Sovereignty Assessment

How sovereign is your cloud, really?

Score your cloud estate against the European Commission's Cloud Sovereignty Framework — the eight sovereignty objectives and official scoring weights the EU now uses to award sovereign-cloud contracts. Four minutes, no email needed for your score.

Start the assessment Free · self-assessed · indicative
8
Commission objectives
16
Questions
4min
To your scorecard
0–4
Readiness bands
The framework

Eight objectives. Brussels' rubric, not ours.

Every question below maps to a contributing factor in the Commission's framework (v1.2.1, Oct 2025) — the same criteria behind the EU institutions' €180M sovereign-cloud procurement. Answer for your organisation's current estate, not the one you're planning.

SOV-1

Strategic Sovereignty

weight 15%

Where decisive authority, ownership, and financing over your cloud services sit — and how stable that is.

1/16 Who has decisive authority over the cloud services your business runs on?

2/16 If a non-EU vendor suspended your service or support tomorrow — sanctions, licensing change, commercial decision — what happens?

SOV-2

Legal & Jurisdictional Sovereignty

weight 10%

Exposure to foreign law — whether non-EU authorities could compel access to your data or systems.

3/16 Which legal system governs the contracts behind your core cloud services?

4/16 Could a non-EU authority — e.g. via the US CLOUD Act — compel access to your data through one of your providers?

SOV-3

Data & AI Sovereignty

weight 10%

Who controls cryptographic access to your data, where it is processed, and how independent your AI capability is.

5/16 Who holds effective cryptographic control over your data?

6/16 Are storage and processing strictly confined to European jurisdictions — with no third-country fallback?

SOV-4

Operational Sovereignty

weight 15%

Whether EU actors can run, support, and evolve the service without non-EU involvement.

7/16 Could your team — or an EU partner — run, patch, and evolve your platform without any non-EU vendor?

8/16 How hard would it be to migrate your workloads to an EU-controlled alternative?

SOV-5

Supply Chain Sovereignty

weight 20%

Where your hardware and software actually come from — and how much of that chain you can see and audit.

9/16 How much visibility do you have into where your hardware is manufactured and whose firmware it runs?

10/16 Where is the software in your cloud stack built and distributed from?

SOV-6

Technology Sovereignty

weight 15%

Openness of the stack: standards, open licensing, auditability, and freedom from vendor lock-in.

11/16 How much of your platform stack is openly licensed, with the right to audit, modify, and redistribute?

12/16 Are your platform's APIs and formats open standards, or proprietary to one vendor?

SOV-7

Security & Compliance Sovereignty

weight 10%

Whether security operations, compliance obligations, and resilience are controlled within the EU.

13/16 Where do your security operations — monitoring, SOC, incident response — run, and under whose jurisdiction?

14/16 Can you — or EU auditors on your behalf — perform independent security audits with full access?

SOV-8

Environmental Sustainability

weight 5%

Long-term autonomy and resilience in relation to energy usage and raw-material scarcity.

15/16 Is your infrastructure powered by renewable or low-carbon energy, with measured efficiency (e.g. PUE) targets?

16/16 Do you measure and disclose sustainability indicators (carbon, water) and practise hardware circularity?

0 / 16 answered
FAQ

Cloud sovereignty, explained

The framework, the SEAL levels, and what your score actually means — the questions we get before and after the assessment.

01 What is a sovereign cloud?

A sovereign cloud is cloud infrastructure that remains under the legal, operational, and technological control of a specific jurisdiction — for European organisations, the EU. In practice it means:

  • EU law governs the service — and is enforceable, not just formally applicable
  • non-EU authorities cannot compel access to data or systems
  • EU actors can run, support, and evolve the platform without foreign vendors
  • the technology stack is open enough to audit — and to leave

Data residency alone does not make a cloud sovereign: data stored in an EU region of a non-EU hyperscaler remains subject to that provider’s home jurisdiction.

02 What is the EU Cloud Sovereignty Framework?

The Cloud Sovereignty Framework is published by the European Commission’s Directorate-General for Digital Services (version 1.2.1, October 2025). It defines eight sovereignty objectives — strategic, legal and jurisdictional, data and AI, operational, supply chain, technology, security and compliance, and environmental sustainability — assessed through 48 specific criteria, and assigns Sovereignty Effectiveness Assurance Levels (SEAL) per objective. The Commission first applied it in the EU institutions’ €180 million sovereign-cloud procurement, and it is becoming the de facto benchmark for evaluating cloud sovereignty in Europe.

