Knowledge Base

Technical Notes.

In-depth architecture patterns, implementation guides, and operational constraints for cloud-native systems.

54 articles

EU-Native Cloud Providers — The Landscape Beyond Hyperscalers and Sovereign JVs

May 16, 2026 14 min read

OVHcloud, Scaleway, Hetzner, IONOS, STACKIT, T Cloud Public, 3DS Outscale, Cegedim.cloud, Aruba. EU-native pure-play providers mapped by compliance tier, service breadth, and procurement fit.

  • Intermediate
  • EU-Native Cloud
  • Cloud Providers
  • Sovereignty
  • Compliance
  • Data Security
  • Vendor
Read Article

Choosing Your Cloud Compliance Posture — A Decision Framework

May 15, 2026 12 min read

The national frameworks, cross-cutting baselines, and regulatory overlays add up to dozens of acronyms. This article is the decision tree that maps 'I am [type of organisation] doing [type of workload] in [geography]' to 'these are the frameworks that actually apply to you'.

  • Intermediate
  • Decision Framework
  • Practitioner
  • Compliance
  • Data Security
  • Cross-Cutting
Read Article

Reading Cloud Attestation Reports — A Practitioner's Guide

May 15, 2026 11 min read

A SOC 2 report, a C5 attestation, an ENS audit certificate, an ACN qualification dossier — what to look for, what to ignore, what to ask follow-up questions about. The practitioner skill that turns compliance documents into actual signal.

  • Intermediate
  • Attestation
  • Audit Reports
  • Practitioner
  • Compliance
  • Data Security
  • Cross-Cutting
Read Article

EU AI Act × Cloud — How AI Regulation Reaches Cloud Providers and Their Customers

May 14, 2026 12 min read

The EU AI Act applies progressively from 2025 through 2027. For cloud providers, two roles matter: provider of general-purpose AI models, and infrastructure for customer-deployed AI systems. For customers, deployer obligations apply at scale. This article walks through what AI Act actually requires of cloud providers, where it intersects with GDPR and NIS2, and what to plan for.

  • Advanced
  • EU AI Act
  • AI
  • GPAI
  • Compliance
  • Data Security
  • Cross-Cutting
  • Sectoral
Read Article

EUCS Watch — Political Tracking of the European Cybersecurity Certification Scheme for Cloud Services

May 14, 2026 11 min read

EUCS has been the most-anticipated and least-delivered EU cloud regulation for half a decade. This article tracks what state EUCS is in as of mid-2026, who's blocking what, what the ANSSI/BSI March 2026 joint statement means, and what realistic adoption scenarios look like. A dated reference article — designed to be re-read against current events.

  • Intermediate
  • EUCS
  • ENISA
  • Sovereignty
  • EU Policy
  • Compliance
  • Data Security
  • Tracking
Read Article

Cloud Encryption Key Custody — BYOK, HYOK, and the Practical Sovereignty Answer

May 13, 2026 12 min read

Provider-managed keys, BYOK, HYOK, External Key Stores. Every cloud sovereignty conversation eventually arrives at key custody. This article walks through the patterns, the hyperscaler implementations (AWS XKS, Azure CMK, Google EKM), the operational trade-offs, and why customer-held keys are the most practical sovereignty answer short of full sovereign cloud.

  • Advanced
  • Encryption
  • BYOK
  • HYOK
  • Key Management
  • Sovereignty
  • Compliance
  • Data Security
  • Cross-Cutting
Read Article

Norway — NSM Grunnprinsipper, Sikkerhetsloven, and the EEA Cloud Position

May 13, 2026 10 min read

Norway is in the EEA. Most EU cloud regulation reaches Norway via EEA incorporation, including GDPR (directly applicable) and NIS2/DORA (in progress). On top, NSM's Grunnprinsipper guide ICT security, Sikkerhetsloven governs classified information, and Finanstilsynet supervises financial-sector cloud. This article maps how the Norwegian regime relates to the EU base.

