---
type: industry
vertical: public
title: Public sector
description: "The framework read for the German public sector: IT-Grundschutz and C5 as the assessment frame, Tier 1 as the default, and the statements that must hold."
status: draft
sidebar:
  order: 50
  label: Public sector
source_url: "https://framework.stackit.cloud/architecture/industries/public/"
source_file: "docs/architecture/industries/public.mdx"
---

For workloads run by or for German public bodies: federal, state and municipal administration,
and the operators who build for them. The mountain is the same as for everyone; this page maps
what the public-sector route demands of it, and adds nothing.

## The regulatory map

What binds here, and what each regime asks of an architecture.

**BSI IT-Grundschutz.** The
<LinkChip href="https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html">BSI's methodology</LinkChip>
for information security, and the frame public bodies in Germany are assessed in. Its protection
needs assessment is a data classification by another name, which is why [`SEC 3`](/architecture/pillars/security/sec-03-data-classification/) stops being
optional here, and it makes [`SEC 1.1`](/architecture/pillars/security/sec-01-security-baseline/#sec-11-derive-the-baseline-from-the-frameworks-you-are-actually-assessed-against), deriving the baseline from the frameworks you are
assessed against, a statement with a known answer.

**BSI C5.** The
<LinkChip href="https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/Kriterienkatalog-C5/kriterienkatalog-c5_node.html">cloud attestation</LinkChip>
public procurement asks a cloud provider for. STACKIT holds
<LinkChip href="https://stackit.com/en/why-stackit/benefits/certificates">C5 Type 2</LinkChip>, which covers the
provider's side; the attestation explicitly leaves a customer side, and [`SOV 8.3`](/architecture/pillars/sovereignty/sov-08-compliance-mapping/#sov-83-establish-the-responsibility-split-per-control), the
responsibility split per control, is where an assessment establishes that yours is covered.

**OZG.** The <LinkChip href="https://www.gesetze-im-internet.de/ozg/">Onlinezugangsgesetz</LinkChip> obliges federal and
state government to offer administrative services electronically. For an architecture this means
the availability of a citizen-facing service is a statutory matter rather than a commercial one,
which changes who sets the reliability targets in [`REL 1`](/architecture/pillars/reliability/rel-01-reliability-targets/) and what an outage costs.

**Citizen data.** Administrative data routinely includes special categories of personal data:
health, social, tax. That is the profile the Advisory Framework's Tier 1 criteria describe.

**Classified information.** Anything carrying a classification, VS-NfD upward, follows the
Geheimschutz regime and the
<LinkChip href="https://www.bsi.bund.de/DE/Themen/Oeffentliche-Verwaltung/Zulassung/zulassung_node.html">BSI's approval process</LinkChip>
for the products that handle it. That regime is [outside this page](#outside-this-page).

**Procurement.** The requirements above arrive in contracts through the EVB-IT terms, the German
public sector's standard contract conditions for IT procurement, whose cloud terms carry the
security attestation and the exit obligations into the agreement. The current edition comes from
your procurement office rather than from a stable public link. The Deutsche
Verwaltungscloud-Strategie points the same direction from the strategy side: administration
clouds are expected to be sovereign and portable, which is [`SOV 10`](/architecture/pillars/sovereignty/sov-10-open-interfaces/) and [`SOV 11`](/architecture/pillars/sovereignty/sov-11-exit-plan/) said by a
buyer.

## The tier default

**Tier 1, sovereignty-mandatory.** The Advisory Framework decides the tier per workload; this
default is what a deviation is recorded against, not a substitute for that decision. It is the
default because the Tier 1 criteria read like a description of administrative data: special
categories of personal data as a matter of routine, and severe consequences if a foreign
authority could compel access to it.

