Open Telekom Cloud vs STACKIT

Compare Open Telekom Cloud and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure

Logo: Open Telekom Cloud

Open Telekom Cloud

Germany· Cloud Computing

Needs review

Shortlist when you need a German Telekom/T-Systems OpenStack public cloud with DE/NL/CH regions and a strong BSI C5/ISO/TISAX package for regulated or public-sector workloads. Skip when you need hyperscaler global PaaS breadth or pure self-hosted OpenStack—consider OVHcloud, Scaleway, or AWS/Azure for those cases.

EU-operated (T-Systems)OpenStack public IaaSBSI C5 Type II (claimed)DE / NL / CH regionsGPU + ModelArts AIPay-as-you-go
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
Open Telekom Cloud vs STACKIT: Snapshot
FeatureLogo: Open Telekom CloudOpen Telekom CloudLogo: STACKITSTACKIT
Country of originGermanyGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityT-Systems International GmbH (Deutsche Telekom group); product marketed as T Cloud Public / Open Telekom CloudSchwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawGerman / EU law for the cloud service (confirm contract)Germany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyPrimary: Telekom/T-Systems twin-core data centers in Germany (Biere/Magdeburg), Netherlands (Amsterdam region), and Switzerland (Bern/Zollikofen). No public indication that AWS, Azure, or GCP is the primary IaaS host. Backups/DR via platform multi-AZ services. Full public subprocessor table not found—request DPA annex. Historical Huawei technology partnership is supply-chain diligence, not US-cloud hosting.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

Deutsche Telekom / T-Systems sovereign European public cloud (now marketed as T Cloud Public): OpenStack-based IaaS and platform services in Germany, Netherlands, and Swiss regions with BSI C5, ISO, and SOC attestations.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: Open Telekom Cloud vs STACKIT
At a glanceLogo: Open Telekom CloudOpen Telekom CloudLogo: STACKITSTACKIT
HQ / operatorGermany — T-Systems / Deutsche TelekomNot listed
Current brandT Cloud Public (formerly Open Telekom Cloud)Not listed
PlatformOpenStack-based public cloudNot listed
RegionsGermany (Biere/Magdeburg), Netherlands, SwitzerlandNot listed
Commercial modelPay-as-you-go (+ optional discounts/reservations)Not listed
Self-hostNo — managed public cloudNot listed
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
HostingNot listedGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
ModelNot listedConsumption-based public cloud + quote-based colocation
Open sourceNot listedUses open-source components; platform itself is managed, not self-hosted
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Key capabilities: Open Telekom Cloud vs STACKIT
Key capabilitiesLogo: Open Telekom CloudOpen Telekom CloudLogo: STACKITSTACKIT
EU-operated (T-Systems)YesYes
OpenStack public IaaSYesNot listed
BSI C5 Type II (claimed)YesNot listed
DE / NL / CH regionsYesNot listed
GPU + ModelArts AIYesNot listed
Pay-as-you-goYesNot listed
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

Open Telekom Cloud

  • OpenStack public cloud with Elastic Cloud Server and GPUs

    Self-service IaaS on OpenStack: Elastic Cloud Server flavors from general-purpose to GPU shapes for AI/ML and graphics, plus Dedicated Host and Bare Metal where the region supports them. Provision via console, API, or automation; Auto Scaling for metric-driven capacity. Suited to production VMs and hybrid patterns that need European operator control rather than a thin VPS plan.

  • Multi-AZ object, block, and file storage in EU regions

    Object Storage Service provides S3-compatible multi-AZ object storage; Elastic Volume Service attaches block disks with snapshots; Scalable File Service offers NFS shared filesystems. Cloud Backup and Recovery and related services back up VMs and volumes into platform object storage. Pin workloads to DE, NL, or Swiss regions according to residency policy.

  • VPC networking, Direct Connect, and security services

    Virtual Private Cloud isolation, Elastic Load Balancer, VPN, NAT, Enterprise Router, and Direct Connect for high-bandwidth hybrid links. Security stack includes Anti-DDoS, WAF, Cloud Firewall, Host Security Service, and Key Management Service with bring-your-own-key options—useful for regulated network architectures without leaving Telekom-operated regions.

  • Cloud Container Engine and managed data services

    Cloud Container Engine runs Kubernetes-managed clusters and images; companion services cover container instances and registries. Relational Database Service supports MySQL, PostgreSQL, and Microsoft SQL with HA and backup patterns; document, cache (Redis-class), MapReduce, and search services extend the data plane. Service availability differs between DE and NL—check the regional matrix before design freezes.

  • ModelArts and sovereign AI positioning

    ModelArts provides an end-to-end AI development path (data prep, training, deployment) on European infrastructure, with GPU-backed instances for training and inference. Aimed at teams that want model and training-data residency under the same European operator as their IaaS—confirm which AI services exist in your chosen region (several AI offerings are DE-focused).

  • Twin-core European data centers (DE, NL, CH)

    Published regions: twin-core Germany (Biere/Magdeburg), Netherlands (Amsterdam area), and Switzerland (Bern/Zollikofen) for Swiss data residency. Vendor claims geo-redundant twin-core design, high availability targets, and renewable-powered German facilities. Not a global multi-continent footprint—by design for European sovereignty shortlists.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: Open Telekom Cloud vs STACKIT
Assurance & complianceLogo: Open Telekom CloudOpen Telekom CloudLogo: STACKITSTACKIT
Independent security / no-logs audit
Not applicable

IaaS platform—not a no-logs consumer VPN. Independent assurance is via ISO/SOC/C5-style audits rather than a no-logs report.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001
Vendor claimed

Vendor certifications page links ISO/IEC 27001 umbrella certificate PDF for download; re-verify serial/date in procurement.

