[{"data":1,"prerenderedAt":434},["ShallowReactive",2],{"navigation-docs_en":3,"/en/blog/bsi-c3a-microsoft-365-procurement-sovereignty-2026-posts_en":51,"/en/blog/bsi-c3a-microsoft-365-procurement-sovereignty-2026-surround-posts_en":423},[4],{"title":5,"path":6,"stem":7,"children":8,"page":25},"En","/en","en",[9],{"title":10,"path":11,"stem":12,"children":13,"page":25},"Docs","/en/docs","en/1.docs",[14,26],{"title":15,"path":16,"stem":17,"children":18,"icon":25},"Getting Started","/en/docs/getting-started","en/1.docs/1.getting-started/1.index",[19,21],{"title":20,"path":16,"stem":17,"children":-1},"Introduction",{"title":22,"path":23,"stem":24,"children":-1},"Migration Roadmap","/en/docs/getting-started/migration-fahrplan","en/1.docs/1.getting-started/2.migration-fahrplan",false,{"title":27,"path":28,"stem":29,"children":30,"page":25},"Technologies","/en/docs/technologies","en/1.docs/2.technologies",[31,35,39,43,47],{"title":32,"path":33,"stem":34,"children":-1},"Nextcloud","/en/docs/technologies/nextcloud","en/1.docs/2.technologies/1.nextcloud",{"title":36,"path":37,"stem":38,"children":-1},"Matrix / Element","/en/docs/technologies/matrix","en/1.docs/2.technologies/2.matrix",{"title":40,"path":41,"stem":42,"children":-1},"ONLYOFFICE","/en/docs/technologies/onlyoffice","en/1.docs/2.technologies/3.onlyoffice",{"title":44,"path":45,"stem":46,"children":-1},"Ubuntu Linux","/en/docs/technologies/ubuntu","en/1.docs/2.technologies/4.ubuntu",{"title":48,"path":49,"stem":50,"children":-1},"Keycloak","/en/docs/technologies/keycloak","en/1.docs/2.technologies/5.keycloak",{"id":52,"title":53,"authors":54,"badge":60,"body":62,"date":376,"description":377,"extension":378,"faq":379,"howto":395,"image":415,"meta":417,"navigation":418,"path":419,"seo":420,"stem":421,"__hash__":422},"posts_en/en/3.blog/25.bsi-c3a-microsoft-365-procurement-sovereignty-2026.md","BSI C3A meets Microsoft 365 – How the new sovereignty criteria catalogue changes the German state tenders in autumn 2026",[55],{"name":56,"to":57,"avatar":58},"europioneer Team","/",{"src":59},"/favicon.svg",{"label":61},"BSI & Cloud Procurement",{"type":63,"value":64,"toc":367},"minimark",[65,69,102,113,118,136,161,165,168,208,218,222,225,276,287,291,297,321,334,338,350],[66,67,53],"h1",{"id":68},"bsi-c3a-meets-microsoft-365-how-the-new-sovereignty-criteria-catalogue-changes-the-german-state-tenders-in-autumn-2026",[70,71,72,73,77,78,81,82,85,86,89,90,93,94,97,98,101],"p",{},"On ",[74,75,76],"strong",{},"27 April 2026"," the German Federal Office for Information Security published the ",[74,79,80],{},"C3A – Criteria enabling Cloud Computing Autonomy"," catalogue. The German-language version follows at the end of the second quarter of 2026. For the first time there is a recognised review standard with which the ",[74,83,84],{},"cloud sovereignty"," of a provider can be assessed objectively along six dimensions. The release falls into a procurement season in which ",[74,87,88],{},"North Rhine-Westphalia"," and ",[74,91,92],{},"Lower Saxony"," have Microsoft 365-related procedures running with bid deadlines on ",[74,95,96],{},"17 and 20 August 2026",", and the federal government is negotiating the successor volume licensing agreement with Microsoft for ",[74,99,100],{},"2027 to 2029",". From the perspective of municipal IT leadership and state procurement offices, two calendars collide within a window of a few weeks.",[70,103,104,105,108,109,112],{},"This post explains what the C3A catalogue technically requires, how ",[74,106,107],{},"Microsoft 365"," scores on the six dimensions, and how ",[74,110,111],{},"procurement offices"," in states and municipalities can build the catalogue into tenders in a legally sound way.",[114,115,117],"h2",{"id":116},"what-c3a-is-and-what-the-catalogue-makes-measurable-for-the-first-time","What C3A is – and what the catalogue makes measurable for the first time",[70,119,120,123,124,127,128,131,132,135],{},[74,121,122],{},"C3A"," is a ",[74,125,126],{},"criteria catalogue",", not a certificate. It complements the well-known security catalogue ",[74,129,130],{},"C5:2026"," with a second, orthogonal review layer: the ",[74,133,134],{},"autonomy"," of cloud use. Where C5 answers \"is the service operated securely\", C3A answers \"can the customer use the service in a self-determined way, if necessary independently of the provider\". C3A conformity requires a valid C5 attestation.",[70,137,138,139,142,143,146,147,150,151,154,155,160],{},"The review runs at two geographic and legal levels. ",[74,140,141],{},"C1"," requires full attribution of the provider to the ",[74,144,145],{},"EU legal order",". ",[74,148,149],{},"C2"," additionally requires attribution to a ",[74,152,153],{},"German legal entity"," and German jurisdiction – intended for social services data, resident registration, critical infrastructure and health care, where NIS-2 obligations apply (see ",[156,157,159],"a",{"href":158},"/en/blog/nis2-gdpr-microsoft-paradox","NIS-2/GDPR paradox",").",[114,162,164],{"id":163},"the-six-dimensions-of-cloud-sovereignty-under-c3a","The six dimensions of cloud sovereignty under C3A",[70,166,167],{},"The catalogue arranges criteria into six clearly separated areas:",[169,170,171,178,184,190,196,202],"ul",{},[172,173,174,177],"li",{},[74,175,176],{},"SOV-1 Strategic sovereignty"," – corporate seat, effective control, provider ownership structure.",[172,179,180,183],{},[74,181,182],{},"SOV-2 Legal and jurisdictional sovereignty"," – jurisdiction, extraterritorial access risks (CLOUD Act, FISA 702).",[172,185,186,189],{},[74,187,188],{},"SOV-3 Data sovereignty"," – physical storage location, access control, key ownership.",[172,191,192,195],{},[74,193,194],{},"SOV-4 Operational sovereignty"," – operation without provider dependency, service continuity.",[172,197,198,201],{},[74,199,200],{},"SOV-5 Supply chain sovereignty"," – dependencies on subcontractors, hardware, cloud services.",[172,203,204,207],{},[74,205,206],{},"SOV-6 Technological sovereignty"," – interoperability, standards, portability.",[70,209,210,211,89,214,217],{},"Each dimension carries ",[74,212,213],{},"basic criteria (C)",[74,215,216],{},"extended criteria (AC)",". The AC criteria describe the stricter proof framework for highly sensitive procedures.",[114,219,221],{"id":220},"how-microsoft-365-scores-on-the-six-c3a-dimensions","How Microsoft 365 scores on the six C3A dimensions",[70,223,224],{},"The assessment is sober:",[169,226,227,233,243,249,255,261],{},[172,228,229,232],{},[74,230,231],{},"SOV-1"," – broken. Microsoft Corporation is a US legal entity; effective control lies in Redmond.",[172,234,235,238,239,242],{},[74,236,237],{},"SOV-2"," – broken. The US CLOUD Act ",[74,240,241],{},"18 U.S. Code §2713"," applies regardless of storage location. Microsoft's own legal counsel in France confirmed under oath in 2025 that a non-disclosure guarantee to European customers is not possible.",[172,244,245,248],{},[74,246,247],{},"SOV-3"," – only partially achievable via the EU Data Boundary and bring-your-own-key solutions.",[172,250,251,254],{},[74,252,253],{},"SOV-4"," – broken. Support, telemetry and update signatures run globally.",[172,256,257,260],{},[74,258,259],{},"SOV-5"," – broken. Hardware and cloud supply chain largely US-dominated.",[172,262,263,266,267,270,271,275],{},[74,264,265],{},"SOV-6"," – partially, with continuing vendor lock-in criticism especially around ",[74,268,269],{},"Microsoft Copilot"," – details in the post on ",[156,272,274],{"href":273},"/en/blog/microsoft-copilot-flex-routing","Copilot flex routing",".",[70,277,278,279,282,283,286],{},"The new ",[74,280,281],{},"Microsoft 365 Local"," variant on ",[74,284,285],{},"Azure Local"," does not change SOV-1 or SOV-2 either.",[114,288,290],{"id":289},"what-nrw-and-lower-saxony-would-have-with-c3a-in-hand","What NRW and Lower Saxony would have with C3A in hand",[70,292,293,294,296],{},"Both federal states have Microsoft 365 procedures running in recent weeks. The federal government's successor volume licensing agreement for 2027 to 2029 is being negotiated in parallel. ",[74,295,122],{}," is available just in time to be built into these successor procedures.",[70,298,299,300,303,304,307,308,307,310,307,313,316,317,160],{},"Concretely this means for procurement offices: instead of formulating the sovereignty reservation as a soft \"evaluation advantage\", C3A can go into the specifications as a ",[74,301,302],{},"mandatory criterion",". Providers that cannot prove C1 or C2 conformity are excluded from the procedure. For European alternatives – ",[74,305,306],{},"openDesk",", ",[74,309,32],{},[74,311,312],{},"Element",[74,314,315],{},"Collabora Online"," – the C3A review is largely answerable positively when operated by a German or European cloud provider (see ",[156,318,320],{"href":319},"/en/alternativen","alternativen",[70,322,323,324,328,329,333],{},"The economic structure remains what we already laid out for comparable procedures such as the ",[156,325,327],{"href":326},"/en/blog/opendesk-partner-program-2026","openDesk partner programme"," and the ",[156,330,332],{"href":331},"/en/blog/euro-office-microsoft-365-alternative-2026","EuroOffice