Cloud usage is based on the shared responsibility model – the provider therefore inevitably makes decisions that can restrict the customer's self-determination. C3A provides a benchmark for this: it defines criteria for assessing whether a cloud offering can be used in a self-determined way in the relevant risk context. The catalogue explicitly positions itself as a guidance framework for establishing transparency and is not binding in itself. Version 1.0 was published on 27 April 2026, initially in English; the BSI has announced a German version.
BSI C3A – Criteria for Cloud Sovereignty
What the new BSI catalogue "Criteria enabling Cloud Computing Autonomy" covers, how the sovereignty criteria SOV-1 to SOV-6 are structured, and how to apply them in provider selection and procurement.
6criteria blocks SOV-1 to SOV-6
90days' advance notice of changes of control (SOV-1)
24hours – maximum age of the source code backup in the EU (SOV-6)
1.0catalogue version, published 27 April 2026 – initially in English
In cloud procurement, digital sovereignty has evolved from a strategic debate into a concretely verifiable requirement. With C3A ("Criteria enabling Cloud Computing Autonomy", version 1.0 of 27 April 2026), the BSI presents for the first time a criteria catalogue that makes the self-determined usability of cloud services assessable against objective, verifiable criteria. The catalogue adopts the structure and objectives of the European Commission's EU Cloud Sovereignty Framework and presupposes fulfilment of the C5 security criteria – sovereignty is thus treated as a complement to, not a replacement for, cloud security. Our knowledge page "Digital Sovereignty" in this topic area explores the conceptual foundations in more depth.
From the EU framework to the BSI catalogue
Key developments at a glance – tap a milestone for details.
Oct 2025
EU Cloud Sovereignty Framework 1.2.1
The European Commission's EU Cloud Sovereignty Framework appears in version 1.2.1. C3A later adopts its structure, objectives and categorisation.
7 Apr 2026
C5:2026 published
The BSI publishes C5:2026, newly incorporating container management, post-quantum cryptography and confidential computing, among other topics. C3A presupposes its fulfilment.
27 Apr 2026
C3A version 1.0
C3A is published, initially in English. The BSI has announced a German version as well as standardised C3A audit processes analogous to the established C5 procedure.
Jul 2026
EUCS still not adopted
The European cloud certification scheme EUCS under the Cybersecurity Act has still not been adopted; the sovereignty requirements discussed in earlier drafts were politically contentious.
The Essentials at a Glance
Six topic blocks — tap to expand.
C3A in context: C5, EU CSF, EUCS
Prerequisite, template, open gap – how the catalogue relates to three frameworks.
- C3A presupposes that the provider fulfils the C5 criteria.
- The security dimension of sovereignty is covered by C5:2026, published on 7 April 2026 – newly incorporating container management, post-quantum cryptography and confidential computing, among other topics.
C5:2026container managementpost-quantum cryptographyconfidential computing
- From the EU Cloud Sovereignty Framework (version 1.2.1, October 2025), C3A adopts the categorisation.
- Two objectives are deliberately omitted: SOV-7 (Security & Compliance) is covered by C5:2026 and IT-Grundschutz, while SOV-8 (environmental sustainability) lies outside the BSI's mandate.
version 1.2.1SOV-7SOV-8IT-Grundschutz
- The European cloud certification scheme under the Cybersecurity Act has still not been adopted (as of July 2026); the sovereignty requirements discussed in earlier drafts were politically contentious.
- C3A and the EU CSF address this gap outside the certification framework.
Cybersecurity Actsovereignty requirements
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
C3A – Criteria enabling Cloud Computing Autonomy, Version 1.0
Primary source dated 27 April 2026: the complete criteria catalogue SOV-1 to SOV-6 with criteria, additional criteria and supplementary guidance (in English).
Cloud Sovereignty Framework, Version 1.2.1
Defines the eight sovereignty objectives SOV-1 to SOV-8, the assurance levels SEAL-0 to SEAL-4 and the weighted Sovereignty Score for the Commission's cloud procurements.
Cloud Computing Compliance Criteria Catalogue (C5:2026)
Security foundation published on 7 April 2026, whose fulfilment C3A presupposes; new additions include container management, post-quantum cryptography and confidential computing.
C3A - Criteria enabling Cloud Computing Autonomy (BSI-Themenseite)
Explains the delineation from SOV-7/SOV-8 and announces standardised C3A audit processes analogous to C5 as well as a German version.
Defining sovereignty requirements for your cloud?
We support you in selecting C3A criteria for your usage scenarios and anchoring them in procurement procedures or provider assessments. Arrange a no-obligation initial consultation.