Back to blog
Frameworks

EU cloud certification and sovereignty: what buyers are actually asking for

European buyers increasingly ask where data sits, who can access it and under whose jurisdiction. What EU cloud certification schemes aim to standardise, and what to answer while the picture settles.
GRC Copilot Team
EU cloud certification and sovereignty: what buyers are actually asking for

"Where is our data, and who can reach it?" has become a standard question in European procurement — and it is rarely satisfied by naming a hosting region. Buyers are asking about jurisdiction, support access and legal exposure, not just geography.

What certification aims to fix

The EU cybersecurity certification framework exists to replace a patchwork of national schemes with common, mutually recognised ones — so a provider certifies once and buyers across member states can rely on it. Schemes are structured around assurance levels, broadly basic, substantial and high, with the rigour of evaluation increasing at each step.

A cloud-specific scheme has been under development for some time, and the contested element has been whether the highest assurance level should carry sovereignty requirements — constraints on jurisdiction, ownership and where support and operations sit. That debate is precisely what buyers are reflecting when they ask their questions.

Treat the certification landscape as unsettled and verify current status before making commitments in a contract. The buyer expectations, however, are already firm and will not wait for the scheme to conclude.

What sovereignty actually means to a buyer

Rarely a single requirement. Usually some combination of:

  • Data residency — where data is stored, including backups and disaster recovery.
  • Operational residency — where the people administering the service sit, and whether support can access data from outside the region. This is the question most often missed, and it is the one that catches providers with follow-the-sun support.
  • Jurisdictional exposure — whether a parent company elsewhere could be compelled to produce data.
  • Key control — whether the customer holds the encryption keys, and whether the provider can technically access plaintext.
  • Portability — the ability to leave, which now also carries obligations under EU data legislation.

Evidence cloud controls across frameworks

GRC Copilot maps cloud controls and evidence across ISO 27001, CSA CCM and regional requirements so one control set answers many questionnaires.

What to answer now

You cannot present a certification that does not yet apply to you, but you can answer the underlying questions precisely — which is what actually unblocks deals:

  1. Name the regions where data is stored, including backups and DR.
  2. State who can access customer data, from which countries, and under what controls and logging.
  3. Describe the encryption model and who holds keys.
  4. List sub-processors with their locations, and how changes are notified.
  5. Explain your legal structure and where the contracting entity sits.
  6. Describe the exit path — format, timeline and cost.

Providers that answer these six concretely tend to satisfy sovereignty questions without a certificate. Providers that answer "we are hosted in the EU" and stop generally do not, because it leaves the operational and jurisdictional questions open.

Relationship to what you already hold

ISO 27001 and CSA CCM cover much of the control substance and are widely accepted in European procurement. What they do not address is jurisdiction and operational access, which are precisely the sovereignty questions. Map your existing evidence and add a clear, factual sovereignty statement rather than waiting for a scheme.

Frequently asked questions

Is EU cloud certification mandatory?

The framework is designed around voluntary schemes, though sector rules or public procurement may effectively require them. Verify current status for your market.

Does hosting in the EU make us sovereign?

No. Residency is one element; operational access and jurisdictional exposure are separate and frequently decisive.

Do we need customer-managed keys?

Only where the threat model or contract requires it. They carry real operational burden — adopt deliberately, not by default.

What satisfies buyers today?

Precise, documented answers on residency, operational access, keys, sub-processors, jurisdiction and exit.

Key takeaways

  • Sovereignty questions are about access and jurisdiction, not only geography.
  • Operational residency — who administers from where — is the most missed element.
  • Answer the six underlying questions concretely; that unblocks deals now.
  • Verify certification scheme status before contractual commitments.
#eucs #cloud-certification #sovereignty #enisa #data-residency #eu-cloud