EU CSF: Assessing Cloud Sovereignty
The European Commission’s Directorate-General for Digital Services developed the Cloud Sovereignty Framework to assess cloud services in procurement. The published framework is version 1.2.1, October 2025; implementation guidance followed on 1 June 2026. It examines who controls a service, which jurisdictions affect it, and which external dependencies it needs.
Assessment
Eight objectives cover strategic, legal and jurisdictional, data and AI, operational, supply chain, technology, security and compliance, and environmental concerns (framework, section 2).
The assessment has two results:
- Sovereignty Effectiveness Assurance Level (SEAL): levels 0–4 express the degree of sovereignty. The contracting authority sets the minimum; the overall level is the lowest achieved across the objectives.
- Sovereignty score: a weighted score compares offers that meet the required SEAL.
The June 2026 guidance explains this distinction on pages 9–11. Its assessment extends to subcontractors, suppliers, and technical layers, rather than stopping at the bidding company (pages 12–13).
BSI C3A turns parts of these objectives into more detailed criteria for cloud autonomy.
Quality Attributes Addressed
The following mappings refer to section 4 of the framework.
| Attribute | How EU CSF addresses it |
|---|---|
| Data Sovereignty | SOV-2 examines exposure to foreign authority; SOV-3 examines customer control over cryptographic access. |
| Data Residency | SOV-3 assesses confinement of storage and processing to European jurisdictions. |
| Portability | SOV-4 assesses migration of workloads to alternative EU-controlled solutions. |
| Compliance | SOV-7 assesses adherence to EU rules and evidence from certifications. |