Book an Appointment

Digital Sovereignty in the Cloud

Who decides whether, where, and under which law your systems run? In 2026, digital sovereignty is no longer an abstract debate but a measurable, auditable category.

In May 2025, the Chief Prosecutor of the International Criminal Court (ICC) lost access to his Microsoft Outlook account — not through a cyberattack, but simply as the result of a US sanction. The incident makes one thing clear: digital sovereignty is not a data protection topic but a question of system control — who decides whether, where, and under which law your computations take place? Around 70% of the European cloud market is held by three US hyperscalers, and according to the 2026 Lünendonk study, 57% of DACH companies have no plan B for their outage. With the EU SEAL framework and the BSI criteria catalog C3A v1.0 (April 27, 2026), sovereignty is now objectively assessable and can be anchored as a procurement criterion. This page puts the dimensions, legal situation, assessment grid, and practical approach into context.

The Essentials at a Glance

01

Sovereignty means system control

Digital sovereignty is not settled by GDPR compliance. What matters is who determines whether, where, and under which law your computations take place — across six levers: compute and infrastructure, industrial ecosystems, platforms, standards, value creation, and structural position. Sovereignty does not arise in any single layer, but from the alignment of all of them.

02

The core legal conflict: GDPR vs. CLOUD Act

The GDPR requires that data does not leave EU jurisdiction; the US CLOUD Act allows US authorities to access data held by US-controlled providers — regardless of where it is stored. In June 2025, Microsoft stated before a French court that it could not guarantee sovereignty against the CLOUD Act. A data center in Frankfurt does not resolve this conflict as long as the provider is subject to US law.

03

Maturity levels: SEAL tiers and BSI C3A

The EU SEAL framework defines eight weighted, auditable sovereignty objectives and five tiers — from SEAL 1 (baseline) through SEAL 2 (personal data) and SEAL 3 (critical infrastructure) up to SEAL 5 (national security). The BSI catalog C3A v1.0 of April 27, 2026 operationalizes the framework for Germany with the criteria areas SOV-1 to SOV-6. This makes it possible to objectively assess the sovereignty position of a cloud deployment and to anchor it in tenders.

04

Technical building blocks: key control and a European stack

Encryption only protects if the provider does not hold the keys itself: for sensitive data, customer-held encryption keys instead of a provider KMS are mandatory (C3A SOV-3), complemented by documented exit paths for data and services. At the same time, the EuroStack initiative shows that a European stack genuinely exists — from cloud and compute (OVHcloud, STACKIT, Scaleway) to applications and AI (Mistral, Aleph Alpha).

05

The regulatory framework 2025/2026

The EU declaration on digital sovereignty (late 2025) was followed by the EU Cloud and AI Development Act and, in April 2026, by the SEAL framework together with a cloud sovereignty tender worth €180 million and the BSI C3A v1.0. Sovereignty is thus shifting from a marketing term to an auditable category. Beware of sovereignty washing: “data stays in the EU” is no proof if the provider's registered seat brings the CLOUD Act into play.

06

A practical approach: five steps

First, classify workloads by sovereignty criticality (C3A SOV-1); second, audit a baseline against the criteria areas of law, operations, and supply chain. Third, document exit plans for data and service paths; fourth, anchor SEAL tiers as an award criterion in RFPs — for example SEAL 2 for personal data and SEAL 3 for critical infrastructure. Fifth, establish key control: customer-held encryption keys, and no provider KMS for sensitive data.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

BSI · 2026

C3A – Criteria enabling Cloud Computing Autonomy v1.0

German criteria catalog for cloud sovereignty (SOV-1 to SOV-6), published on April 27, 2026, based on the EU Cloud Sovereignty Framework.

Europäische Union · 2026

EU SEAL Framework / Cloud Sovereignty Tender 2026

Eight weighted, auditable sovereignty objectives with five tiers (SEAL 1–5), combined with a procurement procedure worth €180 million (April 17, 2026).

Atlantic Council · 2026

Digital sovereignty – Europe's declaration of independence?

Analysis of the European sovereignty debate and the concentration of the EU cloud market on a small number of US providers.

Lünendonk · 2026

Lünendonk-Studie 2026

57% of DACH companies have no plan B for the outage of their hyperscaler.

Gartner · 2026

Worldwide Sovereign Cloud IaaS Spending 2026

Puts worldwide spending on sovereign cloud IaaS in 2026 at $80bn (+35.6%).

VamiSec · 2026

VamiSec Live-Webinar: Digitale Souveränität

60-minute live webinar on system control, GDPR vs. CLOUD Act, SEAL/BSI C3A, and a five-step action plan.

Have your cloud sovereignty assessed against BSI C3A

VamiSec assesses your cloud sovereignty along the BSI criteria catalog C3A — complementing established audit baselines such as the BSI C5. Contact us for an assessment of your sovereignty posture.