Sovereignty
SEAL levels 0 to 4 and the Cloud Sovereignty Framework
The European Commission's sovereignty grid: eight weighted objectives and five assurance levels, from SEAL-0 to SEAL-4.
What the Cloud Sovereignty Framework is for
Rather than a yes/no, in 2025-2026 the European Commission published a scoring grid, the Cloud Sovereignty Framework, which measures sovereignty objective by objective and summarises it in an assurance level, the SEAL.
Assessment happens in two stages: minimum thresholds per objective, where a single failure eliminates, then a weighted score out of one hundred to rank offers. The question becomes “at which level, on which objective, with what trajectory” rather than “sovereign or not”.
SEAL stands for Sovereignty Effectiveness Assurance Level. The definitions below are the Commission's; the weightings are in the framework document, to be verified at the source before any quantified citation.
The five SEAL levels
From entirely non-European control (SEAL-0) to full sovereignty down to the chips (SEAL-4), which no one reaches today.
SEAL-0
No sovereignty: service, technology or operations under the exclusive control of non-European third parties.
SEAL-1
Jurisdictional sovereignty: EU law applies formally, but its practical application remains limited.
SEAL-2
Data sovereignty: EU law enforceable with no extra technical measure; non-EU dependencies remain.
SEAL-3
Digital resilience: immunity against a non-European supply disruption; non-EU control only marginal.
SEAL-4
Full sovereignty: EU control down to the chips, with no critical non-European dependency. Out of reach today.
The eight objectives and their weight
The score is spread across eight sovereignty objectives, from strategic to environmental. The heaviest weight falls on the hardware supply chain, where Europe is most dependent.
The objectives cover governance and ownership (strategic), exposure to non-European laws (legal), cryptographic control and the independence of AI models (data and AI), the ability to operate without non-European third parties (operational), the provenance of hardware and software (supply chain), open standards and the absence of lock-in (technological), security and GDPR/NIS2/DORA compliance, and energy efficiency (environment).
Applied to an AI phone system, the “data and AI” objective is central: that is where speech recognition, the language model and speech synthesis sit, often operated outside Europe.
The weight is on hardware
The framework's most heavily weighted objective is the supply chain: design, manufacture and distribution of hardware and software. It is the hardest dependency to reduce, and the reason SEAL-4 remains theoretical.
First application: the Sovereign Cloud tender
On 17 April 2026, the Commission awarded its “Sovereign Cloud” tender for its own institutions, with an eligibility threshold set at SEAL-2. It is the first time a major public buyer has ranked its providers on an explicit sovereignty scale.
Three of the four winners were ranked SEAL-3 and one SEAL-2. The point for a buyer is not the logo, but the ability to require a precise level and verify it objective by objective.
None of this is binding on the private sector today, but public tenders, banks under DORA and NIS2 essential entities are starting to ask for a SEAL level or a SecNumCloud qualification.
Frequently asked questions
What does SEAL-3 mean?
Does anyone reach SEAL-4 today?
Is the SEAL level mandatory?
Primary sources
What level should your telephony be at?
We assess your voice chain objective by objective, without overselling.