Germany Cloud Application Security and API Management Guide
Germany Cloud Application Security & API Management
Germany cloud and API guide • Updated August 5, 2026

Germany Cloud Application Security and API Management: 2026 Market Guide

A source-linked guide to Germany’s cloud adoption, application security, API management market, sovereign-cloud options, regulation, runtime risks, and practical buyer decisions.

Germany’s cloud market is no longer defined only by migration. The harder questions in 2026 are how to govern a growing API estate, reduce provider dependency, protect sensitive data, maintain resilience, and produce evidence that security, operations, procurement, and assurance teams can actually use.

How to read the numbers: official adoption statistics, industry surveys, and commercial market forecasts answer different questions. “Cloud security,” “application security,” “CNAPP,” “API management,” and “API security” also overlap. Their values should not be added together or treated as one uniform market.
Market signalLatest linked evidenceBuyer interpretation
Official paid-cloud adoption54% of German enterprises with 10+ employees in 2025Cloud use is mainstream, but adoption still varies sharply by company size.
Broader business cloud use86% use cloud services; 14% plan or discuss adoptionFor Bitkom’s survey population, cloud is effectively universal or under active consideration.
Security as a buying priority95% call security, privacy, and compliance trust a must-haveSecurity evidence is a procurement requirement, not an optional add-on.
Resilience pressure28% of cloud users reported serious outagesFailover, telemetry, recovery, and provider dependencies must be tested.
Cloud computing estimateUSD 65.05B in 2026; USD 131.29B by 2031One broad commercial model projects sustained double-digit growth.
Cloud security estimateUSD 2.9826B in 2026; USD 6.1293B by 2033Cloud growth increases demand for identity, posture, workload, data, and runtime controls.
API management estimateApproximately USD 0.36B in Germany in 2026API governance, gateways, developer platforms, and analytics are becoming core operating capabilities.

Germany Cloud Market Forecasts for 2026

Mordor Intelligence estimates Germany’s cloud computing market at USD 56.52 billion in 2025, USD 65.05 billion in 2026, and USD 131.29 billion by 2031, with a forecast CAGR of 15.08% from 2026 to 2031.

Fortune Business Insights uses a different market model and reports USD 53.94 billion in 2025 and USD 128.29 billion by 2032. Both forecasts indicate strong expansion, but their values should not be averaged because the included products, services, and revenue definitions differ.

The useful conclusion is not one perfect market-size number. Germany is a large, expanding cloud economy, while official adoption data shows that smaller and mid-sized enterprises still have substantial room to deepen usage.

What belongs inside the Germany cloud market?

Infrastructure

Compute, storage, networking, databases, containers, Kubernetes, backup, disaster recovery, AI infrastructure, and edge capacity.

Platforms

Application platforms, integration, API management, event streaming, observability, identity, data engineering, AI services, and developer tooling.

Software

Enterprise SaaS, industry applications, collaboration, ERP, CRM, analytics, security, and cloud-delivered operational systems.

Services

Migration, modernization, managed operations, security, compliance, FinOps, sovereignty design, resilience, and exit planning.

Germany cloud application security and API management architecture

Germany Cloud Adoption and Resilience Data

Destatis, Germany’s Federal Statistical Office, reports that 54% of enterprises with at least 10 employees purchased cloud services in 2025. The rate was 51% among companies with 10–49 employees, 65% among those with 50–249 employees, and 86% among enterprises with 250 or more employees.

Enterprise groupPaid cloud-service useWhat it suggests
All enterprises with 10+ employees54%Cloud adoption is broad, but not yet uniform.
10–49 employees51%Smaller companies remain the largest expansion opportunity.
50–249 employees65%Mid-market cloud estates increasingly need formal governance and security operations.
250+ employees86%Large enterprises are likely to manage multiple clouds, accounts, APIs, and service owners.

The Bitkom Cloud Report 2026 measures a different population: 603 German companies with at least 20 employees. It reports that 86% currently use cloud services, while another 14% are planning or discussing adoption. Among respondents, 34% use hybrid cloud and 38% use multiple cloud providers.

The same study shows that cloud decisions are becoming more security- and sovereignty-driven. 95% identify trust in IT security, data protection, and compliance as a must-have provider criterion; 98% say the provider’s country of origin matters; and 64% of cloud users say US government policy is causing them to reconsider their cloud strategy.

