Operation Sovereignty – What the Bundestag's Microsoft Exit Teaches SMEs, Schools and Public Bodies
Operation Sovereignty – What the Bundestag's Microsoft Exit Teaches SMEs, Schools and Public Bodies
In May 2026, a cross-party commission under Bundestag Vice President Andrea Lindholz adopted the new IT strategy of the German Bundestag. The headline: the roughly 10,000 workplaces in Berlin and in the constituency offices will be migrated step by step to European and open-source software. Microsoft 365 remains in parallel use for the time being, but is to be replaced over time by the Phoenix Suite of the public-sector IT service provider Dataport and by the BSI-certified messenger Wire. The programme is known internally as Operation Sovereignty.
For IT managers in German SMEs, school boards and municipalities, the Bundestag decision is more than a political signal. It supplies a five-pillar method that is transferable as a procurement grid and migration plan – not one to one, but structurally. We unpack what the Bundestag has actually decided, which products sit behind the pillars, and how the same logic applies to an 80-person SME or a school board with fifteen schools.
What the Bundestag decided in May 2026
The Lindholz commission took twelve months and adopted a strategic path rather than a cut-off date. The key points:
- Five pillars as the procurement grid: office software, AI applications, secure cloud, collaboration services, continuous security architecture.
- Step-by-step replacement rather than a big bang. The sequence: messenger first, then office, then cloud migration of data holdings.
- Phoenix Suite from Dataport as the central office component alongside Microsoft 365.
- Wire as messenger, because as of June 2026 it is the only service certified under the BSI Technical Guideline TR-03174.
- Multi-year transition without a hard end-date. The strategy commits to the path, not to a deadline.
The decision is a direct consequence of two prior developments: the Cloud and AI Development Act, which since 3 June 2026 has obliged public buyers to sovereignty tiers, and the CJEU line on the GDPR compliance of Microsoft cloud services in public administration. The Bundestag is not under direct supervision of the German data protection conference, but it follows the same benchmark.
The five pillars – what sits behind each
Pillar 1 – Office software. The Phoenix Suite is the open-source-based workplace suite of Dataport. It bundles Nextcloud, Collabora Online, Element/Matrix, Open-Xchange and Keycloak under a shared management and identity layer. Dataport operates the suite from German data centres without a hyperscaler sub-processor. The Phoenix Suite is not directly available to SMEs, but a comparable stack can be obtained as openDesk or as Nextcloud Hub 26 Spring with Euro-Office from managed hosters.
Pillar 2 – AI applications. The commission explicitly aimed for a sovereign LLM stack – European models such as Aleph Alpha and Mistral, hosted by European-owned providers. Microsoft Copilot is not approved, because the documented Flex Routing outside the EU Data Boundary creates a BSI risk assessment that includes a peak-load exception – a state that is not acceptable for parliamentary data.
Pillar 3 – Secure cloud. Hosting in German data centres, European ownership, no US corporation as sub-processor. Concretely, this means CADA level 3 and above. The Bundestag works with the established public-sector IT service providers and with commercial vendors that follow the same logic.
Pillar 4 – Collaboration services. Wire as messenger, because BSI-certified. Video conferencing via Jitsi and BigBlueButton. Element/Matrix is grandfathered in as an existing component but is not the default. Phasing out Microsoft Teams is the first concrete deliverable of the strategy.
Pillar 5 – Security architecture. Cross-cutting. Identity through Keycloak, MFA mandatory, BSI IT-Grundschutz as the audit benchmark. We covered the relevant modules in detail in BSI IT-Grundschutz and Microsoft 365 – the Bundestag strategy uses the same grid for configuring the stack itself.
Phoenix Suite and Wire – the two concrete components
Phoenix Suite has been in productive use in Schleswig-Holstein, Hamburg, Bremen, Mecklenburg-Vorpommern and Saxony-Anhalt since 2023. Its operator Dataport is a public-law institution jointly owned by these five states – structurally outside the scope of the CLOUD Act. The suite is not directly licensable by private customers because it is tied to Dataport's ownership structure. For SMEs and private schools the same technical stack is available through other channels – see pillar 1.
Wire is a messenger founded in Berlin, today incorporated as a Swiss-German entity, with end-to-end encryption. The BSI certification under Technical Guideline TR-03174 as of June 2026 covers key management, metadata minimisation, server location in Germany and audit capability. Wire is the only messenger with this certification in early summer 2026. Element/Matrix is technically eligible for the same certification and is already in use by many public bodies – see Microsoft Teams alternative – Element/Matrix – but has not yet completed the TR-03174 review.
