Cloud Sovereignty Framework:
Digital sovereignty has established itself as a strategic priority in Europe. In October 2025, the European Commission published “ ” (CSF). This framework of cloud sovereignty objectives addresses the strategic need to ensure a high level of protection for data and processing carried out in the cloud by cloud service providers, against extraterritorial access, and its alignment with the European Union’s regulatory requirements, such as the General Data Protection Regulation, the Data Act and NIS2, amongst others.
The key is no longer simply to migrate to the cloud, but to do so under conditions of sovereignty. In this context, the CSF establishes that sovereignty should not be understood as technological isolation, but as effective control. It implies that data and digital infrastructure remain under the intended jurisdiction, protected against extraterritorial interference and managed in accordance with the applicable regulatory standards mentioned above. In short, it means ensuring that the adoption of the cloud does not compromise the legal, operational and strategic decision-making capacity of the organisation or the State within the EU.
What does this new framework of recommendations issued by the EU mean for organisations that provide and/or use cloud services on a daily basis?
The CSF lists eight sovereignty objectives, from ‘SOV-1’ to ‘SOV-8’, each assigned a weighting where 20% is the maximum and 5% the minimum. They are as follows:
| Objective | % | Description |
| Strategic sovereignty | 15 | Degree of alignment of the provider with the EU’s legal, economic and political framework, ensuring stability, governance and consistency with European strategic priorities |
| Legal and jurisdictional sovereignty | 10 | Assessment of the applicable regulatory environment, exposure to foreign legislation and the actual ability to enforce rights against the supplier |
| Data sovereignty and AI | 10 | Level of control, protection and independence over data and artificial intelligence systems, particularly with regard to extraterritorial access or claims |
| Operational sovereignty | 15 | The ability to operate, monitor and develop technology without relying on actors subject to external influences, ensuring continuity and resilience |
| Supply chain sovereignty | 20 | Transparency regarding the origin of critical components and control over technological dependencies that could compromise European autonomy |
| Technological sovereignty | 15 | Degree of openness, interoperability and independence of the technological architecture, avoiding proprietary lock-ins or structural dependencies |
| Security and compliance sovereignty | 10 | Effective control of security measures, regulatory compliance and operational resilience under European jurisdiction |
| Environmental sustainability | 5 | Service autonomy and resilience in relation to energy consumption, dependence on raw materials and long-term sustainability |
These sovereignty objectives are used to calculate the degree of sovereignty offered by a cloud data processing service, which is ultimately assigned a score ranging from SEAL – 0 (total dependence on third countries) to SEAL – 4 (full hosting and processing within the EU). This is calculated using a formula provided in the CSF.
However, this quantitative approach is not without its limitations. As Dries Buytaert has pointed out1 , scoring-based models tend to treat all factors of sovereignty as weightable elements within an index, without distinguishing between those that merely contribute to the level of sovereignty and those that make it structurally possible. In particular, elements such as open-source software, which allow effective control to be maintained even in the face of changes in supplier, acquisitions or discontinuities, are diluted in the overall score, despite being crucial for sustainable sovereignty over time.
However, this factor is not neutral. In many projects, the entity controlling development retains the ability to modify the licensing regime in future versions, potentially evolving towards more restrictive or even proprietary models. This power introduces a significant tension: the sovereignty provided by open source rests on acquired rights over existing versions and on the possibility of forking the project, but it does not eliminate the risk that effective control may once again become concentrated in the hands of the supplier through changes to the licence or to the governance of development.
From this perspective, the measurement of sovereignty should not be limited to an aggregation of quantifiable guarantees, but should incorporate a logic of prerequisites. Certain attributes, such as the ability to audit, modify and operate systems without dependence on third parties, should be established as baseline conditions rather than mere scoring factors. Ultimately, this highlights the difference between formal and material sovereignty: the former is demonstrated through regulatory or geographical criteria; the latter requires actual capabilities for control, substitution and operational continuity, directly influencing the assessment of risk and the soundness of cloud decisions.
Why should your organisation care?
The European Union has made it clear through the Cloud Sovereignty Framework and European initiatives such as CIGREF’s Trusted Cloud Referential v22 , the Gaia-X standards and architecture3 , and the European framework of cybersecurity obligations (ENISA, NIS2, DORA), that digital sovereignty is no longer a theoretical debate. With this Cloud Sovereignty Framework, the EU is setting a strategic direction, enabling public administrations and organisations to establish criteria for determining how sensitive they are to sovereignty.
Beyond new recommendations such as the Cloud Sovereignty Framework or the European Digital Ecosystem, the relevant question is how we view sovereignty, in that it does not consist solely of knowing where the servers are, but rather involves much more fundamental issues:
- Who can legally access your data?
- Under which jurisdiction does your cloud provider operate?
- What happens in the event of a conflict between international regulations?
- Does your critical activity depend on technological decisions taken outside the EU?
For many organisations—including technology firms, financial institutions, universities, healthcare centres, public bodies and industrial companies—these issues are no longer merely hypothetical. In the current regulatory environment, the adoption of cloud services requires the structured analysis of regulatory compliance mentioned above, legal risk management and robust controls over data and digital infrastructure.
A more demanding context
The protection of sensitive data, intellectual property, developments in artificial intelligence and strategic information form the core of many organisations’ activities. In this context, digital sovereignty becomes a tool for:
- Reducing regulatory and geopolitical risks
- Strengthen legal certainty
- Protect intangible assets
- Boost the confidence of customers, investors and partners
Furthermore, it is likely that sovereignty criteria will begin to influence public procurement processes and projects funded by the EU.
A question of positioning
Beyond regulatory compliance, choosing a cloud infrastructure aligned with European standards can become a differentiating factor for organisations, companies or public administrations, amongst others, that are sensitive to sovereignty, providing a greater degree of assurance and legal certainty by having the cloud hosted within the European Union.
Examples of CFS application
- EU tender: The European Commission has launched a €180 million tender4 to procure cloud services that meet digital sovereignty criteria. The aim is to reduce dependence on external providers and establish a clear benchmark for European standards in cloud services for EU institutions and agencies.
- Sweego: the French private company highlights its alignment with the CSF, emphasising its 100% European infrastructure and governance as a distinguishing feature in terms of independence and compliance5
.
Spain promotes European autonomy in AI through strategic investment and public-private collaboration
The Spanish Government has announced an investment of €100 million to support companies’ participation in the Important Project of Common European Interest on Artificial Intelligence (IPCEI-AI)6 , a key initiative to strengthen a next-generation European AI ecosystem based on cross-border cooperation and industrial innovation. This initiative forms part of the European strategy to boost global competitiveness in artificial intelligence through public-private partnerships, technological development and industrial scaling, connecting over 110 companies and mobilising large-scale private investment through initiatives such as the EU Champion Initiative.
Conclusion
The CSF is not an immediate obligation, but it is a clear signal of the direction in which the European cloud services market is heading. It is not merely a matter of assessing which cloud provider offers the best technical or economic conditions, but of determining the control regime and legal safeguards applicable to the infrastructure on which critical data and information are hosted. In an environment marked by technological competition and regulatory fragmentation, digital sovereignty is establishing itself as a factor in security, reputation and competitive advantage.
Anticipating this is not just a technical decision: it is a strategic one.
At Across Legal, we can help your organisation translate this framework into concrete decisions to align your cloud strategy with European expectations.
↳ Discover more content in the section Insight.
↳ Do you want to stay up today about the sector related news? Follow us on LinkedIn.




