geopolitical continuity. The criteria for that level have not been publicly enumerated. The Schwarz Digits press release does not link to the catalogue. Trade-press coverage describes the model but does not reproduce the criteria text. Until the full catalogue is published, the highest level of ES³ is an aspiration with a label rather than a verified property — which is the kind of distinction your committee has to be able to make in writing before citing the standard.

How to use ES³ without being captured by it

There are three ways a procurement committee can engage with ES³, and the choice has consequences.

Use it as a screening filter, not as an award criterion. A tender can require all bidders to disclose their ES³ self-assessment level without making the level the basis of selection. This treats ES³ as a structured-disclosure instrument: bidders have to report against a known framework, the committee compares responses, and the committee’s own architecture team — not the standard’s writer — judges what the disclosures mean. This use is defensible regardless of whether ES³ ever becomes a neutral standard.

Use it as input alongside Gaia-X labelling, SecNumCloud qualification and BSI C5. ES³ is one signal among several. Citing it alongside other criteria, with documented reasoning about why each criterion matters for the specific tender, is the procurement-defensible approach. This requires more work than citing a single standard but produces a tender record that survives Vergabekammer scrutiny if any bidder challenges the criteria.

Use it as award criterion — only with the conflict named in writing. If political pressure or budget timetable requires citing ES³ as a hard criterion, the procurement file should contain an explicit acknowledgement that the standard’s author is a market participant, an analysis of why this is acceptable in the specific tender context, and a statement of how the committee verified the criteria-selection independently. This use is exposed to Vergabekammer challenge but defensible if the file is built carefully.

The fourth option — cite ES³ as if it were a neutral standard — is the option that will, on the first contested tender, produce the case law every other procurement officer will then have to read.

What this article is not

Anyone reading this analysis as a claim that ES³ is bad has missed the point — European procurement urgently needs criteria, and a vendor-led standard with audit infrastructure is meaningfully better than the current state. The analysis operates one layer deeper: at the structural conflict of interest between standard author and market participant, which exists independently of the motivations of individual actors. Assumptions about the standard’s future fate — whether it becomes the dominant European reference or is superseded by the CADA regulatory four-level system — are outside the scope of the investigation. For procurement committees that want to cite ES³ in a tender, this analysis does not substitute for procurement-law advice.

The question your committee has to answer

The procurement question for your 2,400-user migration is short and worth saying out loud: would you adopt a sovereignty maturity model written by Microsoft and verified by KPMG, on the same terms? If the answer is no, the corresponding standard for ES³ requires the same critical scrutiny.

The conflict of interest does not disappear because the writing vendor is European rather than American. It is reduced — jurisdictional exposure does change between vendors, and Schwarz Digits’ commercial calculus does not include voluntary cooperation with US Congressional subcommittees — but the criteria-selection problem is identical. The German federal procurement layer, with the new §58 VgV sovereignty clause, will be reading the early ES³ citations carefully to set the precedent for what counts as well-built justification and what counts as captured procurement.

The signal in the next twelve months is what happens to the criteria catalogue. If the full ES³ catalogue is published, with each criterion sourced to a defensible architectural property, the standard moves from procurement signal to procurement input. If the catalogue stays behind summaries and case studies, ES³ is a marketing artefact wearing audit clothing — and the procurement files that cited it will not survive the first challenge.

Sources


Topic overview: Digital Sovereignty in Europe Related articles: Sovereignty on Microsoft’s servers, What the veto changes