arrow_circle_right NOVIARC – SPYROSOFT CLOUD FOUNDRY

From compliance pressure to a platform you own

Since 6 December 2025, Germany’s NIS2 implementation has made cybersecurity risk management a management-body responsibility, with fines of up to €10 million for essential entities and no grace period. We migrate your regulated workloads to a sovereign Kubernetes platform where residency and access are documented, built with NoviArc – Spyrosoft Cloud Foundry.

Two Data Center Specialists Conducting Cloud Storage Capacity Audit. Sovereign cloud migration

arrow_circle_right SOVEREIGN CLOUD MIGRATION

Why NoviArc?

$1 million a year

saved by consolidating workloads onto Kubernetes

up to 80%

lower total migration cost

weeks

to a tailored, orchestrated cluster

€0

in licence fees – you pay for the service, not software

arrow_circle_right THE REGULATORY REALITY

Compliance is no longer optional

Germany’s NIS2 implementation came into force with no grace period, and the scope has expanded significantly. Four facts now shape platform decisions.

Personal accountability

Risk-management measures must be demonstrable today, and responsibility sits with the management body, with fines of up to €10 million for essential entities.

Ownership matters

An EU subsidiary with a US parent may still fall within the US CLOUD Act’s scope. Your NIS2 documentation needs to address that risk clearly – without turning it into a criticism of the provider.

Licence and build trade-offs

Per-core licences, such as OpenShift or Tanzu, rise as you scale. A do-it-yourself build can leave you exposed for more than 12 months. Neither option is easy to defend under audit.

Evidence on demand

Every access request to sensitive data needs a documented trail. NIS2 incident reporting timelines start with an early warning within 24 hours.

arrow_circle_right WHAT WE BUILD

NoviArc – a platform that’s sovereign by construction

NoviArc – Spyrosoft Cloud Foundry is built around principles that regulated organisations need to satisfy simultaneously.

Sovereign

No US company in the ownership, control, or software layer – a clear answer for your auditor and board.

Portable

Upstream Kubernetes on European infrastructure, including OVHcloud, Scaleway, and on-premises environments. You control the stack, which removes the biggest switching barrier.

Production-ready

More than 20 mature open-source components, pre-integrated. No 12-month build, no configuration debt, and no avoidable architectural risk while the clock is running.

Hardened to the regulation

Aligned with NIS2 Art. 21 and BSI Act requirements, CIS-hardened, and delivered with SSO/MFA, secrets management, and a full audit trail from day one.

arrow_circle_right MAPPED TO THE REGULATION

No black boxes: every requirement maps to a control

Each NIS2 Art. 21 measure category maps to a specific, CNCF-grade open-source component your engineers already know.

Access control and MFA

NIS2 expectation: access-control policies, asset management, and multi-factor authentication for systems handling essential services.

  • Single sign-on with enforced MFA across the platform – no shared or standing cluster credentials
  • Role-based access control scoped per team, with least-privilege defaults
  • Access changes are declarative and reviewable, with identity configured as code

Cryptography and secrets

NIS2 expectation: policies and procedures for cryptography and, where appropriate, encryption.

  • Secrets, API keys, and certificates are kept out of source code or repositories
  • Dynamic, short-lived credentials reduce the attack surface and simplify rotation
  • Every request for a sensitive token is logged and added to the audit trail

Audit trail and effectiveness

NIS2 expectation: procedures to assess the effectiveness of cybersecurity risk-management measures, supported by evidence.

  • A full audit trail documents access requests to sensitive resources
  • Monitoring and alerting are pre-built and active from the first minute the cluster runs
  • Full telemetry gives auditors clear evidence when they ask how a control works

Supply chain security

NIS2 expectation: supply chain security, including risks linked to direct suppliers and service providers.

  • Upstream, CNCF-governed open source – no proprietary control plane you cannot review
  • A private image registry with automated vulnerability scanning helps block images with known critical CVEs
  • You can audit the full component list and its open-source governance (CNCF / Apache)

Data residency and routing

Compliance need: demonstrable control over where data resides, how traffic is routed, and who may be able to compel access.

  • Sovereign ingress and load balancing inside your cluster – no third-country intermediary in the path
  • Data resides on European infrastructure (OVHcloud, Scaleway, on-premises) under EU jurisdiction
  • Full control of encryption certificates inside your own cluster

arrow_circle_right THE OWNERSHIP TEST

Sovereign by design vs. sovereign by ownership

The European Commission’s Cloud Sovereignty Framework evaluates factors that an operating model alone cannot change: strategic sovereignty, including ownership and governance (SOV-1), and exposure to non-EU laws such as the US CLOUD Act (SOV-2). Here is the side-by-side view.

Comparison Tab. Sovereign by design vs. sovereign by ownership
Comparison Tab. Sovereign by design vs. sovereign by ownership

arrow_circle_right HOW NOVIARC USES AI

AI with human oversight

AI-assisted migration

An agent inventories your estate, maps dependencies, and drafts the migration plan – reducing the slow, manual work behind discovery. Every recommendation is reviewed and approved by a Spyrosoft architect before it reaches you.

arrow_circle_right FROM ASSESSMENT TO MIGRATION

Your migration plan, generated as code – with your team approving every step

Migration and re-platforming projects often stall at the analysis stage, which can take weeks by hand. An AI agent scans your infrastructure, maps each service to a portable equivalent, and generates the migration as executable GitOps code. Your engineers review and approve every decision – they check the work, but don’t redo it.

counter_1

Audit

The agent scans your existing infrastructure and produces a complete, machine-readable inventory of resources, dependencies, costs, and risks.

  • Every managed service identified and classified
  • Cost per service benchmarked against a European-operator equivalent
  • Third-country access exposure flagged at component level, where relevant
counter_2

Mapping

Each service is mapped to an open, portable equivalent on NoviArc, creating a substitution plan with a savings estimate. Your architects sign it off before any code changes are made.

  • Managed functions → containerised workloads on upstream Kubernetes
  • Managed databases → self-managed equivalents on EU infrastructure
  • External CDN or WAF → in-jurisdiction open-source ingress, where required
counter_3

Migration

The agent generates the plan as code: GitOps manifests, Helm charts, and a test suite. Execution is supervised and incremental, so you validate each stage before the next begins.

  • Repeatable – the same process moves your first workload and your tenth
  • De-risked – automated tests validate behaviour before cutover
  • Auditable – every step is a Git commit with a clear change record

Migration stops being a one-off transformation project and becomes a repeatable service.

arrow_circle_right ENGINEERING HONESTY

When NoviArc is not the right answer

Check your workloads first. NoviArc is not a universal replacement for every hyperscaler service. It may not be the right fit if:

Your architecture is deeply dependent on proprietary serverless platforms.

You rely heavily on provider-specific managed databases.

Re-platforming would require substantial redesign that outweighs the benefits.

Sovereignty and portability are not material requirements for your workloads.

Want to optimise cloud cost? Here’s the fix

arrow_circle_right

arrow_circle_rightCONTACT US

Book a 30-minute architecture review

In 30 minutes, our platform engineers will review your architecture, identify where third-country access risk may exist, and show what a sovereign substrate could change.

Filip Różański Spyrosoft

Filip Rozanski

Head of Managed Services