SAP vs STACKIT

Compare SAP and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Microsoft Azure

Logo: SAP

SAP

Germany· Cloud Computing

Needs review

Shortlist SAP when you need S/4HANA-class ERP breadth under a German parent entity and can fund a structured implementation. Skip when you want lightweight self-serve finance SaaS without a transformation partner. Consider Salesforce when CRM is the system of record, or a Microsoft Dynamics / Azure-centric stack when identity and productivity are already standardised on Microsoft.

EU-operatedFull ERP suiteS/4HANA CloudISO 27001 (claimed)B2B DPA published
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
SAP vs STACKIT: Snapshot
FeatureLogo: SAPSAPLogo: STACKITSTACKIT
Country of originGermanyGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedYesNo
HeadquartersGermanyGermany
Legal entitySAP SE, Dietmar-Hopp-Allee 16, 69190 Walldorf (Mannheim HRB 719915)Schwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawGerman entity; order forms may name local SAP affiliatesGermany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
EU-hosted statusPartialNot listed
Hosting / residencyMixed: SAP-operated data centers (including Walldorf / St. Leon-Rot, Germany) plus Enterprise Cloud Services documented on AWS, Microsoft Azure, Google Cloud Platform, or customer data centers. Product-specific subprocessor lists are primarily on My Trust Center for customers.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

German-headquartered enterprise ERP suite (SAP Cloud ERP / S/4HANA) for finance, supply chain, procurement, and HR.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: SAP vs STACKIT
At a glanceLogo: SAPSAPLogo: STACKITSTACKIT
HQWalldorf, GermanyNot listed
Legal entitySAP SE (HRB 719915 Mannheim)Not listed
Product focusCloud ERP / S/4HANANot listed
Commercial modelEnterprise subscription and licences (quote-based)Not listed
Open sourceNoUses open-source components; platform itself is managed, not self-hosted
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
HostingNot listedGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
ModelNot listedConsumption-based public cloud + quote-based colocation
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Data residency regionsCustomer-selectable; Americas, Europe, Asia Pacific (incl. SAP DE sites and hyperscalers)Not listed
Compliance certs (claimed)ISO 27001, SOC 1/2, BSI C5, plus regional attestations via Trust CenterNot listed
Key capabilities: SAP vs STACKIT
Key capabilitiesLogo: SAPSAPLogo: STACKITSTACKIT
EU-operatedYesYes
Full ERP suiteYesNot listed
S/4HANA CloudYesNot listed
ISO 27001 (claimed)YesNot listed
B2B DPA publishedYesNot listed
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

SAP

  • SAP S/4HANA Cloud ERP core

    Public and private cloud editions cover finance, supply chain, procurement, sales, and related processes on an in-memory data model with role-based UX. Scope and extensibility differ between Public Edition (standardised) and Private Edition (closer to classic on-premises flexibility).

  • GROW and RISE packaging

    SAP GROW targets organisations starting on standardised AI-enabled cloud ERP. RISE with SAP supports existing on-premises customers migrating toward cloud with transformation services. Packaging choice drives implementation shape more than feature marketing slides.

  • Integration via SAP BTP

    SAP Business Technology Platform and Integration Suite provide APIs, iPaaS connectivity, and extension points to link SAP ERP with third-party and legacy systems. Expect integration projects rather than plug-and-play SMB connectors.

  • Selectable cloud regions and sovereign options

    Customers can choose data center regions; SAP documents Americas, Europe, and Asia Pacific availability, including SAP-operated German sites and hyperscaler regions. Sovereign / regulated options (for example German IT-Grundschutz messaging for SAP-owned facilities) exist but must be contracted explicitly.

  • Trust Center compliance artifacts

    SAP publishes ISO 27001, SOC, C5, and other certificates plus DPAs through the Trust Center and customer portals. Audit reports for specific services are often gated to customers rather than fully public PDFs.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: SAP vs STACKIT
Assurance & complianceLogo: SAPSAPLogo: STACKITSTACKIT
Independent security / no-logs audit
Not applicable

ERP suite; not a no-logs privacy network product. Rely on SOC/ISO/C5 attestations instead.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001
Vendor claimed

Trust Center lists ISO 27001 certificates for cloud services and publishes certificate finder entries (e.g. Central / Enterprise Cloud Services).

