Cloud sovereignty has long been more than just a political buzzword. It is increasingly becoming a strategic requirement for companies, public authorities, and critical infrastructures in Europe. With the new Cloud Sovereignty Framework The EU has now created a concrete assessment framework that not only demands sovereignty, but also makes it measurable. This is a milestone for everyone who wants to provide cloud services or use them responsibly.
What lies behind the new EU framework
The EU Commission defines eight so-called Sovereignty Objectives (SOV-1 to SOV-8), which cover various dimensions of digital sovereignty:
- SOV-1: Strategic sovereignty – EU anchoring of ownership, governance, and value creation
- SOV-2: Legal sovereignty – Protection against access by third countries
- SOV-3: Data & AI sovereignty – Control over data and AI models
- SOV-4: Operational sovereignty – Operational capability without dependence on non-EU suppliers
- SOV-5: Supply chain sovereignty – Transparency and control over hardware, software, and suppliers
- SOV-6: Technological sovereignty – Openness, auditability, interoperability
- SOV‑7: Security and compliance sovereignty – EU-compliant security processes
- SOV‑8: Sustainability – Energy efficiency, circular economy, CO₂ transparency
The framework is supplemented by the SEAL levels (Sovereignty Effectiveness Assurance Levels) from 0 (no sovereignty) to 4 (full digital sovereignty) and a weighted Sovereignty score, that makes the quality of an offer measurable.
More than security: Why the framework is a game changer
While previous certifications such as ISO 27001 or C5 primarily address security aspects, the Cloud Sovereignty Framework goes much further. It evaluates who has the Control over data, infrastructure, and processes. This makes sovereignty a measurable property and to the real Competitive advantage for European providers.
Political signal: Summit for digital sovereignty in Berlin
On November 18, 2025 took place in Berlin Summit on European digital sovereignty initiated by Germany and France. German Chancellor Friedrich Merz and French President Emmanuel Macron took part, as did 23 digital ministers from EU countries, EU Commission Vice-President Henna Virkkunen, and around 1,000 high-ranking guests from politics, business, science, and civil society.12
The goal was to Europe's digital independence to strengthen its position in areas such as cloud infrastructure, artificial intelligence, and data centers. One focus was on reducing Dependencies on US suppliers such as AWS, Microsoft Azure, or Google—particularly due to legal risks arising from US laws such as the CLOUD Act or FISA 702.345
Results of the summit:
- Signal effect: Starting signal for joint investments in European cloud and AI platforms67
- Projects: Presentation of solutions such as the European Digital Identity Wallet and German and French open-source workplace solutions („openDesk,“ „La Suite“)8
- Gaia-X in the spotlight: as a central infrastructure for sovereign data exchange9
The message is clear: Sovereignty is now a matter for the boss – with concrete economic, regulatory, and technological consequences for providers and decision-makers.
Opportunities for European providers
The framework gives European cloud providers the opportunity to participate in tenders and win contracts with security-critical customers. clearly differentiate. Those who consistently develop their services in line with SOV criteria and SEAL levels strengthen their market position—especially in the public sector and among KRITIS operators.
One example of this is our Business Filemanager. We developed this solution specifically with digital sovereignty in mind and meet the framework's key requirements:
- Hosting in Germany and on-premise options
- Storage and processing exclusively in the EU for SaaS operations
- 100 % Ownership of the data remains with the users.
- No Cloud Act risks due to US connection
- High security standards and transparent terms of use
These features exemplify how digital sovereignty can already be implemented today in technical, organizational, and legal terms—and what potential this offers for European providers.
What IT decision-makers should do now
The framework not only provides guidance for providers—IT decision-makers should also align their strategy with it:
- Critically examine cloud offerings: Where is the data stored? Who has access to it? What legal dependencies exist?
- Establishing sovereignty as a strategic criterion: Consider sovereignty alongside price and performance
- Prioritize suppliers with EU roots: for compliance and resilience reasons
Outlook: What happens next
The EU framework is the starting point. The next step is planned for 2026 with the Cloud & AI Development Act, which will set out binding requirements for sovereign cloud and AI services—especially for public procurement and critical infrastructure.
Conclusion
With the Cloud Sovereignty Framework Supported by the recent summit on European digital sovereignty, Europe is moving toward measurable digital independence. Providers who align themselves with these criteria are positioning themselves for the future. And decision-makers are given a tool to integrate sovereignty into procurement processes in a concrete way.