alternative",": sovereignty-capable stacks come in over 36 months mostly between 40 and 55 percent below the Microsoft comparison calculation, because legal advice, compliance effort and extraterritoriality risks fall away.",[114,335,337],{"id":336},"conclusion-and-next-steps","Conclusion and next steps",[70,339,340,342,343,345,346,349],{},[74,341,122],{}," is neither a certificate nor an obligation – but the only publicly available, verifiable metric for ",[74,344,84],{}," in Germany. For state procurement offices and municipal IT leadership, the catalogue is from now on the clean instrument to translate sovereignty requirements into a ",[74,347,348],{},"legally sound specification",". Anyone who concludes the autumn 2026 tenders without a C3A reference structurally defers the sovereignty question into the next contract cycle.",[70,351,352,353,356,357,359,360,363,364,275],{},"For the concrete implementation we recommend three steps. First, the live analysis of your Microsoft 365 data flows at ",[156,354,355],{"href":355},"/en/microsoft",". Second, the categorised overview of sovereign providers at ",[156,358,319],{"href":319},". Third, an initial consultation via ",[156,361,362],{"href":362},"/en/contact"," for a C3A-conform migration plan aligned with your state or municipal procurement cycle. Price orientation for small and mid-sized authorities is at ",[156,365,366],{"href":366},"/en/pricing",{"title":368,"searchDepth":369,"depth":369,"links":370},"",2,[371,372,373,374,375],{"id":116,"depth":369,"text":117},{"id":163,"depth":369,"text":164},{"id":220,"depth":369,"text":221},{"id":289,"depth":369,"text":290},{"id":336,"depth":369,"text":337},"2026-08-18T00:00:00.000Z","Germany's BSI C3A catalogue makes cloud sovereignty measurable. What the new criteria mean for Microsoft 365 tenders in NRW and Lower Saxony this autumn.","md",[380,383,386,389,392],{"q":381,"a":382},"What is the BSI C3A criteria catalogue and when was it published?","C3A stands for \"Criteria enabling Cloud Computing Autonomy\" and was published on 27 April 2026 by the German Federal Office for Information Security. A German-language version follows at the end of the second quarter of 2026. C3A is the first objective and verifiable criteria catalogue with which cloud sovereignty can be assessed along six dimensions. The catalogue complements the well-known security catalogue C5 – it does not replace it. C3A conformity requires an existing C5 conformity as a prerequisite. The catalogue explicitly has no direct regulatory effect and is instead intended as a \"guiding framework\" for procurement, contract negotiation and supplier evaluation.",{"q":384,"a":385},"Is C3A binding for public tenders?","No, C3A is not yet a legal obligation. Procurement offices can nevertheless include the catalogue as a minimum requirement in tender specifications from now on. Procurement law allows technical requirements to be aligned with recognised standards, and with the BSI publication C3A is a recognised standard. Procurement platforms such as tendigo.de, DTVP and it-ausschreibung.de show that the first tenders already name the C3A dimensions as award criteria. The EU Commission and the Cloud and AI Development Act (CADA) are also examining whether C3A can serve as a reference for the future Union Assurance Levels UAL 3 and UAL 4 – background in our post on the [CADA sovereignty package](/en/blog/cada-eu-tech-sovereignty-package-public-sector-2026).",{"q":387,"a":388},"Does Microsoft 365 meet the C3A dimensions for the public sector?","Not fully at present. Microsoft 365 in the standard cloud variant delivers C5 attestations but fails on at least three of the six C3A dimensions. Strategic sovereignty (SOV-1) is broken via the US corporate seat. Legal sovereignty (SOV-2) fails on the US CLOUD Act 18 U.S. Code §2713. Operational sovereignty (SOV-4) depends on global support chains. Even the new sovereign-cloud variants such as Microsoft 365 Local do not resolve the SOV-1 and SOV-2 points – background in the post on [sovereignty washing 2026](/en/blog/sovereignty-washing-microsoft-365-local-municipalities-2026).",{"q":390,"a":391},"What do the C3A review levels C1 (EU level) and C2 (Germany level) mean?","C3A defines basic (C) and extended (AC) criteria for each of the six dimensions. On top of that there are two geographic and legal review levels. C1 requires full attribution of a provider to the EU legal order. C2 additionally requires full attribution to German jurisdiction and a German legal entity. C2 is intended for areas with a high protection requirement – social services data, resident