Cloud resilience is now a board-level operating issue

Bitkom’s 2026 resilience findings add an operational warning: 28% of cloud-using companies experienced serious cloud outages during the previous 12 months. Although 82% maintain emergency and restart plans and 69% monitor cloud services themselves, only 8% use a second cloud provider specifically as outage protection.

Why Destatis and Bitkom differ: Destatis measures paid cloud-service purchases under an official statistical framework for enterprises with at least 10 employees. Bitkom surveys companies with at least 20 employees and asks broader cloud-use questions. Both are useful, but they answer different questions.

Cloud Application Security in Germany

Cloud application security is not one product category. It spans secure development, application testing, cloud posture, workload protection, CNAPP, API security, WAF and bot controls, identity, data security, observability, incident response, and managed services. The practical buying task is to map each control to a specific risk, lifecycle stage, and deployment point.

Germany cloud security market estimate

Grand View Research estimates Germany’s cloud security market at USD 2.9826 billion in 2026 and forecasts USD 6.1293 billion by 2033, with a stated CAGR of 10.8% from 2026 to 2033.

Application security and CNAPP estimates

Commercial application-security estimates vary widely because some reports count testing tools, services, runtime protection, cloud controls, and adjacent categories differently. The same caution applies to CNAPP and standalone API-security estimates. Use those figures as directional indicators, not as directly comparable totals.

CategoryPrimary roleCommon gap
Application security testingFind design, code, dependency, and configuration weaknesses before releaseCannot prove the complete production inventory or real caller behavior
CNAPPCloud posture, workload, entitlement, and code-to-cloud contextMay not understand API objects, sequences, response data, or business intent
WAF and bot controlsHTTP threat filtering, signatures, protocol enforcement, and automation controlsCoverage of identity-object behavior and business workflows varies
API managementPublication, routing, policy, developer access, analytics, and lifecycle governanceUnmanaged paths and behavior-based abuse may require another layer
Runtime API securityTraffic-based discovery, behavior analysis, sensitive-data context, investigation, and selective responseDoes not replace secure design, testing, IAM, posture, or resilience engineering

Germany’s Cloud API Market

There is no widely accepted standalone statistical category for a “Germany cloud API market.” API demand is distributed across cloud platforms, API management, integration, SaaS connectivity, industrial data exchange, developer services, event-driven systems, and API security. A useful market view therefore combines adoption data, API-management forecasts, infrastructure investment, and real buyer requirements.

Demand drivers

Cloud modernization

Applications are being decomposed into services and connected through internal, partner, mobile, and public APIs.

Sovereign and hybrid architecture

German buyers increasingly evaluate where data, control planes, keys, logs, support, metadata, and operations reside.

Industrial and partner integration

Manufacturing, automotive, logistics, energy, healthcare, retail, finance, and public services rely on controlled machine-to-machine and partner APIs.

AI agents and automation

Machine-speed API use increases the importance of service identities, authorization, quotas, workflow controls, data protection, and audit evidence.

Portability and switching

The EU Data Act increases attention to interoperable interfaces, exportable configurations, data portability, and tested exit procedures.

Cyber resilience

BSIG, DORA, BSI C5, and sector requirements increase demand for inventory, supplier control, incident evidence, recovery, and continuity.

What should a market model measure?

Separate platform revenue from API-enabled business revenue. Also separate API management from API security, integration, observability, consulting, and managed operations. Otherwise, the same spending can be counted more than once.

API Management in Germany

API management is becoming a core operating layer for German digital services. It helps teams publish, govern, route, document, monitor, and monetize APIs, but its security coverage depends heavily on the gateway, policy model, traffic visibility, and deployment architecture.

Market Research Future estimates the Germany API management market at USD 256.16 million in 2024, USD 310.97 million in 2025, and USD 2.16225 billion by 2035, with a stated 21% CAGR for 2025–2035.

Fortune Business Insights separately reports that Europe’s API management market reached USD 1.96 billion in 2025 and projects USD 2.55 billion in 2026. Its Germany estimate is approximately USD 0.36 billion in 2026.

For global context, Mordor Intelligence values the worldwide API management market at USD 8.86 billion in 2025, USD 10.32 billion in 2026, and USD 22.11 billion by 2031, with a stated 16.45% CAGR for 2026–2031.

