Book an Appointment

BSI C3A – Criteria for Cloud Sovereignty

What the new BSI catalogue "Criteria enabling Cloud Computing Autonomy" covers, how the sovereignty criteria SOV-1 to SOV-6 are structured, and how to apply them in provider selection and procurement.

In cloud procurement, digital sovereignty has evolved from a strategic debate into a concretely verifiable requirement. With C3A ("Criteria enabling Cloud Computing Autonomy", version 1.0 of 27 April 2026), the BSI presents for the first time a criteria catalogue that makes the self-determined usability of cloud services assessable against objective, verifiable criteria. The catalogue adopts the structure and objectives of the European Commission's EU Cloud Sovereignty Framework and presupposes fulfilment of the C5 security criteria – sovereignty is thus treated as a complement to, not a replacement for, cloud security. Our knowledge page "Digital Sovereignty" in this topic area explores the conceptual foundations in more depth.

The Essentials at a Glance

01

Objective: making autonomy measurable

Cloud usage is based on the shared responsibility model – the provider therefore inevitably makes decisions that can restrict the customer's self-determination. C3A provides a benchmark for this: it defines criteria for assessing whether a cloud offering can be used in a self-determined way in the relevant risk context. The catalogue explicitly positions itself as a guidance framework for establishing transparency and is not binding in itself. Version 1.0 was published on 27 April 2026, initially in English; the BSI has announced a German version.

02

Structure: six criteria blocks SOV-1 to SOV-6

The catalogue is organised into six blocks: SOV-1 Strategic sovereignty (jurisdiction, corporate seat, effective control, 90-day advance notice of changes of control), SOV-2 Legal and jurisdictional sovereignty (including an annual risk assessment of extraterritorial non-EU laws and audit rights for authorities), SOV-3 Data sovereignty (data residency options EU/Germany, external key management, client-side encryption, external identity providers), SOV-4 Operational sovereignty (EU operations staff, a SOC in the EU or Germany, disconnect/reconnect capability with disconnect tests at least annually), SOV-5 Supply chain sovereignty (disclosure of software dependencies based on SBOMs as well as of hardware and service dependencies) and SOV-6 Technology sovereignty (including a source code backup in the EU no older than 24 hours). The catalogue distinguishes between criteria, optional additional criteria and supplementary guidance; many criteria exist in an EU variant and a stricter Germany variant.

03

Application in procurement and provider selection

Cloud customers use C3A to select the relevant criteria for each usage scenario and thereby define their own sovereignty baseline – for example as verifiable requirements in specifications or provider assessments. The EU Cloud Sovereignty Framework shows how this can work in procurement: there, the assurance levels SEAL-0 to SEAL-4 serve as minimum requirements per sovereignty objective (offers below them are excluded) and a weighted Sovereignty Score serves as an award criterion. At the same time, the BSI points out that restricting procurement procedures to EU or Germany variants must be justified and legally permissible, for example on grounds of public security.

04

Self-declaration vs. independent audit

A standardised attestation procedure like the one for C5 does not yet exist for C3A: the BSI has announced standardised C3A audit processes and report usage analogous to the established C5 procedure. The catalogue itself provides for providers to demonstrate fulfilment of selected criteria through evidence in the course of an audit. In the EU Cloud Sovereignty Framework, by contrast, the assessment rests on bidders' statements, supporting evidence and public documentation – in effect a structured self-declaration evaluated by the contracting authority. Until reliable C3A audit reports become available, you should consistently cross-check self-declarations against existing evidence such as C5 attestations or SOC 2 reports.

05

Relationship to C5, EU CSF and EUCS

C3A presupposes that the provider fulfils the C5 criteria – the security dimension of sovereignty is covered by C5:2026, published on 7 April 2026, which newly incorporates container management, post-quantum cryptography and confidential computing, among other topics. From the EU Cloud Sovereignty Framework (version 1.2.1, October 2025), C3A adopts the categorisation but deliberately omits two objectives: SOV-7 (Security & Compliance) is covered by C5:2026 and IT-Grundschutz, while SOV-8 (environmental sustainability) lies outside the BSI's mandate. The European cloud certification scheme EUCS under the Cybersecurity Act, by contrast, has still not been adopted (as of July 2026); the sovereignty requirements discussed in earlier drafts were politically contentious. C3A and the EU CSF address this gap outside the certification framework.

06

Limitations of the catalogue

C3A is neither a law nor a certificate: it only takes effect once customers or contracting authorities anchor the criteria contractually. An established audit and attestation procedure is still lacking, so provider statements can for now only be independently validated to a limited extent. The catalogue also deliberately refrains from a binary "sovereign" label – which criteria and additional criteria apply depends on the usage scenario and risk context and requires your own requirements analysis. Cloud security itself and sustainability aspects are not covered by C3A; it refers to C5:2026 and other frameworks instead.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

C3A – Criteria enabling Cloud Computing Autonomy, Version 1.0

Primary source dated 27 April 2026: the complete criteria catalogue SOV-1 to SOV-6 with criteria, additional criteria and supplementary guidance (in English).

Europäische Kommission, Generaldirektion Digitale Dienste · 2025

Cloud Sovereignty Framework, Version 1.2.1

Defines the eight sovereignty objectives SOV-1 to SOV-8, the assurance levels SEAL-0 to SEAL-4 and the weighted Sovereignty Score for the Commission's cloud procurements.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Cloud Computing Compliance Criteria Catalogue (C5:2026)

Security foundation published on 7 April 2026, whose fulfilment C3A presupposes; new additions include container management, post-quantum cryptography and confidential computing.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

C3A - Criteria enabling Cloud Computing Autonomy (BSI-Themenseite)

Explains the delineation from SOV-7/SOV-8 and announces standardised C3A audit processes analogous to C5 as well as a German version.

Defining sovereignty requirements for your cloud?

We support you in selecting C3A criteria for your usage scenarios and anchoring them in procurement procedures or provider assessments. Arrange a no-obligation initial consultation.