BSI C3A meets Microsoft 365 – How the new sovereignty criteria catalogue changes the German state tenders in autumn 2026
BSI C3A meets Microsoft 365 – How the new sovereignty criteria catalogue changes the German state tenders in autumn 2026
On 27 April 2026 the German Federal Office for Information Security published the C3A – Criteria enabling Cloud Computing Autonomy catalogue. The German-language version follows at the end of the second quarter of 2026. For the first time there is a recognised review standard with which the cloud sovereignty of a provider can be assessed objectively along six dimensions. The release falls into a procurement season in which North Rhine-Westphalia and Lower Saxony have Microsoft 365-related procedures running with bid deadlines on 17 and 20 August 2026, and the federal government is negotiating the successor volume licensing agreement with Microsoft for 2027 to 2029. From the perspective of municipal IT leadership and state procurement offices, two calendars collide within a window of a few weeks.
This post explains what the C3A catalogue technically requires, how Microsoft 365 scores on the six dimensions, and how procurement offices in states and municipalities can build the catalogue into tenders in a legally sound way.
What C3A is – and what the catalogue makes measurable for the first time
C3A is a criteria catalogue, not a certificate. It complements the well-known security catalogue C5:2026 with a second, orthogonal review layer: the autonomy of cloud use. Where C5 answers "is the service operated securely", C3A answers "can the customer use the service in a self-determined way, if necessary independently of the provider". C3A conformity requires a valid C5 attestation.
The review runs at two geographic and legal levels. C1 requires full attribution of the provider to the EU legal order. C2 additionally requires attribution to a German legal entity and German jurisdiction – intended for social services data, resident registration, critical infrastructure and health care, where NIS-2 obligations apply (see NIS-2/GDPR paradox).
The six dimensions of cloud sovereignty under C3A
The catalogue arranges criteria into six clearly separated areas:
- SOV-1 Strategic sovereignty – corporate seat, effective control, provider ownership structure.
- SOV-2 Legal and jurisdictional sovereignty – jurisdiction, extraterritorial access risks (CLOUD Act, FISA 702).
- SOV-3 Data sovereignty – physical storage location, access control, key ownership.
- SOV-4 Operational sovereignty – operation without provider dependency, service continuity.
- SOV-5 Supply chain sovereignty – dependencies on subcontractors, hardware, cloud services.
- SOV-6 Technological sovereignty – interoperability, standards, portability.
Each dimension carries basic criteria (C) and extended criteria (AC). The AC criteria describe the stricter proof framework for highly sensitive procedures.
How Microsoft 365 scores on the six C3A dimensions
The assessment is sober:
- SOV-1 – broken. Microsoft Corporation is a US legal entity; effective control lies in Redmond.
- SOV-2 – broken. The US CLOUD Act 18 U.S. Code §2713 applies regardless of storage location. Microsoft's own legal counsel in France confirmed under oath in 2025 that a non-disclosure guarantee to European customers is not possible.
- SOV-3 – only partially achievable via the EU Data Boundary and bring-your-own-key solutions.
- SOV-4 – broken. Support, telemetry and update signatures run globally.
- SOV-5 – broken. Hardware and cloud supply chain largely US-dominated.
- SOV-6 – partially, with continuing vendor lock-in criticism especially around Microsoft Copilot – details in the post on Copilot flex routing.
The new Microsoft 365 Local variant on Azure Local does not change SOV-1 or SOV-2 either.
What NRW and Lower Saxony would have with C3A in hand
Both federal states have Microsoft 365 procedures running in recent weeks. The federal government's successor volume licensing agreement for 2027 to 2029 is being negotiated in parallel. C3A is available just in time to be built into these successor procedures.
Concretely this means for procurement offices: instead of formulating the sovereignty reservation as a soft "evaluation advantage", C3A can go into the specifications as a mandatory criterion. Providers that cannot prove C1 or C2 conformity are excluded from the procedure. For European alternatives – openDesk, Nextcloud, Element, Collabora Online – the C3A review is largely answerable positively when operated by a German or European cloud provider (see alternativen).
The economic structure remains what we already laid out for comparable procedures such as the openDesk partner programme and the EuroOffice alternative: sovereignty-capable stacks come in over 36 months mostly between 40 and 55 percent below the Microsoft comparison calculation, because legal advice, compliance effort and extraterritoriality risks fall away.
Conclusion and next steps
C3A is neither a certificate nor an obligation – but the only publicly available, verifiable metric for cloud sovereignty in Germany. For state procurement offices and municipal IT leadership, the catalogue is from now on the clean instrument to translate sovereignty requirements into a legally sound specification. Anyone who concludes the autumn 2026 tenders without a C3A reference structurally defers the sovereignty question into the next contract cycle.
For the concrete implementation we recommend three steps. First, the live analysis of your Microsoft 365 data flows at /en/microsoft. Second, the categorised overview of sovereign providers at /en/alternativen. Third, an initial consultation via /en/contact for a C3A-conform migration plan aligned with your state or municipal procurement cycle. Price orientation for small and mid-sized authorities is at /en/pricing.
Sovereignty Washing 2026 – Why Microsoft 365 Local and the Munich Sovereignty Studio do not release German municipalities from the CLOUD Act
M365 Local is GA, the Munich Sovereignty Studio is open, openDesk 1.17 is in the Chancellery – municipalities need a fact-check, not marketing.
The Schleswig-Holstein blueprint – 80 percent LibreOffice migration and what German states, municipalities and SMEs can copy from it in autumn 2026
Schleswig-Holstein has migrated 80 % of its state administration to LibreOffice. What German states, municipalities and SMEs can take from the €15M blueprint now.