The monthly briefing for IT services founders, investors, and M&A advisors.
In This Edition
Three weeks ago, the iX-Magazine investigation into sovereignty washing landed. The next morning, thirty-one founders and investors were in my inbox asking the same question: how do you actually evaluate this? This edition is the answer. The European Cloud Sovereignty Report 2026, the evidence-based mapping of seventeen relevant European sovereign cloud offerings, was published just this month. The deal market is repricing accordingly.
Five minutes. That is all you need. Let's go.
What I See Right Now · How to read a sovereignty pitch
Featured Report · European Cloud Sovereignty Report 2026
Expert Spotlight · Stefan Biehler on six dimensions of sovereignty
Deal Radar · Seven headline deals plus a wider April and May sweep
On My Radar · EU Commission tender, EU AI Act shifts, AWS audit milestones, Germany's €250M AI bet
What I See Right Now
Sovereignty Washing: How to See Through the Marketing
Every cloud provider selling into Europe right now claims to be sovereign. Read the marketing pages and you would think the problem has been solved.
It has not. Earlier this year I started looking at this market more seriously. tecRacer, the AWS Premier Partner where IT Capital Fund I holds the majority, was selected as a launch partner for AWS European Sovereign Cloud, which forced me to understand the landscape from the inside. The public debate on the topic at the time was emotional, black-and-white, and dominated by high-level marketing claims. I started with a simple Excel for myself, just to map out who actually offered what. After posting the structured comparison on LinkedIn, the feedback came in from KRITIS providers, insurers, regulated-industry startups, and almost every relevant sovereign cloud vendor in Europe. That feedback turned the Excel into the Sovereign Cloud Compass.
The Compass now underpins two publications this month. Three weeks ago, iX-Magazine ran "Sovereignty Washing" on heise.de. This month, the European Cloud Sovereignty Report 2026 was published: 17 providers, 31 criteria, 334 verifiable sources, fully mapped to the EU Cloud Sovereignty Framework.
What the data shows is uncomfortable for both sides of the Atlantic. There is no overall winner. There are providers with strong governance but weak technical guardrails, and providers with strong technical guardrails but structural jurisdictional exposure. Almost every provider has at least one open flank. The marketing rarely tells you which one. Three findings stand out.
The GmbH facade.
US hyperscalers stand up EU subsidiaries, populate advisory boards with EU citizens, and brand the result as sovereign. Microsoft Sovereign Cloud scores 0.9 out of 5 on Law and Jurisdiction. AWS European Sovereign Cloud reaches 2.1. The technical guardrails (Nitro System, Confidential Computing, full audit evidence) are often more robust than at European competitors. But the legal exposure to FISA 702 and the CLOUD Act is structural. No GmbH construction changes that.
The EU flag as a shield.
European providers raise EU ownership as if it ended the discussion. It does not. Several providers score 5 out of 5 on EU ownership and 0 or 1 out of 5 on Confidential Computing. That means no hardware-level workload isolation: an admin with kernel access can read the memory of your VM in cleartext. EU ownership without technical guardrails is sovereignty theater, just in the other direction.
Cryptography is the market's weak point.
The market average across all 17 providers on Cryptography and Key Control is 2.09 out of 5, the lowest of any sovereignty axis. Operator Access Exclusion sits at 1.94. EU root certificate authorities at 1.59. Independent sovereignty advisory boards at 0.47. This is where the next two years of competitive differentiation will be decided. Providers that close this gap and document it transparently will win regulated workloads. Those that keep marketing the EU flag instead will not.
The point of the Compass and the Report is not to crown a winner. It is to give IT decision-makers a vendor-neutral way to make a choice they have to make anyway, on the dimensions that actually matter for their specific workload. A KRITIS operator under NIS2 will weight different criteria than a financial services firm under DORA. The Compass lets them. For IT services founders and investors, this market is at an inflection point: the providers who close the Cryptography gap visibly will move ahead, and the M&A premiums will follow.
"Sovereignty is risk management, not a creed. Those who cannot measure it do not decide; they follow the most convincing narrative."
