01Objective: making autonomy measurable
Cloud usage is based on the shared responsibility model – the provider therefore inevitably makes decisions that can restrict the customer's self-determination. C3A provides a benchmark for this: it defines criteria for assessing whether a cloud offering can be used in a self-determined way in the relevant risk context. The catalogue explicitly positions itself as a guidance framework for establishing transparency and is not binding in itself. Version 1.0 was published on 27 April 2026, initially in English; the BSI has announced a German version.
02Structure: six criteria blocks SOV-1 to SOV-6
The catalogue is organised into six blocks: SOV-1 Strategic sovereignty (jurisdiction, corporate seat, effective control, 90-day advance notice of changes of control), SOV-2 Legal and jurisdictional sovereignty (including an annual risk assessment of extraterritorial non-EU laws and audit rights for authorities), SOV-3 Data sovereignty (data residency options EU/Germany, external key management, client-side encryption, external identity providers), SOV-4 Operational sovereignty (EU operations staff, a SOC in the EU or Germany, disconnect/reconnect capability with disconnect tests at least annually), SOV-5 Supply chain sovereignty (disclosure of software dependencies based on SBOMs as well as of hardware and service dependencies) and SOV-6 Technology sovereignty (including a source code backup in the EU no older than 24 hours). The catalogue distinguishes between criteria, optional additional criteria and supplementary guidance; many criteria exist in an EU variant and a stricter Germany variant.
03Application in procurement and provider selection
Cloud customers use C3A to select the relevant criteria for each usage scenario and thereby define their own sovereignty baseline – for example as verifiable requirements in specifications or provider assessments. The EU Cloud Sovereignty Framework shows how this can work in procurement: there, the assurance levels SEAL-0 to SEAL-4 serve as minimum requirements per sovereignty objective (offers below them are excluded) and a weighted Sovereignty Score serves as an award criterion. At the same time, the BSI points out that restricting procurement procedures to EU or Germany variants must be justified and legally permissible, for example on grounds of public security.
04Self-declaration vs. independent audit
A standardised attestation procedure like the one for C5 does not yet exist for C3A: the BSI has announced standardised C3A audit processes and report usage analogous to the established C5 procedure. The catalogue itself provides for providers to demonstrate fulfilment of selected criteria through evidence in the course of an audit. In the EU Cloud Sovereignty Framework, by contrast, the assessment rests on bidders' statements, supporting evidence and public documentation – in effect a structured self-declaration evaluated by the contracting authority. Until reliable C3A audit reports become available, you should consistently cross-check self-declarations against existing evidence such as C5 attestations or SOC 2 reports.
05Relationship to C5, EU CSF and EUCS
C3A presupposes that the provider fulfils the C5 criteria – the security dimension of sovereignty is covered by C5:2026, published on 7 April 2026, which newly incorporates container management, post-quantum cryptography and confidential computing, among other topics. From the EU Cloud Sovereignty Framework (version 1.2.1, October 2025), C3A adopts the categorisation but deliberately omits two objectives: SOV-7 (Security & Compliance) is covered by C5:2026 and IT-Grundschutz, while SOV-8 (environmental sustainability) lies outside the BSI's mandate. The European cloud certification scheme EUCS under the Cybersecurity Act, by contrast, has still not been adopted (as of July 2026); the sovereignty requirements discussed in earlier drafts were politically contentious. C3A and the EU CSF address this gap outside the certification framework.
06Limitations of the catalogue
C3A is neither a law nor a certificate: it only takes effect once customers or contracting authorities anchor the criteria contractually. An established audit and attestation procedure is still lacking, so provider statements can for now only be independently validated to a limited extent. The catalogue also deliberately refrains from a binary "sovereign" label – which criteria and additional criteria apply depends on the usage scenario and risk context and requires your own requirements analysis. Cloud security itself and sustainability aspects are not covered by C3A; it refers to C5:2026 and other frameworks instead.