"Sovereign" has become a sales word. Any provider with a data centre in Frankfurt or Amsterdam puts it on the website, and most of them mean nothing more by it than that the servers sit in Europe.
Choosing a sovereign cloud means assessing a provider across eight measurable dimensions, from legal jurisdiction to supply chain, rather than on where the data centre happens to be. An official framework for this has existed since October 2025, and it has been applied in practice since April 2026. You can lift those criteria straight into your own procurement.
This guide turns that framework into the questions you put to a provider, and into what you write down before you sign.
What does sovereign actually mean?
The European Commission turned the term into a scale. The Cloud Sovereignty Framework defines Sovereignty Effectiveness Assurance Levels, shortened to SEAL, running from SEAL-0 to SEAL-4. Providers are scored per dimension rather than as a whole. That is what makes the framework usable: you see where a provider is strong and where it is not, instead of accepting one word that covers everything.
| Level | What it means in practice |
|---|---|
| SEAL-0 | No demonstrable sovereignty |
| SEAL-1 | Limited guarantees, usually data location only |
| SEAL-2 | Minimum to bid in the EU tender |
| SEAL-3 | The level most awarded European providers reached |
| SEAL-4 | Full EU supply chain, from chips to software |
The eight dimensions cover strategic, legal, operational and environmental considerations, plus supply chain transparency, technological openness, security, and compliance with EU law. That last group is where most "sovereign" offerings run aground: the servers are in the EU, but the management software, the support organisation or the parent company is not.
Note what SEAL-4 means in practice. A complete EU chain including chips is out of reach for almost everyone today. That is no reason to ignore the level. It is a reason to press anyone who claims it.
Why you can borrow the Commission's criteria
The framework is not theory. In April 2026 the European Commission awarded a sovereign cloud contract worth up to €180 million over six years to four European providers, applying explicit sovereignty criteria for the first time. SEAL-2 was the floor to compete at all. Most of the awarded providers scored SEAL-3.
Two things there are useful to an ordinary company. First, there is now a published yardstick that providers have already been scored against, so you do not have to invent criteria. Second, the Commission deliberately picked four suppliers instead of one to avoid depending on a single party. That reasoning applies to your organisation as much as to an EU institution.
The Dutch government is running a parallel track. The Rijk is building its own sovereign cloud service and has a proof of concept underway, with results going to parliament at the end of 2026. Its justification contains the number that explains the urgency: roughly 70 percent of the European cloud market is held by a handful of large non-European providers. The wider Dutch context is in our guide to digital sovereignty and AI in the Netherlands.
What do you ask a provider?
These are the questions that separate a provider selling sovereignty from one delivering it. Ask in writing. Require written answers.
Which jurisdiction is the parent company under? Not the data centre. The legal entity. A European subsidiary of a US parent falls under US powers through that parent, no matter where the disks sit or which trade register the subsidiary appears in. Ask for the full ownership structure.
Who can technically reach the data, and from which country? Support staff looking over your shoulder from another continent is access. Ask where the support organisation sits, what procedure gives an individual engineer access to a customer environment, what logging is kept of that access, and how long those records are retained before they are rotated out.
What happens when a foreign authority makes a demand? Ask whether the provider is obliged to inform you, whether it contests such demands, and whether it publishes a transparency report with actual numbers.
Which parts of the service run on third-party software? Hypervisor, management plane, identity and monitoring often come from non-European vendors. That need not be a problem. It does need to be on the table.
How do I get out? Ask about export formats, about how long a full export takes at your data volume, and for a test export during the trial period. A provider who refuses to demonstrate that has answered the question.
What is the SEAL score per dimension, and who assessed it? A provider that bid on the EU tender has those numbers. A provider that has never heard of the framework is selling data location.
[ TIME SAVED ]
Save 12 hours per week on tracing after the fact where customer data sits and who can reach it
What do you write into the contract?
The European Data Act has strengthened your position on exit, and that changes what a contract needs to cover. From 12 January 2027, switching charges and data egress charges for moving to another provider are prohibited. Until that date, providers may still charge a reduced fee no higher than the costs they actually incur. Infrastructure providers must additionally take reasonable measures so that you reach functional equivalence after switching.
That is the floor. Everything above it you negotiate yourself: the notice period and the export window, the format in which data and configuration are handed over, whether encryption keys stay with you throughout, and who actually performs the export in the case where your own team cannot. Cover what happens if the provider is acquired by a party outside the EU, because that is the scenario where sovereignty quietly evaporates without anything about the service changing.
The practical side of a migration is covered in the EU Data Act and switching cloud providers. For the wider contract terms around AI services, start with buying AI software.
When is a sovereign cloud the wrong choice?
Two situations, and they are rarely named.
The first: you depend on a specific service that only a hyperscaler offers. A specialised database, a model family, an ecosystem your application leans on. A European provider without it forces you to rebuild, and that bill rarely comes in below the risk you were covering. Split instead. The sensitive part sovereign, the rest where it already runs.
The second: you are too small for the fixed cost. European providers are on average more expensive per unit of compute and their contracts more often carry minimum commitments. Below a certain size you are mostly buying a higher rate without a matching risk to offset it.
There is a third path that tends to go missing from this comparison: no cloud at all. Running sensitive processing in-house has become technically reachable, and the recurring cost of it is worked out in what running your own AI environment costs. The full local-versus-cloud trade-off sits in our guide to local AI for business.
Where this lands
Sovereignty is a score per dimension, not a badge you tick, and that score belongs in your selection document next to price and performance. The Commission's eight dimensions hand you that structure without any need to draft criteria yourself.
Ask about ownership structure, about who can technically reach the data and from where, and for a demonstrated export. Fix the exit route before you sign rather than at the moment you need it. The provider who answers these questions without hesitating is usually also the provider you still want three years from now.