The first independent, evidence-based market analysis of European sovereign cloud offerings, fully mapped to the EU Cloud Sovereignty Framework. Authored by Jörn Petereit, creator of the Sovereign Cloud Compass. Free download.
Stefan Biehler: Six Dimensions of Sovereignty, From Inside KRITIS
Stefan Biehler
Enterprise Architecture & IT Strategy · Leading German statutory health insurer
Stefan Biehler covers enterprise architecture and IT strategy at one of Germany's largest statutory health insurers. Previously sixteen years as Head of Enterprise Architecture at RWE. Over twenty-five years of experience inside critical infrastructure organisations at the intersection of strategy, regulated industry, and IT evaluation.
IT Capital Partners: Stefan, you have spent 25 years at the point where cloud adoption moves from strategy to reality. When a provider knocks today with "sovereign cloud," what is your first reflex?
Stefan Biehler: Two words: skepticism and curiosity. Over the past three years the word "sovereign" has been stretched and reinterpreted so broadly that it carries little meaning on its own. Every organisation has to define how it wants to measure sovereignty and, more importantly, how it intends to manage sovereignty risks. My first reflex is therefore always the same question: sovereign in which dimension? Legally, meaning under which jurisdiction? Technically, meaning support for open standards and the degree of portability and exit capability? Operationally, meaning EU-only personnel with access? Commercially, meaning ownership inside the EU or in third countries? Supply chain, meaning how deep is the dependency on non-EU vendors? Compliance, meaning is NIS2-conformity of the workloads even feasible?
These dimensions are routinely conflated in vendor pitch decks. Only once you separate them cleanly do you get to a usable assessment. That is exactly why I find the Sovereign Cloud Compass useful: it forces this separation into a measurable form.
IT Capital Partners: What has actually changed in evaluation over the past 24 months? C5, NIS2, and the EU AI Act are now in force or about to be. Where is the substance, where is the compliance theater?
Stefan Biehler: Regulation has done two things. First, it has provided the guardrails that were missing from vendor conversations before. Regulation replaces a vague feeling of sovereignty with concrete requirements: legal conformity, compliance, vendor lock-in, exit strategies, critical functions, concentration risk. Under NIS2, the entire health insurer is classified as a "particularly important entity." NIS2 defines obligations not only for KRITIS-relevant IT systems, but for every process and every IT solution relevant to service delivery. The implementation work is substantial, but it is useful.
Second, C5 certification requires an audit apparatus in which provider and user now have to document jointly what was previously undocumented. That is useful too. Where I see theatre: C5 certification is legally required for cloud computing in healthcare, but the term "cloud computing" itself is not unambiguously defined. Private-cloud providers in particular may not feel obligated to demonstrate C5 certification for every service, leaving you to rely solely on the provider's self-declaration. BSI C5 Type 2 made the difference because it is an auditor-led process with sample testing. Pure self-declarations shift the risk, they do not reduce it. The next 18 months will show which providers can manage the transition from marketing sovereignty to auditable sovereignty.
IT Capital Partners: EU providers versus US hyperscalers with sovereign-cloud offerings. From the user side, what are the real trade-offs?
Stefan Biehler: The trade-off is not binary. EU providers structurally have the cleaner legal position: no FISA 702, no CLOUD Act, clear European ownership. What organisations fear most is business interruption caused by political decisions in the provider's home country. Here, EU providers are clearly ahead of the US hyperscalers. Whether to carry that risk with a US hyperscaler is a business decision. Where EU providers are still behind: in the breadth and technical depth of IT security and cryptography mechanisms, for example confidential computing models, key management technologies such as Customer Key, and complete audit trails across all administrative access. The hyperscalers' technology lead in those areas is simply enormous.
The US hyperscalers address sovereignty requirements through European operating entities, supervisory boards, and technical isolation at the network layer. But the risk of an operating ban remains. What a KRITIS operator has to do in practice is decide at the workload level. A master-data system holding insured-member data must meet stricter sovereignty requirements than an office solution.
IT Capital Partners: In the European Cloud Sovereignty Report 2026 the market average for Cryptography and Key Control sits at 2.09 out of 5, the weakest score across all six axes. From your practice: does this gap affect you today, or is it more a topic for the next two years?
