To guarantee enterprise-grade resilience, security, and digital sovereignty for our customers, every application must pass the STACKIT Technical Quality Gate before being listed on the Marketplace.
At STACKIT, we strictly adhere to BSI C5 compliance, meaning we have zero access to your project environments or customer data. Therefore, our Quality Gate operates on architectural compliance, robust security validation, and binding self-attestation.
The STACKIT Quality Framework (4 Pillars)
Section titled “The STACKIT Quality Framework (4 Pillars)”Your software is evaluated against the STACKIT Certified Sovereign ISV framework, which consists of four core pillars.
Pillar A — Sovereignty (ES³) Your application must pass the ES³ assessment (completed in Phase 7), proving data residency and immunity against third-country access.
Pillar B — Technical Resilience & Cloud-Native Your architecture must be designed for failure. This includes mandatory Multi-AZ deployments across at least two STACKIT Availability Zones and a stateless architecture, preferably utilizing the STACKIT Kubernetes Engine (SKE).
Pillar C — Factory-Readiness (Standardization) You should leverage STACKIT’s predefined Infrastructure-as-Code (IaC) templates. Implementations should be based on the STACKIT Landing Zone repository and our Terraform Blueprints for services like PostgreSQL and Object Storage.
Pillar D — Enterprise Security & Compliance Enforced encryption (at rest and in transit), strict IAM policies without excessive administrative privileges, and systematic vulnerability management.
Security Validation & Recommended Penetration Testing (Pentest)
Section titled “Security Validation & Recommended Penetration Testing (Pentest)”To protect both your customers and the reputation of the STACKIT platform, we strongly recommend conducting a comprehensive Penetration Test (Pentest) prior to commissioning your application.
Contractual Obligations (PBA Annex 2 TOMs)
Section titled “Contractual Obligations (PBA Annex 2 TOMs)”While STACKIT cannot directly inspect your live infrastructure or enforce a specific third-party audit, please note your contractual commitment:
Regulatory Alignment in the EU
Section titled “Regulatory Alignment in the EU”For ISVs targeting European enterprise and regulated markets, aligning your security testing with European standards is critical. A penetration test in the EU context serves as an authorized security audit aligned with strict regulatory frameworks:
- TIBER-EU: A framework for threat-led penetration testing under real-world conditions.
- DORA (Digital Operational Resilience Act): Mandates rigorous and regular security testing for software vendors serving the financial sector in the EU.
- NIS-2 & Cyber Resilience Act (CRA): Broaden obligations for digital service providers and software manufacturers to identify, manage, and report software vulnerabilities.
Executing a structured pentest ensures your application meets these evolving European compliance requirements.
Self-Attestation & Formal Confirmation
Section titled “Self-Attestation & Formal Confirmation”Until full integration into the STACKIT Partner Portal is available, the Technical Quality Gate concludes with a formal email-based Technical Self-Attestation.
Submission Process
Section titled “Submission Process”The Technical Lead or CTO of your organization must send a formal confirmation email to the ISV
Factory team at isv-sales@digits.schwarz.
Required Confirmation Content: By submitting this email, your technical management explicitly confirms that:
- The application architecture adheres to the 4 Pillars of the STACKIT Quality Framework.
- All Technical and Organizational Measures (TOMs) defined in PBA Annex 2 have been technically validated and fully implemented in your production deployment.
- Appropriate security validation (e.g., vulnerability scans or penetration testing) has been conducted to verify the software’s resilience prior to launch.
Phase Completion Criteria
Section titled “Phase Completion Criteria”- Architecture complies with the 4 Pillars of the STACKIT Quality Framework.
- Security controls and PBA Annex 2 TOMs technically validated.
- Pre-commissioning Penetration Test (Pentest) conducted (strongly recommended).
- Formal Technical Self-Attestation email sent to
isv-sales@digits.schwarzby the ISV Technical Lead. - Milestone achieved: Solution is granted the “STACKIT Sovereign Factory Approved” status and is ready for Placement & Marketplace Enablement.
Support & Contact
Section titled “Support & Contact”If you encounter blockers or have questions regarding this phase, reach out to the ISV Factory team:
- Contact Email:
isv-sales@digits.schwarz - Documentation & Knowledge Base: docs.stackit.cloud
- Platform Status: status.stackit.cloud