+31 (0)43 30 88 400 | office@comex.eu

The new European yardstick for cloud sovereignty. What does this mean for storage?
Cloud and storage providers are increasingly calling their services European, sovereign, trusted, or compliant. These terms sound clear, but individually they say little about the actual control an organization has over its data and infrastructure.
Data may be located in a Dutch data center, while the provider falls under foreign legislation. Management may take place from a third country. The software and firmware may depend on a single non-European producer. It can also be difficult or costly to move data to another environment.
Europe is trying to bring these different aspects together in a more objective assessment framework. Digital sovereignty thus becomes less of a marketing claim and more of a measurable risk profile.
Register for free for our webinar “The new European yardstick for cloud sovereignty. How to test your storage providers” on September 25. Can’t make it? You will still receive the recording.
Why a European data location is not enough
The location of data remains important. Organizations need to know where their primary data, backups, replicas, and metadata are stored and processed.
Yet that is only one part of digital sovereignty.
An organization can store its data entirely within the European Union and still be dependent on:
- A parent company outside the EU.
- Foreign legislation with cross-border effects.
- Non-European administrators and support teams.
- Closed software, firmware, or file formats.
- External key managers.
- A single provider for maintenance and security updates.
- Limited possibilities to export or migrate data.
European data storage is about location. Digital sovereignty is about the ability to make independent choices and maintain control when circumstances change.
The European Cloud Sovereignty Framework
The European Commission developed the Cloud Sovereignty Framework for assessing providers within a European cloud tender.
The framework is based on existing European and national initiatives, including Gaia-X, the Trusted Cloud Referential from CIGREF, ENISA, NIS2, DORA, and national cloud strategies.
The model assesses providers in eight areas.
1. Strategic sovereignty
This looks at a provider’s position within the European legal, financial, and industrial ecosystem. Who is the owner? Where are decisions made? What happens in the event of a takeover or when foreign support falls away?
2. Legal and jurisdictional sovereignty
This component assesses which legislation applies to the provider. It also examines whether authorities outside the EU can enforce access to data or systems.
3. Data and AI sovereignty
Organizations must maintain control over access to their data. This requires, among other things, insight into who uses data, where processing takes place, who manages cryptographic keys, and how data is demonstrably deleted.
4. Operational sovereignty
Can the service be managed, maintained, and continued within the EU? Or is knowledge, access, or support from a party outside the EU still required for this?
5. Supply chain sovereignty
Hardware, software, firmware, and updates each have their own origin and dependencies. The framework therefore looks further than just the provider with which an organization signs a contract.
6. Technological sovereignty
Open standards, documented interfaces, and interoperability reduce dependence on a single provider. Closed technology can make switching, integrating, and independent management more difficult.
7. Security and compliance
Certifications and alignment with European legislation play an important role. This also looks at the location and authority of security teams, logging, monitoring, and incident response.
8. Ecological sustainability
Energy consumption, raw materials, reuse, and dependence on energy sources are included in the continuity of service.
The provider is not only assessed substantively in these areas. The framework also uses Sovereignty Effectiveness Assurance Levels, abbreviated as SEAL.
The five SEAL levels
The Cloud Sovereignty Framework distinguishes five levels:
- SEAL-0. No demonstrable sovereignty and full control from parties outside the EU.
- SEAL-1. European legislation is formally applicable, but non-European parties maintain actual control.
- SEAL-2. European legislation is applicable and enforceable, while relevant dependencies outside the EU persist.
- SEAL-3. European parties have clear influence and control from third countries is limited.
- SEAL-4. Technology and operations fall entirely under European control and have no critical dependencies outside the EU.
A solution does not have to reach the highest level for every application. The required level depends on the risk, the sensitivity of the data, and the consequences of failure or loss of control.
The four levels from the Cloud and AI Development Act
In addition to the Cloud Sovereignty Framework, the European Commission presented the proposal for the Cloud and AI Development Act, CADA, in June 2026.
The proposal contains four assurance levels for cloud and AI sovereignty:
- Level 1. Data is stored and processed within the European Union.