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

ISO/IEC 27017 (cloud security)
Vendor claimed

Claimed with downloadable attestation PDF on certifications page.

Not listed
ISO/IEC 27018 (cloud PII)
Vendor claimed

Claimed with downloadable attestation PDF on certifications page.

Not listed
SOC 2 / SOC 3
Vendor claimed

SOC 2 Type II (request report); SOC 3 public PDF linked on certifications page. SOC 1 Type II also claimed.

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

BSI C5 Type II
Vendor claimed

Vendor claims BSI C5:2020 Type II (ISAE 3000); detailed report typically on request via audit-reports download flow.

Not listed
TISAX Level 3
Vendor claimed

Vendor states TISAX Level 3 for Germany and Netherlands regions.

Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

GDPR / EU data protection
Vendor claimed

EU operator, EU/CH regions, ISO 27018/27701 claims, DPA language on marketing pages—confirm signed DPA for your entity.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

German Telekom/T-Systems operator, no known US parent of the cloud business, primary hosting on Telekom EU/CH data centers (not AWS/GCP/Azure). Not a legal clearance of zero extraterritorial risk. Historical Huawei tech partnership is separate supply-chain diligence. Not legal advice.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Vendor GDPR pages state DPA, TOMs, and audit reports available for B2B; obtain current signed pack—not fully self-serve public template verified here.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

EU AI Act
Partial

Platform offers AI services (ModelArts) that may fall under customer AI Act obligations; OTC itself is infrastructure—not an automated high-risk AI system assessment by EuropeanStack.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

BSI C5 Type 2Not listed
Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

Considerations & known limitations: Open Telekom Cloud vs STACKIT
Considerations & known limitationsLogo: Open Telekom CloudOpen Telekom CloudLogo: STACKITSTACKIT
Historical Huawei technology partnership
Medium

Platform launched with Huawei hardware/software partnership; residual stack components may still matter for sensitive public-sector RFPs. T-Systems states independent operation. Review supply-chain docs under NDA.

Not listed
Service catalog differs by region
Medium

Several services (e.g. ModelArts, bare metal, some database/analytics SKUs) are unavailable in NL or limited to DE. Design against the live regional matrix, not the full marketing list.

Not listed
Limited public subprocessor table
Low

Unlike some SaaS vendors, a complete public subprocessor inventory was not found on marketing pages. Request DPA annex and subcontractor list before high-assurance processing.

Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Smaller global ecosystem than AWS/Azure/GCP
Low

Expect fewer regions, fewer proprietary PaaS services, and a smaller marketplace than US hyperscalers. Migration tools and partner ecosystem exist but differ in depth.

Not listed
Brand transition OTC → T Cloud Public
Low

Documentation, console URLs, and community still mix Open Telekom Cloud and T Cloud Public names. Factor rebrand into runbooks and vendor risk registers.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

Open Telekom Cloud

Best fit when

  • German public sector and regulated buyers needing Telekom-group operator plus BSI C5 / ISO package
  • Enterprises pinning workloads to DE, NL, or Swiss twin-core regions under GDPR (and Swiss DSG where relevant)
  • Teams wanting OpenStack-based IaaS with ECS, object/block storage, VPC, and Kubernetes (CCE) without US hyperscaler residency defaults
  • AI/ML projects that require GPU capacity and ModelArts-class tooling with European data residency messaging
  • Hybrid architectures using Direct Connect / VPN into Telekom data centers with 24/7 European support expectations

Poor fit when

  • Workloads that require dozens of global regions or deep proprietary hyperscaler PaaS catalogs
  • Buyers seeking a free self-hosted OpenStack distribution rather than a commercial public cloud
  • Teams that need every service in every region—several AI, bare-metal, and data services are DE-only or limited
  • Organisations that reject any non-European technology supply chain without further review (historical Huawei partnership)

Consider instead when

  • When: You need extensive bare-metal catalogs and a very large multi-country EU footprint

    Consider: OVHcloud

    Different operator (France) and product packaging; compare bare-metal and region maps.

  • When: You prefer developer-centric European cloud packaging outside the Telekom stack

    Consider: Scaleway or Exoscale

    Scaleway for FR/NL-oriented developer UX; Exoscale for Swiss multi-zone IaaS + managed K8s.

  • When: You need global regions, marketplace depth, or proprietary PaaS only hyperscalers provide

    Consider: AWS, Microsoft Azure, or Google Cloud Platform

    Accept US-parent CLOUD Act exposure and multi-region complexity in exchange for breadth.

  • When: You want German-market hosting adjacency with a different commercial/product mix

    Consider: IONOS

    Often compared for German buyers; validate IaaS depth vs OTC enterprise cloud features.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

Open Telekom Cloud

  • Will T-Systems provide the current full subprocessor/subcontractor list and signed DPA annex for our legal entity and region?
  • What is the residual Huawei (or other non-EU) component inventory for the regions we will use, and is it acceptable under our procurement policy?
  • Which services in our target architecture are available in DE vs NL vs Swiss regions with which SLAs?
  • Can we obtain current C5 Type II and SOC 2 reports (not only marketing claims and SOC 3 summary) under NDA?
  • For AI workloads, which ModelArts/GPU SKUs and data paths apply, and how do they map to our EU AI Act role?

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?