[{"data":1,"prerenderedAt":514},["ShallowReactive",2],{"navigation-docs_en":3,"/en/blog/bundestag-operation-sovereignty-microsoft-exit-2026-posts_en":51,"/en/blog/bundestag-operation-sovereignty-microsoft-exit-2026-surround-posts_en":504},[4],{"title":5,"path":6,"stem":7,"children":8,"page":25},"En","/en","en",[9],{"title":10,"path":11,"stem":12,"children":13,"page":25},"Docs","/en/docs","en/1.docs",[14,26],{"title":15,"path":16,"stem":17,"children":18,"icon":25},"Getting Started","/en/docs/getting-started","en/1.docs/1.getting-started/1.index",[19,21],{"title":20,"path":16,"stem":17,"children":-1},"Introduction",{"title":22,"path":23,"stem":24,"children":-1},"Migration Roadmap","/en/docs/getting-started/migration-fahrplan","en/1.docs/1.getting-started/2.migration-fahrplan",false,{"title":27,"path":28,"stem":29,"children":30,"page":25},"Technologies","/en/docs/technologies","en/1.docs/2.technologies",[31,35,39,43,47],{"title":32,"path":33,"stem":34,"children":-1},"Nextcloud","/en/docs/technologies/nextcloud","en/1.docs/2.technologies/1.nextcloud",{"title":36,"path":37,"stem":38,"children":-1},"Matrix / Element","/en/docs/technologies/matrix","en/1.docs/2.technologies/2.matrix",{"title":40,"path":41,"stem":42,"children":-1},"ONLYOFFICE","/en/docs/technologies/onlyoffice","en/1.docs/2.technologies/3.onlyoffice",{"title":44,"path":45,"stem":46,"children":-1},"Ubuntu Linux","/en/docs/technologies/ubuntu","en/1.docs/2.technologies/4.ubuntu",{"title":48,"path":49,"stem":50,"children":-1},"Keycloak","/en/docs/technologies/keycloak","en/1.docs/2.technologies/5.keycloak",{"id":52,"title":53,"authors":54,"badge":60,"body":62,"date":451,"description":452,"extension":453,"faq":454,"howto":473,"image":496,"meta":498,"navigation":499,"path":500,"seo":501,"stem":502,"__hash__":503},"posts_en/en/3.blog/17.bundestag-operation-sovereignty-microsoft-exit-2026.md","Operation Sovereignty – What the Bundestag's Microsoft Exit Teaches SMEs, Schools and Public Bodies",[55],{"name":56,"to":57,"avatar":58},"europioneer Team","/",{"src":59},"/favicon.svg",{"label":61},"Sovereignty",{"type":63,"value":64,"toc":439},"minimark",[65,69,102,109,114,117,149,158,162,194,209,215,221,236,240,248,265,269,272,307,311,314,318,351,355,374,378,384,389,392,397],[66,67,53],"h1",{"id":68},"operation-sovereignty-what-the-bundestags-microsoft-exit-teaches-smes-schools-and-public-bodies",[70,71,72,73,77,78,81,82,85,86,89,90,93,94,97,98,101],"p",{},"In ",[74,75,76],"strong",{},"May 2026",", a cross-party commission under Bundestag Vice President ",[74,79,80],{},"Andrea Lindholz"," adopted the new IT strategy of the German Bundestag. The headline: the roughly ",[74,83,84],{},"10,000 workplaces"," in Berlin and in the constituency offices will be migrated step by step to European and open-source software. Microsoft 365 remains in parallel use for the time being, but is to be replaced over time by the ",[74,87,88],{},"Phoenix Suite"," of the public-sector IT service provider ",[74,91,92],{},"Dataport"," and by the BSI-certified messenger ",[74,95,96],{},"Wire",". The programme is known internally as ",[74,99,100],{},"Operation Sovereignty",".",[70,103,104,105,108],{},"For IT managers in German SMEs, school boards and municipalities, the Bundestag decision is more than a political signal. It supplies a ",[74,106,107],{},"five-pillar method"," that is transferable as a procurement grid and migration plan – not one to one, but structurally. We unpack what the Bundestag has actually decided, which products sit behind the pillars, and how the same logic applies to an 80-person SME or a school board with fifteen schools.",[110,111,113],"h2",{"id":112},"what-the-bundestag-decided-in-may-2026","What the Bundestag decided in May 2026",[70,115,116],{},"The Lindholz commission took twelve months and adopted a strategic path rather than a cut-off date. The key points:",[118,119,120,127,133,138,143],"ul",{},[121,122,123,126],"li",{},[74,124,125],{},"Five