14-day trial – test cloud infrastructure for free!
    Compliance

    Kubernetes building blocks for regulated industries

    We deliver the technical and organizational building blocks that financial services providers, healthcare organizations, and regulated companies need for their compliance architecture.

    Important: The final compliance assessment (BaFin BAIT/VAIT, DORA, KRITIS, patient data protection) is performed by the customer within their own regulatory context — focusnet delivers the infrastructure and the supporting evidence (DPA, certificates, TOM catalog, etc.).

    • ISO 27001 certified + PCI DSS Level 2
    • BSI C5 in preparation (Q3 2026)
    • GDPR Art. 28 compliant
    • NIS2-compliant
    • Building blocks for BAIT/VAIT/DORA outsourcing architectures
    • No US CLOUD Act — German jurisdiction

    For an initial structured assessment, start the free NIS2 readiness check.


    Cloud native meets regulation: a unique challenge

    Regulated companies face a twofold challenge with Kubernetes: the technology is complex, and the regulatory requirements leave no room for error.

    The key questions your compliance department will ask:

    • Where exactly do our workloads run? In which data center, on which hardware?
    • Who has access to the infrastructure? Is there access by foreign authorities?
    • Is data encrypted in transit and at rest?
    • Are there audit trails for all administrative actions?
    • How is tenant separation ensured?
    • Does the provider meet ISO 27001? Does it operate an ISMS?
    • Is there a data processing agreement pursuant to Art. 28 GDPR?
    • How are security incidents reported?

    At focusnet, the answer to every one of these questions is: yes, that is covered.


    focusnet compliance at a glance

    RequirementStandardWhat focusnet delivers
    Information securityISO 27001Certified (baseline evidence)
    Cloud-specificBSI C5In preparation (Q3 2026)
    Data protectionGDPRFully compliant, DPA pursuant to Art. 28
    Data transfersSchrems IINo transfers to third countries
    US government accessUS CLOUD ActNot applicable (German company)
    CybersecurityNIS2 (EU 2022/2555)Measures implemented, reporting channels established
    Payment processingPCI DSS Level 2Certified
    IT baseline protectionBSIAligned with BSI standards
    Banking supervisionBAIT/MaRisk/DORAInfrastructure building blocks; compliance remains with the customer
    Insurance supervisionVAITInfrastructure building blocks; compliance remains with the customer
    Health dataGDPR Art. 9Technical measures; compliance remains with the controller

    ISO 27001: What this means for your infrastructure

    focusnet operates a certified information security management system (ISMS) in accordance with ISO/IEC 27001. This includes:

    Organizational measures:

    • Documented security policies and processes
    • Regular risk analyses and assessments
    • Defined roles and responsibilities
    • Training and awareness for all employees
    • Regular internal and external audits
    • Management reviews and continuous improvement

    Technical measures:

    • Encryption in transit (TLS 1.3) and at rest
    • Multi-factor authentication for all administrative access
    • Network segmentation and firewall rules
    • Intrusion detection and prevention
    • Regular vulnerability assessments
    • Patch management with defined SLAs

    Physical measures:

    • Data center access controls (biometric + chip card)
    • Video surveillance and alarm systems
    • Redundant power supply (UPS, diesel generators)
    • Climate control and fire protection
    • Geo-redundant backup locations

    GDPR compliance: more than just a location

    Data processing agreement (DPA)

    focusnet provides all customers with a complete DPA pursuant to Art. 28 GDPR:

    • Subject matter and duration of processing clearly defined
    • Nature and purpose of processing documented
    • Technical and organizational measures (TOMs) included in the annex
    • Subprocessor register complete and transparent
    • Processing on documented instructions — focusnet acts only on customer instructions
    • Audit rights — audit options for the controller
    • Data deletion — documented processes after contract termination
    • Notification duties — timely notification in the event of incidents

    Records of processing activities

    focusnet maintains records of processing activities pursuant to Art. 30 GDPR. On request, we provide the relevant information for your own records.

    Data protection impact assessment (DPIA)

    For high-risk processing (e.g., health data), focusnet offers support in preparing the data protection impact assessment pursuant to Art. 35 GDPR. Our technical and organizational measures are documented and auditable.


