TEMPOsystem · Europe
Sovereignty

Which level are you on?

The European Union now has a cloud sovereignty scale. It did not merely write it: it buys with it. A provider below the required level is no longer set aside by an opinion — it is set aside by a contract.

It is already used to buy

On 17 April 2026, the European Commission awarded four sovereign cloud contracts: €180m over 6 years, with a minimum requirement of SEAL-2. All four winners are European.

  • Post Telecom (LU-FR), with OVHcloud and CleverCloud
  • STACKIT (Germany, Schwarz Group)
  • Scaleway (France, Iliad Group)
  • Proximus (BE-FR-LU), with S3NS, Clarence and Mistral

The Commission explicitly encourages public and private buyers to use this framework. It is not an internal grid: it is the vocabulary in which European procurement now writes its requirements.

The four levels

The proposed Cloud and AI Development Act establishes a sovereignty framework with four assurance levels. Each level contains the one below it.

The four levels
LevelWhat it requires
SEAL1Data is processed and stored on infrastructure located in the Union.
SEAL2Adds independence from third countries and transparency over the software supply chain.
SEAL3The provider is owned and controlled from the Union, with criteria extending to the nationality of personnel. A third-country provider may obtain Commission recognition.
SEAL4Full transparency and control over the software supply chain, and no interference from a third country.

⚠ Commission proposal — legislative procedure under way, not yet applicable.

What is assessed

The Commission's evaluation framework holds 48 criteria across 8 categories. They produce a score from SEAL-0 — complete lack of sovereignty — to SEAL-4 — a full EU supply chain, from chips to software.

What we measured

This measurement covers articles 3, 4 and 5 of the Digital Constitution, not the levels of the European framework. It awards no level. It shows what level 2 — independence from third countries, supply-chain transparency — will find when it looks.

1,000 websites drawn at random, 882 reachable, measured on 19 September 2026. The full dataset is published as open data: anyone can re-run it.

882sites measured, out of 1,000 drawn
3third-party hosts per site, median
9.1 → 21.5%by self-hosting fonts and libraries

Fewer than one site in ten satisfies all three articles at once.

What we measured
Non-profitsControl
no third-party call13.9%11.0%
no known tracker53.5%47.7%
no consent wall70.3%62.1%
all three at once10.1%7.9%

The digital threshold of French non-profits — Licence Ouverte 2.0. 454 non-profit sites, 428 control sites, 498 distinct third-party hosts encountered.

The first step up is not a migration: self-hosting fonts and libraries, and removing the analytics tag, more than doubles the share of conforming sites. Without changing a pixel.

Moving up a level

Two places where dependency sits, and where it can be measured:

Your connected products

The Data Act gives you access to the data your machines produce, and the right to switch cloud provider. A right you do not exercise is a dependency you are paying for.

Data Act →

Your machines

A robotised line depends on software, parts and support whose origin can be documented. Level 2 asks for that documentation; the Machinery Regulation and the AI Act already do.

Robotics →

Knowing where you stand

We measure your site and your services against the criteria published by the Commission, and we hand over the record — what holds, what does not, and in which order to fix it. The record is dated; it can be produced as evidence.

See pricing The 27 European texts

Sources