Two qualifications. The tier is established per data set rather
than per workload, [`SOV 1.3`](/architecture/pillars/sovereignty/sov-01-sovereignty-tier/#sov-13-classify-per-data-set-because-a-workload-rarely-sits-at-one-tier), and parts of a public estate legitimately sit lower: an open-data
portal or a public website carries none of the data the criteria describe. And deviating from the
default is not a finding; an undocumented deviation is. [`SOV 1.2`](/architecture/pillars/sovereignty/sov-01-sovereignty-tier/#sov-12-record-the-reasoning-rather-than-only-the-result) is where the reasoning lands.

## The pillar weighting

Four pillars shift; each shift traces to the map.

**Sovereignty & Compliance leads.** At Tier 1 nearly every question in the pillar binds as
mandatory, per the tier table in the [pillar overview](/architecture/pillars/sovereignty/), and the evidence
duties, [`SOV 7`](/architecture/pillars/sovereignty/sov-07-auditability/) and [`SOV 8`](/architecture/pillars/sovereignty/sov-08-compliance-mapping/), are what an audit against C5 and IT-Grundschutz actually consumes.

**Security is elevated, and externally framed.** The baseline is not yours to choose:
IT-Grundschutz supplies the frame, which turns [`SEC 1`](/architecture/pillars/security/sec-01-security-baseline/) from a design question into a conformance
question and makes the protection needs assessment the input to [`SEC 3`](/architecture/pillars/security/sec-03-data-classification/).

**Reliability is elevated for citizen-facing services.** The OZG makes availability a statutory
duty, so [`REL 1`](/architecture/pillars/reliability/rel-01-reliability-targets/) targets derive from a service mandate rather than from revenue, and the
deadline-day peak, the day a filing period ends, is the load [`REL 7`](/architecture/pillars/reliability/rel-07-scaling-and-headroom/) sizes for.

**Operational Excellence is elevated as the evidence machine.** Infrastructure as code with
reviewed changes, [`OPS 3`](/architecture/pillars/operational-excellence/ops-03-everything-as-code/), is the change record an auditor reads, and [`SOV 7.4`](/architecture/pillars/sovereignty/sov-07-auditability/#sov-74-make-evidence-a-by-product-rather-than-a-project)'s
evidence-as-by-product is only reachable through it.

Performance Efficiency, Cost Optimization and Sustainability do not shift. A walkthrough covers
them as it covers any workload; public money makes cost attribution no less interesting, it
simply does not reweight the route.

## The statement core

What an assessment of a public-sector workload accounts for regardless of where the conversation
went: each of these ends evidenced or in the risk register. At Tier 1 the sovereignty pillar's
own tier table already binds most of its questions; the core names the statements a review has
to reach an answer on.