  • Intermediate
  • Norway
  • NSM
  • Sikkerhetsloven
  • Finanstilsynet
  • Compliance
  • Data Security
  • Adjacent Jurisdiction
Read Article

Switzerland — FINMA, nFADP, and the Cloud Framework Outside the EU

May 12, 2026 10 min read

Switzerland is not in the EU and not in the EEA, but is deeply bilateral with both. The cloud framework is composed: FINMA Circular 2018/3 for financial services, the revised nFADP for data protection (GDPR-aligned with lower penalties), and sector-specific regulation for healthcare, defence, and classified information. For Slovak organisations with Swiss customers — and Swiss organisations consuming EU cloud — the regime is adjacent but procedurally distinct.

  • Intermediate
  • Switzerland
  • FINMA
  • nFADP
  • FDPIC
  • Compliance
  • Data Security
  • Adjacent Jurisdiction
Read Article

United Kingdom — NCSC Cloud Security Principles and the Post-Brexit Position

May 12, 2026 10 min read

The UK left the EU but kept GDPR (as UK GDPR), kept ISO standards, and did not adopt EUCS. NCSC's 14 Cloud Security Principles are the operative UK government cloud guidance, with Cyber Essentials and Cyber Essentials Plus as the certification scheme. For EU CSPs serving UK customers (and UK CSPs serving EU customers), the regime is adjacent but distinct.

  • Intermediate
  • United Kingdom
  • NCSC
  • Cloud Security Principles
  • Compliance
  • Data Security
  • Adjacent Jurisdiction
Read Article

Hyperscaler EU Data Boundary Commitments — What They Actually Mean

May 10, 2026 11 min read

Microsoft EU Data Boundary, AWS European Sovereign Cloud, Google Workspace EU Data Boundary. Three different commitments, three different scopes, three different things being promised. This article unpacks what each actually covers, what each excludes, and how to read the technical small print.

  • Intermediate
  • EU Data Boundary
  • Hyperscaler
  • Data Residency
  • Sovereignty
  • Compliance
  • Data Security
  • Vendor
Read Article

Sovereign Cloud Products in 2026 — The European Landscape

May 9, 2026 13 min read

Hyperscaler joint ventures, EU-native operators, partner sovereign clouds, and dedicated sovereign regions. The European sovereign cloud market in 2026 has more options than three years ago, but the variety hides real differences in what each product actually delivers. This article maps the landscape.

  • Intermediate
  • Sovereign Cloud
  • Product Landscape
  • Sovereignty
  • Compliance
  • Data Security
  • Vendor
Read Article

Finland — PiTuKri: Guidance That Doubles as the Gate for Classified Information

May 8, 2026 11 min read

PiTuKri is officially guidance, not statutory. In practice, it is the gate for handling Finnish classified information in the cloud. The Finnish NIS2 transposition (Act 124/2025) has been in force since April 2025; the replacement criteria library is in public consultation and scheduled for finalisation in autumn 2026 — until then, a real gap between the new risk-based law and the 2020 cloud framework exists.

  • Intermediate
  • Finland
  • PiTuKri
  • Traficom
  • NIS2
  • Compliance
  • Data Security
Read Article

Poland — KSC and the Pending National Cybersecurity Certification System

May 7, 2026 10 min read

Poland regulates cloud through the National Cybersecurity System (KSC). The NIS2-aligned amendment (informally 'KSC2') entered into force on 3 April 2026 with a pending Constitutional Court review. The parallel National Cybersecurity Certification System (KSCC) was adopted in June 2025 and is operationalising.

  • Intermediate
  • Poland
  • KSC
  • KSCC
  • NASK
  • NIS2
  • Compliance
  • Data Security
Read Article

Czechia — NÚKIB and the New Cybersecurity Act: NIS2 Without a Dedicated Cloud Scheme

May 6, 2026 10 min read

Czechia has no dedicated cloud qualification framework. Cloud security is regulated horizontally through the new Cybersecurity Act (264/2025 Sb.), effective 1 November 2025, with a full implementing-decree stack already in force (408, 409, 410/2025 Sb. and others). NÚKIB supervises; CSPs are assessed as supply-chain participants.