Core API management capabilities

Gateway and traffic control

Routing, TLS, authentication integration, quotas, rate limits, transformations, caching, and policy execution.

Lifecycle governance

Design, publication, versioning, documentation, deprecation, ownership, and approval.

Developer experience

Portals, subscriptions, credentials, onboarding, documentation, examples, and consumer analytics.

Business enablement

Partner access, products, plans, monetization, usage measurement, service-level commitments, and ecosystem management.

API management is not the same as runtime API security

Capability API management Runtime API security
Publish and document APIsCore capabilityUsually consumes inventory rather than owning publication
Route and transform trafficCore gateway capabilityMay observe or enforce, depending on deployment
Issue subscriptions and plansCore capabilityNot normally the system of record
Discover unmanaged APIsDepends on gateway and inventory coverageTraffic-based discovery can reveal unknown routes
BOLA or IDOR behaviorStatic policy may not understand object historyIdentity-object behavior analysis
Business logic abuseRate limits and policies provide partial coverageSequence, frequency, value, peer, and historical analysis
Response data leakageSchema validation may helpRequest and response data inspection
SIEM-ready attack evidenceOperational logs and policy eventsSecurity context, timeline, identity, object, data, and behavior

German buyers designing an enterprise API layer can compare the roles in Ammune’s guides to enterprise API gateways and comprehensive API management platforms.

German Sovereign Cloud and Regional Infrastructure

Germany’s cloud market is shaped by more than data-center location. Buyers increasingly evaluate operational sovereignty, legal jurisdiction, data residency, encryption-key control, support access, supply-chain dependencies, portability, resilience, and exit strategy.

ProviderCurrent Germany signalBuyer caveat
AWSThe first AWS European Sovereign Cloud Region opened in Brandenburg in January 2026.Verify the exact services, support model, operational boundaries, account structure, and failover design available to the intended workload.
Microsoft AzureGermany West Central and Germany North appear in Azure’s region documentation.Germany North is restricted for specific customer scenarios, including regional disaster recovery; service and zone availability also varies by region.
Google CloudGoogle lists Frankfurt as europe-west3 and Berlin as europe-west10.Confirm product-level regional availability, key-management options, support access, backups, and cross-region dependencies.
Oracle CloudOracle lists Germany Central in Frankfurt with three availability domains.Specialized services can have narrower regional availability than the core region.

Cloud exit and portability

The EU Data Act has applied since September 12, 2025. Cloud and API programs should maintain exportable API definitions, configurations, logs, identities, policies, schemas, keys, observability context, and runbooks rather than treating portability as a contractual paragraph only.

Germany’s Regulatory and Assurance Landscape

GDPR

Personal-data processing through APIs requires appropriate security, minimization, access control, retention discipline, breach handling, and processor governance.

BSI C5:2026

C5:2026 contains 168 criteria across 17 subject areas for assessing cloud-service security and transparency.

German NIS2 implementation

Germany’s NIS2 implementation took effect on December 6, 2025, bringing registration, risk-management, and incident-reporting obligations into force for covered entities.

DORA

DORA has applied since January 17, 2025 to covered financial entities, with requirements for ICT risk, incident reporting, resilience testing, and third-party risk.

EU Data Act

The Data Act has applied since September 12, 2025, including rules relevant to connected-product data and switching between data-processing services.

Cyber Resilience Act

Reporting obligations for actively exploited vulnerabilities and severe incidents begin September 11, 2026; most broader product requirements apply from December 11, 2027.

What regulation means for API programs

  • Maintain a current inventory of APIs, owners, consumers, data classes, dependencies, regions, and suppliers.
  • Collect security-relevant events with enough context for investigation and reporting without copying unnecessary sensitive values.
  • Test failover, recovery, certificate rotation, dependency failure, incident communications, and cloud exit.
  • Control machine identities, tokens, secrets, service accounts, partner credentials, and privileged operations.
  • Document third-party responsibilities, support access, subcontractors, data handling, evidence retention, and deletion.

Runtime API Security Priorities

NIST SP 800-228 Update 1 organizes API risks and controls across the lifecycle, while the OWASP API Security Top 10:2023 remains OWASP’s current API-specific Top 10 release. Together, they help buyers evaluate the gap between cloud posture, application testing, API management, and real production behavior.

