Cyso Cloud vs SAP

Compare Cyso Cloud and SAP on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Microsoft Azure

Logo: Cyso Cloud

Cyso Cloud

Netherlands· Cloud Computing

Needs review

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)
Logo: SAP

SAP

Germany· Cloud Computing

Needs review

Shortlist SAP when you need S/4HANA-class ERP breadth under a German parent entity and can fund a structured implementation. Skip when you want lightweight self-serve finance SaaS without a transformation partner. Consider Salesforce when CRM is the system of record, or a Microsoft Dynamics / Azure-centric stack when identity and productivity are already standardised on Microsoft.

EU-operatedFull ERP suiteS/4HANA CloudISO 27001 (claimed)B2B DPA published
Cyso Cloud vs SAP: Snapshot
FeatureLogo: Cyso CloudCyso CloudLogo: SAPSAP
Country of originNetherlandsGermany
CategoryCloud ComputingCloud Computing
Open sourceYesNo
Self-hostedNoYes
HeadquartersNetherlandsGermany
Legal entityCyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395SAP SE, Dietmar-Hopp-Allee 16, 69190 Walldorf (Mannheim HRB 719915)
Governing lawNot listedGerman entity; order forms may name local SAP affiliates
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
EU-hosted statusNot listedPartial
Hosting / residencyPrimary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.Mixed: SAP-operated data centers (including Walldorf / St. Leon-Rot, Germany) plus Enterprise Cloud Services documented on AWS, Microsoft Azure, Google Cloud Platform, or customer data centers. Product-specific subprocessor lists are primarily on My Trust Center for customers.
Summary

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

German-headquartered enterprise ERP suite (SAP Cloud ERP / S/4HANA) for finance, supply chain, procurement, and HR.

Tags
At a glance: Cyso Cloud vs SAP
At a glanceLogo: Cyso CloudCyso CloudLogo: SAPSAP
HQAlkmaar, NetherlandsWalldorf, Germany
Legal entityCyso B.V. (Cyso Group)SAP SE (HRB 719915 Mannheim)
Founded1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 2025Not listed
RegionsAmsterdam, Frankfurt (more under investigation)Not listed
StackOpenStack + managed Kubernetes (KCSP)Not listed
Commercial modelPay-as-you-go / hourly; optional trial via salesEnterprise subscription and licences (quote-based)
Product focusNot listedCloud ERP / S/4HANA
Open sourceNot listedNo
Data residency regionsNot listedCustomer-selectable; Americas, Europe, Asia Pacific (incl. SAP DE sites and hyperscalers)
Compliance certs (claimed)Not listedISO 27001, SOC 1/2, BSI C5, plus regional attestations via Trust Center
Key capabilities: Cyso Cloud vs SAP
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: SAPSAP
EU-operated (NL)YesYes
OpenStack IaaSYesNot listed
Managed Kubernetes (KCSP)YesNot listed
AMS + FRA regionsYesNot listed
ISO 27001 (claimed)YesYes
NEN 7510 (claimed)YesNot listed
Full ERP suiteNot listedYes
S/4HANA CloudNot listedYes
B2B DPA publishedNot listedYes

Cyso Cloud

  • OpenStack public IaaS on EU hardware

    Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

  • S3-compatible NVMe object storage

    Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

  • Enterprise Managed Kubernetes (KCSP)

    CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

  • European networking and multi-AZ design

    VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

  • Private cloud and wholesale options

    Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

SAP

  • SAP S/4HANA Cloud ERP core

    Public and private cloud editions cover finance, supply chain, procurement, sales, and related processes on an in-memory data model with role-based UX. Scope and extensibility differ between Public Edition (standardised) and Private Edition (closer to classic on-premises flexibility).

  • GROW and RISE packaging

    SAP GROW targets organisations starting on standardised AI-enabled cloud ERP. RISE with SAP supports existing on-premises customers migrating toward cloud with transformation services. Packaging choice drives implementation shape more than feature marketing slides.

  • Integration via SAP BTP

    SAP Business Technology Platform and Integration Suite provide APIs, iPaaS connectivity, and extension points to link SAP ERP with third-party and legacy systems. Expect integration projects rather than plug-and-play SMB connectors.

  • Selectable cloud regions and sovereign options

    Customers can choose data center regions; SAP documents Americas, Europe, and Asia Pacific availability, including SAP-operated German sites and hyperscaler regions. Sovereign / regulated options (for example German IT-Grundschutz messaging for SAP-owned facilities) exist but must be contracted explicitly.

  • Trust Center compliance artifacts

    SAP publishes ISO 27001, SOC, C5, and other certificates plus DPAs through the Trust Center and customer portals. Audit reports for specific services are often gated to customers rather than fully public PDFs.

Assurance & compliance: Cyso Cloud vs SAP
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: SAPSAP
Independent security / no-logs audit
Not found

Security measures and pen-testing philosophy are described; no public independent no-logs or IaaS audit report found beyond ISMS certs.

Not applicable

ERP suite; not a no-logs privacy network product. Rely on SOC/ISO/C5 attestations instead.

