Cloud Sovereignty Framework
Cloud Sovereignty Framework: Digital sovereignty has established itself as a strategic priority in Europe. In October 2025, the European Commission published “ ” (CSF). This framework of cloud sovereignty objectives addresses the strategic need to ensure a high level of protection for data and processing carried out in the cloud by cloud service providers, against extraterritorial access, and its alignment with the European Union’s regulatory requirements, such as the General Data Protection Regulation, the Data Act and NIS2, amongst others. The key is no longer simply to migrate to the cloud, but to do so under conditions of sovereignty. In this context, the CSF establishes that sovereignty should not be understood as technological isolation, but as effective control. It implies that data and digital infrastructure remain under the intended jurisdiction, protected against extraterritorial interference and managed in accordance with the applicable regulatory standards mentioned above. In short, it means ensuring that the adoption of the cloud does not compromise the legal, operational and strategic decision-making capacity of the organisation or the State within the EU. What does this new framework of recommendations issued by the EU mean for organisations that provide and/or use cloud services on a daily basis? The CSF lists eight sovereignty objectives, from ‘SOV-1’ to ‘SOV-8’, each assigned a weighting where 20% is the maximum and 5% the minimum. They are as follows: Objective % Description Strategic sovereignty 15 Degree of alignment of the provider with the EU’s legal, economic and political framework, ensuring stability, governance and consistency with European strategic priorities Legal and jurisdictional sovereignty 10 Assessment of the applicable regulatory environment, exposure to foreign legislation and the actual ability to enforce rights against the supplier Data sovereignty and AI 10 Level of control, protection and independence over data and artificial intelligence systems, particularly with regard to extraterritorial access or claims Operational sovereignty 15 The ability to operate, monitor and develop technology without relying on actors subject to external influences, ensuring continuity and resilience Supply chain sovereignty 20 Transparency regarding the origin of critical components and control over technological dependencies that could compromise European autonomy Technological sovereignty 15 Degree of openness, interoperability and independence of the technological architecture, avoiding proprietary lock-ins or structural dependencies Security and compliance sovereignty 10 Effective control of security measures, regulatory compliance and operational resilience under European jurisdiction […]






