European sovereign cloud: from political concern to measurable requirements

Full name
October 2, 2026
5 min read
European sovereign cloud journey analysis
European sovereign cloud: from political concern to measurable requirements
What started as a debate about data location has become a test of who controls infrastructure, operations and continuity. Procurement, the Cloud Sovereignty Framework and national programmes are turning that test into concrete requirements.

Europe is redrawing the rules of the cloud market. What started as a debate about data location is becoming a broader test of who controls infrastructure, operations, technology choices and continuity when geopolitical or commercial conditions change.

The decisive issue is how sovereignty is translated into workload-specific requirements. As thresholds become more concrete, they begin to determine provider eligibility and force suppliers to make the control model behind each service transparent.

Sovereignty becomes an operating principle

European governments are beginning to reserve sensitive workload categories for delivery models in which European entities can keep the service running and govern critical changes without unrestricted dependence on a foreign technology vendor.

Public buyers are looking through the service label to the operating model behind it. They increasingly expect evidence that administrative authority sits within the sovereign boundary, and that continuity does not depend on the technology owner remaining fully available.

Three moves from 2026 show how far this has travelled from statements of intent:

  • In April 2026 the European Commission awarded a Sovereign Cloud tender worth EUR 180 million for EU institutions, bodies and agencies to four European provider groups, leaving out US hyperscalers directly.
  • On 8 April 2026 the French government's digital agency announced a state-wide push to reduce extra-European digital dependencies, including an exit from Windows to Linux and the migration of 80,000 health-insurance agents.
  • On 25 May 2026 the Dutch government blocked Kyndryl's proposed acquisition of Solvinity, the cloud provider behind DigiD-related infrastructure, citing public-interest and security concerns.
European governments move from questioning US cloud sovereignty to operational action: EU tender, France, Netherlands
Procurement, workload migration and open-source alternatives have become concrete policy tools. Source: Frenus analysis.

Portugal, Denmark, Spain, Switzerland and Italy are turning digital sovereignty into national cloud plans, dependency-reduction strategies and public-sector migration programmes.

Different national approaches, one structural concern

National implementation is diverging in exactly the details that determine bid eligibility. The same service may qualify in one market but require a different certification boundary or a locally controlled operating setup in another.

France is setting explicit reduction targets for extra-European software, while Portugal and Germany are embedding sovereignty into national cloud criteria and public-sector architectures. A single Europe-wide product label will therefore not be sufficient.

This fragmentation is already influencing portfolio decisions, as we observe in engagements with European ICT providers. They increasingly need to explain which national requirements they can address, and where local adaptations or partners remain necessary. A risk-based market is emerging: standard workloads may continue to use global platforms, while identity, defence, health and critical infrastructure require stronger safeguards.

Public procurement turns political intent into market demand

The Commission's cloud tender demonstrates that sovereignty can act as an initial gate rather than a later scoring advantage. An offering that misses the required assurance level may never enter the comparison on functionality or price.

Major European procurements are likely to influence national administrations and regulated industries. They provide a reference for defining acceptable exposure to foreign jurisdiction, supply chains and external technology layers.

Our client engagements suggest the most immediate pressure is emerging around software sovereignty. As governments reduce dependence on hyperscaler-owned collaboration suites for sensitive workloads, providers risk losing eligibility despite sovereign infrastructure credentials. That creates new space for European-owned collaboration and software vendors inside public-sector ICT stacks.

European providers can use local control to challenge hyperscalers in selected segments. That advantage only holds when it is supported by credible delivery capacity, scalable services and clear proof of control and isolation.

The Cloud Sovereignty Framework turns ambition into criteria

The Cloud Sovereignty Framework gives buyers a structured way to compare services that previously carried similar sovereign labels but offered very different levels of control.

Cloud Sovereignty Framework: eight sovereignty objectives, five SEAL assurance levels and the timeline to the CADA proposal
Eight sovereignty objectives with fixed weights, five assurance levels, and the path from CSF v1.2.1 to the CADA proposal. Source: Frenus analysis.

SEAL levels act as qualification thresholds. A strong result in one area cannot compensate for unresolved foreign-law exposure, opaque subcontracting or limited operational autonomy elsewhere. That changes the conversation between buyers and providers: sovereignty has to be explained across the complete service chain, not through data residency or the location of a legal entity alone.

The Commission's own application of the framework confirms that sovereignty does not require every technology component to originate in Europe. European operations and ownership can be combined with selected non-European technologies, provided the remaining dependencies are transparent and compatible with the required assurance level. This creates a pragmatic route for alliances between European operators and global technology providers, and it makes the division of control inside those alliances commercially decisive.