Stefan Biehler: The finding does not surprise me. It does affect us, but in a different place than most people think. The actual problem is not the availability of encryption technology and key management solutions. They are available, but they often have to be set up and operated by the customer, which is far from an integrated solution. BYOK or Customer-Controlled Key sound straightforward on a marketing slide. In practice it requires a key management system that can be integrated into applications in an operationally safe way.
In large migrations we often face the decision whether to start with the provider's out-of-the-box encryption and switch to BYOK only in a second wave. That illustrates why the market average sits at 2.09: many providers have the building blocks, but not the tooling maturity that would let a customer use them without significant engineering effort. From my point of view, this is the largest differentiation opportunity for providers over the next two years.
IT Capital Partners: What advice would you give IT services founders who want to address KRITIS organisations as customers, especially in the current sovereignty wave?
Stefan Biehler: Three things. First, lead with functionality, not sovereignty. Position sovereignty as an integral part of the solution, not as your sales argument.
Second, you need audit evidence, not marketing statements. Your solution has to be legally compliant, particularly on geographic data restrictions and operator access. Looking ahead, the solution will need to fulfil C5, ISO 27001, or comparable standards, otherwise it will not get through our supplier evaluation. Third, plan for contract terms of several years. KRITIS organisations are thorough in evaluation, because the regulatory risk is high. That is not an obstacle, it is the entry barrier. Once cleared, it leads to very stable customer relationships. Those who can endure it build customer relationships over many years, not two.
Deal Radar
My picks from April and May 2026. The theme this month writes itself: sovereignty, European platform building, and the AI labs that big enterprises are buying instead of building.
🛡️ Airbus to acquire Quarkslab (France) • 21 April 2026
Airbus Defence and Space signed for the Paris and Rennes based sovereign cyber specialist (around 100 employees, Tikehau-backed). Combined with Ultra Cyber (UK, March) and Infodas (Germany, 2024), Airbus now runs cyber activity across FR, UK, DE, ES, FI. A pan-European sovereign cyber play built deal by deal. If you are building cyber capability with European jurisdiction at the core, your strategic buyer set just got more aggressive.
🛰️ Sopra Steria completes Starion and Nexova (Europe-wide) • Closing 30 April 2026
Sopra Steria's CS Group closed Starion and Nexova: around 700 engineers across nine European countries, roughly €100M revenue, anchored by ESA, EUMETSAT, national defense ministries. The combined CS Group now passes €200M revenue in space and cybersecurity. Sopra Steria's framing in the release reads like a thesis statement for the segment: "Escalating global geopolitical tensions and rising stakes in European digital sovereignty offer a double-digit growth outlook." Critical-systems integration with EU jurisdiction is now a growth category, not a niche.
🧠 SAP to acquire Prior Labs (Germany) • 4 May 2026
SAP committed more than €1 billion over four years for Freiburg-based Prior Labs, the pioneer of Tabular Foundation Models. The 18-month-old company (founders Frank Hutter, Noah Hollmann, Sauraj Gambhir) continues as an independent unit, positioned by SAP as "a globally-leading frontier AI lab for structured data, in Europe." TabPFN downloads passed three million. One of the largest German venture exits ever, and the clearest signal yet that European corporates would rather buy a frontier AI lab than try to build one.
🔐 DBAG and Direttissima invest in Bug Bounty Switzerland • 29 April 2026
DBAG took a minority stake in Lucerne-based Bug Bounty Switzerland as its seventh Long-Term Investment, alongside lead investor Direttissima Growth Partners. BBS combines around 16,000 ethical hackers with AI-driven testing under its Cyber Resilience Shield platform. DBAG's framing was direct: "AI is structurally expanding attack surfaces." The Mittelstand version of the Quarkslab logic: regulated buyers want continuous testing under European jurisdiction, and the platforms that can deliver it are now PE-priced.