pillars"," as the procurement grid: office software, AI applications, secure cloud, collaboration services, continuous security architecture.",[121,128,129,132],{},[74,130,131],{},"Step-by-step replacement"," rather than a big bang. The sequence: messenger first, then office, then cloud migration of data holdings.",[121,134,135,137],{},[74,136,88],{}," from Dataport as the central office component alongside Microsoft 365.",[121,139,140,142],{},[74,141,96],{}," as messenger, because as of June 2026 it is the only service certified under the BSI Technical Guideline TR-03174.",[121,144,145,148],{},[74,146,147],{},"Multi-year transition"," without a hard end-date. The strategy commits to the path, not to a deadline.",[70,150,151,152,157],{},"The decision is a direct consequence of two prior developments: the ",[153,154,156],"a",{"href":155},"/en/blog/cada-eu-tech-sovereignty-package-public-sector-2026","Cloud and AI Development Act",", which since 3 June 2026 has obliged public buyers to sovereignty tiers, and the CJEU line on the GDPR compliance of Microsoft cloud services in public administration. The Bundestag is not under direct supervision of the German data protection conference, but it follows the same benchmark.",[110,159,161],{"id":160},"the-five-pillars-what-sits-behind-each","The five pillars – what sits behind each",[70,163,164,167,168,170,171,170,174,170,177,180,181,183,184,188,189,193],{},[74,165,166],{},"Pillar 1 – Office software."," The Phoenix Suite is the open-source-based workplace suite of Dataport. It bundles ",[74,169,32],{},", ",[74,172,173],{},"Collabora Online",[74,175,176],{},"Element/Matrix",[74,178,179],{},"Open-Xchange"," and ",[74,182,48],{}," under a shared management and identity layer. Dataport operates the suite from German data centres without a hyperscaler sub-processor. The Phoenix Suite is not directly available to SMEs, but a comparable stack can be obtained as ",[153,185,187],{"href":186},"/en/blog/opendesk-partner-program-2026","openDesk"," or as Nextcloud Hub 26 Spring with ",[153,190,192],{"href":191},"/en/blog/euro-office-microsoft-365-alternative-2026","Euro-Office"," from managed hosters.",[70,195,196,199,200,203,204,208],{},[74,197,198],{},"Pillar 2 – AI applications."," The commission explicitly aimed for a sovereign LLM stack – European models such as Aleph Alpha and Mistral, hosted by European-owned providers. ",[74,201,202],{},"Microsoft Copilot is not approved",", because the documented ",[153,205,207],{"href":206},"/en/blog/microsoft-copilot-flex-routing","Flex Routing outside the EU Data Boundary"," creates a BSI risk assessment that includes a peak-load exception – a state that is not acceptable for parliamentary data.",[70,210,211,214],{},[74,212,213],{},"Pillar 3 – Secure cloud."," Hosting in German data centres, European ownership, no US corporation as sub-processor. Concretely, this means CADA level 3 and above. The Bundestag works with the established public-sector IT service providers and with commercial vendors that follow the same logic.",[70,216,217,220],{},[74,218,219],{},"Pillar 4 – Collaboration services."," Wire as messenger, because BSI-certified. Video conferencing via Jitsi and BigBlueButton. Element/Matrix is grandfathered in as an existing component but is not the default. Phasing out Microsoft Teams is the first concrete deliverable of the strategy.",[70,222,223,226,227,230,231,235],{},[74,224,225],{},"Pillar 5 – Security architecture."," Cross-cutting. Identity through Keycloak, MFA mandatory, ",[74,228,229],{},"BSI IT-Grundschutz"," as the audit benchmark. We covered the relevant modules in detail in ",[153,232,234],{"href":233},"/en/blog/bsi-it-grundschutz-microsoft-365","BSI IT-Grundschutz and Microsoft 365"," – the Bundestag strategy uses the same grid for configuring the stack itself.",[110,237,239],{"id":238},"phoenix-suite-and-wire-the-two-concrete-components","Phoenix Suite and Wire – the two concrete