Sovereign, Cheap, Easy — Pick Two: The 2026 Hosting Economics Report

We priced one fifty-person company five ways: two hyperscalers, a European discount provider, a self-built cluster in Prague, and managed hosting. Ten sections with primary sources — and the biggest line in self-hosting is not the hardware.

Every few months a new number goes around. Cloud is forty percent cheaper. On-premises is fifty percent cheaper. Both claims get published, both cite real data, and both are useless on their own — because they are answering different questions, for different companies, with different things left out of the spreadsheet.

So we priced it properly. One company, fifty people, one honest specification, and every option costed against it at public list prices: two hyperscalers, a European discount provider, building it yourself in a Prague data centre, and our own managed platform. Every figure below is traceable to a source, and the two figures that are estimates rather than list prices are marked as such.

The answer is not the one either side of the argument usually gives.

DocumentedIn progressAssessment

Documented = a published list price, a law in force, an official statistic or a court decision. In progress = a legal challenge or proposal not yet decided. Assessment = our own estimate or modelling, with the assumptions stated.

01

Assessment

What a fifty-person company actually needs

Most cost comparisons start with a server size. That is the wrong end. Start with the people, work out what they do all day, and the server size falls out of it.

A fifty-person business — a manufacturer, a distributor, a professional services firm — typically runs four things that must not stop: the business system that holds orders and invoices, the file store everyone works from, the identity and network services that let people log in at all, and a web or application front end. Mail is almost always a subscription now and sits outside this comparison, as does anything running on a laptop.

From headcount to hardware

50employeesERP and databaseorders, invoices, stock — 8 vCPU, 32 GBFile and document storeshared drives, archive — 2 vCPU, 8 GBIdentity, DNS, printlogins and network services — 2 vCPU, 8 GBWeb and applicationsintranet, integrations — 4 vCPU, 16 GBTOTAL TO BE HOSTED16 vCPU64 GB RAM2 000 GB SSDdedicated, not burstableno memory oversubscriptionplus 2 TB outbound traffic

Sizing is deliberately conservative and assumes no oversubscription. A company with heavy CAD, video or analytics will need more; one that has moved most of its stack to software-as-a-service will need less. Every price in this article is calculated against this exact specification.

Why dedicated resources, not burstable

The cheapest instance classes at every provider share physical cores between tenants. That is fine for a test environment and poor for a system that fifty people wait on at nine in the morning. Comparing a shared-core instance against a dedicated one is the single most common way these comparisons get rigged, so every option here is priced on dedicated resources.

02

Assessment

Building it yourself, priced properly

The self-hosting case usually opens with a server quote and closes there. That is where it goes wrong, and the first mistake is not financial — it is a counting error.

Two servers is not redundancy. A two-node cluster cannot tell the difference between "the other node has failed" and "I cannot reach the other node", so it either refuses to act or both halves try to take over the same storage. The minimum honest number for a cluster that survives losing a node — and survives you patching a node on a Tuesday afternoon — is three.

Why the minimum is three nodes, not two

Two nodesno majority is possible when the link dropsNode A1 of 2 votesNode B1 of 2 votesNeither side has a majoritythe cluster stops, or both sides write to the same diskand you restore from backupThree nodestwo survivors out of three are a majorityNode AvoteNode BvoteNode CfailedA and B hold quorum and keep runningthe same is true while you patch one node deliberatelynobody is woken up

The same logic applies to storage replicas. It is the reason a genuinely resilient small cluster costs roughly half again what the first quote says — and the reason a two-node build should be described as a single server with a spare, not as high availability.

With three nodes, redundant switching, a UPS and a rack in a Prague data centre, the capital cost lands near €37,000 and the recurring costs are modest. Spread over a five-year life, the infrastructure looks like this.

Self-hosted infrastructure, cost per month over a five-year life

€617Hardware€37 000 over60 months€285Colocation10U in Praguepower included€247Supportvendor coverand spares€133HypervisorProxmox VE3 sockets€108Backup software10 workloads€40Offsite copy2 TB, second siteTOTAL €1 429 PER MONTH — INFRASTRUCTURE ONLY, NOBODY OPERATING IT

Hardware is a market estimate for the stated configuration from Czech resellers in August 2026 and is the one line here that is not a published list price. Colocation, hypervisor and backup licensing are list prices. Excludes VAT.

