Book an Appointment

BSI C3A – Criteria for Cloud Sovereignty

What the new BSI catalogue "Criteria enabling Cloud Computing Autonomy" covers, how the sovereignty criteria SOV-1 to SOV-6 are structured, and how to apply them in provider selection and procurement.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

6criteria blocks SOV-1 to SOV-6
90days' advance notice of changes of control (SOV-1)
24hours – maximum age of the source code backup in the EU (SOV-6)
1.0catalogue version, published 27 April 2026 – initially in English

In cloud procurement, digital sovereignty has evolved from a strategic debate into a concretely verifiable requirement. With C3A ("Criteria enabling Cloud Computing Autonomy", version 1.0 of 27 April 2026), the BSI presents for the first time a criteria catalogue that makes the self-determined usability of cloud services assessable against objective, verifiable criteria. The catalogue adopts the structure and objectives of the European Commission's EU Cloud Sovereignty Framework and presupposes fulfilment of the C5 security criteria – sovereignty is thus treated as a complement to, not a replacement for, cloud security. Our knowledge page "Digital Sovereignty" in this topic area explores the conceptual foundations in more depth.

From the EU framework to the BSI catalogue

Key developments at a glance – tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

C3A in context: C5, EU CSF, EUCS

Prerequisite, template, open gap – how the catalogue relates to three frameworks.

Prerequisite
  • C3A presupposes that the provider fulfils the C5 criteria.
  • The security dimension of sovereignty is covered by C5:2026, published on 7 April 2026 – newly incorporating container management, post-quantum cryptography and confidential computing, among other topics.
C5:2026container managementpost-quantum cryptographyconfidential computing

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

C3A – Criteria enabling Cloud Computing Autonomy, Version 1.0

Primary source dated 27 April 2026: the complete criteria catalogue SOV-1 to SOV-6 with criteria, additional criteria and supplementary guidance (in English).

Europäische Kommission, Generaldirektion Digitale Dienste · 2025

Cloud Sovereignty Framework, Version 1.2.1

Defines the eight sovereignty objectives SOV-1 to SOV-8, the assurance levels SEAL-0 to SEAL-4 and the weighted Sovereignty Score for the Commission's cloud procurements.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Cloud Computing Compliance Criteria Catalogue (C5:2026)

Security foundation published on 7 April 2026, whose fulfilment C3A presupposes; new additions include container management, post-quantum cryptography and confidential computing.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

C3A - Criteria enabling Cloud Computing Autonomy (BSI-Themenseite)

Explains the delineation from SOV-7/SOV-8 and announces standardised C3A audit processes analogous to C5 as well as a German version.

Defining sovereignty requirements for your cloud?

We support you in selecting C3A criteria for your usage scenarios and anchoring them in procurement procedures or provider assessments. Arrange a no-obligation initial consultation.