components",[70,241,242,244,245,247],{},[74,243,88],{}," has been in productive use in Schleswig-Holstein, Hamburg, Bremen, Mecklenburg-Vorpommern and Saxony-Anhalt since 2023. Its operator ",[74,246,92],{}," is a public-law institution jointly owned by these five states – structurally outside the scope of the CLOUD Act. The suite is not directly licensable by private customers because it is tied to Dataport's ownership structure. For SMEs and private schools the same technical stack is available through other channels – see pillar 1.",[70,249,250,252,253,256,257,259,260,264],{},[74,251,96],{}," is a messenger founded in Berlin, today incorporated as a Swiss-German entity, with end-to-end encryption. The ",[74,254,255],{},"BSI certification under Technical Guideline TR-03174"," as of June 2026 covers key management, metadata minimisation, server location in Germany and audit capability. Wire is the only messenger with this certification in early summer 2026. ",[74,258,176],{}," is technically eligible for the same certification and is already in use by many public bodies – see ",[153,261,263],{"href":262},"/en/blog/microsoft-teams-alternative","Microsoft Teams alternative – Element/Matrix"," – but has not yet completed the TR-03174 review.",[110,266,268],{"id":267},"why-the-bundestag-template-is-an-opportunity-for-smes","Why the Bundestag template is an opportunity for SMEs",[70,270,271],{},"Three structural arguments:",[273,274,275,281,292],"ol",{},[121,276,277,280],{},[74,278,279],{},"A procurement grid on a single page."," The five-pillar method is a spreadsheet, not a political manifesto. If you, as IT lead of an 80-person SME or as IT manager of a school board with fifteen schools, translate the Bundestag path into your own organisation, you have a grid that is immediately understood in board meetings and school board discussions.",[121,282,283,286,287,291],{},[74,284,285],{},"BSI certification as audit evidence."," A BSI-certified messenger component such as Wire is a one-line proof in audits against NIS2 and the BSI IT-Grundschutz catalogue. A Microsoft Teams configuration takes several pages – and is still vulnerable, as our ",[153,288,290],{"href":289},"/en/blog/nis2-gdpr-microsoft-paradox","NIS2 and GDPR analysis"," shows.",[121,293,294,297,298,302,303,306],{},[74,295,296],{},"Reduce concentration risk."," The ",[153,299,301],{"href":300},"/en/blog/dora-microsoft-365-exit-strategy-banks-2026","DORA concentration-risk logic"," applies formally only to banks, but the underlying principle applies to any SME. Anyone who pushes all five pillars onto a single US corporation has a systemic risk on the balance sheet – and no recourse beyond Microsoft's service level agreements in the event of damage. The recent ",[74,304,305],{},"Exchange Online outage EX1331830"," on 2 June 2026 with more than six hours of mail delays across three continents made that point exemplarily.",[110,308,310],{"id":309},"migration-the-five-pillar-method-at-sme-scale","Migration – the five-pillar method at SME scale",[70,312,313],{},"The HowTo section above documents six steps for translating the method to SME scale. The sequence matters: first the procurement grid, then collaboration (messenger and video), then office (Nextcloud + browser office), then cloud migration of data holdings, then the identity layer, and only last AI. Starting with AI builds on shaky ground. Skipping collaboration keeps the most expensive and compliance-critical Microsoft share in operation.",[110,315,317],{"id":316},"glossary","Glossary",[118,319,320,325,330,335,340,346],{},[121,321,322,324],{},[74,323,100],{},": internal name of the Bundestag IT strategy of May 2026 for the step-by-step replacement of proprietary US software, tabled by the Lindholz commission.",[121,326,327,329],{},[74,328,88],{},": open-source-based workplace suite of the IT service provider Dataport, in productive use in five German states and, in time, in the