{"id":4062,"date":"2026-06-03T23:04:59","date_gmt":"2026-06-03T22:04:59","guid":{"rendered":"https:\/\/upcloud.com\/global\/?p=4062"},"modified":"2026-06-03T23:04:59","modified_gmt":"2026-06-03T22:04:59","slug":"8-layers-european-digital-sovereignty-explained","status":"publish","type":"post","link":"https:\/\/upcloud.com\/global\/blog\/8-layers-european-digital-sovereignty-explained\/","title":{"rendered":"The 8 layers of European digital sovereignty explained"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Digital sovereignty is a critical topic in Europe today, driving significant market activity. Organizations are actively assessing their technology stacks, searching for sovereign solutions, and planning migrations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we will examine sovereignty as many organizations understand it now, why this approach is misleading, and the proper strategy for achieving a sovereign stack. Finally, we will discuss the options available and whether we can achieve 100% sovereignty in Europe.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Misleading picture of sovereignty<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Our experience indicates a significant gap in the understanding of digital sovereignty. Let\u2019s break down the core issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, consider data sovereignty. Many organizations traditionally viewed the location of data storage as the primary determinant, seeking to store data within European regions, such as Frankfurt-based data centers. However, as we will explore, this leads to a far more complex evaluation than initially anticipated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second area concerns the software an organization utilizes. Obvious targets for transition include ecosystem-heavy office suites like Microsoft or Google. However, replacing these often reveals a &#8220;Pandora&#8217;s box&#8221; of multilayered software systems, complex tools, and deep-seated dependencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, organizations are increasingly scrutinizing their primary infrastructure vendors. Hyperscalers like Amazon Web Services (AWS), Google Cloud, and Microsoft Azure are primary targets for assessment due to their market dominance and widespread use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In summary, the traditional view of sovereignty is often limited to these three components:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/upcloud.com\/media\/3-sovereignty-components-1024x576.png\" alt=\"-\" class=\"wp-image-82808\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If this seems incomplete, you are correct. These three elements represent only a fraction of a much broader and more nuanced landscape, as illustrated below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/upcloud.com\/media\/incomplete-sovereignty-components-1024x576.png\" alt=\"-\" class=\"wp-image-82811\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here we can see the full puzzle, but these three elements we defined before are just a small part of the full picture.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Moreover, these elements aren\u2019t the main parts of the overall sovereignty framework; they fall within broader areas.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Cloud Sovereignty Framework defined by the European Commission<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The previous illustration highlights significant gaps in the common understanding of digital sovereignty.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recognizing this, the European Commission released the <a href=\"https:\/\/commission.europa.eu\/document\/download\/09579818-64a6-4dd5-9577-446ab6219113_en\" target=\"_blank\" rel=\"noopener\">Cloud Sovereignty Framework in October 2025<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This framework serves as a foundation for Cloud Sovereignty assessments, designed to evaluate an organization&#8217;s posture across eight key domains.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a look at the picture below.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/upcloud.com\/media\/broader-sovereignty-components-1024x576.png\" alt=\"-\" class=\"wp-image-82812\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Now we have 8 puzzles which surround the center one &#8211; digital sovereignty. Let\u2019s discuss the importance of each of these domains.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Strategic sovereignty<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The objectives of this domain focus on the strategic choices and decisions organizations make regarding providers and technologies. This domain assesses whether the provider aligns with European strategic interests, including ownership, corporate governance, investment structure, decision-making power, and long-term stability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A great example here is ownership. The vendor we selected can be European-based, using European datacenters, etc. But it is also important who owns the vendor. If this vendor is a subsidiary of a non-EU organization, different jurisdictions may apply. For example, if the parent organization belongs to US jurisdiction, then the Cloud Act and FISA 702 apply.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This domain describes more than governance. It describes whether Europe has a meaningful influence over the digital infrastructure. And who else has it too?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Legal and jurisdictional sovereignty<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This domain explores the topic we introduced in the previous domain in greater depth. It covers exposure to foreign laws, enforceability of customers&#8217; rights, data access requests, and so on. This is especially important for the public sector, regulated industries, critical infrastructure, and the military.<br>This might imply not only to the direct vendor but also to the subcontractors of our vendor, especially if that entity processes our users\u2019 data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Data and AI sovereignty<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This domain covers data and AI sovereignty by focusing on the protection, control, and independence of data assets and services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It means we need to assess where data is stored and processed, how it is encrypted, and how we deal with encryption keys and tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As this domain also covers AI, it encompasses not only data storage and processors but also prompts, embeddings, training data, processes, inference pipelines, and dependencies. We must assess whether the models and inferences we use are used for training new models. How? How do we ensure data security? How do we design the service to ensure the process does not allow data to be leaked?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Data sovereignty is often considered as storage sovereignty. This is a very misleading perspective, as the domain is much broader than that. Data processing, data transfer, and most importantly today, the AI toolset and its processing pipelines are also in scope.