A cloud is sovereign when no party outside the European Union can interrupt it, read it or condition it. Until recently that was an opinion: everyone called "sovereign" whatever suited them. Since October 2025 there is a public yardstick — eight weighted objectives and five levels, from SEAL-0 to SEAL-4 — and in April 2026 the European Commission used it to award a €180 million contract. You can use it too, today, on your own provider.
01What is a "sovereign cloud"?
The word was hollowed out before it was ever defined. "Sovereign" has been stuck on offerings that keep data in a European datacentre, on those with a local subsidiary signing the contract, on those with a well-drafted data processing agreement. None of these, on its own, answers the question that matters: who can compel the provider to act against your interest, and what happens to your service on that day.
We have already grounded the distinction in our article on operational sovereignty: data residency is geography, sovereignty is control. What is new is that the distinction now has a measurable shape and — rarer still — a public document setting it out, written by the people who buy cloud for the European institutions.
02How does the European Union measure sovereignty?
With the Cloud Sovereignty Framework, version 1.2.1, published in October 2025 by the European Commission's Directorate-General for Digital Services (European Commission, Cloud Sovereignty Framework v1.2.1). It is not a law and not a certification: it is the instrument a contracting authority uses to assess, in a procurement procedure, how sovereign a cloud offering is. The document states that it draws on existing work — France's Cloud de Confiance referential, Gaia-X policy rules, the European cybersecurity certification framework — and turns it into criteria a tender can apply.
The structure is simple and worth learning, because it is the most complete grid of questions available in Europe today. Eight sovereignty objectives, each with a weight in the final score:
- SOV-5 · Supply chain (20%) — geographic source of key components and manufacturing, jurisdiction of the firmware, where and by whom software is architected, packaged and updated. The highest weight of the eight.
- SOV-1 · Strategic (15%) — where the bodies with decisive authority over the service sit, what assurances exist against a change of control, ability to keep operating if vendor support is withdrawn.
- SOV-4 · Operational (15%) — the capacity of EU operators to run and maintain the service without the non-EU vendor, availability of documentation and source code, support delivered from within the EU.
- SOV-6 · Technology (15%) — open APIs and protocols, licences allowing audit and modification, visibility into the whole sub-supplier chain, independence in high-performance computing.
- SOV-2 · Legal and jurisdictional (10%) — degree of exposure to non-EU laws with cross-border reach (the document explicitly names the US CLOUD Act and the Chinese Cybersecurity Law) and the existence of legal, contractual or technical channels through which non-EU authorities could compel access.
- SOV-3 · Data and AI (10%) — ensuring that only the customer, not the provider, has effective control over cryptographic access to the data; no fallback to third countries; governance of AI models.
- SOV-7 · Security and compliance (10%) — certifications, adherence to GDPR, NIS2 and DORA, security teams operating exclusively under EU jurisdiction, independent audit rights.
- SOV-8 · Environmental sustainability (5%) — energy efficiency, circular economy, transparency on emissions.
Two distinct mechanisms sit on top of the objectives. The first is SEAL (Sovereignty Effectiveness Assurance Level): the tender specifications set a minimum level for each objective, and — in the framework's own words — tenders that do not offer the required levels consistently across all objectives will be rejected. The second is the Sovereignty Score, the weighted sum of the scores, which feeds the quality score as an award criterion. Entry barrier and league table, kept separate.
The five SEAL levels, as the framework defines them: SEAL-0, no sovereignty (exclusive control by non-EU third parties, governed entirely outside the EU); SEAL-1, jurisdictional sovereignty (EU law formally applies, with limited practical enforceability); SEAL-2, data sovereignty (EU law applicable and enforceable, with material non-EU dependencies and indirect third-party control); SEAL-3, digital resilience (EU actors with meaningful but not full influence, marginal non-EU control); SEAL-4, full digital sovereignty (technology and operations under complete EU control, no critical non-EU dependencies).
03The yardstick in practice: the €180 million tender
A criterion is worth what its application is worth. On 17 April 2026 the Commission awarded four contracts, worth up to €180 million over six years, for the sovereign cloud of the Union's institutions, bodies and agencies. To be eligible, providers had to reach at least SEAL-2, the data sovereignty level (European Commission, 17 April 2026).
