Important: The final compliance assessment (BaFin BAIT/VAIT, DORA, KRITIS, patient data protection) is performed by the customer within their own regulatory context — focusnet delivers the infrastructure and the supporting evidence (DPA, certificates, TOM catalog, etc.).
- ISO 27001 certified + PCI DSS Level 2
- BSI C5 in preparation (Q3 2026)
- GDPR Art. 28 compliant
- NIS2-compliant
- Building blocks for BAIT/VAIT/DORA outsourcing architectures
- No US CLOUD Act — German jurisdiction
For an initial structured assessment, start the free NIS2 readiness check.
Cloud native meets regulation: a unique challenge
Regulated companies face a twofold challenge with Kubernetes: the technology is complex, and the regulatory requirements leave no room for error.
The key questions your compliance department will ask:
- Where exactly do our workloads run? In which data center, on which hardware?
- Who has access to the infrastructure? Is there access by foreign authorities?
- Is data encrypted in transit and at rest?
- Are there audit trails for all administrative actions?
- How is tenant separation ensured?
- Does the provider meet ISO 27001? Does it operate an ISMS?
- Is there a data processing agreement pursuant to Art. 28 GDPR?
- How are security incidents reported?
At focusnet, the answer to every one of these questions is: yes, that is covered.
focusnet compliance at a glance
| Requirement | Standard | What focusnet delivers |
|---|---|---|
| Information security | ISO 27001 | Certified (baseline evidence) |
| Cloud-specific | BSI C5 | In preparation (Q3 2026) |
| Data protection | GDPR | Fully compliant, DPA pursuant to Art. 28 |
| Data transfers | Schrems II | No transfers to third countries |
| US government access | US CLOUD Act | Not applicable (German company) |
| Cybersecurity | NIS2 (EU 2022/2555) | Measures implemented, reporting channels established |
| Payment processing | PCI DSS Level 2 | Certified |
| IT baseline protection | BSI | Aligned with BSI standards |
| Banking supervision | BAIT/MaRisk/DORA | Infrastructure building blocks; compliance remains with the customer |
| Insurance supervision | VAIT | Infrastructure building blocks; compliance remains with the customer |
| Health data | GDPR Art. 9 | Technical measures; compliance remains with the controller |
ISO 27001: What this means for your infrastructure
focusnet operates a certified information security management system (ISMS) in accordance with ISO/IEC 27001. This includes:
Organizational measures:
- Documented security policies and processes
- Regular risk analyses and assessments
- Defined roles and responsibilities
- Training and awareness for all employees
- Regular internal and external audits
- Management reviews and continuous improvement
Technical measures:
- Encryption in transit (TLS 1.3) and at rest
- Multi-factor authentication for all administrative access
- Network segmentation and firewall rules
- Intrusion detection and prevention
- Regular vulnerability assessments
- Patch management with defined SLAs
Physical measures:
- Data center access controls (biometric + chip card)
- Video surveillance and alarm systems
- Redundant power supply (UPS, diesel generators)
- Climate control and fire protection
- Geo-redundant backup locations
GDPR compliance: more than just a location
Data processing agreement (DPA)
focusnet provides all customers with a complete DPA pursuant to Art. 28 GDPR:
- Subject matter and duration of processing clearly defined
- Nature and purpose of processing documented
- Technical and organizational measures (TOMs) included in the annex
- Subprocessor register complete and transparent
- Processing on documented instructions — focusnet acts only on customer instructions
- Audit rights — audit options for the controller
- Data deletion — documented processes after contract termination
- Notification duties — timely notification in the event of incidents
Records of processing activities
focusnet maintains records of processing activities pursuant to Art. 30 GDPR. On request, we provide the relevant information for your own records.
Data protection impact assessment (DPIA)
For high-risk processing (e.g., health data), focusnet offers support in preparing the data protection impact assessment pursuant to Art. 35 GDPR. Our technical and organizational measures are documented and auditable.
