With its decision to adopt SAP’s cloud infrastructure operated within Germany, defence electronics manufacturer HENSOLDT is the latest company in a sensitive industry to seek greater data sovereignty. But what does this shift actually mean for defence-sector IT, and how sovereign can "sovereign cloud" solutions be?
Secure-by-design: By moving selected workloads to SAP’s German-hosted sovereign cloud, HENSOLDT aims to balance regulatory compliance with IT modernisation in the defence sector.
(Bild: HENSOLDT)
Digital transformation in the defence sector has long been shaped by a structural tension: while modern cloud environments promise scalability, cost-efficiency and integration potential, they often fall short of the strict regulatory and sovereignty requirements imposed by national and European frameworks. HENSOLDT’s recent move to adopt SAP’s sovereign cloud infrastructure—operated entirely within SAP-owned data centres in Germany—signals a pragmatic attempt to resolve this tension.
The solution in use is hosted in-country and, according to SAP, aligned with the most stringent German and EU requirements in areas such as data governance, IT security and operational transparency. These factors are particularly relevant for companies like HENSOLDT, which process defence-related information and operate in a highly regulated environment.
Crucially, HENSOLDT’s deployment will initially be limited to non-classified data—a distinction that reflects both regulatory caution and technical pragmatism. Operating in this "grey zone" allows the company to validate the infrastructure in practice before extending its use to more sensitive domains. At the same time, the scope of certifications and oversight mechanisms—such as whether the infrastructure meets BSI C5 or comparable standards—has not been made public.
What is clear is that the cloud migration forms part of a broader trend in Europe to reduce technological dependency on foreign hyperscalers and regain control over critical digital infrastructure. Unlike AWS, Microsoft Azure or Google Cloud, SAP is both headquartered and governed under European law, which provides legal and jurisdictional clarity for companies operating in the defence domain. However, even SAP’s solutions remain technologically embedded in global ecosystems—raising the question of how far digital sovereignty can be achieved purely through location-based hosting.
In strategic terms, HENSOLDT is not only modernising its own IT, but also contributing to an emerging industrial standard in secure cloud use. If successful, this controlled migration approach may serve as a blueprint for other medium- and large-scale players in the defence industry who face similar constraints.
The technical details of the platform—such as its tenant architecture, access management, encryption and integration depth—remain undisclosed. What is likely, however, is that the infrastructure will enable greater automation and interoperability with SAP's broader Business Technology Platform in the future. Whether this transition will also influence operational IT systems or remain confined to administrative and development environments is still open.
For the time being, HENSOLDT is framing the move as a clear step towards greater autonomy, resilience and innovation capability. In a statement, CIO André Scheidhammer emphasised that “responsible innovation and digital sovereignty” are not mutually exclusive—and that HENSOLDT intends to play an active role in shaping Germany’s secure digital future.
From a defence-policy perspective, the timing of the announcement is also notable. With geopolitical uncertainty and cybersecurity threats on the rise, European governments have placed renewed emphasis on strategic IT control. Projects like GAIA-X and the push for a European Secure Cloud reflect broader political will—but also underline the complexity of balancing innovation, regulation and industry needs in practice.
The partnership between HENSOLDT and SAP can thus be seen as both a technological pilot and a political signal. Its success—or failure—will likely inform how other actors in sensitive sectors approach sovereign IT infrastructure in the years ahead. (mbf)
Date: 08.12.2025
Naturally, we always handle your personal data responsibly. Any personal data we receive from you is processed in accordance with applicable data protection legislation. For detailed information please see our privacy policy.
Consent to the use of data for promotional purposes
I hereby consent to Vogel Communications Group GmbH & Co. KG, Max-Planck-Str. 7-9, 97082 Würzburg including any affiliated companies according to §§ 15 et seq. AktG (hereafter: Vogel Communications Group) using my e-mail address to send editorial newsletters. A list of all affiliated companies can be found here
Newsletter content may include all products and services of any companies mentioned above, including for example specialist journals and books, events and fairs as well as event-related products and services, print and digital media offers and services such as additional (editorial) newsletters, raffles, lead campaigns, market research both online and offline, specialist webportals and e-learning offers. In case my personal telephone number has also been collected, it may be used for offers of aforementioned products, for services of the companies mentioned above, and market research purposes.
Additionally, my consent also includes the processing of my email address and telephone number for data matching for marketing purposes with select advertising partners such as LinkedIn, Google, and Meta. For this, Vogel Communications Group may transmit said data in hashed form to the advertising partners who then use said data to determine whether I am also a member of the mentioned advertising partner portals. Vogel Communications Group uses this feature for the purposes of re-targeting (up-selling, cross-selling, and customer loyalty), generating so-called look-alike audiences for acquisition of new customers, and as basis for exclusion for on-going advertising campaigns. Further information can be found in section “data matching for marketing purposes”.
In case I access protected data on Internet portals of Vogel Communications Group including any affiliated companies according to §§ 15 et seq. AktG, I need to provide further data in order to register for the access to such content. In return for this free access to editorial content, my data may be used in accordance with this consent for the purposes stated here. This does not apply to data matching for marketing purposes.
Right of revocation
I understand that I can revoke my consent at will. My revocation does not change the lawfulness of data processing that was conducted based on my consent leading up to my revocation. One option to declare my revocation is to use the contact form found at https://contact.vogel.de. In case I no longer wish to receive certain newsletters, I have subscribed to, I can also click on the unsubscribe link included at the end of a newsletter. Further information regarding my right of revocation and the implementation of it as well as the consequences of my revocation can be found in the data protection declaration, section editorial newsletter.