It is already used to buy
On 17 April 2026, the European Commission awarded four sovereign cloud contracts: €180m over 6 years, with a minimum requirement of SEAL-2. All four winners are European.
- Post Telecom (LU-FR), with OVHcloud and CleverCloud
- STACKIT (Germany, Schwarz Group)
- Scaleway (France, Iliad Group)
- Proximus (BE-FR-LU), with S3NS, Clarence and Mistral
The Commission explicitly encourages public and private buyers to use this framework. It is not an internal grid: it is the vocabulary in which European procurement now writes its requirements.
The four levels
The proposed Cloud and AI Development Act establishes a sovereignty framework with four assurance levels. Each level contains the one below it.
| Level | What it requires |
|---|---|
| SEAL1 | Data is processed and stored on infrastructure located in the Union. |
| SEAL2 | Adds independence from third countries and transparency over the software supply chain. |
| SEAL3 | The provider is owned and controlled from the Union, with criteria extending to the nationality of personnel. A third-country provider may obtain Commission recognition. |
| SEAL4 | Full transparency and control over the software supply chain, and no interference from a third country. |
⚠ Commission proposal — legislative procedure under way, not yet applicable.
What is assessed
The Commission's evaluation framework holds 48 criteria across 8 categories. They produce a score from SEAL-0 — complete lack of sovereignty — to SEAL-4 — a full EU supply chain, from chips to software.
- Strategic considerations
- Legal considerations
- Operational considerations
- Environmental considerations
- Supply chain transparency
- Technological openness
- Security
- Compliance with EU laws
What we measured
This measurement covers articles 3, 4 and 5 of the Digital Constitution, not the levels of the European framework. It awards no level. It shows what level 2 — independence from third countries, supply-chain transparency — will find when it looks.
1,000 websites drawn at random, 882 reachable, measured on 19 September 2026. The full dataset is published as open data: anyone can re-run it.
Fewer than one site in ten satisfies all three articles at once.
| Non-profits | Control | |
|---|---|---|
| no third-party call | 13.9% | 11.0% |
| no known tracker | 53.5% | 47.7% |
| no consent wall | 70.3% | 62.1% |
| all three at once | 10.1% | 7.9% |
The digital threshold of French non-profits — Licence Ouverte 2.0. 454 non-profit sites, 428 control sites, 498 distinct third-party hosts encountered.
The first step up is not a migration: self-hosting fonts and libraries, and removing the analytics tag, more than doubles the share of conforming sites. Without changing a pixel.
Moving up a level
Two places where dependency sits, and where it can be measured:
Your connected products
The Data Act gives you access to the data your machines produce, and the right to switch cloud provider. A right you do not exercise is a dependency you are paying for.
Data Act →Your machines
A robotised line depends on software, parts and support whose origin can be documented. Level 2 asks for that documentation; the Machinery Regulation and the AI Act already do.
Robotics →Knowing where you stand
We measure your site and your services against the criteria published by the Commission, and we hand over the record — what holds, what does not, and in which order to fix it. The record is dated; it can be produced as evidence.
Sources
- Sovereign cloud services procurement, European Commission — https://commission.europa.eu/news-and-media/news/commission-advances-cloud-sovereignty-through-strategic-procurement-2026-04-17_en
- Cloud Sovereignty Framework — https://commission.europa.eu/news-and-media/news/sovereign-cloud-framework-explained-2026-06-01_en
- Cloud and AI Development Act, COM(2026) 502 — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52026PC0502