LineBasisPer monthOver 5 years
3 × 1U server, 16-core, 128 GB, 2 × 3.84 TB NVMe€27,000 capital, 60-month life€450€27,000
2 × 25 GbE switch, UPS, rack, PDU, cabling€10,000 capital, 60-month life€167€10,000
Colocation, 10U, Prague690 CZK per U per month€285€17,100
Vendor hardware support and spares8% of capital per year€247€14,800
Proxmox VE Standard€530 per socket per year × 3€133€7,950
Backup software10 workloads, subscription€108€6,500
Offsite backup capacity2 TB, second location€40€2,400
Infrastructure totalbefore anyone operates it€1,429€85,750

What this number is not

It is not a total cost of ownership. It is the cost of the equipment existing in a rack. Nothing above patches an operating system, tests a restore, answers an alert at two in the morning, or renews a certificate. That is the next section, and it is larger than everything on this page put together.

Sources10 Colocation price list11 Proxmox pricing12 Backup licensing3 ČNB rates

03

Documented

The engineer nobody budgets for

Servers do not administer themselves, and this is the line that decides the whole comparison. The Czech Statistical Office publishes what these people actually earn. For 2025, released in July 2026, the average gross monthly pay for database and network specialists in the Czech Republic was 86,572 CZK; across all ICT specialists in the private sector it was 101,729 CZK.

Gross pay is not the cost. On top of it an employer pays 24.8% social insurance and 9% health insurance — 33.8% before anyone has bought a laptop, a training course or a certification exam.

€4,785

true monthly cost to the employer of one specialist at the published average gross wage, including statutory contributions

86,572 CZK gross × 1.338, converted at 24.21 CZK per euro — Czech Statistical Office and Czech National Bank

That is €57,400 a year for one person, and one person is not a service. A full-time employee covers forty hours of a week that contains one hundred and sixty-eight. The remaining one hundred and twenty-eight hours — every night, every weekend, the whole of August — are covered by hope, or by that person's mobile phone.

What one full-time engineer actually covers

ONE FULL-TIME ENGINEER · ONE WEEK = 168 HOURS40 h128 hours uncoveredbusiness hours, minus holiday, sick leave and training23.8% of the weekGENUINE 24/7 COVER WITH REST-PERIOD COMPLIANCE4.2 full-time equivalents · about €20,100 per month

The 4.2 figure is the arithmetic of covering 168 hours with 40-hour weeks, before holiday and sickness cover. Most fifty-person companies rightly decide they cannot justify this — and then quietly run without it, which is a risk decision rather than a cost saving.

The realistic assumption we use

Nobody hires 4.2 engineers for fifty users. For the comparison table we assume the honest middle: one full-time engineer for the self-built option, because someone must own the hardware, the hypervisor and the restores; and half a full-time engineer for unmanaged cloud, where the provider owns the hardware but you still own every operating system, patch, backup and alert. Managed hosting is priced with neither, because that work is in the fee.

Sources1 Czech Statistical Office2 Social insurance rates3 ČNB rates

04

Documented

GDPR, the CLOUD Act, and a sentence said under oath

Ask most people where their company's data is and they will name a city. Frankfurt, Dublin, Amsterdam. That answer describes geography, and geography is not the question the law asks. The question is whose courts can compel the company holding the data to hand it over.

The United States CLOUD Act, in force since 2018, answers that plainly. The Department of Justice's own white paper on the Act states that a provider subject to US jurisdiction must produce data in its custody or control regardless of whether that data is stored inside or outside the United States. A German data centre operated by an American corporation is inside the reach of an American order.

This is not a theoretical reading. On 10 June 2025, in a hearing of the French Senate, Microsoft France's legal director was asked under oath whether he could guarantee that French citizens' data held in Microsoft's cloud would never be passed to US authorities without French approval.

