In my earlier blog on sovereign cloud geopolitical risks, I argued that increasing geopolitical tensions, from renewed US isolationist policies to rising concerns over extraterritorial legal access and unilateral state action, have exposed critical vulnerabilities for EU organisations that depend on global cloud services. These vulnerabilities include lack of control over critical infrastructure, and exposure to laws like the US CLOUD Act that can override contractual protections.
Figure 1: EU Cloud Sovereignty Framework Overview
In response to these risks, in October 2025 the European Commission published its Cloud Sovereignty Framework. This is a concrete, measurable set of requirements and assurance mechanisms designed provide measurable sovereignty criteria for cloud services. This is an important step to help both EU enterprises and EU public organizations mitigate these risks.
From Risk Landscape to Risk Measures
In this blog I will map the geopolitical risks I previously identified to the specific measures in the Cloud Sovereignty Framework. Compliance with these measures are assessed and quantified through the Sovereignty Effectiveness Assurance Level (SEAL) system.
Data Sovereignty and Legal Vulnerabilities
The US Government through legal instruments like the CLOUD Act, as well as executive actions, has repeatedly demonstrated its ability to reach beyond its borders to access data, compel service providers and restrict technology exports. For foreign businesses using US-based cloud providers, or services hosted in US-influenced jurisdictions, this creates a fundamental problem of trust, continuity, and control.
Framework Measures:
The SOV-2 and SOV-3 measures in the EU’s standard explicitly assesses control over legal jurisdiction and protection against extraterritorial legal claims. Providers must demonstrate that EU law governs key aspects of data storage and processing, and that mechanisms exist to limit access by third-country authorities.
Operational and Infrastructure Sovereignty Risks
Cloud service administration may follow the sun. If administrators are US citizens or employed by a US company, they can be legally required to access, monitor, or even disrupt services, without the knowledge or consent of the customer.
Physical data centers, networking equipment, and other infrastructure elements may reside in or depend on US-based entities. In times of political conflict or sanctions, governments could seize, disable, or restrict this infrastructure - disrupting or severing access to critical business operations.
Framework Response:
The framework’s SOV-4 sovereignty measures require operational control metrics, including local presence of support staff, operational autonomy, and control over administrative access. Providers must prove these elements against minimum SEAL requirements to qualify.
Technology Sovereignty and Reliance on Proprietary Solutions
Cloud services depend upon a complex technology stack. This depends upon proprietary hardware and software to deliver a proprietary user environment. While the basic capabilities of networking, storage and computing may support open standards, the value of the services to the end user is increased through proprietary middleware and managed services. These also include Generative AI tools now largely delivered as cloud services.
Framework Response:
The framework’s SOV-5 and SOV-6 measures cover supply chain transparency and technological openness. Providers must disclose the origin of hardware, software dependencies, and compliance with open standards. This will make it easier to spot non-EU dependencies.
It also provides an incentive for providers to adopt open and interoperable technologies, a goal that is aligned with EU initiatives such as Gaia-X, which promotes federated and transparent data ecosystems built on common standards.
Cyber Resilience
As recognized in the EU NIS2 directive cloud services have become indispensable for operational agility, scalability, and innovation. However, organizations have become dependent on these to operate with a highly optimized and just in time approach. Any loss of access can have a significant impact as was illustrated by the recent AWS service outage Cloud services must provide organizations with the capabilities to secure their use to ensure resilience in the face of cyber threats.
Framework Response:
The framework SOV-7 measures the extent to which security operations, compliance obligations, and resilience measures are controlled within the EU, to ensure independence from foreign jurisdictions and long-term operational assurance.
Sovereignty Washing
There is a risk that some cloud providers could make marketing “sovereignty promises” that offer limited real protection against legal, operational or geopolitical risk exposure.
Framework Response:
By defining concrete sovereignty objectives and requiring the production of tangible evidence at each level, the Cloud Sovereignty Framework protects against superficial claims. To claim sovereignty Cloud services must meet verifiable criteria that reflect genuine sovereignty attributes.
Opinion - Sovereignty With Teeth
Although the framework was initially designed for EU institution tenders, this Framework is likely to become a de facto benchmark across other sectors. While some sectors such as finance, pharmaceuticals and healthcare already have strict industry regulation, other industries will benefit from adopting these measures and assurance levels to guide cloud strategy, risk management, and compliance decisions.
The Cloud Sovereignty Framework bridges a crucial gap between concept and measurement. By defining clear sovereignty criteria, requiring tangible evidence and providing measurable assurance levels, it gives organizations the tools to help mitigate the geopolitical risks that my earlier blogs described.
Not all use cases have the same needs for digital sovereignty. Organizations should take a risk-based approach to choosing cloud services that best meet their business requirements and risk appetite. This framework will provide a useful benchmark to help in making this choice.