Why the Bundestag template is an opportunity for SMEs
Three structural arguments:
- A procurement grid on a single page. The five-pillar method is a spreadsheet, not a political manifesto. If you, as IT lead of an 80-person SME or as IT manager of a school board with fifteen schools, translate the Bundestag path into your own organisation, you have a grid that is immediately understood in board meetings and school board discussions.
- BSI certification as audit evidence. A BSI-certified messenger component such as Wire is a one-line proof in audits against NIS2 and the BSI IT-Grundschutz catalogue. A Microsoft Teams configuration takes several pages – and is still vulnerable, as our NIS2 and GDPR analysis shows.
- Reduce concentration risk. The DORA concentration-risk logic applies formally only to banks, but the underlying principle applies to any SME. Anyone who pushes all five pillars onto a single US corporation has a systemic risk on the balance sheet – and no recourse beyond Microsoft's service level agreements in the event of damage. The recent Exchange Online outage EX1331830 on 2 June 2026 with more than six hours of mail delays across three continents made that point exemplarily.
Migration – the five-pillar method at SME scale
The HowTo section above documents six steps for translating the method to SME scale. The sequence matters: first the procurement grid, then collaboration (messenger and video), then office (Nextcloud + browser office), then cloud migration of data holdings, then the identity layer, and only last AI. Starting with AI builds on shaky ground. Skipping collaboration keeps the most expensive and compliance-critical Microsoft share in operation.
Glossary
- Operation Sovereignty: internal name of the Bundestag IT strategy of May 2026 for the step-by-step replacement of proprietary US software, tabled by the Lindholz commission.
- Phoenix Suite: open-source-based workplace suite of the IT service provider Dataport, in productive use in five German states and, in time, in the Bundestag.
- Dataport: public-law institution jointly owned by Schleswig-Holstein, Hamburg, Bremen, Mecklenburg-Vorpommern and Saxony-Anhalt; operator of the Phoenix Suite.
- Wire: end-to-end-encrypted messenger; as of June 2026 the only service certified under the BSI Technical Guideline TR-03174.
- TR-03174: BSI Technical Guideline for secure messenger services. Covers encryption, metadata minimisation, key management, localisation and audit capability.
- BSI IT-Grundschutz: methodical catalogue from the German Federal Office for Information Security, with modules for every IT component.
How europioneer plugs in
europioneer operates the European open-source stack as a managed hosted service – Nextcloud Hub 26 Spring including Euro-Office and Collabora Online, Element on Matrix for chat (Wire connectivity in preparation), Open-Xchange for email, Keycloak for identity. Hosting in German and EU data centres without a hyperscaler sub-processor. For translating the Bundestag five-pillar method to an SME, a school board or a municipality, we deliver the procurement grid of step 1, the pilots of steps 2 and 3, and the configuration of the security and identity layer of step 5. Live view of the remaining Microsoft dependencies at /en/microsoft. Component overview of the European stack at /en/alternativen. Packages and prices at /en/pricing. Pilot conversation at /en/contact.
Conclusion
In May 2026 the Bundestag adopted a procurement grid that every German SME and every school board can use as a template. The five-pillar method is not a marketing story but a workable path: collaboration first, office second, cloud and identity as a consequence, AI deliberately last. The concrete product choice differs by organisation – the Phoenix Suite for state-level procurement, openDesk and Nextcloud Hub for SMEs, Wire as the BSI-certified messenger component everywhere. Anyone who sets the path now will not be under time pressure when the EU AI Act GPAI obligations enter into force on 2 August 2026 – and will be on firm procurement ground against CADA level 3 in early 2027.
Request an Operation Sovereignty pilot →
Related posts:
- openDesk Partner Program 2026 – the Sovereign Workplace for SMEs
- Euro-Office 1.0 – the sovereign Microsoft 365 alternative in technical practice
- CADA and the EU Tech Sovereignty Package – why level 3 is forcing German public bodies in 2026
- Microsoft Teams alternative – Element/Matrix in 2026 safely deployed
- Microsoft 365 Copilot Flex Routing – how the EU Data Boundary is being silently softened in 2026
- BSI IT-Grundschutz and Microsoft 365 – why the combination cannot be compliant
- DORA, CTPP designation and Microsoft 365 – why banks need a robust exit strategy in 2026
- NIS2 and GDPR with Microsoft 365 – the compliance paradox of German companies
Euro-Office 1.0 – the sovereign Microsoft 365 alternative in a technical hands-on review
Euro-Office 1.0 launched on 9 June 2026 as a European Microsoft 365 alternative. What the suite delivers technically and who should adopt it now.
EU AI Act – What German SMEs must document for Microsoft Copilot by 2 August 2026
On 2 August 2026 the EU AI Act's GPAI obligations kick in. What SMEs must now document for Microsoft Copilot and which sovereign alternatives hold up.