Microsoft France, French Senate, 10 June 2025

“No, I cannot guarantee that.”

Anton Carniaux, Director of Public and Legal Affairs

Asked under oath whether French citizens' data stored in Microsoft's cloud could be shielded from US authorities. He added that Microsoft resists requests it considers unfounded — which is a policy, not a jurisdictional limit.

Where the data sits and where the order lands

EUROPEAN UNION — PHYSICAL LOCATIONFrankfurt data centreyour data, encrypted at restEU subsidiaryoperates the site, holds the keysGDPR applies here — and is fully satisfieddata residency, processing agreements, transfer safeguards: all in orderUNITED STATES — CORPORATE CONTROLUS parent companysubject to a CLOUD Act production orderfor data in its custody or control, anywhereThe order follows the company,not the building.Encryption at rest does not change thisif the provider can produce the keys.

Nothing here means GDPR has been breached — a compliant EU deployment can be entirely lawful. It means the residency question and the jurisdiction question have different answers, and only one of them is printed on the marketing page.

The practical test

Ask a prospective provider one question: which courts can order you to disclose our data, and is any company in your ownership chain incorporated outside the EU? A provider that has to check with a parent company has answered it.

Sources13 DOJ CLOUD Act paper14 French Senate hearing

05

Documented

EU, US, Asia: where your data really lives

Every large provider now offers a European region, and several offer a "sovereign" one. These are real engineering efforts and they genuinely reduce risk. They do not all answer the same question, and the differences matter more than the names suggest.

Three things are worth separating. Can you pin the data to an EU location? Is the entity that controls it governed solely by EU law? And can engineering or support staff outside the EU reach the systems in the course of ordinary operations?

Residency, jurisdiction and reach — by provider

EU regionEU-only jurisdictionNon-EU parentAmazon Web Servicesincluding the European Sovereign CloudMicrosoft AzureGoogle CloudAlibaba Cloudmainland operations under Chinese lawOVHcloudHetznerDEXA-ITone country, one jurisdiction, one company

Filled teal = yes. Hollow amber = partially, through a contractual or structural arrangement rather than by simple fact of incorporation. Filled red = yes, and it is the point. Small grey = no.

The first column is the easy one — every provider in that list can now keep your data at rest inside the EU, and most European businesses stop reading there. The second column asks whether the entity controlling the data answers to EU law alone; sovereign offerings genuinely improve this through separate operating companies and local staffing, but they do not sever the ownership chain, which is why those marks are partial rather than full. The third column is simply whether a company outside the EU exists that can be ordered to act. That is the question the CLOUD Act turns on, and no amount of regional engineering changes the answer.

Asia adds a further layer. In mainland China the law requires cloud services to be operated by a licensed local entity, which is why Microsoft's Chinese cloud is a physically separate system run by 21Vianet rather than a region of global Azure, and why Google has no mainland region at all. If your data touches an Asian operation, "the same provider" frequently means a different company under a different legal system.

Question a buyer should askHyperscaler with EU regionEuropean providerDEXA-IT
Where is the data physically stored?EU region of your choosingEU, usually one or two countriesCzechia only
Which law governs the operating company?EU law, plus the parent's home lawEU lawCzech and EU law
Can staff outside the EU access systems for support?Possible under documented safeguardsUsually notNo — all staff are in Czechia and Slovakia
Who signs your data processing agreement?Usually an EU subsidiary of a foreign groupThe providerDEXA - IT, s.r.o.
Can you visit the building?NoRarelyYes, by arrangement

Sources15 Azure China regions16 AWS European Sovereign Cloud17 Gartner sovereign cloud

06

In progress

The transfer framework has been struck down twice. It is being challenged again.

If your provider transfers personal data to the United States, the legal basis is usually the EU-US Data Privacy Framework — the European Commission's 2023 decision that the US offers adequate protection. It is valid law today. The General Court upheld it in September 2025.

It is also the third such arrangement in twenty-five years, and the first two were annulled by the Court of Justice.

