Skip to content
Book a call
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français
Flagships
Perstat Uptime monitoring, incident management and status pages for teams who promise availability. NextPKI Find, renew and manage certificates, whoever issued them. Databurg Audit-proof compliance documentation for companies with reporting duties.
Trust & crypto
sqlclient A native database client for macOS. Local, with no detour via someone else's servers. FoldMail An email client with encryption that is meant seriously, S/MIME and OpenPGP. Claro An app for separated parents: handovers, arrangements and costs in one place.
Bundle of the month
Reliability Bundle

Perstat + NextPKI as a single billed package. NIS2 evidence and certificate lifecycle from one cockpit.

Learn more
Learn
Blog Release notes, compliance news, roadmap. Careers
Trust
Legal & privacy DPA, sub-processor list.
Bundle of the month
Reliability Bundle

Perstat + NextPKI as a single billed package. NIS2 evidence and certificate lifecycle from one cockpit.

Learn more
Products Perstat NextPKI Databurg sqlclient FoldMail Claro
Imprint
Language
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français
Book a call
Skip to content
EU Sovereignty

The Cloud Sovereignty Framework: When Sovereignty Becomes a Measurable Procurement Criterion

13.07.2026 · 3 min read

With the Cloud Sovereignty Framework, the European Commission makes digital sovereignty assessable: eight objectives, a SEAL tier model, and a first 180 million euro award. What it means for procurement and provider selection.

Digital sovereignty was long a term for keynote speeches, hard to pin down and harder still to verify. With the Cloud Sovereignty Framework, the European Commission has turned it into an evaluation grid. The version published in October 2025 (1.2.1) defines eight sovereignty objectives and a methodology for classifying cloud providers in a structured way. April 2026 brought the practical test: a framework contract worth 180 million euros for sovereign cloud services for the EU institutions, awarded to four European providers.

That shifts the debate. Sovereignty is no longer just a marketing promise, but a criterion that is asked for and scored in tenders.

Eight objectives instead of a gut feeling

The framework groups sovereignty into eight objective dimensions: strategic, legal and jurisdictional, data and AI, operational, supply chain, technological, security and compliance, and environmental sustainability. The value lies in the completeness. Whoever looks only at the hosting location may capture the legal dimension but overlook the supply chain behind operations, or the question of who retains control of the technical stack when it matters.

Only the interplay produces a defensible picture. A provider can host in Frankfurt and still hang off a parent company outside the EU whose jurisdiction reaches through in case of doubt.

SEAL makes the result comparable

At the heart of the methodology is the Sovereignty Effectiveness Assurance Level, or SEAL. It bundles the assessment into tiers that mark thresholds for different sovereignty claims: SEAL-2 for the highest level of data sovereignty, SEAL-3 for technological autonomy, and SEAL-4 for full sovereignty. An authority therefore does not have to weigh every detail itself, but can set a target tier and measure offers against it.

That is the real advance. A tier logic translates a diffuse aim into a requirement that can be tendered, compared and verified. For providers it means sovereignty becomes attestable, not merely assertable.

Why this reaches beyond the institutions

The first award concerned the EU institutions themselves, with four European providers receiving the contracts. What is interesting, though, is the announced continuation: the Commission is working to make the evaluation methodology available to other authorities and member states as well. Once national and municipal contracting bodies use the same grid, SEAL becomes a shared language for sovereignty in public procurement.

For companies that supply the public sector or serve regulated customers, that is an early indicator. What applies to EU institutions today tends to resurface soon in downstream tenders and supplier questionnaires.

What makes sense now

Three questions are worth asking regardless of the next tender: in which of the eight dimensions is your own cloud usage actually sovereign, and where does it hang off a non-European jurisdiction? Which target tier do your use cases really need, since not every workload demands SEAL-4? And can you evidence your position, not just assert it?

The Datargo platform is built for EU hosting in Frankfurt and operator control within the EU, which addresses several of these dimensions at once. The point itself, though, is independent of any provider, namely to assess sovereignty in future along the eight objectives rather than at the single data-centre location.

Sovereignty is no longer asserted. It is assessed.

Back to the blog

Datargo Datargo

Datargo GmbH, Frankfurt am Main. We build and operate our own software products on our own infrastructure in the European Union.

EU hosting, Frankfurt GDPR-native Made in Germany
Products
  • Perstat
  • NextPKI
  • Databurg
  • sqlclient
  • FoldMail
  • Claro
Company
  • Contact
  • Careers
  • Blog
  • Status page
Legal
  • Imprint
  • Privacy
© 2026 Datargo GmbH. All rights reserved.
Germany · English

Datargo® and Databurg® are registered trademarks of Datargo GmbH. All other product names, logos, and trademarks mentioned are the property of their respective owners.