Co-Founder and VP Product Strategy & Customer Experience
For years, "sovereign cloud" meant whatever a provider's marketing said it meant. That is changing. On June 3rd, 2026, the European Commission proposed the Cloud and AI Development Act as part of its Tech Sovereignty Package. At its core is a four-level assurance framework for cloud sovereignty, intended for public-sector bodies to apply based on their own risk assessments, with providers recognized after audit.
CADA is still a proposal, with final adoption targeted for late 2027. But the framework is already shaping expectations. In April 2026, the Commission awarded a €180 million sovereign cloud contract to four provider groups using explicit sovereignty criteria, the first EU procurement to do so. Suppliers to the public sector, and regulated industries watching closely, should expect similar criteria to appear in their own contracts.
Data residency answers one question: where is the data stored? Sovereignty asks several more:
A workload stored in an EU region can still score low on the first two. That is why a graded framework is more useful than a single label.
Not every workload needs the highest level of assurance, and treating everything as maximally sensitive is expensive and slows innovation. A practical approach:
Use the time before adoption to build a data classification that maps cleanly onto assurance levels. When the framework becomes binding, or when a public-sector customer asks for it, the answer will be a lookup rather than a project.
Want to map your data classes to sovereignty requirements? Talk to our specialists.
Sources