How long each EU-US transfer arrangement lasted

20002007201420212027Safe Harbour · 2000–2015annulled — Schrems IPrivacy Shieldannulled — Schrems II · 2016–2020DPF · 2023–MECHANISM IN FORCE FOR TRANSFERS OF PERSONAL DATA TO THE UNITED STATES

The pattern is not proof that the current framework will fall. It is the reason a prudent buyer treats "we rely on the adequacy decision" as a plan with a dependency, rather than as a settled fact.

A new question arrived on 29 June 2026. In Trump v. Slaughter the US Supreme Court ruled on the removal protections that underpin the independence of the Federal Trade Commission — the body the adequacy decision leans on for enforcement on the American side. Within days the privacy group noyb called for the decision to be withdrawn in an orderly way, and a separate appeal by a French legislator is already pending before the Court of Justice.

Jul 2023

DPF adopted

The Commission finds the United States adequate for the third time.

Sep 2025

Upheld

The General Court dismisses the first challenge and confirms validity.

29 Jun 2026

Trump v. Slaughter

A US Supreme Court ruling on the independence of the agency the framework relies on.

Now

Appeal pending

A further appeal sits before the Court of Justice; an opinion is expected in the next year or so.

If annulled

Contracts reopen

Transfers fall back on standard clauses plus a case-by-case impact assessment, as after 2020.

What this is worth in money

Nothing, until it happens — and then it is a project. After Schrems II, thousands of European companies spent months re-papering contracts and re-assessing transfers for systems that had not changed at all. Keeping the data with a provider that never transfers it to a third country is not a legal opinion. It is the absence of a dependency.

Sources18 Adequacy decision 2023/179519 DPF after the ruling

07

Documented

NIS2 and DORA turned "what if they fail" into paperwork

Until recently, asking what happens if your cloud provider disappears was a thought experiment. For a growing share of European companies it is now a documented obligation with a named owner.

NIS2 extends cyber security duties across a wide range of sectors and makes supply chain security an explicit requirement — you are answerable for the security of your direct suppliers, not only your own systems. DORA goes considerably further for financial entities: a register of every ICT third-party arrangement, an assessment of concentration risk, mandatory contract terms covering data location and audit rights, and a tested exit strategy for every critical service.

What the two regimes actually demand of a cloud buyer

NIS2essential and important entities, many sectorsSecurity of your direct suppliers is your dutyRisk management measures, documentedIncident reporting on a statutory clockManagement is personally accountablePrinciple-based — you choose howDORAfinancial entities and their ICT providersRegister of every ICT third-party arrangementConcentration risk assessed and evidencedMandatory contract terms: location, audit, exitA tested exit plan for every critical servicePrescriptive — the auditor has a checklist

If you are not in financial services, DORA does not bind you. It is still the clearest published statement of what a regulator considers adequate diligence on a cloud provider, which makes it a useful checklist regardless of sector.

The part that catches people out

An exit strategy has to be tested, not merely written. A plan that says "we would restore to another provider" and has never been executed is the compliance equivalent of a backup nobody has restored. Ask your provider whether they will help you leave, and whether that has ever been rehearsed.

There is a piece of good news attached. Under the EU Data Act, the fees providers charge for switching away are being phased out entirely: from 12 January 2027 switching charges, including the egress fees historically used to make leaving expensive, are prohibited for cloud services in the EU. The lock-in that made these obligations painful is being legislated away.

Sources20 NIS2 Directive21 DORA Regulation22 EU Data Act

08

Assessment

When the hyperscaler is genuinely the right answer

An article that concluded "always choose the smaller provider" would not be worth reading, because it is not true. There are workloads where a hyperscaler is not merely defensible but obviously correct, and the pattern is consistent: the cloud wins whenever the shape of the demand is more expensive to own than to rent.

Where each option is actually the cheapest

Does your peak load exceedyour average by more than 3×?YESNOSeasonal retail, launches,batch analytics, model trainingHyperscaleryou are renting the peak you wouldotherwise have to buy and idleDo you have staff to runit around the clock?NOYESManaged private cloudsteady load, no team to hire,jurisdiction mattersSelf-hostedonly once the team existsfor other reasonsALSO CHOOSE A HYPERSCALER WHEN:· you need managed services no small provider offers — large-scale ML training, global content delivery, planet-scale databases· your users are on several continents and latency to each of them is a product requirement, not a preference

The honest summary: rent elasticity, own steadiness. Most of a fifty-person company's estate is steady — the ERP does not need to scale to ten times its size on Black Friday — which is why the same company can sensibly do both.