RiskWhy it mattersEvidence to require
BOLA and tenant isolationAuthenticated users or services access objects belonging to another customer, tenant, vehicle, machine, patient, account, or partner.Identity, tenant, object, route, authorization result, response, history, and peer comparison
Property-level authorization and response leakageResponses expose fields or records the consumer is not permitted to receive. In OWASP 2023, this is addressed under API3 Broken Object Property Level Authorization.Expected and observed schema, sensitive fields, consumer role, record count, and policy outcome
Business-flow abuseAttackers use valid functions in invalid sequences, frequencies, values, or automation patterns.Workflow stage, timing, repeated actions, business value, outcome, and behavioral baseline
Data exfiltrationCloud APIs can move personal, financial, industrial, or operational data at machine speed.Data class, quantity, direction, destination, identity, route, object, and historical deviation
Token and secret leakageCredentials appear in headers, parameters, payloads, errors, logs, traces, or responses.Masked credential type, location, service, route, direction, and containment action
Inventory and schema driftNew hosts, routes, methods, versions, and fields appear outside approved contracts and gateways.Expected versus observed inventory, first seen, owner, deployment, consumer, and data impact
Resource and AI-service abuseExpensive endpoints, searches, exports, models, and industrial operations are consumed excessively.Cost, latency, concurrency, identity, route, quota, business value, and anomaly context
Unsafe third-party API consumptionExternal API responses, redirects, webhooks, and dependencies are trusted without sufficient validation.Supplier, destination, schema, certificate, response validation, timeout, retry, and error behavior

Security telemetry that reduces alert fatigue

Useful events group activity by service, identity, tenant, object, data class, trace, deployment, and business impact. Raw payload collection should be minimized, masked, access-controlled, and retained only as long as justified.

Runtime visibility for Germany cloud APIs and API management

Germany Cloud and API Security Buyer Checklist

Evaluation areaQuestions to askProof required
Category and exclusionsIs the product API management, AppSec, CNAPP, WAF, observability, API security, or a combination?Capability map with explicit exclusions and control ownership
Germany and EU deploymentWhich regions, sovereign options, private deployments, and on-premises patterns are supported?Region-specific architecture, service list, data flow, and support model
Traffic and inventory coverageCan it observe gateway, direct, internal, partner, mobile, Kubernetes, GraphQL, gRPC, and agentic API traffic?Traffic-source matrix and measured discovery against a known inventory
Data governanceWhat payload data is collected, masked, stored, exported, accessed, retained, and deleted?Field-level demonstration, retention controls, tenant isolation, and support-access records
Authorization and behaviorDoes it understand identity, tenant, object, property, function, sequence, value, frequency, and history?Explainable allow-and-deny tests using controlled scenarios
API-management integrationDoes it integrate with gateways, inventories, developer portals, IAM, policy systems, and service catalogs?End-to-end workflow demonstration
Regulation and assuranceHow does it support C5 evidence, NIS2, DORA, GDPR, the Data Act, CRA processes, and third-party risk?Control mapping and auditable evidence—not a generic compliance claim
SOC operationsCan events be normalized, grouped, enriched, assigned, investigated, exported, and closed?End-to-end incident workflow with evidence minimization
Performance and resilienceWhat are the measured latency, throughput, scale, failure, recovery, bypass, and upgrade characteristics?Benchmark and failover test in the customer’s target architecture
Commercial and exit modelHow are calls, bandwidth, services, regions, sensors, users, and retention priced? Can data and policy be exported?Three-year scenario model and tested export procedure

Five-phase proof of value

  1. Baseline: define representative APIs, identities, data classes, traffic paths, success measures, and safety boundaries.
  2. Discovery: compare observed hosts, routes, methods, versions, and consumers with the approved inventory.
  3. Detection: run authorized scenarios for authorization, workflow abuse, data exposure, enumeration, drift, and resource consumption.
  4. Operations: measure alert quality, investigation time, SIEM workflows, masking, access controls, and reporting.
  5. Production fit: test latency, throughput, high availability, failover, rollback, upgrades, retention, total cost, and exit.

Use Ammune’s API security vendor evaluation checklist, digital-transformation guide, and sensitive-data protection strategy to structure the assessment.