Industry-specific compliance
Financial services: BAIT, MaRisk, VAIT, DORA
Relevant regulations (in brief):
- MaRisk (BaFin minimum requirements for risk management): requirements for IT outsourcing — outsourcing notification, risk analysis, contract design
- BAIT (BaFin supervisory requirements for IT in financial institutions, BaFin circular): detailed rules for information risk management, IT strategy, IT operations, access rights management, contingency exercises
- VAIT (supervisory requirements for IT in insurance undertakings): the equivalent circular for insurers (Section 26 VAG)
- DORA (Digital Operational Resilience Act, EU 2022/2554, binding since January 17, 2025): EU-wide regulation for financial sector IT — mandatory TLPT testing, subcontractor registers, stricter incident reporting
How focusnet supports these requirements:
| Requirement | Building block delivered by focusnet |
|---|---|
| Outsourcing management | DPA pursuant to Art. 28 GDPR + SLA contract + technical reports |
| Information risk management | ISO 27001 ISMS, TOM catalog, BSI C5 (Q3 2026) |
| IT operations | Managed service with documented change and incident processes |
| Access management | RBAC + MFA + audit logs |
| IT contingency management | Redundancy, backup, incident response process; contingency exercises are organized by the customer |
| Outsourcing oversight | On request: ISO 27001 certificate, TOM catalog, records of processing activities |
| Subcontractor transparency (DORA) | List of subcontractors in use available on request |
What the customer must handle themselves (regardless of which platform they choose):
- Outsourcing notification to BaFin / cloud notification
- Risk analysis and cloud risk assessment
- Contractual governance (service levels, exit strategy)
- Contingency exercises with their own application
- Under DORA: inclusion in their own ICT subcontractor register
Dedicated infrastructure for the financial sector: With a dedicated cluster, the customer gets dedicated hardware with their own control plane and worker nodes, their own VLAN, and their own public IP. focusnet continues to manage the control plane (updates, patches). No shared infrastructure with other customers — a building block for the tenant separation that BaFin expects in the context of outsourcing.
Healthcare: patient data and Art. 9 GDPR
Relevant regulations:
- GDPR Art. 9: special categories of personal data (health data)
- German Patient Data Protection Act (PDSG): requirements for IT systems in healthcare
- Connector services/TI: telematics infrastructure connectivity
- DiGA regulation: digital health applications
How focusnet protects health data:
| Requirement | focusnet measure |
|---|---|
| Encryption | TLS 1.3 in transit, encryption at rest |
| Access control | RBAC with granular roles, MFA |
| Audit trail | Complete logging of all access |
| Network isolation | Kubernetes network policies, dedicated VLANs |
| Data location | Data center locations in Germany only |
| Incident response | Defined reporting processes, fast communication |
| Backup & recovery | Regular backups, documented recovery |
Public sector: BSI and IT baseline protection
Relevant regulations:
- BSI IT-Grundschutz: framework for information security
- EVB-IT Cloud: supplementary contract terms for cloud services in German public procurement
- Online Access Act (OZG): digital government services
focusnet for the public sector:
- German infrastructure without US dependencies
- ISO 27001 as the basis for BSI IT-Grundschutz conformity
- DPA and compliance documentation for procurement procedures
- Dedicated clusters for maximum isolation
Audit trails and evidence obligations
focusnet offers extensive audit capabilities:
Kubernetes audit logs:
- All API requests are logged
- Who changed what, and when? — fully traceable
- Export to external SIEM systems possible
Rancher audit logs:
- All actions in the Rancher UI are logged
- Login events, role assignments, configuration changes
- Filtering by user and timestamp
Infrastructure logs:
- Node events and system logs
- Network events via KubeOVN (flow counts, policy hits)
- Storage events and capacity changes
Audit rights and how they work in practice:
Under Art. 28 GDPR and as part of our contracts, controllers are entitled to oversight and audit rights. In practice, we offer multi-tiered audit options — on-site audits by every individual customer would be neither feasible nor in the interest of the other tenants:
| Audit type | Who can use it | What we provide |
|---|---|---|
| Written | every customer with a DPA | ISO 27001 certificate, TOM catalog, subcontractor list, records of processing activities |
| Standardized reports | every customer | BSI C5 report (from Q3 2026), SOC 2 Type II planned |
| Questionnaire-based | every customer | Responses to CRSA, VDA-ISA, and comparable standard questionnaires |
| On-site audit | major accounts with a master agreement | by prior arrangement in individual cases, within an agreed audit scope |
| Supervisory authority audits | supervisory authorities (BaFin, BSI, etc.) | full cooperation and data disclosure as required by law |
Defense in depth: multi-layered security
Layer 1: Physical security
|-- ISO 27001 certified data centers
|-- Biometric access controls
|-- Video surveillance, fire protection, UPS
Layer 2: Network security
|-- Dedicated VLANs
|-- Kubernetes network policies + extended L7 policies (KubeOVN)
|-- Virtual and physical firewalls
Layer 3: Cluster security
|-- RKE2 (security-hardened)
|-- Pod Security Standards
|-- RBAC with least-privilege principle
|-- Kubernetes audit logging
Layer 4: Application security
|-- Harbor vulnerability scanning
|-- Image signing (Notary)
|-- Admission controllers
|-- Runtime security (add-on)
Layer 5: Data security
|-- Encryption at rest
|-- TLS 1.3 in transit
|-- Backup & recovery
|-- Data deletion processes
NIS2: prepared for the new EU cybersecurity directive
The NIS2 Directive (EU 2022/2555) massively expands the range of affected companies starting in 2025. Financial services providers, healthcare organizations, and digital infrastructure fall under the stricter requirements.
