Staffan Lindblad, Cybersecurity and Compliance Specialist at Elastx.

How sovereign is your cloud? The EU has created a scale from 0 to 4

Just because your data is stored in Sweden or the EU does not automatically mean that only European actors can access it. Who owns the cloud provider, where administration takes place and which laws apply also matter.

For organisations handling personal data, sensitive information or critical services, maintaining control is important. The GDPR sets requirements for the protection of personal data when it is transferred outside the EU/EEA. At the same time, the laws of the country where a provider or its owner is based may affect the ability of authorities to request access to data.

The European Commission has now developed a way to assess these types of dependencies. The Cloud Sovereignty Framework breaks digital sovereignty down into eight areas. The SEAL 0–4 scale represents different levels of control and independence.

For Staffan Lindblad, Cybersecurity and Compliance Specialist at Elastx, the important development is that something that has long been difficult to define can now be assessed and compared.

– For years, "sovereign cloud" has been something almost any cloud provider could put in a brochure. The problem is that customers have had no real way to compare those claims. Now we finally have a common benchmark, says Staffan Lindblad.

SEAL in 30 seconds

SEAL stands for Sovereignty Effectiveness Assurance Level. Put simply, the scale describes the degree of actual control European actors have over a cloud service, its technology and its operations.

SEAL 0: No specific level of sovereignty can be assured. SEAL 1: Basic safeguards are in place, but significant dependencies outside the EU remain. SEAL 2: Control has been strengthened, but important external dependencies remain. SEAL 3: A high degree of European control, with limited critical dependencies outside the EU. SEAL 4: The highest level, with European control and no critical dependencies that could compromise sovereignty.

The framework assesses eight areas: strategic sovereignty, legal and jurisdictional sovereignty, data and AI sovereignty, operational sovereignty, supply chain sovereignty, technology sovereignty, security and compliance sovereignty, and environmental sustainability.

It is not enough to ask where your data is stored

Two cloud providers may both have data centres in Sweden while having very different risk profiles. One may be Swedish-owned and administered by staff in Sweden. The other may be part of an international group with support teams, administrators and escalation paths across several countries.

– I usually ask a simple question: if an administrator account needs to be restored at three in the morning, who does it, where is that person located and which laws are they subject to? Digital sovereignty is not just about where the data is stored. It is about who actually has control, says Staffan.

The model is now being used in practice

In April 2026, the Cloud Sovereignty Framework was used in the European Commission's own procurement of sovereign cloud services, worth up to €180 million.

– What is interesting is that the burden of proof has shifted. Previously, buyers had to try to see through providers' claims. Now providers need to demonstrate what control actually looks like, area by area. Sovereignty is not a label. It is something that must be verifiable, says Staffan.

SEAL 4 also shows what Europe is still missing

The highest level is, in practice, very difficult for a complete cloud service to achieve today. This is not only down to the cloud provider. SEAL 4 also requires critical technologies and supply chains to be under European control. Today, Europe still depends on technology from other parts of the world, including processors and accelerators - specialised chips used for tasks such as AI computing.

SEAL 4 therefore does more than show how sovereign a cloud service is. It also highlights the dependencies Europe needs to reduce in order to become more digitally independent.

We tested the model on Elastx

Elastx has also carried out a self-assessment against the criteria. The result was a Sovereignty Score of 87% and SEAL 3.

The two results measure different things. The Sovereignty Score is a weighted average across the eight areas. SEAL instead follows the weakest-link principle: a high average is not enough if a single criterion is assessed at a lower SEAL level.

Elastx reaches SEAL 4 in strategic sovereignty, legal and jurisdictional sovereignty, and security and compliance sovereignty. In areas including data and AI, operations, technology and supply chains, individual criteria keep the overall level at SEAL 3.

– That is also one of the strengths of the model. We score 87% overall, but SEAL 3 also shows where our own dependencies remain, says Staffan.

Three questions to ask your cloud provider

The Cloud Sovereignty Framework is a procurement tool, not legislation. But its principles can already be applied today:

1. Who ultimately owns your company, and which countries' laws can apply to you through your ownership structure?

2. Where are the people with administrative access located – including when an issue is escalated?

3. Can you demonstrate your digital sovereignty area by area, including where you still depend on actors outside the EU?

A clear picture of where control lies and which risks remain provides a better basis for decision-making. A blanket statement that "we are sovereign" does not.

SEAL measures, CADA takes the next step

SEAL and the Cloud Sovereignty Framework are not legislation. At the same time, the EU is working on the Cloud and AI Development Act (CADA).

Put simply: SEAL shows how much control we have today. CADA is about strengthening Europe's own cloud and AI capacity.

For anyone buying cloud services, one question is becoming increasingly important:

Who actually controls the digital infrastructure our organisations depend on?

__

Read also: Rules don't build data centres – why CADA could become the EU's most important cloud proposal

More on how we approach security: Elastx Trust Center

Show all news