Four European groupings won: a Luxembourgish-French partnership led by Post Telecom with OVHcloud and Clever Cloud; Germany's STACKIT (Schwarz Group); France's Scaleway (Iliad Group); and a Belgian-French-Luxembourgish partnership led by Proximus with S3NS, Clarence and Mistral. Three of them reached SEAL-3. The Proximus consortium stopped at SEAL-2: S3NS — the joint venture between Thales and Google Cloud — did not demonstrate immunity from a non-EU supply chain disruption. CISPE, the association of European cloud providers, sharply criticised the outcome, warning that it risks institutionalising "sovereignty washing" (The Register, 20 April 2026).
Beyond the controversy, the interesting fact is a different one: the yardstick discriminated. It separated four offerings that all present themselves on the market as "sovereign", and it separated them precisely on the point marketing avoids — supply chain and corporate control, not the datacentre map. That has never happened before in a European public procedure, and it is why this document is worth more than ten white papers.
04What about the hyperscalers' "sovereign clouds"?
They deserve to be looked at without prejudice and without discounts. On 15 January 2026 AWS made the AWS European Sovereign Cloud generally available, with its first region in Brandenburg: a dedicated governance structure in Europe, a new parent company and three subsidiaries incorporated in Germany, operational staff made up of EU residents and — in the company's words — "zero operational control outside of EU borders", with €7.8 billion of announced investment (AWS, press release of 15 January 2026). This is not free marketing: it is a serious corporate and industrial reorganisation, and a sign that European regulatory pressure works.
That said, the framework does not ask where the people are. It asks three different things: who holds decisive authority over the service and what assurances exist against a change of control (SOV-1); what exposure remains to non-EU laws with cross-border reach and which channels could still compel access (SOV-2); and where hardware, firmware and software come from, with their 20% weight (SOV-5). These are questions answered with corporate documents and supply records, not with a press release.
It should be said honestly: none of these offerings has a public SEAL assessment today, and SEAL is not a badge you obtain — it is a judgement a contracting authority forms inside a procedure. What you can do, though, is take the same questions and put them in your own tender documents: a provider's written answer carries a weight its website never will.
05What changes with the Cloud and AI Development Act?
On 3 June 2026 the Commission presented its proposal for a Cloud and AI Development Act, the centrepiece of the technological sovereignty package (European Commission, CADA). The proposal takes the logic of the framework beyond the Commission's own procurement: it introduces four Union assurance levels for cloud sovereignty and provides that cloud providers serving public sector bodies meet at least the baseline level, with higher levels for critical sectors on the basis of Member State risk assessments; essential entities under NIS2 may carry out similar assessments (Covington, CADA analysis, June 2026).
Do not run ahead: it is a proposal, not a law. It still has to go through negotiation between Council and Parliament, and the sovereignty levels are precisely where the hardest political fight is expected: thresholds and definitions may change. But the direction is readable, and it has one immediate practical consequence: sovereignty is moving from conference topic to condition of market access. If you sell to the public sector, or to an essential entity that answers to NIS2, those questions will reach your supplier questionnaire long before they reach the Official Journal.
06How to use it, without waiting for Brussels
You do not need to be a European institution. The document is public, the questions work on any provider, and the exercise takes half a day. Take your three to five critical cloud providers and ask in writing: who holds decisive authority over the service and what assurances exist against a change of control; which national law governs the contract and the operations; which non-EU laws reach the corporate chain, and through which channels a foreign authority could obtain access; who holds the encryption keys; where hardware, firmware and software come from; who operates the service and from where; how much it costs and how many days it takes to leave.
You will recognise them: they are the five tests of operational sovereignty — jurisdiction, keys, exit, continuity, competence — at the granularity of a European tender. It is the same method we use for DORA and compliance: the picture first, the decisions after. And if the picture shows that some processes survive none of those questions, the answer is architectural: operational sovereignty means moving those processes onto sovereign software, on-premise or EU-hosted, without lock-in by design — including the case of AI without vendor lock-in. If you want to start from the picture — network, data, providers, jurisdictions — the first step is a seven-day on-prem audit. To discuss your own case, write to us.