    Industry-specific compliance

    Financial services: BAIT, MaRisk, VAIT, DORA

    Relevant regulations (in brief):

    • MaRisk (BaFin minimum requirements for risk management): requirements for IT outsourcing — outsourcing notification, risk analysis, contract design
    • BAIT (BaFin supervisory requirements for IT in financial institutions, BaFin circular): detailed rules for information risk management, IT strategy, IT operations, access rights management, contingency exercises
    • VAIT (supervisory requirements for IT in insurance undertakings): the equivalent circular for insurers (Section 26 VAG)
    • DORA (Digital Operational Resilience Act, EU 2022/2554, binding since January 17, 2025): EU-wide regulation for financial sector IT — mandatory TLPT testing, subcontractor registers, stricter incident reporting

    How focusnet supports these requirements:

    RequirementBuilding block delivered by focusnet
    Outsourcing managementDPA pursuant to Art. 28 GDPR + SLA contract + technical reports
    Information risk managementISO 27001 ISMS, TOM catalog, BSI C5 (Q3 2026)
    IT operationsManaged service with documented change and incident processes
    Access managementRBAC + MFA + audit logs
    IT contingency managementRedundancy, backup, incident response process; contingency exercises are organized by the customer
    Outsourcing oversightOn request: ISO 27001 certificate, TOM catalog, records of processing activities
    Subcontractor transparency (DORA)List of subcontractors in use available on request

    What the customer must handle themselves (regardless of which platform they choose):

    • Outsourcing notification to BaFin / cloud notification
    • Risk analysis and cloud risk assessment
    • Contractual governance (service levels, exit strategy)
    • Contingency exercises with their own application
    • Under DORA: inclusion in their own ICT subcontractor register

    Dedicated infrastructure for the financial sector: With a dedicated cluster, the customer gets dedicated hardware with their own control plane and worker nodes, their own VLAN, and their own public IP. focusnet continues to manage the control plane (updates, patches). No shared infrastructure with other customers — a building block for the tenant separation that BaFin expects in the context of outsourcing.

    Healthcare: patient data and Art. 9 GDPR

    Relevant regulations:

    • GDPR Art. 9: special categories of personal data (health data)
    • German Patient Data Protection Act (PDSG): requirements for IT systems in healthcare
    • Connector services/TI: telematics infrastructure connectivity
    • DiGA regulation: digital health applications

    How focusnet protects health data:

    Requirementfocusnet measure
    EncryptionTLS 1.3 in transit, encryption at rest
    Access controlRBAC with granular roles, MFA
    Audit trailComplete logging of all access
    Network isolationKubernetes network policies, dedicated VLANs
    Data locationData center locations in Germany only
    Incident responseDefined reporting processes, fast communication
    Backup & recoveryRegular backups, documented recovery

    Public sector: BSI and IT baseline protection

    Relevant regulations:

    • BSI IT-Grundschutz: framework for information security
    • EVB-IT Cloud: supplementary contract terms for cloud services in German public procurement
    • Online Access Act (OZG): digital government services

    focusnet for the public sector:

    • German infrastructure without US dependencies
    • ISO 27001 as the basis for BSI IT-Grundschutz conformity
    • DPA and compliance documentation for procurement procedures
    • Dedicated clusters for maximum isolation

    Audit trails and evidence obligations

    focusnet offers extensive audit capabilities:

    Kubernetes audit logs:

    • All API requests are logged
    • Who changed what, and when? — fully traceable
    • Export to external SIEM systems possible

    Rancher audit logs:

    • All actions in the Rancher UI are logged
    • Login events, role assignments, configuration changes
    • Filtering by user and timestamp

    Infrastructure logs:

    • Node events and system logs
    • Network events via KubeOVN (flow counts, policy hits)
    • Storage events and capacity changes

    Audit rights and how they work in practice:

    Under Art. 28 GDPR and as part of our contracts, controllers are entitled to oversight and audit rights. In practice, we offer multi-tiered audit options — on-site audits by every individual customer would be neither feasible nor in the interest of the other tenants:

    Audit typeWho can use itWhat we provide
    Writtenevery customer with a DPAISO 27001 certificate, TOM catalog, subcontractor list, records of processing activities
    Standardized reportsevery customerBSI C5 report (from Q3 2026), SOC 2 Type II planned
    Questionnaire-basedevery customerResponses to CRSA, VDA-ISA, and comparable standard questionnaires
    On-site auditmajor accounts with a master agreementby prior arrangement in individual cases, within an agreed audit scope
    Supervisory authority auditssupervisory authorities (BaFin, BSI, etc.)full cooperation and data disclosure as required by law

    Defense in depth: multi-layered security

    Layer 1: Physical security
       |-- ISO 27001 certified data centers
       |-- Biometric access controls
       |-- Video surveillance, fire protection, UPS
    
    Layer 2: Network security
       |-- Dedicated VLANs
       |-- Kubernetes network policies + extended L7 policies (KubeOVN)
       |-- Virtual and physical firewalls
    
    Layer 3: Cluster security
       |-- RKE2 (security-hardened)
       |-- Pod Security Standards
       |-- RBAC with least-privilege principle
       |-- Kubernetes audit logging
    
    Layer 4: Application security
       |-- Harbor vulnerability scanning
       |-- Image signing (Notary)
       |-- Admission controllers
       |-- Runtime security (add-on)
    
    Layer 5: Data security
       |-- Encryption at rest
       |-- TLS 1.3 in transit
       |-- Backup & recovery
       |-- Data deletion processes
    

    NIS2: prepared for the new EU cybersecurity directive

    The NIS2 Directive (EU 2022/2555) massively expands the range of affected companies starting in 2025. Financial services providers, healthcare organizations, and digital infrastructure fall under the stricter requirements.