KKR-backed DATAGROUP signed Eindhoven-based Valid Managed Services: around 180 employees, €35M revenue, Modern Workplace plus infrastructure, network, security. This is DATAGROUP's first acquisition outside Germany and the opening move of its declared strategy "to become a leading European IT services provider." For Dutch, Belgian, and Austrian mid-cap MSPs in the €20 to €60M revenue range, the buyer set just expanded by one well-capitalized, German-anchored platform that has yet to fire its first integration shot.
☁️ IG&H acquires CloudNation (Netherlands) • 28 April 2026
IK Partners-backed IG&H, an Utrecht digital transformation consultancy in financial services, healthcare and retail, acquired CloudNation from Atomic Group: 60+ AWS and Azure engineers with cloud-native and AI delivery capability. The CEO framing was unusually honest: "Many organisations struggle to move from strategy to execution. With CloudNation we gain the competence to realise cloud and AI transformations effectively." Strategy consultancies acquiring cloud and AI engineering shops to close their execution gap is the dominant Benelux pattern. Engineering-heavy specialists with €5 to €30M revenue and a working AI practice are now on every digital consultancy's target list.
🤖 Accenture acquires Keepler Data Tech (Spain) • 8 April 2026
Accenture acquired Madrid-headquartered Keepler, a cloud-native AI and data specialist with around 240 people across Madrid, London, and Lisbon. Coverage spans data strategy, cloud-native foundations, and generative and agentic AI deployment, including ethical-AI and compliance frameworks. Following the Faculty closing in Q1, Accenture's pattern of buying European AI capability rather than scaling it organically extends to Iberia. The EMEA AI consolidation wave is reaching beyond France and the UK.
Also noteworthy in April and May 2026: Afinum acquires Frankfurt GRC and cyber specialist sequrio, third Afinum X platform (27 April) • EITCO (Adelis) signs DMSFACTORY for DMS and ECM (1 April) • Dataciders (Rivean) acquires DataSpark from Possehl, agentic AI and RPA (13 April) • Communardo (Bregal) signs Aety, Copenhagen Atlassian, completing its pan-Nordic platform (30 April) • MAIT (DBAG VIII) acquires Belgian 4ITEGO, €43M revenue, PTC and Ansys for Benelux manufacturing (15 April) • Nord Holding takes majority in VisionmaxX for ca. €160M at 13.3x EBITDA, German dental MSP (15 April) • Five Arrows-backed BioPhorum acquires PharmaX Solutions, 50 professionals across four European offices (7 May) • Verdane and Telenor establish 50/50 JV in Telenor Connexion at SEK 7.5bn enterprise value, 18x EBITDA, top 10 global IoT platform with 31M SIM cards (12 May).
The Pattern I See
Three themes connect the deals this month. First, sovereignty has moved from positioning to balance sheet. Airbus, Sopra Steria, DBAG's bet on Bug Bounty Switzerland, and the Quarkslab and Starion exits are not isolated. They are a coordinated repricing of European cyber, space, and resilience specialists with EU and Swiss jurisdiction at the core. Second, Europe is buying its AI and engineering labs back. SAP's €1 billion plus commitment to Prior Labs is the headline signal, but the pattern repeats across IG&H, Accenture, and the smaller DACH PE deals: strategic and PE buyers would rather acquire AI and cloud capability than try to scale it organically. Third, the cross-border IT services platform build is in full swing. DATAGROUP's first international acquisition twelve months into KKR ownership, Communardo completing its Nordics platform, MAIT moving into Benelux manufacturing, Verdane structuring a global IoT carve-out. If you are a specialist in cyber, sovereign cloud, AI engineering, public-sector digitalization, or vertical managed services with EU footprint, the buyer set just got deeper and the valuation conversation just got more serious.
A Note From Me
Quick note on the fund Eike and I are building
This newsletter usually tracks what others are doing. Since the sovereignty theme this month sits inside the segment Eike and I are actively investing in, a brief transparency note.
IT Capital Fund I is a DACH small-cap buyout fund. The strategy: acquire profitable IT services companies (€5 to €30m revenue) and build them into European champions through operational excellence and programmatic Buy and Build. The framework comes directly from scaling Cloudflight from €25m to €100m revenue and exiting at €400m to Partners Group as COO and CFO.