### Sovereignty & Compliance

| Statement | What makes it mandatory here |
|---|---|
| [`SOV 1.1`](/architecture/pillars/sovereignty/sov-01-sovereignty-tier/#sov-11-determine-which-tier-applies-using-the-advisory-framework-definition) | The tier decision is the hinge of the whole route, and it must be Advisory's, recorded |
| [`SOV 1.2`](/architecture/pillars/sovereignty/sov-01-sovereignty-tier/#sov-12-record-the-reasoning-rather-than-only-the-result) | Deviations from the Tier 1 default are legitimate only as recorded reasoning |
| [`SOV 2.1`](/architecture/pillars/sovereignty/sov-02-placement-and-residency/#sov-21-choose-region-and-availability-zone-deliberately-against-the-tier) | Placement against the tier is what sovereign procurement bought |
| [`SOV 2.2`](/architecture/pillars/sovereignty/sov-02-placement-and-residency/#sov-22-trace-the-processing-location-of-every-dependency-not-only-the-obvious-ones) | The dependency nobody traced is where residency fails first |
| [`SOV 3.1`](/architecture/pillars/sovereignty/sov-03-telemetry-residency/#sov-31-treat-telemetry-as-data-carrying-the-classification-of-what-it-describes) | Telemetry carries citizen data the moment a log does |
| [`SOV 3.3`](/architecture/pillars/sovereignty/sov-03-telemetry-residency/#sov-33-apply-the-same-boundary-to-backups-exports-and-copies) | Backups and exports leave the boundary more quietly than workloads do |
| [`SOV 4.1`](/architecture/pillars/sovereignty/sov-04-key-ownership/#sov-41-establish-per-data-set-who-is-technically-able-to-decrypt) | Who can technically decrypt is the question a foreign-access scenario turns on |
| [`SOV 4.2`](/architecture/pillars/sovereignty/sov-04-key-ownership/#sov-42-hold-the-keys-yourself-where-the-tier-requires-it) | Tier 1 is where customer-held keys stop being optional |
| [`SOV 5.1`](/architecture/pillars/sovereignty/sov-05-operator-access/#sov-51-establish-who-can-technically-reach-the-data-including-the-provider) | Provider reach must be established, not assumed, for the liability the tier names |
| [`SOV 5.2`](/architecture/pillars/sovereignty/sov-05-operator-access/#sov-52-close-the-data-in-use-gap-where-the-tier-requires-it) | Data in use is the gap the strictest criteria ask about |
| [`SOV 6.1`](/architecture/pillars/sovereignty/sov-06-jurisdictional-chain/#sov-61-maintain-a-current-inventory-of-every-party-that-processes-your-data) | The processing inventory is what a supervisory question is answered from |
| [`SOV 6.2`](/architecture/pillars/sovereignty/sov-06-jurisdictional-chain/#sov-62-establish-jurisdiction-rather-than-only-location) | Jurisdiction, not location, is what compelled access follows |
| [`SOV 7.1`](/architecture/pillars/sovereignty/sov-07-auditability/#sov-71-record-the-actions-an-auditor-or-investigator-will-ask-about) | The audit trail is what IT-Grundschutz and C5 audits consume |
| [`SOV 7.2`](/architecture/pillars/sovereignty/sov-07-auditability/#sov-72-protect-records-against-modification-by-the-parties-they-record) | Records alterable by the recorded party are not evidence |
| [`SOV 7.3`](/architecture/pillars/sovereignty/sov-07-auditability/#sov-73-retain-for-the-period-the-obligation-requires) | Retention here follows the obligation, not the storage bill |
| [`SOV 8.1`](/architecture/pillars/sovereignty/sov-08-compliance-mapping/#sov-81-identify-which-frameworks-actually-apply) | Which frameworks apply is the first thing an assessor establishes |
| [`SOV 8.3`](/architecture/pillars/sovereignty/sov-08-compliance-mapping/#sov-83-establish-the-responsibility-split-per-control) | C5 leaves a customer side; unowned controls are uncovered controls |
| [`SOV 9.1`](/architecture/pillars/sovereignty/sov-09-identity-sovereignty/#sov-91-establish-who-operates-your-identity-control-plane) | The identity control plane decides who can reach everything else |
| [`SOV 11.2`](/architecture/pillars/sovereignty/sov-11-exit-plan/#sov-112-rehearse-the-parts-that-can-be-rehearsed) | The exit obligations in the contract are only real if rehearsed |

