Strengths profile
Capability rating of STACKIT (1–10) — against the average of all other providers and the average of its peer group.
Assessment
STACKIT impresses as a sovereign Germany-based cloud with the highest scores for operational control and data security, but is clearly focused on IaaS/PaaS use cases in the DACH region due to a limited portfolio in AI, Big Data, and Collaboration, as well as a lack of global reach.
USP
STACKIT offers maximum operational sovereignty (10/10) and technological independence (9/10) on an open platform with end-to-end Confidential Computing for the highest compliance requirements.
Recommendation
The provider is ideal for organizations that must operate Linux-based IaaS and PaaS workloads (Linux 10/10) under strict EU data sovereignty and with strong Managed Database services (8/10), without requiring global presence or workplace tools.
Last verified: 2026-07
Points in favor
- Maximum operational sovereignty (10/10): STACKIT achieves the highest score in the comparison field for operational control from Europe, supported by a SEAL Score of 8.2/10 (82%) and SEAL 3 certification.
- Strong data security and encryption (9/10): With a score of 9/10 (avg. others: 7.8), the platform offers technical protection mechanisms such as Confidential Cloud by Edgeless Systems, Confidential Server, and a Secrets Manager (Encryption 8/10).
- Excellent Linux support (10/10): With the highest score in the comparison field (10/10, avg. others: 8.7), STACKIT is an optimal target platform for Linux workloads and open-source ecosystems.
- Solid Managed Database portfolio (8/10): The offering of true DBaaS services (8/10, avg. others: 7.1) includes PostgreSQL Flex, MariaDB, SQLServer Flex, MongoDB Flex, Redis, and OpenSearch.
- Attractive pricing structure for certain resources: Although the overall price rating is 5/10 (avg. others: 6.5), STACKIT stands out with free egress costs (10/10) and competitive prices for Kubernetes Premium (8.7/10) and RAM (7.7/10).
- Broad compliance basis: The platform holds relevant certifications such as BSI C5, ISO 27001, ISO 20000, ISO 50001, CSA STAR, as well as SOC 1, 2, and 3.
Things to consider
- No global reach (1/10): With only 2 regions in 2 countries (Germany and Austria) and 3 Availability Zones, the provider is unsuitable for workloads outside Europe (avg. others: 4.8).
- Weak AI and Big Data offering: The categories AI (3/10, avg. others: 5) and Big Data (3/10, avg. others: 5) are thinly populated; many AI services are only 'announced' and Dremio is in beta stage.
- Collaboration limited to a single resell product (5/10): Workplace functions come solely via Workspace by STACKIT (sovereign Google Workspace with key custody in Germany); a native first-party mail/office/chat portfolio is absent.
- Limited strategic options (5/10): The portfolio is strongly focused on IaaS/PaaS and offers less room for innovation for future, complex use cases than the average (avg. others: 6.3).
- No Bare Metal offering (1/10): Dedicated physical servers are not offered (avg. others: 5.5), which limits specific hardware requirements.