- Level 2. The provider demonstrates independence from third countries and transparency regarding the software chain.
- Level 3. The provider is owned from within the EU and is managed from within the EU. Additional conditions may apply to personnel and operational control.
- Level 4. There is full transparency and control over the software chain, without interference from third countries.
The four CADA levels and the five SEAL levels are not identical models. However, they show the same development. Europe is looking increasingly further than just the physical location of data.
Compliance and sovereignty are not the same
A solution can be certified and compliant, yet still have strong dependencies outside Europe.
ISO 27001, for example, shows that an organization has set up an information security management system. The certification does not automatically say who legally has control over the provider or how easily a customer can switch.
GDPR compliance also does not mean that a solution is fully sovereign. The GDPR sets rules for the processing and protection of personal data. Digital sovereignty also includes operational autonomy, technological independence, continuity, and the supply chain.
Conversely, a European provider is not automatically compliant. Even a fully European provider must be able to demonstrate appropriate security, processes, documentation, and controls.
Organizations must therefore answer both questions separately:
- Does the solution meet our legal and compliance obligations?
- Does the solution offer sufficient control and autonomy for our risk profile?
What questions do you ask a storage provider?
What questions do you ask a storage provider?
The new European frameworks provide organizations with concrete starting points for provider selection and risk assessment.
Ask a provider, among other things:
- Where do you store and process our primary data, backups, metadata, and log data?
- Which jurisdictions do the provider, the parent company, and subcontractors fall under?
- Can authorities outside the EU enforce access to data or systems?
- Who has technical access to our data and cryptographic keys?
- From which countries are management, monitoring, and support performed?
- Where were software and firmware developed?
- Which critical components are dependent on providers outside the EU?
- Can we manage the environment independently if support falls away?
- Can we export data completely and in a usable format?
- What costs, terms, and technical limitations apply when switching?
- Can data, backups, and archives be demonstrably and permanently deleted?
- Which certifications, audit reports, and technical evidence are available?
Do not just ask for confirmation. Ask for substantiation. Think of architecture documentation, contractual agreements, audit reports, certificates, data flows, and exit procedures.
Align the required level with the application
Full European sovereignty for every dataset is not feasible or necessary for every organization.
A public website has a different risk profile than medical records, financial data, government archives, or intellectual property. Backup data can also be more sensitive than expected, as it often contains a full copy of systems and business information.
Therefore, start with a classification:
- Which data and applications are business-critical?
- Which legal obligations apply?
- What are the consequences if a provider blocks access?
- How long can the organization go without the data or service in question?
- Which foreign dependencies are acceptable?
- What evidence must the organization be able to show to directors, customers, auditors, or regulators?
Based on this, an appropriate level of control can be chosen per workload.
From claim to demonstrable control
The discussion about European cloud and storage is shifting. Just saying that data is located within Europe is no longer sufficient.
Organizations must be able to explain:
- Who has legal and technical control.
- Which dependencies exist within the infrastructure.
- How service is continued in the event of failure or conflicts.
- How data can be recovered, exported, and deleted.
- What evidence is available for audits and compliance.
The new European yardstick helps organizations answer these questions more objectively. Not to exclude every foreign provider, but to make risks visible and to substantiate conscious choices.
Webinar on September 25
Do you want to know how your current cloud and storage providers score on these criteria?
During the webinar ‘The new European yardstick for cloud sovereignty. How to test your storage providers’, we explain the European frameworks and translate them into concrete questions for provider selection, tenders, and storage projects.
Afterwards, you will receive a practical assessment framework with which you can test your own providers.
Date | Friday, September 25, 2026 |
Time | 1:30 PM – 2:30 PM |
Location | Online via Microsoft Teams |
Participation | Free of charge |
Sources.
Cloud Sovereignty Framework, European Commission
https://commission.europa.eu/document/download/09579818-64a6-4dd5-9577-446ab6219113_en
Cloud and AI Development Act, European Commission
https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act

Subscribe for tips and info