Common Market and Architecture Mistakes

  • Adding incompatible market estimates. Cloud security, application security, CNAPP, API management, and API security overlap.
  • Assuming a gateway sees every API. Direct service, east-west, partner, legacy, and unmanaged routes may bypass it.
  • Equating residency with sovereignty. Operations, support, keys, metadata, legal entities, dependencies, and exit options also matter.
  • Treating a region as a service guarantee. Product availability, availability zones, support models, and recovery options vary by region.
  • Buying posture without runtime evidence. Configuration risk does not explain how identities, objects, data, and workflows behave in production.
  • Buying runtime monitoring without pre-runtime controls. Secure design, testing, code review, schema governance, IAM, and cloud posture remain necessary.
  • Relying only on rate limits. Low-and-slow abuse can remain within quotas while violating authorization or business intent.
  • Collecting sensitive payloads indiscriminately. Monitoring must minimize, mask, protect, and govern personal, financial, industrial, and credential data.
  • Ignoring cloud exit. APIs, schemas, policies, identities, telemetry, evidence, and runbooks need portable formats and tested migration procedures.

Where Ammune Fits in a German Cloud and API Architecture

Ammune can be evaluated as a runtime API security layer that complements cloud platforms, API management, secure development, CNAPP, IAM, observability, SIEM, and incident response. The right question is not whether one platform replaces every adjacent control, but whether it closes measurable gaps in the customer’s actual traffic and operating model.

API discovery

Evaluate discovery of real hosts, routes, methods, versions, consumers, direct-service paths, internal APIs, and changed or undocumented endpoints.

Behavior context

Validate analysis of identity, tenant, object, route, sequence, frequency, value, response, peer, and historical behavior.

Sensitive-data protection

Test approved request and response inspection, classification, masking, schema drift, response leakage, and unusual extraction patterns.

Operational evidence

Connect evidence to SOC, SIEM, DevSecOps, incident response, managed services, executive reporting, and assurance workflows.

Deployment patterns to evaluate

Monitoring mode

Observe a supported feed of decrypted API traffic for discovery, learning, investigation, and proof of value without becoming the enforcement path.

Inline mode

Deploy on approved API paths when blocking or throttling is required, with measured latency, high availability, failover, bypass, and rollback.

Hybrid cloud

Evaluate consistent visibility across German and EU regions, sovereign environments, private cloud, Kubernetes, data centers, and selected edge locations.

Managed operations

Confirm that MSSPs or internal SOC teams can investigate evidence, tune policies, report outcomes, and support incident response.

Procurement principle: evaluate Ammune with controlled scenarios and measurable outcomes in the buyer’s own German or EU environment. Product fit should be demonstrated, not inferred from category labels.
Ammune API security evaluation for German cloud environments

Conclusion

Germany’s 2026 cloud story is about control as much as growth. Cloud adoption is broad, security and sovereignty strongly influence provider selection, outages expose resilience gaps, and APIs connect an increasing share of business operations.

A mature operating model combines API management, secure development, cloud posture, identity, runtime behavior, sensitive-data protection, tested recovery, supplier governance, and evidence that operations and assurance teams can use. Ammune can be evaluated as one runtime API security component within that broader architecture.

Sources, Market Data, and Methodology

Methodology: official statistics and regulatory sources are used for adoption and legal dates. Bitkom is an industry survey. Market-size figures are commercial estimates with proprietary definitions and are presented separately. Sources were rechecked on August 5, 2026.
TopicSourceHow it is used
Germany cloud adoptionDestatis 2025 cloud tableOfficial paid-cloud adoption by enterprise size.
Cloud strategy and resilienceBitkom Cloud Report 2026; resilience findingsIndustry-survey findings on usage, hybrid and multi-cloud, sovereignty, security priorities, and outages.
Germany cloud computing marketMordor Intelligence; Fortune Business InsightsNon-comparable commercial estimates and forecasts.
Germany cloud securityGrand View Research2025 revenue, 2026 estimate, 2033 forecast, and CAGR.
Germany API managementMarket Research Future; Fortune Business InsightsCountry estimates using different methodologies.
Cloud assuranceBSI C5 introduction; C5:2026Current cloud-assurance criteria and subject areas.
German NIS2 implementationBSI NIS2 information; current BSIGEffective date, registration, risk-management, and incident obligations.
DORA and Data ActDORA; Data ActApplication dates, operational resilience, data access, and cloud switching.
Cyber Resilience ActBSI CRA overviewSeptember 2026 reporting milestone and broader 2027 applicability.
Germany cloud regionsAWS; Azure; Google Cloud; OracleCurrent regional infrastructure and availability caveats.
API lifecycle protectionNIST SP 800-228 Update 1; OWASP API Security Top 10:2023Lifecycle controls and current API-specific risk categories.