There is no prize for purity

The best answer for many companies is a split: the steady core on predictable private infrastructure, the spiky or specialised parts on a hyperscaler, and a clear understanding of which data may cross between them. Anyone who tells you the whole estate must live in one place is selling something.

09

Documented

How we priced it

Comparison tables are easy to rig, so here are the rules we used. Every option delivers the same specification from section 01, every price is the published list price on the date shown, and where a figure is our own estimate it is labelled.

The rules every column obeys

COUNTED IN EVERY COLUMN16 dedicated vCPU, 64 GB RAM2 000 GB fast SSD2 TB outbound traffic per monthDaily backup, 30-day retentionVendor support at the standard tierThe people needed to operate itone engineer self-hosted · half an engineer unmanaged cloud · none managedDELIBERATELY EXCLUDEDVAT — every price is netApplication licences and mail subscriptionsLaptops, phones and the office networkMigration and one-off project workNegotiated discounts — list prices onlyA second physical site for the self-hosted buildincluding one would raise the self-hosted figure, not lower it

Converted at 24.21 CZK and 1.154 USD to the euro, the Czech National Bank rates for 7 August 2026. All figures verified on 8 August 2026. Cloud list prices change; the method is the durable part.

Where we could be accused of bias, and what we did about it

We sell managed hosting, so the two places bias could enter are the staffing assumption and the exclusion of discounts. On staffing we used the lowest defensible figure — half an engineer for unmanaged cloud, not one. On discounts, hyperscalers negotiate harder than we do at this size, so excluding them slightly favours us; we have also shown the three-year committed price, which is where their real discount lives.

10

Assessment

The table

Here is the same workload, five ways.

Total monthly cost — infrastructure and the people to run it

€3 508AWS Frankfurton demand€3 141AWS Frankfurt3-year commitment€2 817Hetznerunmanaged€6 214Self-hosted3 nodes, Prague€1 045DEXA-ITmanaged, CzechiaInfrastructurePeople to operate itManaged — operation included in the fee

The gold portion is the same work in every column. It is bought differently, not avoided. Only the last column has no gold, because operating the platform is what the fee pays for.

OptionInfrastructurePeopleTotal / monthOver 3 yearsJurisdiction
AWS Frankfurt, on demand€1,116€2,392€3,508€126,288EU region, US parent
AWS Frankfurt, 3-year commitment€749€2,392€3,141€113,076EU region, US parent
Hetzner Cloud, unmanaged€425€2,392€2,817€101,412Germany / Finland
Self-hosted, 3 nodes, Prague€1,429€4,785€6,214€223,704Czechia
DEXA-IT, managed€1,045included€1,045€37,620Czechia only

Three things in that table are worth saying out loud, because none of them is the headline anyone expects.

Hetzner has the cheapest infrastructure by a distance, and it is not close. At €425 a month it undercuts everything else here, including us. If you have an engineering team already, and jurisdiction beyond "somewhere in the EU" is not a requirement, that is an excellent answer and we would say so to your face.

Self-hosting is the most expensive option, and the hardware is not why. The equipment is €1,429 a month; the person is €4,785. Seventy-seven percent of the cost of running your own servers is a salary. This is the number that turns the usual argument on its head — the capital cost people worry about is the part that barely matters.

The hyperscaler's discount does not close the gap, because it does not touch the largest line. Committing for three years cuts AWS compute by roughly half and moves the total by ten percent, because the operating cost is unchanged and the operating cost is most of the bill.

€63,792

difference over three years between managed private hosting in Czechia and the cheapest unmanaged cloud option, once the people are counted

DEXA-IT €37,620 against Hetzner Cloud plus half an engineer, €101,412 — list prices, August 2026

So: sovereign, cheap, easy — pick two?

