The EU Cloud Sovereignty Framework, Explained (2026 Guide)
What the European Commission's eight-objective Cloud Sovereignty Framework actually scores, why an EU region is not sovereignty, and how buyers should use it.
EuropeanStack Editorial·
European cloud procurement acquired a scoring system in October 2025. Alongside a €180 million sovereign cloud tender, the European Commission established a Cloud Sovereignty Framework that rates providers across eight objectives, among them legal jurisdiction, operational control, and supply-chain transparency. That structure matters well beyond the tender it was written for, because it turns "sovereign" from an adjective into a set of questions with checkable answers. This guide covers what the framework measures, why an EU region on an American cloud scores differently from an EU-owned provider, and how a private buyer can borrow the structure without running a public tender.
What Is the EU Cloud Sovereignty Framework?
The Cloud Sovereignty Framework is a scoring model the European Commission established in October 2025, alongside a €180 million sovereign cloud procurement tender, which assesses providers against eight objectives rather than a single pass-or-fail test. Its immediate job was ranking bids. The wider effect is a shared vocabulary that vendors now have to answer in, including well outside public procurement.
Two developments frame it. In November 2025, all 27 EU member states signed a declaration affirming a shared ambition to strengthen Europe's digital sovereignty and reduce strategic dependencies. A proposed Cloud and AI Development Act (CADA) would go further, strengthening Europe's cloud and AI capacity and setting a common sovereignty framework across the bloc.
Worth stating plainly: the framework is not a law, and it bans nothing. Buyers outside public procurement can ignore it entirely. Its value is narrower and more practical — this is the first widely referenced attempt to separate the things that "sovereign cloud" marketing routinely blends together.
What Do the Eight Objectives Actually Measure?
The objectives measure control rather than location — which legal system can compel access, who operates the environment day to day, and what the provider itself depends on. Where the bytes sit is one input among several, not the answer.
Three of the eight carry most of the weight for a buyer reading a vendor claim:
| Objective | The question it asks | What a weak answer looks like |
|---|---|---|
| Legal jurisdiction | Which country's legal process can reach this provider and the data it holds? | "Our data centres are in the EU" — a geographic answer to a legal question. |
| Operational control | Who administers, supports, and can technically access the environment, and from where? | Support and engineering staffed outside the EU, with nothing committed on the record. |
| Supply-chain transparency | What does the provider itself depend on — hardware, software, subprocessors, and their jurisdictions? | No published subprocessor list, or one that stops at the first tier. |
Each of the three can be verified without the vendor's cooperation, which is what makes them useful to a buyer. Corporate ownership appears in national company registries. Support-team location shows up in job listings, status pages, and incident post-mortems. Subprocessor lists are generally published as a consequence of GDPR obligations, and reading one tells you more about a provider's real dependency graph than any sovereignty landing page will.
Why Does an EU Region on a US Cloud Score Differently?
An EU region operated by a US-controlled company scores well on residency and badly on jurisdiction, because the framework treats those as separate objectives. Data sits in Europe while the operator stays reachable by American legal process, wherever that data happens to sit. Our CLOUD Act guide covers the mechanics; the framework's contribution is to stop the two being scored as one thing.
This is why the large American providers built "sovereign cloud" tiers: EU data boundaries, EU-resident support staff, local trustee or partner structures. These are real engineering commitments, and for plenty of workloads they represent a defensible middle ground. They are also, precisely, risk reduction inside a foreign jurisdiction rather than exit from it. No contractual arrangement changes who ultimately controls the operating company — a distinction our data residency guide works through in detail.
The same logic applies to software one layer up. A European-branded SaaS product owned by a US parent inherits that parent's jurisdiction, which is why every EuropeanStack review verifies ultimate ownership rather than brand headquarters. Our directory stats show how much of the "European" market is US-owned, and the methodology page sets out how that verification works.
How Big Is European Sovereign Cloud in 2026?