Bundestag.",[121,331,332,334],{},[74,333,92],{},": public-law institution jointly owned by Schleswig-Holstein, Hamburg, Bremen, Mecklenburg-Vorpommern and Saxony-Anhalt; operator of the Phoenix Suite.",[121,336,337,339],{},[74,338,96],{},": end-to-end-encrypted messenger; as of June 2026 the only service certified under the BSI Technical Guideline TR-03174.",[121,341,342,345],{},[74,343,344],{},"TR-03174",": BSI Technical Guideline for secure messenger services. Covers encryption, metadata minimisation, key management, localisation and audit capability.",[121,347,348,350],{},[74,349,229],{},": methodical catalogue from the German Federal Office for Information Security, with modules for every IT component.",[110,352,354],{"id":353},"how-europioneer-plugs-in","How europioneer plugs in",[70,356,357,358,361,362,365,366,369,370,101],{},"europioneer operates the European open-source stack as a managed hosted service – Nextcloud Hub 26 Spring including Euro-Office and Collabora Online, Element on Matrix for chat (Wire connectivity in preparation), Open-Xchange for email, Keycloak for identity. Hosting in German and EU data centres without a hyperscaler sub-processor. For translating the Bundestag five-pillar method to an SME, a school board or a municipality, we deliver the procurement grid of step 1, the pilots of steps 2 and 3, and the configuration of the security and identity layer of step 5. Live view of the remaining Microsoft dependencies at ",[153,359,360],{"href":360},"/en/microsoft",". Component overview of the European stack at ",[153,363,364],{"href":364},"/en/alternativen",". Packages and prices at ",[153,367,368],{"href":368},"/en/pricing",". Pilot conversation at ",[153,371,373],{"href":372},"/en/contact?subject=Operation-Sovereignty-Pilot","/en/contact",[110,375,377],{"id":376},"conclusion","Conclusion",[70,379,380,383],{},[74,381,382],{},"In May 2026 the Bundestag adopted a procurement grid that every German SME and every school board can use as a template."," The five-pillar method is not a marketing story but a workable path: collaboration first, office second, cloud and identity as a consequence, AI deliberately last. The concrete product choice differs by organisation – the Phoenix Suite for state-level procurement, openDesk and Nextcloud Hub for SMEs, Wire as the BSI-certified messenger component everywhere. Anyone who sets the path now will not be under time pressure when the EU AI Act GPAI obligations enter into force on 2 August 2026 – and will be on firm procurement ground against CADA level 3 in early 2027.",[70,385,386],{},[153,387,388],{"href":372},"Request an Operation Sovereignty pilot →",[390,391],"hr",{},[70,393,394],{},[74,395,396],{},"Related posts:",[118,398,399,404,409,414,419,424,429,434],{},[121,400,401],{},[153,402,403],{"href":186},"openDesk Partner Program 2026 – the Sovereign Workplace for SMEs",[121,405,406],{},[153,407,408],{"href":191},"Euro-Office 1.0 – the sovereign Microsoft 365 alternative in technical practice",[121,410,411],{},[153,412,413],{"href":155},"CADA and the EU Tech Sovereignty Package – why level 3 is forcing German public bodies in 2026",[121,415,416],{},[153,417,418],{"href":262},"Microsoft Teams alternative – Element/Matrix in 2026 safely deployed",[121,420,421],{},[153,422,423],{"href":206},"Microsoft 365 Copilot Flex Routing – how the EU Data Boundary is being silently softened in 2026",[121,425,426],{},[153,427,428],{"href":233},"BSI IT-Grundschutz and Microsoft 365 – why the combination cannot be compliant",[121,430,431],{},[153,432,433],{"href":300},"DORA, CTPP designation and Microsoft 365 – why banks need a robust exit strategy in 2026",[121,435,436],{},[153,437,438],{"href":289},"NIS2 and GDPR with Microsoft 365 – the compliance paradox of German