Digital Sovereignty’s Impact on Open Source Companies

‘Sovereignty’ is a word we borrowed from statecraft: a sovereign country is independent in its decisions. The term ‘Digital Sovereignty’ is a more recent invention that applies to organizations and even individuals.

The European Commission published the EU Cloud Sovereignty Framework (CSF), which breaks sovereignty down into eight objectives:

  • SOV-1: Strategic: ownership and governance are controlled, avoiding external dependencies.
  • SOV-2: Legal and Jurisdictional: protects against external laws and unauthorized access.
  • SOV-3: Data and AI: control and privacy compliance for data and AI models in the cloud.
  • SOV-4: Operational: day-to-day cloud administration, management, and support are handled securely from within.
  • SOV-5: Supply Chain: protects against vendor lock-in and external bottlenecks.
  • SOV-6: Technology Openness: encourages open standards and the freedom to choose technologies.
  • SOV-7: Security and Compliance: aligns cloud services with European cybersecurity standards, frameworks, and audit rules.
  • SOV-8: Environmental Sustainability: green transition goals and energy-efficient infrastructure practices.

 

Each objective is rated on the Sovereignty Effectiveness Assurance Level scale, from SEAL-0 to SEAL-4. SEAL-4 means an EU supply chain, from the chips up to the software.

The mechanic I find most interesting is that a provider does not get one SEAL level. It receives eight, and the overall level is the lowest of them. Your weakest objective decides your rating, not your average. Anyone who has ever tuned a storage stack will recognize that logic.

This is no longer a paper exercise. In April, the Commission awarded a sovereign cloud contract worth up to €180 million over six years to four European providers, with SEAL-2 as the minimum bar for eligibility. Sovereignty has become a procurement instrument with money attached. Predictably, one of the awards is already being publicly contested as ‘sovereignty-washing’.

What poured oil on the fire was the ICC case I wrote about last autumn. After the US sanctioned court officials, the chief prosecutor lost access to his Microsoft-hosted mail account, and his bank accounts in the Netherlands were closed. EU banks with US exposure preferred to over-comply rather than take any risk. Microsoft disputes the framing and maintains it never suspended services to the ICC as an organization. For me, the detail of who pressed which button matters far less than the lesson: neither the mail nor the banking depended on a European decision.

In the US, similar discussions have taken place, only with different verbiage. There it is ‘economic security’ and ‘supply chain resilience’, mostly aimed at China, and where Europe says ‘technological sovereignty’, Washington says ‘technological leadership’. Different branding, same substance.

So who benefits and who suffers when sovereignty gains weight in sourcing decisions?

My feeling is that smaller vendors benefit, and I happily include LINBIT in that group. A framework that asks ‘who owns you, whose laws apply, can I operate this without you, and can I read the source?’ rewards exactly the properties a small European open source company has by default. The hyperscalers will feel some headwind, though they are not standing still, and ‘sovereign’ regions run by local operating entities are their answer. Whether that clears a SEAL-3 or SEAL-4 bar is the argument of the next few years.

For LINBIT, the practical point is that our products and services can serve as a building block for a sovereign cloud offering in any bloc. Being open source, we satisfy the technology openness objective outright. Because the source is open, that argument does not stop at the EU border. An MSP in the US or in Asia can make the same case in their own verbiage. An MSP aiming for full SEAL-4 is not held back by choosing LINBIT for its storage stack.

Picture of Philipp Reisner

Philipp Reisner

Philipp Reisner is founder and CEO of LINBIT in Vienna/Austria. His professional career has been dominated by developing DRBD, a storage replication for Linux. Today he leads a company of about 30 employees with locations in Vienna, Austria and Portland, Oregon.

Talk to us

LINBIT is committed to protecting and respecting your privacy, and we’ll only use your personal information to administer your account and to provide the products and services you requested from us. From time to time, we would like to contact you about our products and services, as well as other content that may be of interest to you. If you consent to us contacting you for this purpose, please tick above to say how you would like us to contact you.

You can unsubscribe from these communications at any time. For more information on how to unsubscribe, our privacy practices, and how we are committed to protecting and respecting your privacy, please review our Privacy Policy.

By clicking submit below, you consent to allow LINBIT to store and process the personal information submitted above to provide you the content requested.

Talk to us

LINBIT is committed to protecting and respecting your privacy, and we’ll only use your personal information to administer your account and to provide the products and services you requested from us. From time to time, we would like to contact you about our products and services, as well as other content that may be of interest to you. If you consent to us contacting you for this purpose, please tick above to say how you would like us to contact you.

You can unsubscribe from these communications at any time. For more information on how to unsubscribe, our privacy practices, and how we are committed to protecting and respecting your privacy, please review our Privacy Policy.

By clicking submit below, you consent to allow LINBIT to store and process the personal information submitted above to provide you the content requested.