    Affected sectors:

    • Financial market infrastructures
    • Healthcare providers
    • Digital infrastructure
    • ICT service management (B2B)
    • Public administration

    focusnet NIS2 measures:

    • Risk management in accordance with ISO 27001
    • Incident response processes with defined reporting deadlines (24h early warning, 72h detailed report)
    • Business continuity management with geo-redundant data center locations
    • Supply chain governance: platform software and operations fully under German control; hardware components (compute, GPU, network) come from global supply chains — as with every cloud provider — but are operated in our German data centers; no US cloud provider and no US parent company has access to platform control
    • Encryption in transit (TLS 1.3) and at rest, access control (RBAC + MFA)
    • Vulnerability management and regular assessments
    • Training and awareness for our own staff

    Recommended architecture for maximum compliance

    Recommended setup:

    • Dedicated cluster L or XL — no shared infrastructure
    • SUSE Observability — logs, metrics, and traces in one; covers monitoring and logging requirements for audit trails
    • SUSE NeuVector — container security with image scanning, runtime protection, and compliance reports
    • S3 storage — for backup archiving and data export

    Costs for a compliance-optimized environment (Dedicated L):

    ComponentPrice/month
    K8s Dedicated L€999
    Cluster management fee€99
    SUSE Observability (logs + metrics + traces)€100
    SUSE NeuVector (container security)€200
    S3 (1 TB backup, flat-rate tier)€15
    Total€1,413/month

    With a 36-month commitment (−35% on K8s + management; add-ons not discounted; S3 not discounted): approx. €964/month.

    For comparison: a dedicated Kubernetes administrator for a BaFin-/healthcare-compliant self-managed solution costs €3,000–5,000+ per month on its own — excluding hardware, storage, licenses, or the compliance documentation.

    Contract terms: Cancellation with 30 days notice to the end of the month, no minimum term (except with a voluntary commitment discount: −15 / −25 / −35% for 12 / 24 / 36 months). Offer exclusively for businesses within the meaning of Section 14 of the German Civil Code (B2B). Egress traffic: tier-specific fair-use allowance, no hard limits (Dedicated 500 GB / vCPU, Flex and Business 250 GB / vCPU). Internal traffic is always unlimited. SLA: 99.9% availability for Flex, Business, and Dedicated.


    FAQ

    1. Can I use focusnet for BaFin-regulated workloads?

    focusnet provides the technical infrastructure that meets the BaFin requirements (BAIT/MaRisk) for IT outsourcing: ISO 27001, dedicated infrastructure, DPA, audit rights, incident response processes. The final compliance assessment rests with your compliance department and, where applicable, with BaFin.

    2. Does focusnet meet the requirements for health data (Art. 9 GDPR)?

    focusnet provides the technical and organizational measures required for processing special categories of personal data: encryption, access control, audit trails, dedicated infrastructure, data center locations in Germany. The data protection responsibility for the processing remains with the controller (you).

    3. Does focusnet provide audit support?

    Yes. focusnet provides audit logs, compliance documentation, and technical information for your internal and external audits. On request, we support supervisory audits and provide the necessary documentation.

    4. How are security incidents reported?

    focusnet has defined incident response processes. Security incidents are reported to affected customers within 72 hours in accordance with GDPR Art. 33. For NIS2-relevant incidents, the stricter reporting deadlines apply (24h early warning, 72h detailed report).

    5. Which tier is suitable for compliance workloads?

    For compliance-critical workloads we recommend K8s Dedicated, because it provides full infrastructure isolation (dedicated VMs with their own CP and worker nodes, dedicated VLAN, dedicated IP; focusnet continues to manage the control plane). K8s Business (vCluster Virtual) offers an isolated control plane on shared hardware with a dedicated IP — suitable for many compliance requirements that do not demand full hardware isolation. The Free tier and Flex are generally not suitable for compliance workloads.

    6. Is there a dedicated contact for compliance questions?

    Yes. For customers with compliance requirements, we provide a dedicated contact who supports you with regulatory questions, audit preparation, and compliance documentation.


    Compliance-ready Kubernetes — without compromise

    ISO 27001, GDPR, NIS2 — focusnet delivers the infrastructure for regulated companies. Try it free for 14 days or schedule a consultation right away.

    Ready for the next step?

    We deliver the technical and organizational building blocks that financial services providers, healthcare organizations, and regulated companies need for their compliance architecture.