companies",{"title":440,"searchDepth":441,"depth":441,"links":442},"",2,[443,444,445,446,447,448,449,450],{"id":112,"depth":441,"text":113},{"id":160,"depth":441,"text":161},{"id":238,"depth":441,"text":239},{"id":267,"depth":441,"text":268},{"id":309,"depth":441,"text":310},{"id":316,"depth":441,"text":317},{"id":353,"depth":441,"text":354},{"id":376,"depth":441,"text":377},"2026-06-23T00:00:00.000Z","In May 2026 the German Bundestag approved an IT strategy to exit Microsoft 365. Five pillars, the Phoenix Suite, Wire – what SMEs can copy from it now.","md",[455,458,461,464,470],{"q":456,"a":457},"What does the Bundestag IT strategy of 2026 actually contain?","A strategy presented in May 2026 by a cross-party commission under Bundestag Vice President Andrea Lindholz. It defines a multi-year, step-by-step migration of the roughly 10,000 workplaces in Berlin and the constituency offices to European and open-source software. The strategy is organised in five pillars – office software, AI applications, secure cloud, collaboration services and a continuous security architecture. Microsoft 365 remains the default for now, but is to be replaced by the Phoenix Suite operated by the public-sector IT service provider Dataport, by the BSI-certified Wire messenger and by further sovereign components.",{"q":459,"a":460},"What is the Phoenix Suite and who operates it?","The Phoenix Suite is the open-source-based workplace suite of Dataport, a public-law institution jointly owned by the German states of Schleswig-Holstein, Hamburg, Bremen, Mecklenburg-Vorpommern and Saxony-Anhalt. The suite bundles Nextcloud, Collabora Online, Element/Matrix, Open-Xchange and Keycloak under a shared management and identity layer. Dataport operates the stack from German data centres without a hyperscaler sub-processor. For the Bundestag, Phoenix Suite is the central office component alongside Microsoft 365 and, in time, its successor.",{"q":462,"a":463},"Why did the Bundestag choose Wire as messenger?","As of June 2026, Wire is the only service certified by the German BSI under the Technical Guideline TR-03174 for secure messengers. The BSI assesses end-to-end encryption, metadata minimisation, key management, server location and audit capability. Wire demonstrably satisfies TR-03174. For a body with confidentiality and secrecy obligations like the Bundestag, BSI certification is not a nice-to-have but a procurement precondition. Matrix/Element is technically eligible for the same certification, but has not completed the TR-03174 review at this point.",{"q":465,"a":466},"Can the Bundestag strategy be transferred to SMEs or school boards?",{"Yes, in adapted form":467},{" The five-pillar methodology – office, AI, cloud, collaboration, security – is a procurement grid that an 80-person SME or a school board with fifteen schools can apply equally":468},{" The biggest lever lies in the sequence":469},"collaboration and office first, then cloud migration of data holdings, then AI strategy. Security is a cross-cutting concern. The concrete product choice differs – the Phoenix Suite is tailored to German state-level procurement, whereas an SME will typically pick openDesk, Nextcloud Hub or Euro-Office directly from a managed hoster.",{"q":471,"a":472},"Will Microsoft 365 remain in the Bundestag permanently?","No, but the transition takes several years. The strategy provides for a step-by-step replacement, not a cut-off date. Microsoft 365 remains in parallel with the Phoenix Suite for the time being. The Microsoft Teams share is the first to be phased out in favour of Wire, then the Outlook share in favour of the Open-Xchange components of the Phoenix Suite. Office and SharePoint follow with a longer lead time. The Lindholz commission has not adopted an end-date clause – the strategy commits to the path, not to a deadline.",{"name":474,"description":475,"totalTime":476,"steps":477},"Translating the Bundestag five-pillar method to an SME or school board","Six steps from the procurement grid to a productive replacement of Microsoft 365 in your own organisation.","P180D",[478,481,484,487,490,493],{"name":479,"text":480},"Translate