registration, critical infrastructure, health care. C1 is sufficient for many state authorities and districts; for public-health offices, social authorities and hospitals under NIS-2 the pragmatic target is C2.",{"q":393,"a":394},"How does C3A affect the current state tenders in August 2026?","The timing is unusually precise. North Rhine-Westphalia and Lower Saxony have Microsoft 365-related procurement procedures with bid deadlines on 17 and 20 August 2026. In parallel, the federal government is negotiating the successor volume licensing agreement with Microsoft for the period 1 January 2027 to 31 December 2029, with a one-year option. Procurement offices can build C3A criteria into successor procedures from now on so that sovereignty-capable alternatives are the default for future contract renewals. Anyone who publishes the autumn 2026 tenders without a C3A reference structurally defers the sovereignty question into the 2027 to 2029 contract period – with the known CLOUD Act risks.",{"name":396,"description":397,"totalTime":398,"steps":399},"How to build C3A requirements into a Microsoft 365 successor tender","A compact review path for procurement offices in states, districts and municipalities to embed C3A criteria as a legally sound minimum requirement in a tender.","P60D",[400,403,406,409,412],{"name":401,"text":402},"Define protection requirement and scope","Classify the data to be processed according to BSI IT-Grundschutz and name the regulatory additional obligations – GDPR Article 9, the German NIS-2 implementation law, social code obligations, critical infrastructure regulation. The classification is the basis for the C3A review level and cannot be adjusted retroactively.",{"name":404,"text":405},"Set the C3A review level C1 or C2","Decide whether your tender requires the EU level C1 or the Germany level C2. For standard administrative workplaces in states and municipalities, C1 is usually sufficient. For health data, social services data, critical infrastructure applications and classified material, C2 is the target.",{"name":407,"text":408},"Set a C5 attestation as a minimum requirement","Require a current C5 attestation from the provider (version C5:2026) as a mandatory criterion in the procurement procedure. Without C5 conformity, the C3A assessment is not possible under the official methodology – the catalogue explicitly requires C5.",{"name":410,"text":411},"Formulate the C3A dimensions as mandatory criteria","Adopt the six C3A dimensions (SOV-1 through SOV-6) as mandatory criteria in the specifications and request a documented proof per dimension. For Microsoft 365 successor procedures this means in practice that all six dimensions must be answered positively – without an exception clause for the provider.",{"name":413,"text":414},"Require proof documents and audit rights","Request written self-declarations on legal entity, signing-key management, support access paths, data-export formats and emergency rights. Link these documents to an audit right that does not require the provider's consent – analogous to the audit rights from the EU Data Act, see [Data Act switching window](/en/blog/eu-data-act-cloud-switching-microsoft-365-exit-january-2027).",{"src":416},"https://images.unsplash.com/photo-1454165804606-c3d57bc86b40?w=1200&q=80",{},true,"/en/blog/bsi-c3a-microsoft-365-procurement-sovereignty-2026",{"title":53,"description":377},"en/3.blog/25.bsi-c3a-microsoft-365-procurement-sovereignty-2026","ImkaFa5NmGeNlBestmmbtnjo50yxkLzrNG6X7K3jBPU",[424,429],{"title":425,"path":426,"stem":427,"description":428,"children":-1},"Sovereignty Washing 2026 – Why Microsoft 365 Local and the Munich Sovereignty Studio do not release German municipalities from the CLOUD Act","/en/blog/sovereignty-washing-microsoft-365-local-municipalities-2026","en/3.blog/24.sovereignty-washing-microsoft-365-local-municipalities-2026","M365 Local is GA, the Munich Sovereignty Studio is open, openDesk 1.17 is in the Chancellery – municipalities need a fact-check, not marketing.",{"title":430,"path":431,"stem":432,"description":433,"children":-1},"The Schleswig-Holstein blueprint – 80 percent LibreOffice migration and what German states, municipalities and SMEs can copy from it in autumn 2026","/en/blog/schleswig-holstein-blueprint-libreoffice-migration-states-municipalities-2026","en/3.blog/26.schleswig-holstein-blueprint-libreoffice-migration-states-municipalities-2026","Schleswig-Holstein has migrated 80 % of its state administration to LibreOffice. What German states, municipalities and SMEs can take from the €15M blueprint now.",1788852143240]