Cloud 7 min read

Sovereign Cloud: What Digital Sovereignty Really Means

Sovereign cloud promises digital sovereignty. What the three layers of data, operations and technology mean, and how to choose without dogma.

Sovereign Cloud: What Digital Sovereignty Really Means

Sovereign Cloud: What Digital Sovereignty Really Means

Sovereign cloud and digital sovereignty used to be a topic for governments and large enterprises. In 2026 they have become a real architecture question for companies of every size. The triggers are not abstract principles but concrete legal and geopolitical shifts. Anyone running workloads in the cloud should understand what sovereignty actually means at a technical level, which providers deliver on which promise, and where a mid-sized company should sensibly draw the line. This article sorts the terms and offers a decision framework without dogma.

What sovereign cloud actually means

Sovereignty is not a switch. It consists of three layers that tend to blur together in practice.

The first layer is data sovereignty. It answers where data physically sits and whether it is subject only to European law. A region label such as eu-central-1 is not enough, because the storage location alone says nothing about who can legally compel access to it.

The second layer is operational sovereignty. This is about who can reach the system, who provides support, and who holds the administrative keys. A cloud whose servers stand in Frankfurt but is remotely administered from the United States is not operationally sovereign.

The third layer is technical sovereignty. It measures whether a company controls the stack far enough that switching providers is possible without a full rebuild. Open standards, portable containers and infrastructure as code are the real levers here, not the marketing label on the product page. This is where sovereignty either holds in operation or stays a line in a contract.

Why this is on the table in 2026

The legal core is the US CLOUD Act of 2018. It obliges US providers to hand over data on a valid government request, regardless of which country stores it. That reaches the European regions of the large US hyperscalers as well. Microsoft has built an EU Data Boundary that keeps storage and processing of personal data inside Europe. It still does not neutralize the CLOUD Act. Microsoft’s own lawyers confirmed before the French Senate that the conflict remains legally unresolved. An EU region is therefore a data-protection plus, not proof of legal sovereignty.

The EU has responded. With its Cloud Sovereignty Framework of October 2025, the Commission defines eight requirements and a sovereignty score that measures how exposed a service is to foreign legislation. In parallel, the EU agency ENISA is working on the EUCS certification scheme. The originally planned sovereignty eligibility criteria, such as the provider’s headquarters, were softened but remain politically contested. Through the NIS2 directive and the Data Act, member states can make certified providers effectively mandatory for critical workloads.

The market is moving accordingly. Gartner expects spending on European sovereign cloud infrastructure to rise from around 6.9 billion US dollars in 2025 to roughly 12.6 billion in 2026. Sovereignty has turned from a compliance obligation into a product segment of its own.

The current provider field

The offering is broader than many assume. It ranges from a separated hyperscaler partition to a fully German cloud.

AWS made its European Sovereign Cloud generally available in Brandenburg on 15 January 2026 and is investing around 7.8 billion euros in the infrastructure. It is operated exclusively by EU-resident staff, is structurally separated from regular AWS, and launches with attestation from BSI, Germany’s federal cybersecurity agency. It is the most consistent answer from a US provider so far, although the open question about US jurisdiction stays in the background. AWS documented the details in its official announcement.

Microsoft combines the EU Data Boundary with Delos Cloud, which runs on Microsoft technology for German public administration. On the European side, STACKIT by Schwarz Digits has become a serious factor. It is operated entirely in Germany, is a founding member of Gaia-X, the European data-infrastructure initiative, and hosts SAP workloads among others. Then there are providers without a US parent, such as IONOS, OVHcloud and Deutsche Telekom’s T-Systems. They deliver the strongest legal sovereignty but usually offer a narrower catalogue of managed services. That is the central trade-off: the more legally sovereign an offering is, the smaller its ecosystem of ready-made services often becomes.

Deciding pragmatically: sovereignty by protection need

The most expensive mistake is to treat sovereignty as an all-or-nothing question. A public marketing site and a system holding health or contract data have entirely different protection needs. The first step is therefore not provider selection but a classification of workloads into public, internal, strictly confidential and regulated.

For non-critical workloads, the standard hyperscaler stays the rational choice in most cases, because service breadth and cost are hard to beat. For sensitive and regulated data, a sovereign partition or a European provider is worth the look. In mixed estates, a two-track setup is often the most honest answer, provided the data flows between the two worlds are cleanly controlled.

What decides the outcome is exit-ability. A team that builds on portable containers, open data formats and automated provisioning from day one keeps switching costs low and retains technical sovereignty regardless of the provider. Open source is not an end in itself here but the foundation of that independence, as we showed in open source for SMEs and with the example of the sovereign workplace OpenDesk. The question of whether a service belongs in the cloud at all or runs better in-house belongs in this assessment too, as the comparison self-hosted vs SaaS lays out. Anyone planning a move should fold sovereignty into the cloud migration strategy as a criterion, rather than retrofitting it later at a higher price.

Conclusion

Sovereignty is not a seal but a spectrum, decided by the protection need of the data and the exit-ability of the system. A company that classifies its workloads, picks the right provider per use case and plans portability from the start gets real control instead of a reassuring label. An EU region is a good start, but it does not replace the architecture decision.

EverBright IT supports exactly this assessment, from data classification through provider comparison to a portable architecture. Learn more about our cloud advisory or get in touch directly.

Frequently Asked Questions

What is a sovereign cloud?

A sovereign cloud is a cloud offering that brings data, operations and technology under European control far enough that access under foreign legislation is excluded or strongly limited. It spans three layers: data residency, operational control through European staff, and technical independence through open, portable standards that allow a provider switch.

Does an EU region protect against the US CLOUD Act?

No, not reliably. An EU region ensures that data is stored in Europe, but it does nothing to change the legal reach of the CLOUD Act. As long as a US parent company is involved, a US authority can demand access. Full legal sovereignty comes only from providers outside US jurisdiction or from structurally separated partitions.

Which sovereign cloud providers operate in Germany?

Available options include the AWS European Sovereign Cloud in Brandenburg, STACKIT by Schwarz Digits, Delos Cloud for public administration, and European providers such as IONOS, OVHcloud and T-Systems. They differ widely in service breadth and in their degree of legal sovereignty, so the choice depends on the protection need of the workloads.

Is sovereign cloud worth it for mid-sized companies?

For parts of the estate yes, for others no. Non-critical workloads keep running cheaply on a standard hyperscaler. For regulated or particularly sensitive data, a sovereign solution lowers legal risk noticeably. The pragmatic path is classification by protection need rather than a blanket decision for the entire infrastructure.

#Sovereign Cloud #Digital Sovereignty #Cloud Strategy #GDPR #Gaia-X
Share:
Sergej Bardin

Sergej Bardin

CEO · AI Strategy & IT Consulting

Helping mid-sized companies adopt AI and shape their cloud strategy. Focus on practical decisions over hype.

AI StrategyMCPRAGMulti-CloudIT ConsultingMid-Market