03 What are the eight sovereignty objectives?

The Commission’s framework groups its 48 criteria under eight objectives, each with an official weight in the Sovereignty Score:

  • SOV-1 Strategic Sovereignty (15%) — where decisive authority, ownership, and financing sit
  • SOV-2 Legal & Jurisdictional Sovereignty (10%) — exposure to non-EU law such as the US CLOUD Act
  • SOV-3 Data & AI Sovereignty (10%) — cryptographic control and EU-confined processing
  • SOV-4 Operational Sovereignty (15%) — whether EU actors can run and evolve the service without foreign involvement
  • SOV-5 Supply Chain Sovereignty (20%, the highest weight) — provenance of hardware, firmware, and software
  • SOV-6 Technology Sovereignty (15%) — open standards, open licensing, freedom from vendor lock-in
  • SOV-7 Security & Compliance Sovereignty (10%) — EU-controlled security operations and audits
  • SOV-8 Environmental Sustainability (5%) — energy efficiency, circularity, and disclosure
04 What are SEAL levels?

SEAL — Sovereignty Effectiveness Assurance Level — is the framework’s five-step scale, assigned per objective:

  • SEAL-0 · No sovereignty — exclusive non-EU control
  • SEAL-1 · Jurisdictional sovereignty — EU law formally applies, with limited practical enforceability
  • SEAL-2 · Data sovereignty — EU law enforceable, but material non-EU dependencies remain
  • SEAL-3 · Digital resilience — meaningful EU influence, with marginal non-EU control
  • SEAL-4 · Full digital sovereignty — complete EU control, subject only to EU law

A provider does not have one SEAL level — it has eight, one per objective, and EU tenders set a minimum level per objective.

05 How is a cloud Sovereignty Score calculated?

The Commission’s formula is a weighted sum: each objective’s score, as a fraction of its maximum, is multiplied by the objective’s official weight, and the results are added into a percentage. The weights are:

  • Supply chain — 20%
  • Strategic, operational, and technology — 15% each
  • Legal & jurisdictional, data & AI, and security & compliance — 10% each
  • Environmental sustainability — 5%

In EU procurement the score ranks bids that have already cleared minimum SEAL thresholds — failing one threshold rejects the bid regardless of the total score.

06 How can I assess my organisation’s cloud sovereignty?

The assessment on this page is a free 16-question self-assessment against the Commission’s framework: two questions per objective, each mapped to the framework’s published contributing factors. It takes about four minutes and produces an instant scorecard — a 0–10 score and readiness band per objective, plus an overall Sovereignty Score computed with the Commission’s official weights — without requiring an email address. A facilitated workshop covering the full 48-criteria questionnaire is available for organisations that need a procurement-grade answer.

07 Is this an official SEAL rating?

No — and this tool deliberately does not assign SEAL levels at all. The Commission determines SEAL holistically per procurement, from evidence and material weaknesses across the full 48-criteria questionnaire; it is not derived from a numeric score. What you get here instead:

  • The Commission's own material — the eight objectives, their contributing factors, and the official scoring weights behind the Sovereignty Score
  • Stakater's own material — the 0–10 score per objective and the readiness band it falls into, on published thresholds (0–1 Band 0, 2–4 Band 1, 5–7 Band 2, 8–9 Band 3, 10 Band 4)

Treat the result as a gap-finding aid, not a certification or a prediction of how a contracting authority would rate you.

08 Why does the US CLOUD Act matter for cloud sovereignty?

The US CLOUD Act allows US authorities to compel US-headquartered providers to produce data in their possession regardless of where it is stored — an EU data centre does not shield data held by a US provider. The Commission’s framework treats this as a core legal-sovereignty question (SOV-2): it assesses the degree of exposure to non-EU laws with cross-border reach and the existence of channels through which non-EU authorities could compel access. Mitigations include EU-contracted providers with no non-EU nexus and customer-held encryption keys.

09 How do I improve a low sovereignty score?

It depends on which objective is weakest:

  • Legal gaps need EU-contracted providers and jurisdictional review — technology cannot fix a legal nexus
  • Technology and operational gaps are addressed by an EU-operable platform built on open standards — a control plane running VMs and Kubernetes in open, portable formats on infrastructure you own, such as Stakater Cloud Orchestrator, removes foreign operational dependency and vendor lock-in
  • Supply-chain gaps need provenance requirements and audit rights in procurement
  • Data gaps need customer-held encryption keys and technically enforced EU confinement
  • Sustainability gaps are solved at the data-centre level — renewable-powered facilities and measured efficiency targets
Next step

Get the full 48-criteria picture.

A facilitated sovereignty workshop: we assess your estate against the complete Commission framework and hand you a prioritised remediation roadmap.