the five pillars to your own organisation","On a single page, populate the five pillars – office, AI, cloud, collaboration, security – for your own organisation. For each pillar, note what is in use today (most often Microsoft 365, sometimes Google Workspace) and what should be permitted going forward. This table becomes the procurement guideline for the next two years. It is signed off by management and serves as the basis for any subsequent supplier selection.",{"name":482,"text":483},"Tackle the collaboration pillar first – messenger and video conferencing","Microsoft Teams is the largest compliance lever with the weakest technical lock-in. Introduce Wire as a BSI-certified messenger component, Jitsi or BigBlueButton for video conferencing. A pilot group of ten to thirty people uses the new tools productively for six weeks. Only then do you proceed to broad rollout. In schools, start with administration and leadership, then teachers, then students.",{"name":485,"text":486},"Office pillar – Nextcloud and Euro-Office or openDesk","Set up Nextcloud Hub 26 Spring as the file and collaboration platform, either managed at a German hoster or in your own data centre. Activate Euro-Office or Collabora Online as the in-browser office engine. For public bodies tied to a German state, openDesk is an alternative because it bundles ZenDIS support. Make the choice per tenant, not organisation-wide.",{"name":488,"text":489},"Cloud pillar – hosting on a European-owned provider","Pick a hosting provider that meets CADA sovereignty level 3 – European ownership, no hyperscaler sub-processor. In early summer 2026, the typical choices are Hetzner, IONOS, OVHcloud, Plusnet and STACKIT. Verify in concrete terms that the platform components Nextcloud, Wire and Open-Xchange run under a data processing agreement without any third-country transfer.",{"name":491,"text":492},"Security pillar – identity layer and certificates","Use Keycloak as the central identity layer for single sign-on across all applications. Multi-factor authentication is mandatory. The BSI IT-Grundschutz modules APP.5.2, OPS.2.2 and CON.3 serve as a checklist for configuring the individual applications. A one-off external audit by an ISO 27001 certifier documents the state and can later be reused for DORA, NIS2 and CADA level 3 evidence.",{"name":494,"text":495},"AI pillar – sovereign LLM connection or conscious abstention","In early summer 2026, the AI pillar is deliberately configured last. If you must migrate now, choose sovereign LLM endpoints – Aleph Alpha, Mistral as European models, OpenAI only via European-owned resellers. Microsoft Copilot is not approved because of Flex Routing outside the EU Data Boundary. If you have no immediate AI need, wait out the EU AI Act GPAI obligations of 2 August 2026 and decide afterwards.",{"src":497},"https://images.unsplash.com/photo-1560969184-10fe8719e047?w=1200&q=80",{},true,"/en/blog/bundestag-operation-sovereignty-microsoft-exit-2026",{"title":53,"description":452},"en/3.blog/17.bundestag-operation-sovereignty-microsoft-exit-2026","LOOtj3lK2kFO-Jjarc6k2prh1JMrBuCSBqSg1oBLUB0",[505,509],{"title":506,"path":191,"stem":507,"description":508,"children":-1},"Euro-Office 1.0 – the sovereign Microsoft 365 alternative in a technical hands-on review","en/3.blog/16.euro-office-microsoft-365-alternative-2026","Euro-Office 1.0 launched on 9 June 2026 as a European Microsoft 365 alternative. What the suite delivers technically and who should adopt it now.",{"title":510,"path":511,"stem":512,"description":513,"children":-1},"EU AI Act – What German SMEs must document for Microsoft Copilot by 2 August 2026","/en/blog/eu-ai-act-microsoft-copilot-smes-august-2026","en/3.blog/18.eu-ai-act-microsoft-copilot-smes-august-2026","On 2 August 2026 the EU AI Act's GPAI obligations kick in. What SMEs must now document for Microsoft Copilot and which sovereign alternatives hold up.",1784618209880]