What Fraunhofer and SAP Published on August 3

Two Fraunhofer institutes did the engineering work: the Institute for Software and Systems Engineering (ISST) and the Institute for Applied and Integrated Security (AISEC). SAP joined as the industrial partner. Together, under the EU's IPCEI-CIS programme, the Important Project of Common European Interest for Next Generation Cloud Infrastructure and Services, they published ApeiroRA, the Apeiro Reference Architecture, as an open-source blueprint on August 3, 2026.

ApeiroRA is not a running service. It is a specification: a documented set of principles and interfaces covering zero trust security, confidential computing, automated lifecycle management, digital twins for resource optimization and AI-supported operations management, published for anyone to read, implement and audit.

The 70 Percent Problem It Targets

Microsoft, Amazon and Google Cloud together hold roughly 70 percent of Europe's cloud infrastructure market, a concentration that gives three American companies outsized influence over pricing, data residency terms and the practical cost of ever leaving. Fraunhofer's own announcement framed ApeiroRA explicitly against that dependence, not as an abstract sovereignty gesture but as an engineering answer to it.

The stated goal is workload mobility: applications should be able to move dynamically between centralized data centers and edge locations near where the data actually originates, cutting the latency and bandwidth cost of routing everything through a small number of distant regions, without being rewritten each time they move.

Why Earlier Sovereign Cloud Efforts Recreated Lock-In

Most products sold under a sovereignty label so far have been a single vendor's own stack: one company's control plane, one company's roadmap, one company's pricing, wrapped in national or European branding. Switching away from that vendor later costs the same as switching away from any hyperscaler, because the lock-in was never about which flag flew over the data center.

The test that exposes the difference is simple: can a workload's definition be handed to a second, unrelated vendor and run there without a rewrite. Under a proprietary sovereign stack the answer is almost always no. That is the gap ApeiroRA is built to close.

An Open Reference Architecture Is a Different Kind of Thing

ApeiroRA is published, not sold. Any vendor, systems integrator or in-house IT team can implement against it, and because the specification itself is public, a workload described in ApeiroRA's terms is portable across every implementation rather than tied to one company's product cycle. That is the structural difference between a reference architecture and a proprietary platform wearing a sovereignty label.

SAP's Andreas Schlosser described the collaboration in Fraunhofer's own announcement as pairing Fraunhofer's methodological depth and structured approach with SAP's product experience to produce, in his words, verifiable and transferable solutions. Verifiable and transferable are the two properties a single-vendor sovereign product structurally cannot offer, however sincerely it uses the word sovereignty.

NeoNephos and What a Procurement Team Should Ask Now

The results feed into the NeoNephos Foundation, a project inside Linux Foundation Europe working on open-source sovereign cloud technology. That placement matters as much as the specification itself: governance sits with a nonprofit foundation rather than with SAP or any single implementer, which is what keeps the architecture open even as vendors build commercial products against it.

For an EU or UK IT buyer, the actionable step is a single question added to every sovereign cloud vendor evaluation from now on: is your architecture documented against an open, publicly auditable reference standard such as ApeiroRA, or is it your own proprietary design. The first answer buys portability. The second buys a new vendor to eventually leave.