72 percent of cyber defense comes from abroad
Around 72 percent of cybersecurity solutions in German companies come from foreign providers, according to studies. The very discipline that is supposed to protect digital sovereignty is itself heavily dependent on imports. For CISOs, this is not a political issue, but a question of risk within their own stack.
Key Takeaways
- The defense is itself import-dependent. Studies cite around 72 percent foreign security solutions and a broad dependence on US technology. Sovereignty is lacking where it would count the most.
- Germany is now writing its own rules. With the C3A criteria catalog of late April 2026, the BSI has presented a technical framework for sovereign cloud use.
- Sovereignty is a stack issue, not a fundamental decision. Reduction is realistic in SOC, detection, and open-source tooling. For operating systems and hyperscalers, it remains a short-term illusion.
Related:Detection Engineering without Vendor Lock: Wazuh Stack 2026 / Where SMEs still lag behind in NIS2 technical requirements
How Dependent the German Security Stack Really Is
What is digital sovereignty in IT security? Digital sovereignty refers to the ability to control one’s own technology autonomously: without uncontrolled external influence and without unwanted data leakage. In the security context, this means keeping detection logic, keys, and log data under one’s own control instead of entrusting them entirely to foreign providers.
The numbers are unsettling. They come from multiple surveys, not a single source. Industry studies consistently report a share of around 72 percent foreign providers in the cybersecurity solutions used by German companies. The dependence on US technology overall, across operating systems, cloud, and supply chains, is given as around 87 percent in the same studies.
These percentages should be seen as an order of magnitude, not official statistics. The direction, however, is clear. For a security team, this is particularly tricky. Relying almost entirely on tools whose manufacturers, update paths, and legal frameworks are outside one’s own jurisdiction poses a risk in the very function that is supposed to reduce risks.
No one will conclude from this that all foreign products should be replaced. That would be neither feasible nor sensible. The right question is different: At which points in the stack is the dependence a real, manageable risk? At which points is it acceptable?
What the US Factor Specifically Means
Dependence on US providers is not inherently a quality issue. US products often deliver a high level of technical security. The risk is legal and political. The US Cloud Act allows US authorities, under certain conditions, access to data processed by a US provider, even if it is physically located in Europe. This residual risk can be mitigated contractually, but not entirely eliminated.
Additionally, there is a new variable. The BSI, in its situation reporting, has pointed out that political developments in the USA can also weaken cybersecurity in Europe. Budget cuts for US security authorities in 2025 are an example: they affect structures from which European defenders have indirectly benefited. Anyone who bases their defense on an ecosystem whose governmental foundation is currently shrinking should at least consider this in their risk assessment.
The C3A Catalog: Germany Writes Its Own Rules
The most concrete step is regulatory in nature. At the end of April 2026, the BSI published the C3A Criteria Catalog, a technical rulebook that defines standards for sovereign cloud use. Instead of formulating a political demand, the catalog describes verifiable technical properties.
The underlying BSI strategy is pragmatic. It does not demand the banishment of non-European products. Instead, it requires that they be technically integrated in such a way that uncontrolled management from outside the EU and unwanted data leakage are technically excluded. This approach differs from a mere ban based on origin. For CISOs, it is the more practical solution. Sovereignty thus becomes an architectural property that can be measured, not a question of company headquarters.
For your own planning, this means: The C3A Catalog provides a vocabulary and a checklist. Even if you do not supply government agencies, you can use the criteria as an evaluation framework for your next procurement.
Where Sovereignty in the Security Stack is Realistic
An honest assessment separates the levels. In some areas, reducing dependence is feasible today; in others, it remains theoretical for years.
| Level in the Stack | Sovereignty Scope | Assessment |
|---|---|---|
| SOC and Detection | high | Open-source stacks like Wazuh or Sigma are a real alternative. |
| Tooling and Automation | medium | Many components can be openly or European-sourced, with integration effort. |
| Identity and Endpoint | low | Market dominance of a few providers makes switching expensive. |
| Operating Systems and Hyperscalers | very low | No full replacement in sight in the short term. |
Assessment by stack level, not a provider rating.
The pattern is clear. The closer a component is to the platform and operating system, the lower the scope. The closer it is to analysis, rules, and processes, the greater the scope. This is precisely why the Security Operations Center is the most sensible starting point. A detection stack made of open components is robust enough for productive operation today. It shifts control over detection logic and data back to your own organization.
What CISOs Need to Consider Now
Three pragmatic steps can be derived from the situation, without any political gestures.
First, the origin of the provider should be included in the risk assessment, not as an exclusion criterion, but as a documented factor with its own evaluation. Second, it is worthwhile to seriously consider open and European options for the next detection or SOC project, as this is where the greatest flexibility lies. Third, the BSI’s C3A catalog should be integrated into procurement as a checklist, even without an official mandate.
Security sovereignty is not a state that a company proclaims. It emerges layer by layer, where a dependency can be resolved without significant damage. Reboot Germany means exactly this in security: not the big break, but the orderly repatriation of control, in places where it is feasible.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
How dependent are German companies on foreign providers for cybersecurity?
Industry studies consistently report a share of around 72 percent of foreign providers in the security solutions used, with dependence on US technology overall given as around 87 percent. These figures should be understood as an order of magnitude, not as official statistics.
What is the BSI’s C3A Criteria Catalog?
The C3A Criteria Catalog is a technical regulation that the BSI published at the end of April 2026. It defines verifiable standards for sovereign cloud use. Instead of formulating a ban on origin, it describes technical properties by which sovereignty can be measured.
Why is dependence on US providers a risk?
It is not a quality problem, but a legal and political one. The US Cloud Act allows US authorities access to data processed by a US provider under certain conditions, even if it is stored in Europe. Additionally, political developments in the USA can weaken cybersecurity in Europe.
Where can a company realistically reduce dependence?
Most easily in SOC and detection engineering, where open stacks like Wazuh or Sigma are a viable alternative, as well as in tooling and automation. Replacing operating systems, identity management, and hyperscaler cloud in the short term is hardly realistic.
Does a company have to apply the C3A catalog if it does not supply to an authority?
There is no obligation in this case. Nevertheless, it makes sense: The catalog provides a ready-made, technically tested evaluation framework that can be adopted into a company’s own cloud and security procurement without an official mandate.
More from the MBF Media Network
Digital ChiefsSovereignty beats price: the new procurement signalcloudmagazinAI devours electricity, the cloud gets the billMyBusinessFutureBerlin City Palace cheaper than the Elbphilharmonie?
Further reading
NIS2 Patchwork: Four States Face EU Court
The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.
Cursor Launches git.exe from Repository Root on Windows
Mindgard: Cursor on Windows executes local repo git.exe without prompt. Reported Dec 2025, still unpatched as of July 2026. Policy and AppLocker mitigations available.
Weakest Supplier Opens Critical Facility
The KRITIS roof law makes supplier reliability a mandatory duty for operators. Governance roadmap to registration.