ISO 27001
Vendor claimed

Vendor publishes ISO/IEC 27001 certificate PDF via Trust Centre / certifications (listed expiry into 2028). Not re-checked on an independent registry for this draft.

Vendor claimed

Trust Center lists ISO 27001 certificates for cloud services and publishes certificate finder entries (e.g. Central / Enterprise Cloud Services).

SOC 2 / SOC 3
Not found

Certifications page explains SOC 2 Type II generally; no clear statement that Cyso currently holds a published SOC 2 report.

Vendor claimed

SOC 1 and SOC 2 reports described on Trust Center; many reports customer-gated via SAP for Me / My Trust Center.

GDPR / EU data protection
Vendor claimed

EU legal entity; AMS/FRA residency claims; Trust Centre GDPR section. Obtain DPA and TOMs for controller/processor mapping.

Vendor claimed

EU parent entity; Trust Center privacy pages and DPAs reference GDPR processing terms.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, primary IaaS claimed on self-operated NL/DE hardware (not AWS/GCP/Azure). Partial because no full public subprocessor schedule and ancillary SaaS (e.g. PostHog analytics, Atlassian-linked status) may involve non-EU providers. Not legal advice.

Partial

German SAP SE parent with no known US parent, but Enterprise Cloud Services explicitly include AWS, Azure, and GCP paths. Medium exposure for hyperscaler-backed tenants. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Marketing (e.g. Azure alternative pages) states Cyso signs a DPA under Dutch law; confirm current template and subprocessor annex in contracting.

Vendor claimed

SAP states it signs DPAs; Trust Center hosts Data Processing Agreement documents for cloud, support, and professional services.

NEN 7510 (Dutch healthcare information security)
Vendor claimed

Vendor publishes NEN 7510 certificate PDF on certifications/Trust Centre pages.

Not listed
EU AI Act
Not applicable

IaaS/infrastructure platform, not an AI system product.

Partial

SAP publishes EU AI Act governance materials for Joule Agents and AI features; customer still must assess in-scope AI uses.

BSI C5Not listed
Vendor claimed

Trust Center lists Cloud Computing Compliance Controls Catalogue (C5) audit reports among EU regional offerings.

Considerations & known limitations: Cyso Cloud vs SAP
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: SAPSAP
Only two live public regions
Medium

Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

Not listed
No default object storage encryption at rest
Medium

Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

Not listed
Incomplete public subprocessor inventory
Medium

Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

Not listed
Certifications are vendor-published PDFs
Low

ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

Not listed
Smaller ecosystem than hyperscalers
Low

Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Not listed
Hyperscaler hosting is commonNot listed
Medium

Even with a German parent, many cloud tenants run on AWS, Azure, or GCP. EU region selection does not remove US-group infrastructure operators from the path. Confirm contracted region and subprocessors.

Heavy implementation programmesNot listed
Medium

S/4HANA and RISE projects typically need partners, data migration, and process redesign. Poor fit if you expected self-serve SaaS onboarding.

Detailed subprocessor lists often customer-gatedNot listed
Low

Public pages confirm lists exist on My Trust Center, but a full anonymous dump was not available in this research pass. Request the list for your exact cloud service before security sign-off.

Catalog category is Cloud Computing, not ERPNot listed
Low

EuropeanStack has no dedicated ERP category yet. This entry is filed under Cloud Computing as the closest existing slug.

Fit

Cyso Cloud

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

SAP

Best fit when

  • Midsize to large enterprises consolidating finance, supply chain, and procurement on one ERP
  • Organisations that need deep industry process templates and multi-country localisation
  • Buyers that require a German / EU parent contracting entity plus formal Trust Center attestations
  • Existing SAP ECC customers planning a RISE or S/4HANA transformation
  • Teams with budget for partner-led implementation rather than pure self-serve SaaS

Poor fit when

  • Startups or SMBs needing only simple invoicing without ERP programme overhead
  • Buyers that require a guaranteed EU-only, non-hyperscaler hosting path without reading the contract region
  • Teams seeking an open-source ERP they can fork and fully self-operate without vendor lock-in
  • CRM-first organisations where Salesforce-class customer platforms are the real system of record

Consider instead when

  • When: Your primary system of record is CRM and revenue operations, not manufacturing or complex finance

    Consider: Salesforce

    Stronger CRM depth; US parent and different compliance posture.

  • When: You already standardise on Microsoft identity, M365, and Azure and want ERP in that estate

    Consider: Microsoft 365 / Azure-centric Dynamics stacks

    Compare total cost of identity + productivity + ERP under one US vendor.

  • When: You need a smaller European mid-market ERP without S/4HANA transformation scope

    Consider: Evaluate EU mid-market ERP vendors outside this catalog (no peer ERP slug listed yet)

    Catalog currently lacks a direct European ERP alternative entry.

Open questions for due diligence

Cyso Cloud

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

SAP

  • Which exact cloud service and region would this buyer contract (Public Edition vs Private Edition vs RISE on which hyperscaler)?
  • Will the order form be with SAP SE or a local affiliate, and which governing law clause applies?
  • Can the vendor provide the current subprocessor list and SOC/C5 reports for the specific service code without an existing customer login?