Cloud sovereignty moved in 2026 from a matter of principle to a public procurement award criterion and a regulatory obligation.
Since April 2026, the European Commission has had an operational Cloud Sovereignty Framework: 48 criteria, grouped into 8 sovereignty objectives, scored on a maturity scale called SEAL (Sovereignty Effectiveness Assurance Level, from SEAL-0 to SEAL-4).
The Cloud Sovereignty Framework: 48 criteria, 8 objectives
This framework evaluates cloud providers against eight sovereignty objectives, each weighted differently: supply chain (20%), strategic (15%), operational (15%), technological (15%), legal & jurisdictional (10%), data & AI (10%), security & compliance (10%), and environmental sustainability (5%).
The supply chain carries more weight than the legal location of data alone — a clear signal to providers who host in Europe without controlling the underlying hardware or software.
What the first €180M contract teaches us
In April 2026, the European Commission awarded a six-year, €180 million framework contract to four winners evaluated against this reference framework.
The S3NS case — a joint venture between Thales and Google Cloud, selected with a SEAL-2 rating only — shows that a local partnership isn't enough to qualify an offer as "sovereign" if the underlying technology remains controlled by a non-European player.
Key takeaways
- Know, for each critical cloud provider, under which jurisdiction it is really governed
- Document the hardware and software supply chain
- Verify contractual and technical reversibility in under six months
- Test a regional loss or provider failure scenario at least once a year
- Be able to state your SEAL level across the eight sovereignty objectives