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

SOC 2 / SOC 3
Vendor claimed

SOC 1 and SOC 2 reports described on Trust Center; many reports customer-gated via SAP for Me / My Trust Center.

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

GDPR / EU data protection
Vendor claimed

EU parent entity; Trust Center privacy pages and DPAs reference GDPR processing terms.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

German SAP SE parent with no known US parent, but Enterprise Cloud Services explicitly include AWS, Azure, and GCP paths. Medium exposure for hyperscaler-backed tenants. Not legal advice.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

SAP states it signs DPAs; Trust Center hosts Data Processing Agreement documents for cloud, support, and professional services.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

BSI C5
Vendor claimed

Trust Center lists Cloud Computing Compliance Controls Catalogue (C5) audit reports among EU regional offerings.

Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

EU AI Act
Partial

SAP publishes EU AI Act governance materials for Joule Agents and AI features; customer still must assess in-scope AI uses.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

TISAX Level 3Not listed
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Considerations & known limitations: SAP vs STACKIT
Considerations & known limitationsLogo: SAPSAPLogo: STACKITSTACKIT
Hyperscaler hosting is common
Medium

Even with a German parent, many cloud tenants run on AWS, Azure, or GCP. EU region selection does not remove US-group infrastructure operators from the path. Confirm contracted region and subprocessors.

Not listed
Heavy implementation programmes
Medium

S/4HANA and RISE projects typically need partners, data migration, and process redesign. Poor fit if you expected self-serve SaaS onboarding.

Not listed
Detailed subprocessor lists often customer-gated
Low

Public pages confirm lists exist on My Trust Center, but a full anonymous dump was not available in this research pass. Request the list for your exact cloud service before security sign-off.

Not listed
Catalog category is Cloud Computing, not ERP
Low

EuropeanStack has no dedicated ERP category yet. This entry is filed under Cloud Computing as the closest existing slug.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Limited public subprocessor inventoryNot listed
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

SAP

Best fit when

  • Midsize to large enterprises consolidating finance, supply chain, and procurement on one ERP
  • Organisations that need deep industry process templates and multi-country localisation
  • Buyers that require a German / EU parent contracting entity plus formal Trust Center attestations
  • Existing SAP ECC customers planning a RISE or S/4HANA transformation
  • Teams with budget for partner-led implementation rather than pure self-serve SaaS

Poor fit when

  • Startups or SMBs needing only simple invoicing without ERP programme overhead
  • Buyers that require a guaranteed EU-only, non-hyperscaler hosting path without reading the contract region
  • Teams seeking an open-source ERP they can fork and fully self-operate without vendor lock-in
  • CRM-first organisations where Salesforce-class customer platforms are the real system of record

Consider instead when

  • When: Your primary system of record is CRM and revenue operations, not manufacturing or complex finance

    Consider: Salesforce

    Stronger CRM depth; US parent and different compliance posture.

  • When: You already standardise on Microsoft identity, M365, and Azure and want ERP in that estate

    Consider: Microsoft 365 / Azure-centric Dynamics stacks

    Compare total cost of identity + productivity + ERP under one US vendor.

  • When: You need a smaller European mid-market ERP without S/4HANA transformation scope

    Consider: Evaluate EU mid-market ERP vendors outside this catalog (no peer ERP slug listed yet)

    Catalog currently lacks a direct European ERP alternative entry.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

SAP

  • Which exact cloud service and region would this buyer contract (Public Edition vs Private Edition vs RISE on which hyperscaler)?
  • Will the order form be with SAP SE or a local affiliate, and which governing law clause applies?
  • Can the vendor provide the current subprocessor list and SOC/C5 reports for the specific service code without an existing customer login?

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?