### Security

| Statement | What makes it mandatory here |
|---|---|
| [`SEC 1.1`](/architecture/pillars/security/sec-01-security-baseline/#sec-11-derive-the-baseline-from-the-frameworks-you-are-actually-assessed-against) | The baseline is externally given: IT-Grundschutz, and whatever the body adds |
| [`SEC 1.2`](/architecture/pillars/security/sec-01-security-baseline/#sec-12-measure-continuously-and-automatically-rather-than-by-periodic-audit) | A conformance frame with yearly audits still needs continuous measurement between them |
| [`SEC 3.1`](/architecture/pillars/security/sec-03-data-classification/#sec-31-classify-every-data-set-before-deciding-where-it-lives) | The protection needs assessment is a classification; unclassified data sets are unfinished work |
| [`SEC 3.3`](/architecture/pillars/security/sec-03-data-classification/#sec-33-find-the-copies-telemetry-backups-caches-test-data-and-exports) | Copies of citizen data inherit every obligation of the original |
| [`SEC 4.1`](/architecture/pillars/security/sec-04-identity/#sec-41-federate-human-identity-to-a-single-source-with-strong-authentication) | Administrative access rests on federated identity with strong authentication |
| [`SEC 5.4`](/architecture/pillars/security/sec-05-least-privilege/#sec-54-review-actual-entitlements-against-intended-ones-on-a-cadence) | Entitlement review is a standing audit expectation, not a hygiene habit |
| [`SEC 7.2`](/architecture/pillars/security/sec-07-encryption/#sec-72-encrypt-at-rest-including-every-copy) | Encryption at rest, including every copy, is table stakes for the data profile |
| [`SEC 7.3`](/architecture/pillars/security/sec-07-encryption/#sec-73-decide-who-is-technically-able-to-decrypt-per-data-set) | Who is technically able to decrypt is the sovereignty question inside security |
| [`SEC 11.1`](/architecture/pillars/security/sec-11-detection-and-response/#sec-111-collect-security-relevant-signals-where-the-subject-cannot-alter-them) | Security records must survive the person they record |
| [`SEC 11.3`](/architecture/pillars/security/sec-11-detection-and-response/#sec-113-define-the-response-before-an-alert-fires) | An incident touching citizen data has reporting duties; the response cannot be improvised |

### Operational Excellence

| Statement | What makes it mandatory here |
|---|---|
| [`OPS 3.1`](/architecture/pillars/operational-excellence/ops-03-everything-as-code/#ops-31-define-every-production-resource-in-version-control) | The change record auditors read only exists if production is defined in version control |
| [`OPS 3.2`](/architecture/pillars/operational-excellence/ops-03-everything-as-code/#ops-32-review-changes-before-they-take-effect) | An unreviewed change is a change without evidence |

### Reliability

| Statement | What makes it mandatory here |
|---|---|
| [`REL 1.2`](/architecture/pillars/reliability/rel-01-reliability-targets/#rel-12-set-availability-rto-and-rpo-per-critical-flow-rather-than-per-workload) | Availability targets follow the service mandate, per flow, not the workload average |
| [`REL 1.4`](/architecture/pillars/reliability/rel-01-reliability-targets/#rel-14-have-each-target-agreed-and-recorded-by-someone-accountable-for-the-outcome) | A statutory duty needs a named owner for the target that implements it |
| [`REL 8.3`](/architecture/pillars/reliability/rel-08-backup-and-restore/#rel-83-restore-on-a-cadence-into-a-clean-environment-and-time-it) | A restore that has not been rehearsed is a continuity claim, not a capability |
| [`REL 9.3`](/architecture/pillars/reliability/rel-09-disaster-recovery/#rel-93-rehearse-it-and-time-the-rehearsal-against-the-rto) | The recovery duty is only met if the rehearsal fits the time the mandate allows |

## Outside this page

**Classified information.** VS-NfD and above is its own regime with its own approvals, decided
case by case with the body's security officer. Nothing on this page makes a workload fit for
classified material.

**The parts of an estate below the default.** Open-data portals, public websites and other
workloads carrying none of the data the Tier 1 criteria describe sit at a lower tier with the
reasoning recorded, and the sovereignty pillar's tier table then releases what does not bind.
The core above shrinks accordingly; the recording duty, [`SOV 1.2`](/architecture/pillars/sovereignty/sov-01-sovereignty-tier/#sov-12-record-the-reasoning-rather-than-only-the-result), is the one thing that never
does.

## Related

- [Sovereignty & Compliance](/architecture/pillars/sovereignty/): the pillar the route leans on most
- [Security](/architecture/pillars/security/): the pillar the external frame lands on