Sovereignty
Interpretation
With headquarters in the EU, data is inherently sovereign. Additionally, the data can be encrypted at rest and in used by Edgeless Systems
SEAL
SEAL 3
Residency
Germany
Shared Resources
Public Cloud
Encryption
Confidential Cloud by Edgeless Systems
All services from STACKIT
76 services across 15 categories
SEAL Framework
Sovereignty Score
- 8.2/10 (82%) Schwarz Group owned, DE/AT only; EU sovereign cloud tender awardee 2026
SOV-1Strategic (15 %)
- 9/10 100% German Schwarz Group ownership
SOV-2Legal & Jurisdictional (10 %)
- 9/10Exclusively EU (German/Austrian) jurisdiction
SOV-3Data & AI (10 %)
- 8/10Data exclusively in DE/AT datacenters
SOV-4Operational (15 %)
- 9/10EU personnel, group-owned datacenters
SOV-5Supply Chain (20 %)
- 7/10Group-owned DCs; standard global hardware sourcing
SOV-6Technology (15 %)
- 8/10Open-source based platform, low lock-in
SOV-7Security & Compliance (10 %)
- 8/10BSI C5, ISO 27001
SOV-8Environmental (5 %)
- 7/10Green energy powered datacenters
Availability & Locations
Compute
Hot Storage
Block Storage
Assets
Cold Storage
Managed Databases
Network & Security
Network
Public IP
Load Balancer
Public DNS
Private Connectivity
DDoS Protection
- Anycast DNS
Orchestration
Container Registry
- Runtimes Container
Orchestration
Virtualization
Hypervisor
- KVMOpenStack-basiert, kein direkter Zugang
Instance as a Service
Management
IaC
- Terraform
- Pulumi
Command Line
Collaboration
- Workspace by STACKIT (sovereign Google Workspace)
MCP Server
Big Data
AI & Machine Learning
Assistant
- AI Model Serving Soon
Translation
- AI Model Serving Soon
Audio Analysis
- AI Model Serving Soon
Computer Vision
- AI Model Serving Soon
NLP
- AI Model Serving Soon
Image Generation
- AI Model Serving Soon
Machine Learning
Quantum Computing
Engine
Compliance & Certificates
C5German cloud security catalogue
ISO 20000IT service management system standard
ISO 27001Information security management system
ISO 50001Energy management for data centers
CSA STARCloud Security Alliance assurance registry
SOC 1,2,3Service organization control audit reports
Cost Indication
Rating
- 5.4/10
CPUvCPU/h
- 4.6/100,0309144 €
GPUH100/h
- 3.4/108,0400000 €
RAMGB/h
- 7.7/100,0029144 €
Managed MySQLRatio1/4
- 7.2/100,0985890 €
Block StorageGB/h | 3000 IOPS
- 2.9/100,0004862 €
S3 StorageGB/h
- 2.8/100,0000364 €
Archive StorageGB/h
- 4.5/100,0214751 €
Kubernetes-Service-PremiumCluster/h
- 8.7/100,0995951 €
Generative AI-Token InputLLama3.3-70B per 1Mil tokens
- 4.8/101,5000000 €
Generative AI-Token OutputLLama3.3-70B per 1Mil tokens
- 4.8/101,7500000 €
Egressper GB
- 10.0/100,0000000 €
Resources & sources: STACKIT
Verified primary sources: products, pricing, compliance and locations straight from the provider.
Frequently asked questions about STACKIT
Who is STACKIT best suited for?
STACKIT is particularly suitable for organizations that must operate Linux-based IaaS and PaaS workloads under strict compliance guidelines. The focus is on maximum sovereignty and data security in the DACH region, rather than on global scaling or workplace integration.
How sovereign is STACKIT compared to other providers?
STACKIT achieves the highest scores in the comparison field for operational sovereignty (10/10) and technological sovereignty (9/10). The SEAL Score is 8.2/10 (82%), underscoring independence from proprietary technology and control from Europe.
How is pricing structured at STACKIT?
The overall price rating is 5.4/10 (avg. others: 6.5), with actual costs depending heavily on the workload. While egress is free (10/10) and Kubernetes Premium and RAM are competitive (8.7/10 and 7.7/10 respectively), CPU (4.6/10) and storage components such as Block Storage (2.9/10) are comparatively expensive.
In which areas is STACKIT particularly strong?
Strengths lie in operational sovereignty (10/10), support for Linux workloads (10/10), and data security and encryption (9/10). The Managed Database portfolio (8/10) and networking capabilities (8/10) also perform above average.
What are the limitations of the portfolio?
The offering is limited in AI (3/10) and Big Data (3/10), with many AI services not yet in production. Collaboration is covered only via a single resell product (Workspace by STACKIT, 5/10); additionally, Bare Metal servers (1/10) and global regions (1/10) are missing, restricting use to European infrastructure workloads.
Which certifications and compliance standards does STACKIT meet?
STACKIT holds a broad spectrum of certifications, including BSI C5, ISO 27001, ISO 20000, ISO 50001, CSA STAR, as well as SOC 1, 2, and 3. Additionally, the platform is certified as SEAL 3, confirming high sovereignty and security.