Credibility will depend on verification. The market broadly supports more measurable sovereignty, but questions remain about the distinction between genuine operational control and repackaged conventional cloud services. Providers will need auditable evidence covering privileged access, encryption, operational processes, supply chains, resilience and exit mechanisms. From our discussions, the strongest concern is not the absence of sovereignty claims. It is the lack of clarity over what those claims mean at individual service and technology-layer level.

How member states, European cloud providers, industry associations and digital rights groups read the Cloud Sovereignty Framework
Reception is constructive rather than negative, with the debate centred on whether the scoring is strict and auditable enough. Source: Frenus analysis.

Germany: portability, architecture and operational demand

Germany's implementation of the EU Data Act moves sovereignty beyond initial provider selection. The ability to switch services and continue operations elsewhere becomes part of the control model. Providers must reduce technical, contractual and organisational barriers to migration and support clearer data export and transition processes.

Germany moves EU Data Act rules into enforcement, making cloud portability a procurement and compliance issue
From the EU Data Act to national enforcement: provider lock-in becomes legally exposed from 2026 and commercially harder from 2027. Source: Frenus analysis.

For hyperscalers, the pressure shifts from contractual assurances to demonstrable exit readiness. Offerings will increasingly need to preserve workload continuity beyond proprietary control points and reduce dependence on closed managed-service layers. Future sourcing decisions are therefore likely to test whether workloads can be re-established elsewhere within a defined transition period.

D-Stack creates common market-entry conditions

Germany's D-Stack is not intended to become one centrally operated national cloud. It defines the technical boundary conditions under which services can be reused across federal, state and municipal administrations. Once a service meets these common standards and connects to shared identity and data structures, it can be deployed across several administrations with fewer authority-specific adjustments.

Germany's Federal Modernization Agenda and D-Stack milestones from 2025 to 2028
The Federal Modernization Agenda has shifted from sovereignty targets to D-Stack standards, cloud procurement and first sovereign workplace rollouts. Source: Frenus analysis.

During joint projects we learned that providers view this standardisation as both an opportunity and a challenge. Repeatable solutions can scale across administrations, while isolated offerings may struggle to move beyond individual lighthouse projects.

The first sovereign workplace, administrative cloud and federal AI deployments will do more than create demand. They will establish reference architectures and operating requirements that later procurements are likely to reuse. Their scalability will be decided below the infrastructure layer: identity continuity and specialist application compatibility must be maintained while legacy and sovereign environments operate in parallel.

The near-term opportunity lies in industrialising the transition through standard migration waves. Suitable applications can move first, while critical legacy services remain stable until their dependencies are resolved. Public-sector scale will be demonstrated when the same onboarding and control model can be operated across multiple authorities. A successful lighthouse project without a repeatable deployment model will have limited value.

Our takeaways

  • No single European market. Common European criteria will increasingly shape eligibility, while national programmes determine the actual architecture, partners and addressable workloads.
  • Sovereignty is a portfolio-management question. In continuous workshops with ICT providers, the immediate task is to identify which services already meet emerging thresholds and which need a different operating model or partnership before procurement requirements harden.
  • The economics change, not just the eligibility. CADA and the CSF will reshape portfolio economics and investment priorities. They increase the value of offerings and partnerships that close specific control gaps without creating new dependencies elsewhere in the stack.
  • Proof beats positioning. We expect the strongest positions to come from providers that can show where the sovereign boundary sits and how it works in practice. Tested delivery patterns with evidenced scalability from comparable public-sector environments will become a major deciding factor.

The market has passed the point where a sovereignty claim was a positioning choice. What matters now is whether the control model behind each service survives an audit, and whether it can be repeated across the next twenty procurements rather than demonstrated once.

About Frenus

We are a market intelligence firm based in Stuttgart. We work with ICT providers and investors on the questions that decide market access: where a portfolio stands against emerging requirements, which submarkets are genuinely addressable, and what a competitor can actually prove. Every two weeks we track this debate with our community in the Cloud Insights and Sovereignty edition.

Talk it through

Marcel Blume leads our market advisory work with ICT providers. He is happy to walk through what the emerging requirements mean for a specific portfolio.

Marcel Blume, Director Market Advisory
Frenus GmbH, Zettachring 8, 70567 Stuttgart
[email protected]
+49 711 99529 610
Book a call

What We Have Learned