It is now 12 months since I wrote my first blog on the risks related to cloud sovereignty. The increasingly unstable geopolitical environment has made cloud sovereignty an important concern for organizations. Cloud sovereignty not only relates to compliance and data confidentiality but also to supply chain risk, for which supplier diversity and technical openness are essential mitigations.
Increasing Awareness and Geopolitical Tensions
Incidents in late 2025 increased awareness of the potential impact of cloud service failures across European industries and public services. Geopolitical tensions have also increased; the war in Ukraine continues, and a new war has started in the Middle East, which has further disrupted global supply chains.
At the same time, the US-based hyperscale cloud service providers have responded to sovereignty concerns by announcing EU sovereign versions of their services. How these will change the sovereignty risk landscape remains to be seen.
Sovereignty in Context
Organizations selecting a sovereign cloud should evaluate offerings in four main dimensions to ensure that the platform can meet their operational needs as well as their sovereignty requirements.
- The service should provide the breadth and depth of the functionality that the organization needs.
- It should align with and support the specific needs of their industry sector.
- It should have appropriate non-functional qualities such as security, openness, and deployability.
- It should meet the physical, legal, and technical sovereignty needs.

Four dimensions of cloud services
Functionality
Cloud services are chosen to support the applications and data used by the organization to innovate, deliver services, reduce costs, and operate securely. This means evaluating:
- The breadth of services available (such as for data, AI, security, and DevOps).
- The depth and maturity of those services (including factors such as scalability, performance, and integration).
- And critically, the level of controls provided to manage the service and secure access, data, and operations.
Sovereign-only platforms may not provide the same depth or breadth of services as the hyperscale platforms. Evaluate the trade-off against your organization’s needs.
Suitability
Buyers should evaluate how suitable the cloud service is for their industry-specific business requirements. Does the service provide solutions that are aligned with their industry sector needs, for example, financial services, telecommunications, healthcare, manufacturing, public services, or government? Organizations should evaluate whether the service:
- Conforms with related EU market sector standards.
- Maintains pre-certified EU regulatory controls for the market sectors.
- Supports compliance blueprints or landing zones tailored for the industry.
- Has local industry specialist partners.
Quality
The ISO/IEC 25010 product quality model defines nine top‑level quality characteristics. These include non-functional requirements, which should be considered as well as functionality. Organizations should evaluate
- Security: the Complementary User Entity Controls provided for the user to secure access and data.
- Portability: the ease with which the customer can switch their workloads to another service provider.
- Deployability: how well the service can be integrated with the existing infrastructure and technologies.
Sovereignty
Buyers should evaluate cloud service sovereignty in the context of their needs. Not all services, applications, and data will have the same sovereignty needs. Consider:
- Physical sovereignty: the location of the infrastructure that delivers the service as well as the operational staff that maintain and secure the service.
- Legal sovereignty: the legal ownership of the service and its infrastructure as well as the jurisdiction governing contracts.
- Technology sovereignty: the use of standardized hardware and software components, allowing infrastructure to be sourced and maintained through multiple suppliers.
Openness is a critical control
Sovereignty is not a feature that can be “added” to a cloud service; it is an outcome of multiple design choices across its architecture, infrastructure, and technical components. Organizations should evaluate cloud providers’ sovereignty claims carefully using the EU Cloud Sovereignty Framework.
Organizations should recognize that cloud sovereignty decisions involve trade-offs. Not all data, workloads, or processes require the same level of sovereignty. Increasing focus on one dimension can impact others, increase complexity, or introduce new risks. The challenge is not to eliminate risk but to understand the risk to make informed decisions about where sovereignty is required and to what degree.
Importantly, sovereignty is another supply chain risk. Organizations should work to build cloud supplier resilience by avoiding technical lock-in. Openness is therefore a critical consideration.