On 1 June 2026 the European Commission published its Cloud Sovereignty Framework as an open document, along with an assessment calculator and an implementation guide. It was originally written to score bids into the Cloud III Dynamic Purchasing System, the tender that procures cloud services for the EU institutions. The Commission has now handed the same tool to every other buyer.
That matters because the framework does something most sovereignty debates avoid. It puts a number on the argument. If your CIO says a service is European, the framework asks how European, on what evidence, and against which of eight specific objectives. If your general counsel says the CLOUD Act is a concern, the framework tells you where in the scoring that concern shows up.
You will start seeing SEAL levels in RFPs from regulated buyers, defence primes and public sector customers before the end of 2026. Here is what those levels mean in language you can use in a Monday morning meeting.
The five SEAL levels
SEAL stands for Sovereignty Effectiveness Assurance Level. There are five of them, from zero to four, and they describe the reality of a service rather than the ambition of the marketing.
| Level | Plain meaning |
| SEAL-0 | No sovereignty. Service, technology and operations sit under a non-EU provider and are governed entirely by non-EU law. |
| SEAL-1 | Jurisdictional sovereignty. EU law formally applies through a European contracting entity, but operations, keys and support still sit outside the EU. |
| SEAL-2 | Data sovereignty. EU law applies and data stays in the EU, but material dependencies on the non-EU parent remain. |
| SEAL-3 | Technological sovereignty. EU law applies, EU actors have meaningful influence over the technology and operations, and the non-EU parent has only marginal control. |
| SEAL-4 | Full digital sovereignty. Technology and operations sit entirely under EU control, under EU law only, with no critical non-EU dependencies. |
The gap that surprises people is between SEAL-1 and SEAL-2. A European data centre is not enough on its own. If the keys, the support staff or the update pipeline sit outside the EU, the score stays at SEAL-1.
The eight objectives that produce the score
A SEAL level is a summary. The scoring underneath it uses eight Sovereignty Objectives, numbered SOV-1 to SOV-8. Read them once and you will spot which of your suppliers are exposed.
| # | Sovereignty Score | Objective | What it scores |
| SOV-1 | 15% | Strategic sovereignty | Strategic sovereignty captures the degree to which a cloud provider (or technology actor) is anchored within the European Union/EEA legal, financial, and industrial ecosystem. It assesses ownership stability, governance influence, and alignment with EU strategic priorities. |
| SOV-2 | 10% | Legal and jurisdictional sovereignty | Legal & Jurisdictional sovereignty evaluates the legal environment, exposure to foreign authority, and enforceability of rights that govern a technology provider and its services. It determines the extent to
which a provider is anchored in European jurisdiction and insulated from external legal claims. |
| SOV-3 | 10% | Data and AI sovereignty | Data & AI sovereignty focuses on the protection, control, and independence of data assets and AI services within the EU/EEA. It addresses how data is secured, where it is processed, and the degree of autonomy customers retain over AI capabilities. |
| SOV-4 | 15% | Operational sovereignty | Operational sovereignty measures the practical ability of EU actors to run, support, and evolve a technology independently of foreign control. It focuses on continuity of operations, skill availability, and resilience against external dependencies. |
| SOV-5 | 20% | Supply chain sovereignty | Supply chain sovereignty evaluates the geographic origin, transparency, and resilience of the technology supply chain,
focusing on the extent to which critical components and processes remain under EU control or exposed to non-EU dependencies. |
| SOV-6 | 15% | Technology sovereignty | Technology sovereignty evaluates the degree of openness, transparency, and independence in the underlying technological stack, ensuring EU actors can interoperate, audit, and evolve solutions without lock-in to foreign proprietary systems. |
| SOV-7 | 10% | Security and compliance sovereignty | Security & Compliance sovereignty measures the extent to which security operations, compliance obligations, and resilience measures are controlled within the EU, ensuring independence from foreign jurisdictions and long-term operational assurance. |
| SOV-8 | 5% | Environmental sustainability | Environmental sustainability assesses autonomy and resilience of cloud services over the long term in relation to energy usage, dependency and raw material scarcity. |
Source: Cloud Sovereignty Framework- Implementation Guidance.pdf, European Commission
The Commission calculator combines these eight scores into a Global Sovereignty Score, and one weak objective drags the whole result. A service can hold ISO 27001, C5 and SecNumCloud and still score badly on SOV-2 the moment a US parent enters the picture.
Why buyers outside EU institutions should care
Three reasons.
- Procurement gravity. Public sector, defence and regulated buyers copy Commission tenders. Once SEAL is quoted in one national procurement, it appears in the next twenty.
- Contract evidence. The framework demands evidence. Ownership records, contract clauses, staff geography, key management architecture, deletion attestations. Vendors that cannot produce those documents in a tender will not produce them in a contract dispute either.
- AI containment. Copilots, meeting summarisers and speech analytics have quietly reset the sovereignty score of workloads that used to pass. SOV-3 is where that shows up, and it is the objective moving fastest.
None of this requires you to be an EU institution. It requires you to buy anything that touches European personal data, regulated industry data or national security data.
Five questions to put to your CIO this quarter
- What SEAL level would our top ten cloud services score today, on the Commission criteria, not on the vendor marketing?
- Which of those services rely on non-EU key management, non-EU support, or non-EU model inference?
- Which of our current contracts allow us to demand a SEAL re-score during the term?
- What is our budget assumption for moving one SEAL level up on our two most sensitive workloads?
- Who inside the company owns the sovereignty score, and to whom do they report?
If any of those questions produces a shrug, the framework is doing its job.
What comes next in this series
Over the next ten weeks we apply the framework to the three workloads Damovo customers ask about most: Unified Communications, Contact Centre, and Enterprise Networking. Each post names the SOV objectives that dominate the score, shows where estates typically sit today, and closes with a short checklist for your next renewal.