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Operational sovereignty<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This domain focuses on migration processes. Or rather, how easy is it to migrate workloads from one vendor to another, especially when considering EU vendors and the problem of vendor lock-in? This also covers the vendor\u2019s capacity and technology, including how much they rely on non-EU solutions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We need to define our needs and understand the vendor\u2019s capabilities in running, supporting, and evolving the technologies independently and without foreign control. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And here is an important catch. We consider here not just applications, software, or whole systems, but also hardware, including the middle layer, operating systems, backups, and encryption processes, which becomes very tricky from the EU organization perspective.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Supply Chain sovereignty<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Supply chain security was not in the scope of interest for many years. It changed several years ago, and today we are increasingly aware of the importance of proper security across CI\/CD, coding, and delivery. Recent breaches and supply chain infections have heightened awareness of it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what about the sovereignty of the supply chain? Where do we run our processes? Who owns the tools we use to deliver our product? These questions must be answered in this domain, as the supply chain is one of the most vulnerable processes: it starts with code that becomes the product. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is the process where all secrets are injected and configured. This is the system that has access almost everywhere in our organization with elevated privileges.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Technology sovereignty<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This domain evaluates the openness, transparency, portability, and independence of the technology stack used in the organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We need to know if we are vendor-locked and how to avoid it. How to preserve the interoperability, auditability, and ability for migration and evolution of the systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It includes questions about the use of proprietary and open source solutions, documentation, and architectural decisions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security and Compliance sovereignty<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This domain measures the extent to which all security operations, compliance obligations, and resilience metrics remain within the EU. This includes security monitoring, incident response, vulnerability management, certification, regulatory alignment, access control, encryption, and so on. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We think here about GDPR, NIS2, or the incoming AI Act, but it is more than just the documents and regulations; it also involves how the processes are organized and who uses, controls, and owns the toolset used in these processes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Environmental sustainability<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Although this doesn\u2019t sound like something we should consider, but in today&#8217;s world these topics like energy consumption and effectiveness, dependency and raw material scarcity become very important.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We see many questions about the energy we use in datacenters &#8211; is it green energy? Also, the most powerful equipment consumes a lot of energy and generates significant heat. How do we deal with it? Global warming isn\u2019t a conspiracy theory; it is a reality, and we must act responsibly to care about our environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not to mention who delivers this energy? This also requires consideration, and this question is connected to the previously explained domains.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">More than data residency<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We see that digital sovereignty, or cloud sovereignty (which can be described as subset of digital sovereignty) is much broader than just the question of where you store your data, or do you use AWS, Azure, GCP or something else.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the provider is European, it has data centers in Europe but does not comply with legal and supply chain requirements; selecting this vendor might be risky. Because we still cannot be sure what will happen with our data and how the vendor will react in the event of an incident or data breach.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sovereignty is not a rejection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">But sovereignty isn\u2019t about isolation. First of all, we are not able to be isolated today. We are dependent on the global market and on the specialization of different regions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We don\u2019t reject global technologies; we need to better understand and control them. Make sure we have plans and remediations for risks and that we can preserve the ability to act independently when it matters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For us in Europe, it isn\u2019t just the compliance topic. It is an economic, industrial, legal, and strategic necessity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A sovereign digital future is not created by slogans<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">But by the real work done by many companies, like UpCloud. Test our services, deploy your workloads using UpCloud\u2019s infrastructure, and prepare yourself to use a European cloud provider.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">If you wish to learn more, explore our offering, and check out\u00a0<\/span><a href=\"https:\/\/demo.upcloud.com\" target=\"_blank\" rel=\"noreferrer noopener\">our demo control panel<\/a><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">, where you can interact with our Hub and services.<\/span> And let\u2019s <a href=\"https:\/\/upcloud.com\/global\/newsletter\/\">stay in touch<\/a>!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Digital sovereignty is a critical topic in Europe today, driving significant market activity. Organizations are actively assessing their technology stacks, searching for sovereign solutions, and [&hellip;]<\/p>\n","protected":false},"author":100,"featured_media":82838,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"3924,892,301,181,391,22","_relevanssi_noindex_reason":"Blocked by a filter function","footnotes":""},"categories":[13,22,91],"tags":[],"class_list":["post-4062","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-sovereignty","category-cloud-infrastructure","category-industry-analyses"],"acf":[],"_links":{"self":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/4062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/users\/100"}],"replies":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/comments?post=4062"}],"version-history":[{"count":11,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/4062\/revisions"}],"predecessor-version":[{"id":7245,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/4062\/revisions\/7245"}],"wp:attachment":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/media?parent=4062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/categories?post=4062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/tags?post=4062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}