Sovereign cloud is growing quickly from a small base. Gartner puts worldwide sovereign cloud spending at roughly $80 billion in 2026. European sovereign cloud spending grows about 83% year over year from a $6.9 billion base in 2025, and the same forecast has it more than tripling between 2025 and 2027.
Now the number that complicates the story. US hyperscalers are collectively investing roughly $600 billion in cloud and AI infrastructure across 2026, a figure that dwarfs Europe's entire sovereign cloud market many times over. Anyone selling European sovereignty as a capacity race is describing something that is not happening. Sovereignty is a procurement and jurisdiction argument instead: a buyer choosing a European provider is choosing whose law applies and who holds the controls, and accepting a narrower service catalogue as the price.
Two commitments show where the European money comes from. France announced in spring 2026 a plan to migrate 2.5 million civil servants from Microsoft to Linux, and the French recovery plan allocated €1.8 billion to cloud sovereignty. Schwarz Gruppe, the German retail group behind Lidl, has invested around €11 billion in STACKIT, the cloud provider it originally built for its own operations. Both figures are substantial in a European frame and modest beside $600 billion. The pattern behind them is consistent: sovereignty spending comes from states and from large enterprises with specific reasons of their own, not yet from a broad market swing.
Which Providers Does the Framework Point Toward?
Providers that score well across all three objectives above tend to be European-owned, European-operated, and open about their supply chain. In practice that means the independent European infrastructure companies rather than the sovereign tiers of American clouds. The main options, each reviewed on this directory:
- Compute and hosting: Hetzner, OVHcloud, Scaleway, IONOS, Exoscale, UpCloud, and STACKIT — compared side by side in our best European cloud hosting roundup.
- Category pages: cloud hosting and object storage list every verified European option with pricing and ownership detail.
- Replacement paths: if you are costing a move, start from EU alternatives to AWS, to Azure, or to Google Cloud.
Honesty about the trade-off belongs here. None of these providers matches AWS, Azure, or Google Cloud on service breadth, managed-service depth, or global region count. Teams that depend on a wide managed catalogue will feel the gap immediately, while teams running ordinary compute, storage, and databases usually will not. That asymmetry, far more than any political argument, decides whether a migration is straightforward or painful.
How Should a Buyer Use the Eight-Objective Idea?
Treat the framework as a questionnaire rather than a score, and ask six questions in order — each filters out a different marketing pattern:
- Who ultimately owns the operating entity, and under which law? Registry filings answer this, not the About page. A non-EU parent means residency at best.
- Who can technically access the environment, and from where? Support, on-call engineering, and third-line escalation all count as access. "EU-only operations" is a commitment worth getting in writing.
- What sits underneath? Ask for the subprocessor list and read to the second tier. European front ends running on American infrastructure are common, and rarely disclosed prominently.
- Who holds the encryption keys? Provider-managed keys protect against theft, not against legal compulsion. Customer-held keys change the answer structurally.
- What happens on exit? Sovereignty without portability is simply a different dependency. Check export formats, egress pricing, and whether leaving is self-service.
- What is the failure mode? Ask what the provider does on receiving a foreign legal demand, and whether it publishes a transparency report. Silence is itself informative.
If you are prioritising: low-sensitivity workloads run fine almost anywhere given sound paperwork. Regulated or long-retention data belongs with a European-owned provider. Data that must sit beyond foreign legal reach needs European ownership or customer-held keys, because neither residency nor a sovereign tier delivers that on its own. Our AI Act guide covers the parallel question for AI systems, where obligations became enforceable in August 2026.
Frequently Asked Questions
Related Reading
- EU data residency: what it actually means — residency, sovereignty, and localisation untangled
- The CLOUD Act explained for EU companies — why ownership beats geography
- The EU AI Act: what became enforceable in August 2026 — the parallel obligations for AI systems
- Migrating off Google Workspace to European tools — the most common first move
- Directory stats — country, category, and ownership breakdowns across the directory