‘Sovereignty’ is a word we borrowed from statecraft: a sovereign country is independent in its decisions. The term ‘Digital Sovereignty’ is a more recent invention that applies to organizations and even individuals.
The European Commission published the EU Cloud Sovereignty Framework (CSF), which breaks sovereignty down into eight objectives:
- SOV-1: Strategic: ownership and governance are controlled, avoiding external dependencies.
- SOV-2: Legal and Jurisdictional: protects against external laws and unauthorized access.
- SOV-3: Data and AI: control and privacy compliance for data and AI models in the cloud.
- SOV-4: Operational: day-to-day cloud administration, management, and support are handled securely from within.
- SOV-5: Supply Chain: protects against vendor lock-in and external bottlenecks.
- SOV-6: Technology Openness: encourages open standards and the freedom to choose technologies.
- SOV-7: Security and Compliance: aligns cloud services with European cybersecurity standards, frameworks, and audit rules.
- SOV-8: Environmental Sustainability: green transition goals and energy-efficient infrastructure practices.
Each objective is rated on the Sovereignty Effectiveness Assurance Level scale, from SEAL-0 to SEAL-4. SEAL-4 means an EU supply chain, from the chips up to the software.
The mechanic I find most interesting is that a provider does not get one SEAL level. It receives eight, and the overall level is the lowest of them. Your weakest objective decides your rating, not your average. Anyone who has ever tuned a storage stack will recognize that logic.
This is no longer a paper exercise. In April, the Commission awarded a sovereign cloud contract worth up to €180 million over six years to four European providers, with SEAL-2 as the minimum bar for eligibility. Sovereignty has become a procurement instrument with money attached. Predictably, one of the awards is already being publicly contested as ‘sovereignty-washing’.
What poured oil on the fire was the ICC case I wrote about last autumn. After the US sanctioned court officials, the chief prosecutor lost access to his Microsoft-hosted mail account, and his bank accounts in the Netherlands were closed. EU banks with US exposure preferred to over-comply rather than take any risk. Microsoft disputes the framing and maintains it never suspended services to the ICC as an organization. For me, the detail of who pressed which button matters far less than the lesson: neither the mail nor the banking depended on a European decision.
In the US, similar discussions have taken place, only with different verbiage. There it is ‘economic security’ and ‘supply chain resilience’, mostly aimed at China, and where Europe says ‘technological sovereignty’, Washington says ‘technological leadership’. Different branding, same substance.
So who benefits and who suffers when sovereignty gains weight in sourcing decisions?
My feeling is that smaller vendors benefit, and I happily include LINBIT in that group. A framework that asks ‘who owns you, whose laws apply, can I operate this without you, and can I read the source?’ rewards exactly the properties a small European open source company has by default. The hyperscalers will feel some headwind, though they are not standing still, and ‘sovereign’ regions run by local operating entities are their answer. Whether that clears a SEAL-3 or SEAL-4 bar is the argument of the next few years.
For LINBIT, the practical point is that our products and services can serve as a building block for a sovereign cloud offering in any bloc. Being open source, we satisfy the technology openness objective outright. Because the source is open, that argument does not stop at the EU border. An MSP in the US or in Asia can make the same case in their own verbiage. An MSP aiming for full SEAL-4 is not held back by choosing LINBIT for its storage stack.