Cloud Sovereignty Framework

How sovereign is your cloud?

Measure your digital sovereignty against the European Commission's Cloud Sovereignty Framework. Start with the 2-minute quick check, or go deep with the full assessment. Either way you'll get your Sovereignty Score, your SEAL assurance level, and exactly what is holding it back.

Quick check 0 / 16 answered
Quick exposure check Two questions per objective For each of the framework's eight objectives: what typically describes you, then where your weakest link sits. Both are needed because the framework scores the average but sets your assurance level from the worst answer. Want per-criterion depth? Switch to the full assessment above.
SOV-1 · Strategic Sovereignty
Typical posture

Where do ownership, control and roadmap influence over your primary provider sit?

Weakest link

If access to the underlying technology were cut off tomorrow, and thinking about who really decides the roadmap — what is the weakest statement still true of you?

SOV-2 · Legal & Jurisdictional Sovereignty
Typical posture

How insulated is your provider from non-EU law (e.g. the US CLOUD Act) and from export-control measures?

Weakest link

The decisive test: could a non-EU authority compel access, and is your contract exclusively under EU law?

SOV-3 · Data & AI Sovereignty
Typical posture

How much control do you have over your data — its keys, its location, its deletion and its access logs?

Weakest link

At your weakest point on data — keys, residency, deletion and logs — what is still true?

SOV-4 · Operational Sovereignty
Typical posture

Could EU teams run, support and exit the service without a non-EU vendor?

Weakest link

Where does a non-EU dependency still remain in running, supporting or exiting the service?

SOV-5 · Supply Chain Sovereignty
Typical posture

How EU-controlled and transparent is the hardware, firmware and software supply chain?

Weakest link

At the least transparent point in your supply chain, what is still true?

SOV-6 · Technology Sovereignty
Typical posture

How open, auditable and lock-in-free is the technology stack?

Weakest link

Where does proprietary lock-in or opacity still remain in the stack?

SOV-7 · Security & Compliance Sovereignty
Typical posture

How EU-controlled are certification, security operations and audit rights? (This asks where your provider's security operations centre and incident response sit — not which regulations apply to you.)

Weakest link

On audit rights and incident handling — the two criteria the framework is strictest about — what is still true?

SOV-8 · Environmental Sustainability
Typical posture

How efficient, circular and transparently reported is the infrastructure?

Weakest link

On the least-measured part of your environmental footprint, what is still true?