Frequently Asked Questions

How large is Germany’s cloud computing market in 2026?

One commercial estimate from Mordor Intelligence values the market at USD 65.05 billion in 2026 and forecasts USD 131.29 billion by 2031. Other analysts use different definitions and values, so market estimates should be treated as directional and should not be averaged.

What does Germany cloud application security include?

It includes secure development, application testing, cloud posture, workload protection, CNAPP, API security, WAF and bot controls, identity, data security, observability, incident response, and managed services. Buyers should map each control to a specific risk, lifecycle stage, and deployment point.

How large is Germany’s API management market?

Fortune Business Insights projects approximately USD 0.36 billion for Germany in 2026. Market Research Future separately reports USD 310.97 million in 2025 and forecasts USD 2.16225 billion by 2035. The methodologies and scopes differ.

What is driving Germany’s cloud API market?

Cloud modernization, SaaS and industrial integration, AI services and agents, public-sector digitization, financial APIs, partner ecosystems, hybrid and sovereign architecture, data portability, and resilience requirements are all increasing API demand.

How many German enterprises use cloud services?

Destatis reports that 54% of German enterprises with at least 10 employees purchased cloud services in 2025. The rate was 51% for enterprises with 10–49 employees, 65% for those with 50–249 employees, and 86% for enterprises with 250 or more employees.

What does the Bitkom Cloud Report 2026 show?

Bitkom reports that 86% of surveyed German companies with at least 20 employees use cloud services and another 14% plan or discuss adoption. The survey also reports 34% hybrid-cloud use, 38% multi-cloud use, and strong concern about security, provider origin, sovereignty, and lock-in.

Why do Destatis and Bitkom report different cloud-adoption rates?

They measure different populations and concepts. Destatis reports paid cloud-service purchases among enterprises with at least 10 employees using an official statistical framework. Bitkom surveys companies with at least 20 employees and asks broader questions about current and planned cloud use.

What does BSI C5:2026 mean for German cloud buyers?

BSI C5:2026 contains 168 criteria across 17 subject areas for assessing cloud-service security and transparency. Buyers can use it to structure assurance discussions, but should still verify service-specific scope, evidence, exclusions, dependencies, and customer responsibilities.

Which regulations influence cloud and API security in Germany?

Important frameworks include the GDPR, Germany’s NIS2 implementation under the current BSIG, DORA for covered financial entities, the EU Data Act, the Cyber Resilience Act, and BSI C5 for cloud assurance. They increase the need for inventory, access control, resilience, supplier governance, monitoring, evidence, and disciplined data handling.

Are sovereign and regional cloud options available in Germany?

Yes. AWS opened its European Sovereign Cloud Region in Brandenburg in January 2026. Azure documents Germany West Central and restricted Germany North, Google Cloud lists Frankfurt and Berlin, and Oracle lists Germany Central in Frankfurt. Service availability and operational models must still be verified per workload.

Does API management provide complete API security?

No. API management commonly covers publication, routing, authentication integration, quotas, policy, developer access, analytics, and lifecycle governance. Unmanaged APIs, object and property authorization, business-flow abuse, response leakage, unusual extraction, and production behavior can require additional controls.

How should a German enterprise evaluate an API security platform?

Use a controlled proof of value covering inventory accuracy, traffic coverage, request and response data handling, authorization, workflow abuse, data exposure, schema drift, SIEM operations, false positives, investigation time, latency, throughput, high availability, rollback, retention, total cost, and exportability.

Evaluate runtime API security for your Germany cloud architecture

Assess Ammune alongside your cloud providers, sovereign-cloud choices, API gateways, management platforms, CNAPP, application security, SIEM, observability, BSI controls, NIS2, DORA, privacy obligations, and resilience plans.

© 2026 Ammune Security. Market estimates use different scopes and methodologies. Regulations, cloud regions, services, prices, product features, forecasts, and assurance requirements should be reverified using the linked sources before publication, procurement, or architecture approval.