How sovereign is
your cloud, really?
Score your cloud estate against the European Commission's Cloud Sovereignty Framework — the eight sovereignty objectives and official scoring weights the EU now uses to award sovereign-cloud contracts. Four minutes, no email needed for your score.
Eight objectives. Brussels' rubric, not ours.
Every question below maps to a contributing factor in the Commission's framework (v1.2.1, Oct 2025) — the same criteria behind the EU institutions' €180M sovereign-cloud procurement. Answer for your organisation's current estate, not the one you're planning.
Cloud sovereignty, explained
The framework, the SEAL levels, and what your score actually means — the questions we get before and after the assessment.
01 What is a sovereign cloud?
A sovereign cloud is cloud infrastructure that remains under the legal, operational, and technological control of a specific jurisdiction — for European organisations, the EU. In practice it means:
- EU law governs the service — and is enforceable, not just formally applicable
- non-EU authorities cannot compel access to data or systems
- EU actors can run, support, and evolve the platform without foreign vendors
- the technology stack is open enough to audit — and to leave
Data residency alone does not make a cloud sovereign: data stored in an EU region of a non-EU hyperscaler remains subject to that provider’s home jurisdiction.
02 What is the EU Cloud Sovereignty Framework?
The Cloud Sovereignty Framework is published by the European Commission’s Directorate-General for Digital Services (version 1.2.1, October 2025). It defines eight sovereignty objectives — strategic, legal and jurisdictional, data and AI, operational, supply chain, technology, security and compliance, and environmental sustainability — assessed through 48 specific criteria, and assigns Sovereignty Effectiveness Assurance Levels (SEAL) per objective. The Commission first applied it in the EU institutions’ €180 million sovereign-cloud procurement, and it is becoming the de facto benchmark for evaluating cloud sovereignty in Europe.
03 What are the eight sovereignty objectives?
The Commission’s framework groups its 48 criteria under eight objectives, each with an official weight in the Sovereignty Score:
- SOV-1 Strategic Sovereignty (15%) — where decisive authority, ownership, and financing sit
- SOV-2 Legal & Jurisdictional Sovereignty (10%) — exposure to non-EU law such as the US CLOUD Act
- SOV-3 Data & AI Sovereignty (10%) — cryptographic control and EU-confined processing
- SOV-4 Operational Sovereignty (15%) — whether EU actors can run and evolve the service without foreign involvement
- SOV-5 Supply Chain Sovereignty (20%, the highest weight) — provenance of hardware, firmware, and software
- SOV-6 Technology Sovereignty (15%) — open standards, open licensing, freedom from vendor lock-in
- SOV-7 Security & Compliance Sovereignty (10%) — EU-controlled security operations and audits
- SOV-8 Environmental Sustainability (5%) — energy efficiency, circularity, and disclosure
04 What are SEAL levels?
SEAL — Sovereignty Effectiveness Assurance Level — is the framework’s five-step scale, assigned per objective:
- SEAL-0 · No sovereignty — exclusive non-EU control
- SEAL-1 · Jurisdictional sovereignty — EU law formally applies, with limited practical enforceability
- SEAL-2 · Data sovereignty — EU law enforceable, but material non-EU dependencies remain
- SEAL-3 · Digital resilience — meaningful EU influence, with marginal non-EU control
- SEAL-4 · Full digital sovereignty — complete EU control, subject only to EU law
A provider does not have one SEAL level — it has eight, one per objective, and EU tenders set a minimum level per objective.
05 How is a cloud Sovereignty Score calculated?
The Commission’s formula is a weighted sum: each objective’s score, as a fraction of its maximum, is multiplied by the objective’s official weight, and the results are added into a percentage. The weights are:
- Supply chain — 20%
- Strategic, operational, and technology — 15% each
- Legal & jurisdictional, data & AI, and security & compliance — 10% each
- Environmental sustainability — 5%
In EU procurement the score ranks bids that have already cleared minimum SEAL thresholds — failing one threshold rejects the bid regardless of the total score.
06 How can I assess my organisation’s cloud sovereignty?
The assessment on this page is a free 16-question self-assessment against the Commission’s framework: two questions per objective, each mapped to the framework’s published contributing factors. It takes about four minutes and produces an instant scorecard — a 0–10 score and readiness band per objective, plus an overall Sovereignty Score computed with the Commission’s official weights — without requiring an email address. A facilitated workshop covering the full 48-criteria questionnaire is available for organisations that need a procurement-grade answer.
07 Is this an official SEAL rating?
No — and this tool deliberately does not assign SEAL levels at all. The Commission determines SEAL holistically per procurement, from evidence and material weaknesses across the full 48-criteria questionnaire; it is not derived from a numeric score. What you get here instead:
- The Commission's own material — the eight objectives, their contributing factors, and the official scoring weights behind the Sovereignty Score
- Stakater's own material — the 0–10 score per objective and the readiness band it falls into, on published thresholds (0–1 Band 0, 2–4 Band 1, 5–7 Band 2, 8–9 Band 3, 10 Band 4)
Treat the result as a gap-finding aid, not a certification or a prediction of how a contracting authority would rate you.
08 Why does the US CLOUD Act matter for cloud sovereignty?
The US CLOUD Act allows US authorities to compel US-headquartered providers to produce data in their possession regardless of where it is stored — an EU data centre does not shield data held by a US provider. The Commission’s framework treats this as a core legal-sovereignty question (SOV-2): it assesses the degree of exposure to non-EU laws with cross-border reach and the existence of channels through which non-EU authorities could compel access. Mitigations include EU-contracted providers with no non-EU nexus and customer-held encryption keys.
09 How do I improve a low sovereignty score?
It depends on which objective is weakest:
- Legal gaps need EU-contracted providers and jurisdictional review — technology cannot fix a legal nexus
- Technology and operational gaps are addressed by an EU-operable platform built on open standards — a control plane running VMs and Kubernetes in open, portable formats on infrastructure you own, such as Stakater Cloud Orchestrator, removes foreign operational dependency and vendor lock-in
- Supply-chain gaps need provenance requirements and audit rights in procurement
- Data gaps need customer-held encryption keys and technically enforced EU confinement
- Sustainability gaps are solved at the data-centre level — renewable-powered facilities and measured efficiency targets
Get the full 48-criteria picture.
A facilitated sovereignty workshop: we assess your estate against the complete Commission framework and hand you a prioritised remediation roadmap.