← Blog
Sovereignty Cloud · EU procurement

Sovereign cloud: how the EU actually measures it

by Team P3·28 July 2026·8 min read

A cloud is sovereign when no party outside the European Union can interrupt it, read it or condition it. Until recently that was an opinion: everyone called "sovereign" whatever suited them. Since October 2025 there is a public yardstick — eight weighted objectives and five levels, from SEAL-0 to SEAL-4 — and in April 2026 the European Commission used it to award a €180 million contract. You can use it too, today, on your own provider.

01What is a "sovereign cloud"?

The word was hollowed out before it was ever defined. "Sovereign" has been stuck on offerings that keep data in a European datacentre, on those with a local subsidiary signing the contract, on those with a well-drafted data processing agreement. None of these, on its own, answers the question that matters: who can compel the provider to act against your interest, and what happens to your service on that day.

We have already grounded the distinction in our article on operational sovereignty: data residency is geography, sovereignty is control. What is new is that the distinction now has a measurable shape and — rarer still — a public document setting it out, written by the people who buy cloud for the European institutions.

Quotable definition. Sovereign cloud: a cloud service over which no non-EU party can exercise decisive control — it cannot compel disclosure of the data, stop the service, or condition its technical evolution. It is assessed across eight dimensions, not by the location of the datacentre.

02How does the European Union measure sovereignty?

With the Cloud Sovereignty Framework, version 1.2.1, published in October 2025 by the European Commission's Directorate-General for Digital Services (European Commission, Cloud Sovereignty Framework v1.2.1). It is not a law and not a certification: it is the instrument a contracting authority uses to assess, in a procurement procedure, how sovereign a cloud offering is. The document states that it draws on existing work — France's Cloud de Confiance referential, Gaia-X policy rules, the European cybersecurity certification framework — and turns it into criteria a tender can apply.

The structure is simple and worth learning, because it is the most complete grid of questions available in Europe today. Eight sovereignty objectives, each with a weight in the final score:

Two distinct mechanisms sit on top of the objectives. The first is SEAL (Sovereignty Effectiveness Assurance Level): the tender specifications set a minimum level for each objective, and — in the framework's own words — tenders that do not offer the required levels consistently across all objectives will be rejected. The second is the Sovereignty Score, the weighted sum of the scores, which feeds the quality score as an award criterion. Entry barrier and league table, kept separate.

The five SEAL levels, as the framework defines them: SEAL-0, no sovereignty (exclusive control by non-EU third parties, governed entirely outside the EU); SEAL-1, jurisdictional sovereignty (EU law formally applies, with limited practical enforceability); SEAL-2, data sovereignty (EU law applicable and enforceable, with material non-EU dependencies and indirect third-party control); SEAL-3, digital resilience (EU actors with meaningful but not full influence, marginal non-EU control); SEAL-4, full digital sovereignty (technology and operations under complete EU control, no critical non-EU dependencies).

The heaviest weight — a fifth of the score — goes neither to law nor to security. It goes to the supply chain: the question no brochure asks itself, namely where the firmware comes from.

03The yardstick in practice: the €180 million tender

A criterion is worth what its application is worth. On 17 April 2026 the Commission awarded four contracts, worth up to €180 million over six years, for the sovereign cloud of the Union's institutions, bodies and agencies. To be eligible, providers had to reach at least SEAL-2, the data sovereignty level (European Commission, 17 April 2026).

Four European groupings won: a Luxembourgish-French partnership led by Post Telecom with OVHcloud and Clever Cloud; Germany's STACKIT (Schwarz Group); France's Scaleway (Iliad Group); and a Belgian-French-Luxembourgish partnership led by Proximus with S3NS, Clarence and Mistral. Three of them reached SEAL-3. The Proximus consortium stopped at SEAL-2: S3NS — the joint venture between Thales and Google Cloud — did not demonstrate immunity from a non-EU supply chain disruption. CISPE, the association of European cloud providers, sharply criticised the outcome, warning that it risks institutionalising "sovereignty washing" (The Register, 20 April 2026).

Beyond the controversy, the interesting fact is a different one: the yardstick discriminated. It separated four offerings that all present themselves on the market as "sovereign", and it separated them precisely on the point marketing avoids — supply chain and corporate control, not the datacentre map. That has never happened before in a European public procedure, and it is why this document is worth more than ten white papers.

