
Meet the Authors
SAP now secures data center connectivity between Walldorf and St. Leon-Rot with BSI-approved Layer 1 encryption from Adva Network Security, approved for VS-NfD classified information.
The quantum-safe optical layer encryption protects every data stream, including replication, backup, and operational traffic, against interception and harvest-now, decrypt-later attacks.
The deployment builds on SAP's 2026 sovereign cloud milestones, following IT-Grundschutz certification in April and BSI VS-NfD authorization for SAP Cloud Infrastructure in June.
Sovereign cloud is no longer a marketing label in Germany. It is becoming a measurable security architecture, and SAP just reinforced one of its most fundamental layers. On August 19, 2026, Adva Network Security, an Adtran company, announced that SAP is using its Layer 1 encryption technology to secure connectivity between SAP’s data centers in Walldorf and St. Leon-Rot, Germany. The solution encrypts data directly at the optical transmission layer. It is approved by the German Federal Office for Information Security (BSI) for information classified up to “Verschlusssache – Nur für den Dienstgebrauch” (VS-NfD), or “For Official Use Only.”
For SAP, the deployment strengthens the security architecture of its German data centers. It supports customers in the public sector, regulated industries, and critical infrastructure that require compliant, controlled processing of sensitive data in Germany, particularly where strict confidentiality, regulatory traceability, and operational security are essential.
Securing the Layer Below Everything Else
Most enterprise security conversations focus on applications, identities, and networks. Layer 1 encryption operates below all of them, encrypting data within the optical transmission layer before it leaves the site. That design secures every data stream crossing the connection, including replication, backup, management, and operational traffic, and protects against interception, manipulation, and unauthorized access. The result is that data transmission between data centers becomes a protected component of sovereign cloud architecture, extending security beyond sites, systems, and applications to the physical transmission layer itself.
The solution combines established cryptographic methods with quantum-secure mechanisms, delivering high-performance, low-latency, and transparent encryption. That matters for enterprise architects planning long-lived infrastructure, because it prepares SAP’s data center interconnects against future threats from quantum computing, including harvest-now, decrypt-later attacks.
“For many organizations, the ability to process sensitive data securely within Germany is a key requirement when selecting cloud services, particularly for government agencies, regulated industries and critical infrastructure providers,” said Christoph Glingener, CTO of Adtran, adding that the deployment “expands the foundation for sovereign cloud offerings in Germany.”
Josef Sißmeir, GM of Adva Network Security, framed the partnership in sovereignty terms: “As a German company with decades of experience in highly secure networks, we’re contributing to digital sovereignty and strengthening trust in critical digital infrastructures.”
A Sequence of Sovereign Cloud Milestones
This announcement does not stand alone. In April 2026, SAP completed ISO/IEC 27001 certification based on the BSI’s IT-Grundschutz methodology for the physical infrastructure of its German data centers. In June 2026, SAP received BSI authorization to process VS-NfD classified information on SAP Cloud Infrastructure in Walldorf and St. Leon-Rot, making it one of only a few providers in Germany with a cloud environment whose key security components carry that authorization. SAPinsider examined the operating model behind that authorization and what it signals for regulated SAP workloads. That sovereign region comprises three independent availability zones in physically separated data centers, interconnected via SAP-owned fiber and BSI-authorized German security hardware.
The Adva Network Security deployment closes a logical gap in that sequence: the fiber between those facilities. Adva Network Security pioneered line-rate Layer 1 encryption and has implemented post-quantum cryptography in its ConnectGuard technology since 2021, with BSI and NATO/EU approvals across its portfolio.
What This Means for SAPinsiders
Sovereignty now extends to the physical layer. CIOs evaluating SAP Sovereign Cloud or Delos Cloud should assess providers on where encryption begins, not just where data resides. SAP’s architecture now covers data in transit at the optical layer, a differentiator in public sector tenders.
Quantum readiness is entering procurement criteria. Enterprise architects should note that quantum-safe mechanisms are already deployed in production SAP infrastructure, and should begin mapping their own cryptographic inventories against post-quantum timelines.
Compliance milestones compound. ERP program managers supporting regulated workloads should track SAP’s progression from IT-Grundschutz certification to VS-NfD authorization to encrypted interconnects, since each milestone expands which workloads can legitimately move to SAP’s German cloud.



