EU CSF: Assessing Cloud Sovereignty

The European Commission’s Directorate-General for Digital Services developed the Cloud Sovereignty Framework to assess cloud services in procurement. The published framework is version 1.2.1, October 2025; implementation guidance followed on 1 June 2026. It examines who controls a service, which jurisdictions affect it, and which external dependencies it needs.

Assessment

Eight objectives cover strategic, legal and jurisdictional, data and AI, operational, supply chain, technology, security and compliance, and environmental concerns (framework, section 2).

The assessment has two results:

  • Sovereignty Effectiveness Assurance Level (SEAL): levels 0–4 express the degree of sovereignty. The contracting authority sets the minimum; the overall level is the lowest achieved across the objectives.
  • Sovereignty score: a weighted score compares offers that meet the required SEAL.

The June 2026 guidance explains this distinction on pages 9–11. Its assessment extends to subcontractors, suppliers, and technical layers, rather than stopping at the bidding company (pages 12–13).

BSI C3A turns parts of these objectives into more detailed criteria for cloud autonomy.

Quality Attributes Addressed

The following mappings refer to section 4 of the framework.

Attribute How EU CSF addresses it
Data Sovereignty SOV-2 examines exposure to foreign authority; SOV-3 examines customer control over cryptographic access.
Data Residency SOV-3 assesses confinement of storage and processing to European jurisdictions.
Portability SOV-4 assesses migration of workloads to alternative EU-controlled solutions.
Compliance SOV-7 assesses adherence to EU rules and evidence from certifications.

References

Official Sources