The EU Cloud Sovereignty Framework is the European Commission’s method for assessing how sovereign a cloud service actually is. It scores providers against eight Sovereignty Objectives using a five-level scale called SEAL (Sovereignty Effectiveness Assurance Level, 0 to 4), and combines the results into a weighted Sovereignty Score used in public procurement. Published by the Commission’s Directorate-General for Digital Services (version 1.2.1, October 2025), it is fast becoming the common language for sovereignty claims across the European cloud and infrastructure market.
This guide explains how the framework works, how the scoring logic behaves in a real tender, and how buyers can use it to evaluate any provider. It also corrects the most common misunderstandings, because sovereignty claims are about to get noisy. This article is based on the official Cloud Sovereignty Framework, Version 1.2.1 (European Commission, 20 October 2025).
What is the EU Cloud Sovereignty Framework?
The framework defines what sovereignty means in practical, assessable terms for cloud services procured by EU institutions. It draws on existing European initiatives including CIGREF’s Trusted Cloud referential, Gaia-X policy rules, and the EU cybersecurity certification landscape (ENISA, NIS2, DORA), as well as national strategies such as France’s Cloud de Confiance and Germany’s Souveräner Cloud.
Its core insight: sovereignty is not one thing. A provider can be strong on operational independence and weak on ownership structure, or strong on data control and weak on supply chain. The framework breaks sovereignty into eight measurable objectives and scores each one separately.
The eight Sovereignty Objectives
| # | Objective | What it measures | Weight |
|---|---|---|---|
| SOV-1 | Strategic Sovereignty | Where decisive authority, ownership, and financing sit, and how stable that is | 15% |
| SOV-2 | Legal & Jurisdictional Sovereignty | Exposure to non-EU laws with cross-border reach, such as the US CLOUD Act, and whether foreign authorities could compel access | 10% |
| SOV-3 | Data & AI Sovereignty | Who controls cryptographic access to data, where processing runs, and how independent AI capabilities are | 10% |
| SOV-4 | Operational Sovereignty | Whether EU actors can run, support, and evolve the service without non-EU involvement | 15% |
| SOV-5 | Supply Chain Sovereignty | Where hardware and software are designed, built, packaged, and distributed, and how transparent the supplier chain is | 20% |
| SOV-6 | Technology Sovereignty | Openness of the stack: standards, open licensing, auditability, and freedom from vendor lock-in | 15% |
| SOV-7 | Security & Compliance Sovereignty | EU-controlled security operations, certifications, and alignment with GDPR, NIS2, and DORA | 10% |
| SOV-8 | Environmental Sustainability | Energy efficiency, renewable sourcing, circularity, and transparent sustainability reporting | 5% |
Supply chain carries the heaviest weight at 20%, a signal that the Commission considers hardware and software provenance the hardest and most consequential sovereignty problem.
The SEAL scale: five levels of assurance
Each objective is scored on the Sovereignty Effectiveness Assurance Level scale:
| Level | Name | What it means |
|---|---|---|
| SEAL-0 | No Sovereignty | The service is under exclusive non-EU control and governed entirely outside EU jurisdiction |
| SEAL-1 | Jurisdictional Sovereignty | EU law formally applies, but enforceability is limited and control remains with non-EU parties |
| SEAL-2 | Data Sovereignty | EU law applies and is enforceable, but material non-EU dependencies remain |
| SEAL-3 | Digital Resilience | EU actors exercise meaningful, though not full, influence, with only marginal non-EU control |
| SEAL-4 | Full Digital Sovereignty | Complete EU control, subject only to EU law, with no critical non-EU dependencies |
A crucial nuance: a provider does not have one SEAL level. It has eight, one per objective, assessed in the context of a specific procurement.
How the scoring works in a real tender
Two mechanisms operate together, and understanding the difference matters more than anything else on this page.
First, SEAL levels act as minimum floors. The tender sets a required minimum level for each objective. A provider that falls below the floor on even one objective is rejected outright, regardless of how strong every other score is. The weakest objective, not the average, decides whether a bid survives.
Second, the Sovereignty Score ranks the survivors. For bids that clear every floor, a weighted percentage is calculated across all eight objectives using the weights above. That score feeds into the tender’s quality evaluation as an award criterion.
The practical consequence: a headline percentage is meaningless on its own. A provider scoring 70% overall but failing one floor loses to a provider scoring 55% that clears them all.
What the framework is not
This is where most early claims in the market go wrong.
There is no SEAL certificate. No accreditation body issues SEAL ratings. An official assessment only exists when a contracting authority scores a provider inside a real procurement procedure.
“We are SEAL-3” is not a valid claim. Without naming the objective and the procurement context, a single-number SEAL claim has no defined meaning under the framework. Treat any vendor leading with one as a signal to ask harder questions.
Geography is not sovereignty. The framework scores jurisdiction and control, not the location of servers or the branding on the building. Infrastructure in Frankfurt does not make a service sovereign if decisive authority over it sits outside the EU.
Self-assessments are not assessments. They are useful preparation, for providers and buyers alike, but only an assessment by a contracting authority produces an official result.
How buyers can use the framework outside public tenders
Although built for EU procurement, the framework is the most rigorous free tool available for evaluating any cloud or infrastructure provider’s sovereignty posture. Enterprises in regulated sectors can apply the same logic:
- Decide your minimum floor per objective based on your risk profile. A FinTech under DORA might set SEAL-2 floors on SOV-2, SOV-3, and SOV-7. A public body might require more.
- Ask each provider for evidence against the contributing factors of each objective, not for a headline claim.
- Reject on floors first, then compare weighted scores among providers that clear them.
Asking a provider “which objectives would you fail a SEAL-2 floor on, and why?” reveals more in one question than a hundred pages of sovereignty marketing.
Frequently asked questions
Is there an official SEAL certification I can look for? No. There is no certification scheme or accreditation body. Official SEAL levels exist only within a specific procurement assessment.
Can a provider with non-EU ownership still score well? Yes, on most objectives. Ownership primarily affects SOV-1 (Strategic Sovereignty). A European-operated provider with non-EU financial ownership can still evidence strong legal safeguards (SOV-2), full EU operational independence (SOV-4), and EU-controlled security operations (SOV-7). The framework was designed precisely to separate these dimensions rather than reduce sovereignty to a single ownership question.
What is the difference between the SEAL level and the Sovereignty Score? SEAL levels are per-objective floors that determine pass or fail. The Sovereignty Score is a weighted percentage across all eight objectives that ranks the bids that already passed.
Does the CLOUD Act automatically disqualify providers with US links? No, but it is directly assessed under SOV-2, which examines exposure to non-EU laws with cross-border reach and whether any legal, contractual, or technical channel exists through which a non-EU authority could compel access to data.
Which regulations does the framework connect to? It references GDPR, NIS2, and DORA within SOV-7, and builds on Gaia-X, CIGREF’s Trusted Cloud referential, and the EU cybersecurity certification framework.
Want to see how a provider, or your own infrastructure, measures up? Download our Cloud Sovereignty Self-Assessment workbook, built on the framework’s official objectives, weights, and floor logic. Get the self-assessment tool