Portfolio in action: tecRacer (the AWS Premier Partner referenced earlier) is the first platform investment, with KAWA commerce (Austria) as the first closed add-on. Fundraising is ongoing toward a Q4 2026 close.
IT Capital Partners
FUND MEMORANDUM · 2026
IT Capital Fund I.
Operator-led investing in European IT Services.
01 Who we are
02 Investment strategy
03 Portfolio in action
04 Pipeline & deployment
05 Fund terms & structure
itcapital.de
Strictly Confidential
54 pages · PDF · Under NDA
For professional or semi-professional investors who would like to learn more, simply reply to this email. I will share the password personally for access to the fund page, where the full Fund Memorandum can be requested against NDA.
Marketing communication. Directed exclusively at semi-professional and professional investors per §1 (19) No. 32 and 33 of the German Capital Investment Code (KAGB). Not an offer or solicitation.
On My Radar
Five Things I Am Tracking
Market Validation
The EU Commission puts its money where its sovereignty mouth is
On 17 April the European Commission awarded its €180M six-year sovereign cloud framework to four providers: a Post Telecom, OVHcloud and CleverCloud consortium, STACKIT (Schwarz Group), Scaleway (Iliad Group), and a Proximus-led group using S3NS, Clarence and Mistral. No US hyperscaler on the list, even those with sovereign-cloud branding. The Commission developed its own sovereignty assessment methodology to score bidders. Read this as the most concrete validation yet that criteria-based, vendor-neutral sovereignty evaluation is now standard procurement practice for European public buyers.
EU co-legislators reached a political agreement on the Digital Omnibus on 7 May. High-risk Annex III obligations move from 2 August 2026 to 2 December 2027. The SME-simplified compliance framework now also covers mid-caps up to 750 employees and €150M revenue. Unchanged: GPAI (in force since August 2025), Article 50 chatbot transparency (still 2 August 2026), and watermarking for AI-generated content (grace period to 2 December 2026 for systems already in market). Net effect: Annex III planning gets sixteen extra months, but watermarking remains the nearest live deadline.
AWS European Sovereign Cloud hits its first audit milestones
Live since 15 January 2026 in Brandenburg, the region this month achieved SOC 2 and BSI C5 reports plus seven ISO certifications, the first independent compliance evidence behind the design promises. In the European Cloud Sovereignty Report 2026 the AWS European Sovereign Cloud scored 2.1 out of 5 on the Law and Jurisdiction axis based on documented commitments. The audit reports start to convert commitments into verifiable evidence. The next iteration of the Compass will reflect that.
Disclosure: tecRacer, the AWS Premier Partner in which IT Capital Fund I holds the majority, is an AWS European Sovereign Cloud launch partner in DACH. I am watching this from both inside and outside the project.
Germany commits €250M to AI sovereignty and bets on the usual suspects
On 27 May the German federal government committed €250M to the new Agentic AI Hub. Allocation: €175M (70 percent) to a T-Systems and SAP consortium, €75M (30 percent) to a consortium around Wiesbaden-based SVA. Sovereignty critics including netzpolitik.org immediately questioned whether channelling this much capital through the largest incumbents actually advances sovereignty or simply concentrates dependencies. The deeper question for IT services founders: when sovereignty becomes a public procurement category, the route to those budgets often runs through partnerships with the anchor consortium members, not around them.
For readers who appreciated this edition on sovereignty, I want to flag a related framework I published earlier this year. The AI-Native Maturity Ladder is the five-level model I use to screen every IT services target. Level 1 is AI-curious, Level 5 is AI-first. Roughly 70% of DACH IT services companies sit on Level 1 or 2, only 8% reach Level 4. The arbitrage between Level 2 and Level 3-4 is where premium pricing will concentrate over the next 36 months. The full methodology is open.
If anything in this edition resonated, I would love to hear from you. Whether you are building an IT services company, evaluating where sovereignty actually matters in your stack, or simply want to exchange perspectives on where this market is heading, my door is always open.
If you are building, integrating, or considering an exit in IT services, I have probably sat in a version of your seat already. Drop me a line.