Affected sectors:
- Financial market infrastructures
- Healthcare providers
- Digital infrastructure
- ICT service management (B2B)
- Public administration
focusnet NIS2 measures:
- Risk management in accordance with ISO 27001
- Incident response processes with defined reporting deadlines (24h early warning, 72h detailed report)
- Business continuity management with geo-redundant data center locations
- Supply chain governance: platform software and operations fully under German control; hardware components (compute, GPU, network) come from global supply chains — as with every cloud provider — but are operated in our German data centers; no US cloud provider and no US parent company has access to platform control
- Encryption in transit (TLS 1.3) and at rest, access control (RBAC + MFA)
- Vulnerability management and regular assessments
- Training and awareness for our own staff
Recommended architecture for maximum compliance
Recommended setup:
- Dedicated cluster L or XL — no shared infrastructure
- SUSE Observability — logs, metrics, and traces in one; covers monitoring and logging requirements for audit trails
- SUSE NeuVector — container security with image scanning, runtime protection, and compliance reports
- S3 storage — for backup archiving and data export
Costs for a compliance-optimized environment (Dedicated L):
| Component | Price/month |
|---|---|
| K8s Dedicated L | €999 |
| Cluster management fee | €99 |
| SUSE Observability (logs + metrics + traces) | €100 |
| SUSE NeuVector (container security) | €200 |
| S3 (1 TB backup, flat-rate tier) | €15 |
| Total | €1,413/month |
With a 36-month commitment (−35% on K8s + management; add-ons not discounted; S3 not discounted): approx. €964/month.
For comparison: a dedicated Kubernetes administrator for a BaFin-/healthcare-compliant self-managed solution costs €3,000–5,000+ per month on its own — excluding hardware, storage, licenses, or the compliance documentation.
Contract terms: Cancellation with 30 days notice to the end of the month, no minimum term (except with a voluntary commitment discount: −15 / −25 / −35% for 12 / 24 / 36 months). Offer exclusively for businesses within the meaning of Section 14 of the German Civil Code (B2B). Egress traffic: tier-specific fair-use allowance, no hard limits (Dedicated 500 GB / vCPU, Flex and Business 250 GB / vCPU). Internal traffic is always unlimited. SLA: 99.9% availability for Flex, Business, and Dedicated.
FAQ
1. Can I use focusnet for BaFin-regulated workloads?
focusnet provides the technical infrastructure that meets the BaFin requirements (BAIT/MaRisk) for IT outsourcing: ISO 27001, dedicated infrastructure, DPA, audit rights, incident response processes. The final compliance assessment rests with your compliance department and, where applicable, with BaFin.
2. Does focusnet meet the requirements for health data (Art. 9 GDPR)?
focusnet provides the technical and organizational measures required for processing special categories of personal data: encryption, access control, audit trails, dedicated infrastructure, data center locations in Germany. The data protection responsibility for the processing remains with the controller (you).
3. Does focusnet provide audit support?
Yes. focusnet provides audit logs, compliance documentation, and technical information for your internal and external audits. On request, we support supervisory audits and provide the necessary documentation.
4. How are security incidents reported?
focusnet has defined incident response processes. Security incidents are reported to affected customers within 72 hours in accordance with GDPR Art. 33. For NIS2-relevant incidents, the stricter reporting deadlines apply (24h early warning, 72h detailed report).
5. Which tier is suitable for compliance workloads?
For compliance-critical workloads we recommend K8s Dedicated, because it provides full infrastructure isolation (dedicated VMs with their own CP and worker nodes, dedicated VLAN, dedicated IP; focusnet continues to manage the control plane). K8s Business (vCluster Virtual) offers an isolated control plane on shared hardware with a dedicated IP — suitable for many compliance requirements that do not demand full hardware isolation. The Free tier and Flex are generally not suitable for compliance workloads.
6. Is there a dedicated contact for compliance questions?
Yes. For customers with compliance requirements, we provide a dedicated contact who supports you with regulatory questions, audit preparation, and compliance documentation.
Compliance-ready Kubernetes — without compromise
ISO 27001, GDPR, NIS2 — focusnet delivers the infrastructure for regulated companies. Try it free for 14 days or schedule a consultation right away.