Not quite, and that is the finding. Hetzner is cheap and European but not easy. AWS is easy and elastic but neither cheap at this size nor sovereign. Self-hosting is sovereign and can be made easy, but only by employing the person who makes it so. What actually collapses the trilemma is sharing the engineer — which is the entire economic argument for managed hosting, and the reason our column has no second number in it.

If your numbers differ, they should

This is one company's shape. Halve the storage and the cloud columns move most; double the traffic and they move again. If you want the same table built against your own workload rather than ours, the resource calculator on our hosting page uses exactly these rates, and we will price the other columns honestly next to it.

Sources4 AWS on-demand pricing5 eu-central-1 rates6 AWS EBS pricing7 AWS egress8 Hetzner repricing9 Hetzner rates23 DEXA-IT pricing

Sources

Every figure in this article points to a source. The “Primary” badge marks official statistics, laws in force, court decisions and providers' own published price lists.

1PrimaryCzech Statistical Office — ICT specialists and their wages, structural wage statistics for 2025, published 1 July 2026

2PrimaryMinistry of Labour and Social Affairs — social insurance rates for 2026 (employer 24.8%, health insurance 9%)

3PrimaryCzech National Bank — foreign exchange market rates, 7 August 2026

4PrimaryAmazon Web Services — EC2 On-Demand instance pricing

5AWS price reference for eu-central-1 (Frankfurt) — m7i.2xlarge at $0.483/hour, gp3 at $0.0952/GB-month, verified 8 August 2026

6PrimaryAmazon Web Services — Elastic Block Store pricing, including gp3 baseline performance

7AWS data transfer out to internet pricing — $0.09/GB for the first 10 TB after 100 GB free, Europe and US regions

8PrimaryHetzner — standardization and price adjustment of server products effective 15 June 2026, announced 27 May 2026

9Hetzner Cloud price list, post-June-2026 rates — CCX43 at €275.99/month, block storage at €0.0572/GB-month, verified August 2026

10PrimaryDC6 Prague — server housing price list (690 CZK per U per month excluding VAT; 12,000 CZK for a full 42U rack)

11PrimaryProxmox — Proxmox VE subscription pricing, per CPU socket per year

12Veeam Backup & Replication pricing benchmark 2026 — universal licence, per workload per year

13PrimaryUS Department of Justice — “Promoting Public Safety, Privacy, and the Rule of Law Around the World: The Purpose and Impact of the CLOUD Act”, white paper

14The Register — Microsoft executive tells the French Senate it cannot guarantee data sovereignty, 25 July 2025

15PrimaryMicrosoft — Azure China regions overview: a physically separate cloud operated by 21Vianet under Chinese law

16PrimaryAmazon — AWS launches the European Sovereign Cloud, first region in Brandenburg, January 2026

17PrimaryGartner — worldwide sovereign cloud IaaS spending forecast to total $80 billion in 2026

18PrimaryCommission Implementing Decision (EU) 2023/1795 — adequacy of the EU-US Data Privacy Framework

19activeMind.legal — the EU-US Data Privacy Framework at risk following the US Supreme Court ruling in Trump v. Slaughter, 29 June 2026

20PrimaryDirective (EU) 2022/2555 (NIS2) — measures for a high common level of cybersecurity across the Union

21PrimaryRegulation (EU) 2022/2554 (DORA) — digital operational resilience for the financial sector, Articles 28–30

22PrimaryRegulation (EU) 2023/2854 (Data Act) — switching between data processing services; charges prohibited from 12 January 2027

23PrimaryDEXA-IT — DEXA-Host pricing: €12.90 per vCPU, €2.49 per GB RAM, €0.12 per GB SSD, management bundles from €69.90 per server per month

All prices verified 8 August 2026 and exclude VAT. Legal position as of 8 August 2026. Cloud list prices change frequently; the method in section 09 is intended to outlast the figures.

Chinese cameras: what the authorities actually say
The Czech cyber agency called them high risk, Canada shut Hikvision down, the EU is drafting a high-risk supplier list. Nine sections, each with primary sources — and real Czech retail prices verified on 6 August 2026.