  • Intermediate
  • Czechia
  • NUKIB
  • Cybersecurity Act
  • NIS2
  • Compliance
  • Data Security
Read Article

Netherlands — BIO2: Government Baseline Becoming a Statutory Obligation

May 5, 2026 10 min read

BIO2 v1.3 is the Dutch government's security baseline since 5 March 2026, superseding BIO v1.04zv. The Cyberbeveiligingswet — the Dutch NIS2 transposition — was approved by the Tweede Kamer on 15 April 2026 and is in Senate review. The cloud profile is operated by hyperscalers via independent attestation.

  • Intermediate
  • Netherlands
  • BIO2
  • BZK
  • NIS2
  • Compliance
  • Data Security
Read Article

Spain — ENS: The National Security Framework Spans Every Public-Sector System

May 2, 2026 10 min read

ENS is not a cloud-specific framework — it covers every public-sector information system. But its cloud profile (PCE) and three-tier model make it one of the more workable EU regimes for hyperscalers.

  • Intermediate
  • Spain
  • ENS
  • CCN
  • NIS2
  • Compliance
  • Data Security
Read Article

Italy — ACN Qualificazione: The Most Procedural Cloud Framework in the EU

Apr 30, 2026 11 min read

Italy's qualification framework is the most formally structured in the EU — statutory timelines, four levels, mandatory public catalogue, and a state-controlled Polo Strategico Nazionale for the strictest workloads.

  • Intermediate
  • Italy
  • ACN
  • Qualificazione
  • NIS2
  • Compliance
  • Data Security
  • PSN
  • Sovereignty
Read Article

Source of Truth — Where Does Your Cloud Actually Live?

Apr 30, 2026 11 min read

If you did not choose a source of truth, the live cloud chose for you. IaC repo, cloud APIs, Backstage, CMDB — pick deliberately and document the choice.

Status Pages, Service Health, and the Things They Will Not Show You

Apr 30, 2026 9 min read

Status pages are public communication, not monitoring. The green dot lags reality by 30+ minutes. Service Health helps. Build your own observability first.

  • Beginner
  • Azure
  • OCI
  • Service Health
  • Incident Response
  • Observability
Read Article

Budgets, Cost Caps, and the Illusion of 'Spending Limits'

Apr 30, 2026 13 min read

No enterprise cloud contract has a billing-level hard cap. Budgets alert. OCI quotas enforce resource ceilings. What is real and what you actually wire up.

Cloud Support — What You Are Actually Paying For

Apr 30, 2026 14 min read

Support tiers sell response time. What you buy is triage access and relationship quality. When premium support earns its cost and when it doesn't.

Discounts and Commitments — The Math the Salespeople Hope You Will Not Do

Apr 30, 2026 12 min read

Reservations save 30–72% only if utilisation stays high. The discount you committed to keeps billing after the workload changes. Here is the math vendors skip.

  • Intermediate
  • Azure
  • OCI
  • FinOps
  • Reservations
  • Cost Optimization
Read Article

RBAC and IAM — Authorisation Models That Look Similar and Are Not

Apr 30, 2026 13 min read

Azure RBAC and OCI IAM look similar until inheritance, deny semantics, and role catalogues diverge. Get the model wrong and least privilege is fiction.

Documentation, the CCoE, and Why Both Decay Faster Than You Think

Apr 30, 2026 11 min read

Documentation rots. CCoEs drift to meetings. The fix is treating docs as a maintained product and the CCoE as an enabling team with a real charter.

How to Learn Azure and OCI Without Chasing Expiring Certifications

Apr 30, 2026 11 min read

Most cloud training is free if you know where to look. Certification names expire in 18–24 months. The durable approach: learn by role track, not by exam code.

