Skip to main content
Back to Glossary
Digital

Cloud Procurement

Procurement procedure for cloud services (SaaS, IaaS, PaaS) for public administration with special requirements for data protection, IT security, and digital sovereignty.

What is Cloud Procurement?

Cloud Procurement refers to tender procedures where public authorities procure cloud services (SaaS, IaaS, PaaS). These procurements have special requirements for data protection, IT security, digital sovereignty, and contract design.

Key Drivers

  • OZG (Online Access Act): Digitalization of government services
  • German government cloud strategy: Multi-cloud approach
  • GAIA-X: European cloud ecosystem
  • BSI C5: Cloud security standard
  • GDPR: Data protection requirements

Special Requirements

Data protection: EU/EEA-only data processing, data processing agreements, no third-country access, data portability at contract end.

IT security: BSI C5 attestation, ISO 27001, encryption, penetration testing, incident response.

Digital sovereignty: Open-source preference, vendor lock-in avoidance, data portability, interoperability, subcontractor transparency.

Cloud Service Models

ModelDescriptionTypical Tender
SaaSSoftware as a ServiceE-filing, DMS, collaboration
IaaSInfrastructure as a ServiceServers, storage, network
PaaSPlatform as a ServiceDevelopment platforms
Private CloudDedicated infrastructureHigh-security applications
Sovereign CloudCloud under German/EU controlGovernment cloud

BSI C5 – Cloud Security Standard

AspectC5 Type 1C5 Type 2
ScopeControl designDesign + effectiveness
PeriodPoint-in-timeMin. 6 months
AssuranceBasic levelHigher security

Patterno Helps

With Patterno-HIT, you can identify public sector cloud tenders. Our AI recognizes cloud-specific requirements (BSI C5, EVB-IT Cloud, GDPR compliance) and filters matching procurements for cloud providers.

Find Matching Tenders

With Patterno you automatically find relevant tenders - based on your profile.

Start for free