20%
weight of supply chain in the sovereignty score: the highest of the eight objectives
SEAL-3
level reached by three of the four winners; the fourth stopped at SEAL-2
€180m
maximum value of the six-year contract awarded to European providers in April 2026

04What about the hyperscalers' "sovereign clouds"?

They deserve to be looked at without prejudice and without discounts. On 15 January 2026 AWS made the AWS European Sovereign Cloud generally available, with its first region in Brandenburg: a dedicated governance structure in Europe, a new parent company and three subsidiaries incorporated in Germany, operational staff made up of EU residents and — in the company's words — "zero operational control outside of EU borders", with €7.8 billion of announced investment (AWS, press release of 15 January 2026). This is not free marketing: it is a serious corporate and industrial reorganisation, and a sign that European regulatory pressure works.

That said, the framework does not ask where the people are. It asks three different things: who holds decisive authority over the service and what assurances exist against a change of control (SOV-1); what exposure remains to non-EU laws with cross-border reach and which channels could still compel access (SOV-2); and where hardware, firmware and software come from, with their 20% weight (SOV-5). These are questions answered with corporate documents and supply records, not with a press release.

It should be said honestly: none of these offerings has a public SEAL assessment today, and SEAL is not a badge you obtain — it is a judgement a contracting authority forms inside a procedure. What you can do, though, is take the same questions and put them in your own tender documents: a provider's written answer carries a weight its website never will.

No one can award themselves a SEAL level. But anyone can ask the framework's questions — and insist that the answers end up in the contract.

05What changes with the Cloud and AI Development Act?

On 3 June 2026 the Commission presented its proposal for a Cloud and AI Development Act, the centrepiece of the technological sovereignty package (European Commission, CADA). The proposal takes the logic of the framework beyond the Commission's own procurement: it introduces four Union assurance levels for cloud sovereignty and provides that cloud providers serving public sector bodies meet at least the baseline level, with higher levels for critical sectors on the basis of Member State risk assessments; essential entities under NIS2 may carry out similar assessments (Covington, CADA analysis, June 2026).

Do not run ahead: it is a proposal, not a law. It still has to go through negotiation between Council and Parliament, and the sovereignty levels are precisely where the hardest political fight is expected: thresholds and definitions may change. But the direction is readable, and it has one immediate practical consequence: sovereignty is moving from conference topic to condition of market access. If you sell to the public sector, or to an essential entity that answers to NIS2, those questions will reach your supplier questionnaire long before they reach the Official Journal.

Proposal ≠ obligation. CADA is under negotiation: do not plan on numbers that can change. Plan instead on the questions, which will not — parent company jurisdiction, keys, supply chain, exit. Whoever already has the answers ready will not be chasing any deadline.

06How to use it, without waiting for Brussels

You do not need to be a European institution. The document is public, the questions work on any provider, and the exercise takes half a day. Take your three to five critical cloud providers and ask in writing: who holds decisive authority over the service and what assurances exist against a change of control; which national law governs the contract and the operations; which non-EU laws reach the corporate chain, and through which channels a foreign authority could obtain access; who holds the encryption keys; where hardware, firmware and software come from; who operates the service and from where; how much it costs and how many days it takes to leave.

You will recognise them: they are the five tests of operational sovereignty — jurisdiction, keys, exit, continuity, competence — at the granularity of a European tender. It is the same method we use for DORA and compliance: the picture first, the decisions after. And if the picture shows that some processes survive none of those questions, the answer is architectural: operational sovereignty means moving those processes onto sovereign software, on-premise or EU-hosted, without lock-in by design — including the case of AI without vendor lock-in. If you want to start from the picture — network, data, providers, jurisdictions — the first step is a seven-day on-prem audit. To discuss your own case, write to us.

In short. Since October 2025 the European Commission measures cloud sovereignty with a public document: eight weighted objectives — supply chain counts for 20%, the highest — and five assurance levels from SEAL-0 to SEAL-4. In April 2026 the yardstick was actually applied: four European groupings awarded €180 million over six years, three at SEAL-3 and one held at SEAL-2 because of its supply chain. SEAL is not a certification and nobody can award it to themselves, but its questions are public: putting them into your own tender documents is today the fastest way to tell a sovereign cloud from an adjective.
[P3]
Team P3
Technical boutique · EU-hosted
P3 team notes on sovereignty, compliance and ICT resilience, written by those who apply them for European SMEs. Write to us →
Would your cloud survive an EU tender's questions?

Find out before a customer asks you.

[ Book Munin ]