IaaS, PaaS, and SaaS Without the Marketing Layer

Apr 30, 2026 12 min read

The service model pyramid tells you nothing operational. What the provider manages, what stays on you, and where lock-in lives — connector, not runtime.

Landing Zones — What They Actually Solve, and the Honest Catch

Apr 30, 2026 14 min read

The most useful and most overengineered concept in cloud adoption. What to take from reference architectures, what to skip, and the real cost of retrofitting.

Naming Conventions That Survive Both Azure and OCI

Apr 30, 2026 11 min read

Names are permanent — embedded in IaC, DNS, and certificates. A bad convention is debt you pay forever. The schema that survives Azure and OCI at real scale.

Regions, Zones, Availability Domains — Where Your Data Actually Lives

Apr 30, 2026 13 min read

Region choice locks in data residency, resilience, and service availability for years. The portal calls it a dropdown. It is an architectural decision.

  • Beginner
  • Azure
  • OCI
  • Regions
  • Availability Zones
  • Data Residency
Read Article

Sandboxes — The Environments You Will Probably Set Up Wrong the First Time

Apr 30, 2026 11 min read

Most orgs skip sandboxes or build them too locked-down to use. Either way, engineers find production. How to build one that gets used without eating budget.

Service Availability by Region — Why You Cannot Trust the Map

Apr 30, 2026 10 min read

Services launch in one US region and stay there a year. Sovereign clouds miss capabilities. 'Available' often means 'with a ticket.' Verify before committing.

  • Beginner
  • Azure
  • OCI
  • Governance
  • Service Availability
  • Region Selection
Read Article

Shared Responsibility — For People Who Stopped Believing the Marketing

Apr 30, 2026 12 min read

The shared responsibility chart is tidy on a slide. In production it falls apart. Managed never means hands-off. What stays on you — every service, every time.

  • Beginner
  • Azure
  • OCI
  • Security
  • Shared Responsibility
  • Compliance
Read Article

Tagging and Metadata That Actually Earn Their Keep

Apr 30, 2026 12 min read

Without enforcement, tagging is fiction. Most orgs believe coverage is higher than reality. The schema, enforcement model, and gotchas on Azure and OCI.

Tenant, Subscription, Management Group, Compartment — and What Actually Owns the Bill

Apr 30, 2026 13 min read

Organisational, billing, and governance boundaries collapse differently across Azure and OCI. Get the mental model wrong on day one and spend years undoing it.

Address Plans — Designing IP Space for Three Clouds and a Future You Cannot See

Apr 30, 2026 15 min read

IPAM tracks allocations. An address plan decides what to allocate and what to reserve. Most orgs skip the plan and pay for it in months of remediation later.

  • Intermediate
  • Azure
  • OCI
  • Networking
  • Address Planning
  • CIDR
Read Article

Hub-and-Spoke, Virtual WAN, and DRG — Three Topology Choices, Two Clouds, One Conversation

Apr 30, 2026 13 min read

Hub-and-spoke, Virtual WAN, OCI DRG v2 — three topologies, overlapping trade-offs. Decision framework and the non-transitive peering gotcha nobody warns about.

  • Intermediate
  • Azure
  • OCI
  • Networking
  • Hub-Spoke
  • Virtual WAN
Read Article

Hybrid Connectivity — ExpressRoute, FastConnect, VPN, and the Reality Behind the Glossy Diagrams

Apr 30, 2026 12 min read

Circuit bandwidth is not end-to-end application throughput. Redundancy is rarely as redundant as it looks. What actually survives production.

  • Intermediate
  • Azure
  • OCI
  • Networking
  • ExpressRoute
  • FastConnect
Read Article

IPAM — IP Address Management Before You Wish You Had Done It

Apr 30, 2026 11 min read

IP space looks infinite until two VNets try to peer with overlapping ranges. By then the fix is renumbering and weeks of work. IPAM costs nothing on day one.

