2 min Security

Zscaler offers sovereign security through Schwarz Digits

Zscaler offers sovereign security through Schwarz Digits

Zscaler and Schwarz Digits, the IT division of the Schwarz Group (owner of Lidl), will collaborate on a sovereign Zero Trust SASE service. The solution runs on the German cloud STACKIT and is intended for critical sectors such as government, defense, finance, and healthcare. All data remains within the EU.

Thanks to this partnership, Zscaler Zero Trust Exchange will run on the infrastructure of STACKIT, Schwarz Digits’ European sovereign cloud. The two parties announced the strategic partnership today. The service is now available to customers across Europe, hosted in German data centers and managed by STACKIT.

European regulations are pushing many organizations toward sovereign solutions. In particular, the implementation of the NIS2 Directive and laws such as DORA and the EU AI Act have made the degree of digital autonomy a key consideration for every IT solution. This naturally applies to security software as well, which also gives concrete form to the broad concept of “digital resilience.”

Zero trust on European soil

Zscaler already offers considerable control for users with sovereignty requirements. Earlier this year, the company expanded its data sovereignty capabilities with separate control, data, and logging planes, ensuring that sensitive data never leaves the required jurisdiction. The partnership with Schwarz Digits combines that concept with a fully-fledged EU cloud.

“In an era of AI-driven cyber threats, a modern Zero Trust SASE solution is the only effective way to protect sensitive corporate data,” says Misha Kuperman, Chief Reliability Officer at Zscaler. According to him, the service helps customers eliminate their attack surface and prevent lateral movement of threats, with EU data residency as the foundation.

Competition is intensifying

STACKIT has now become more than just a German initiative, even though Germany remains at the core of the infrastructure. KPN previously launched a sovereign cloud with STACKIT for the Netherlands, targeting the government, finance, healthcare, and energy sectors.

European security players will likely argue that only they can offer truly sovereign solutions for European customers. However, the same principle applies in the security sector as elsewhere in the IT stack: established U.S. players are not only attractive options, but they are also aligning themselves as closely as possible with EU requirements. This makes an announcement like this fairly predictable, but also decisive for organizations that need to set clear boundaries, particularly with cloud providers.