Policy as Code and Quotas — Where Governance Stops Being a Wiki Page

Apr 30, 2026 13 min read

Governance as a wiki page is fiction. Governance is what the platform enforces. EPAC, Security Zones, quotas, Cloud Guard — the gaps and how to combine them.

  • Intermediate
  • Azure
  • OCI
  • Governance
  • Policy as Code
  • Compliance
Read Article

DORA Article 30 — Cloud Contracts, Audit Rights, and Exit Strategies

Apr 28, 2026 12 min read

DORA Article 30 specifies the contractual content every financial entity must obtain from its cloud providers. The list is long, the substance is operational, and most pre-DORA cloud contracts do not meet it. This article walks through each clause, what it means in practice, and what financial entities and cloud providers actually negotiate.

  • Advanced
  • DORA
  • Article 30
  • Contracts
  • Financial Sector
  • Exit Strategy
  • Compliance
  • Data Security
Read Article

Slovakia — KsVC: How MIRRI Decides Which Cloud Services the Government Can Use

Apr 26, 2026 12 min read

The Slovak government cloud catalogue is mandatory for the public sector and tied to the national cybersecurity audit framework. As of mid-2026, it is also operationally out of step with the NIS2-era risk-based regime — the methodology still classifies by U1–U4 while the underlying law has moved to risk analysis.

  • Intermediate
  • Slovakia
  • KsVC
  • MIRRI
  • NBÚ
  • NIS2
  • Compliance
  • Data Security
Read Article

DORA CTPP Regime — Direct ESA Supervision of Critical Cloud Providers

Apr 24, 2026 12 min read

The Critical Third-Party Provider regime is the most consequential innovation in DORA. For the first time in EU law, the European Supervisory Authorities can directly supervise cloud providers — not via their financial-services customers, but as named regulated entities. This article walks through how CTPP designation actually works, what direct supervision means operationally, and what hyperscalers do to prepare.

  • Advanced
  • DORA
  • CTPP
  • ESA
  • Financial Sector
  • Compliance
  • Data Security
  • Hyperscaler
Read Article

France — ANSSI SecNumCloud: The Strictest Sovereignty Framework in the EU

Apr 22, 2026 12 min read

Single qualification level, 350+ requirements, hard caps on non-EU ownership, immunity from extraterritorial law. SecNumCloud is the framework that defined the modern EU sovereignty debate.

  • Intermediate
  • France
  • ANSSI
  • SecNumCloud
  • NIS2
  • Compliance
  • Data Security
  • Sovereignty
Read Article

DORA for Cloud — Overview of the EU Financial-Sector Operational Resilience Regime

Apr 18, 2026 10 min read

The Digital Operational Resilience Act has been in force since January 2025 and applies to every financial entity in the EU. This article is the overview — what DORA is, its five pillars, and how it fits with national frameworks. For the CTPP regime and contractual content, see the dedicated deep-dive articles.

  • Advanced
  • DORA
  • Financial Sector
  • NIS2
  • Compliance
  • Data Security
  • Sectoral
Read Article

CSA STAR Registry — The Cross-Cutting Trust Layer Across Frameworks

Apr 16, 2026 9 min read

The Cloud Security Alliance STAR Registry is the closest thing the cloud industry has to a global trust register. Three assurance levels, the CCM as the underlying control matrix, and integration with most major national frameworks. Useful as a navigation layer when comparing CSPs across heterogeneous compliance regimes.

  • Intermediate
  • CSA STAR
  • CSA CCM
  • Compliance
  • Data Security
  • Cross-Cutting
  • Attestation
Read Article

Germany — BSI C5: The Attestation That Quietly Became Europe's Reference

Apr 14, 2026 12 min read

C5 is not a certification, it is an attestation — and that distinction matters. The framework most adopted by hyperscalers, the de facto reference for EUCS Substantial, and the one that pairs cleanly with SOC 2. C5:2026 was published in March 2026, with C5:2020 remaining operative until audit periods beginning on or after 1 June 2027.

  • Intermediate
  • Germany
  • BSI C5
  • BSI
  • NIS2
  • Compliance
  • Data Security
  • Attestation
Read Article

NIS2 Supply Chain — What Essential Entities Actually Need From Cloud Providers

Apr 11, 2026 11 min read

NIS2 doesn't just regulate operators directly — it regulates their supply chains, including cloud providers. This article unpacks what NIS2 supply-chain obligations actually look like for cloud customers and what evidence cloud providers must produce, with the per-country variation that matters in practice.

  • Advanced
  • NIS2
  • Supply Chain
  • Essential Entities
  • Compliance
  • Data Security
  • Cross-Cutting
Read Article

GDPR Article 28 and the EU Cloud Code of Conduct — What They Actually Demonstrate

Apr 9, 2026 10 min read

GDPR Article 28 is the operative article for every controller-processor cloud relationship. The EU Cloud Code of Conduct is the most pragmatic instrument for demonstrating Article 28 compliance at scale. This article walks through what Article 28 actually requires and what the CoC actually demonstrates.

  • Advanced
  • GDPR
  • EU Cloud CoC
  • Article 28
  • Compliance
  • Data Security
  • Cross-Cutting
  • Privacy
Read Article

SOC 2 Reports — How to Actually Read Them

Apr 7, 2026 12 min read

SOC 2 is the most commonly referenced cloud security attestation in procurement. It is also the one most often misread — Type 1 confused with Type 2, scope confused with depth, exception language misunderstood. This article walks through what a SOC 2 report actually contains and how to read it for real signal.

  • Intermediate
  • SOC 2
  • AICPA
  • Attestation
  • Compliance
  • Data Security
  • Cross-Cutting
  • Practitioner
Read Article

ISO 27001 / 27017 / 27018 / 27701 — The Universal Underlay Every National Framework Builds On

Apr 4, 2026 11 min read

Every national cloud security framework in Europe — KsVC, BSI C5, ENS, ACN, SecNumCloud, PiTuKri, BIO2 — references some combination of ISO 27001, 27017, 27018, and 27701. Knowing what each standard actually covers (and where each stops) is the prerequisite for working effectively with any of them.

  • Advanced
  • ISO 27001
  • ISO 27017
  • ISO 27018
  • ISO 27701
  • Compliance
  • Data Security
  • Cross-Cutting
Read Article

Data Security in the Cloud — How EU Member States Actually Decide What's Safe

Apr 2, 2026 14 min read

Every EU member state grades cloud security differently, and the 'European' scheme that was supposed to harmonise them has been stuck for two years. Here is the actual map — who leads, who drifts, and what a multicloud operator has to navigate.

  • Beginner
  • EU
  • Compliance
  • Data Security
  • Sovereignty
  • EUCS
  • NIS2
Read Article

Introduction to BPM Solutions: Camunda, Activiti and Kogito

Mar 12, 2025 10 min read

A practical introduction to modern BPM engines. What they solve, how they differ, and how to choose between Camunda, Activiti and Kogito for your organisation.

Azure Landing Zones: Scalable Cloud Foundations at Enterprise Scale

Jan 8, 2025 11 min read

The standardised foundation for Azure adoption at scale. Architecture, design areas, platform vs. application zones, and the right IaC deployment approach.

  • Advanced
  • Azure
  • OCI
  • Landing Zones
  • Governance
  • Cloud Adoption Framework
  • IaC
Read Article

GitOps at Scale with Argo CD and Multi-Cluster Kubernetes

Nov 15, 2024 9 min read

Production-grade GitOps with Argo CD across multiple Kubernetes clusters. Progressive delivery, drift detection, and the Azure vs OCI platform choice.

  • Intermediate
  • Azure
  • OCI
  • Argo CD
  • GitOps
  • Kubernetes
  • Progressive Delivery
Read Article