"Where is our data, and who can reach it?" has become a standard question in European procurement — and it is rarely satisfied by naming a hosting region. Buyers are asking about jurisdiction, support access and legal exposure, not just geography.
What certification aims to fix
The EU cybersecurity certification framework exists to replace a patchwork of national schemes with common, mutually recognised ones — so a provider certifies once and buyers across member states can rely on it. Schemes are structured around assurance levels, broadly basic, substantial and high, with the rigour of evaluation increasing at each step.
A cloud-specific scheme has been under development for some time, and the contested element has been whether the highest assurance level should carry sovereignty requirements — constraints on jurisdiction, ownership and where support and operations sit. That debate is precisely what buyers are reflecting when they ask their questions.
Treat the certification landscape as unsettled and verify current status before making commitments in a contract. The buyer expectations, however, are already firm and will not wait for the scheme to conclude.
What sovereignty actually means to a buyer
Rarely a single requirement. Usually some combination of:
- Data residency — where data is stored, including backups and disaster recovery.
- Operational residency — where the people administering the service sit, and whether support can access data from outside the region. This is the question most often missed, and it is the one that catches providers with follow-the-sun support.
- Jurisdictional exposure — whether a parent company elsewhere could be compelled to produce data.
- Key control — whether the customer holds the encryption keys, and whether the provider can technically access plaintext.
- Portability — the ability to leave, which now also carries obligations under EU data legislation.
Evidence cloud controls across frameworks
GRC Copilot maps cloud controls and evidence across ISO 27001, CSA CCM and regional requirements so one control set answers many questionnaires.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
What to answer now
You cannot present a certification that does not yet apply to you, but you can answer the underlying questions precisely — which is what actually unblocks deals:
- Name the regions where data is stored, including backups and DR.
- State who can access customer data, from which countries, and under what controls and logging.
- Describe the encryption model and who holds keys.
- List sub-processors with their locations, and how changes are notified.
- Explain your legal structure and where the contracting entity sits.
- Describe the exit path — format, timeline and cost.
Providers that answer these six concretely tend to satisfy sovereignty questions without a certificate. Providers that answer "we are hosted in the EU" and stop generally do not, because it leaves the operational and jurisdictional questions open.
Relationship to what you already hold
ISO 27001 and CSA CCM cover much of the control substance and are widely accepted in European procurement. What they do not address is jurisdiction and operational access, which are precisely the sovereignty questions. Map your existing evidence and add a clear, factual sovereignty statement rather than waiting for a scheme.
Frequently asked questions
Is EU cloud certification mandatory?
The framework is designed around voluntary schemes, though sector rules or public procurement may effectively require them. Verify current status for your market.
Does hosting in the EU make us sovereign?
No. Residency is one element; operational access and jurisdictional exposure are separate and frequently decisive.
Do we need customer-managed keys?
Only where the threat model or contract requires it. They carry real operational burden — adopt deliberately, not by default.
What satisfies buyers today?
Precise, documented answers on residency, operational access, keys, sub-processors, jurisdiction and exit.
Key takeaways
- Sovereignty questions are about access and jurisdiction, not only geography.
- Operational residency — who administers from where — is the most missed element.
- Answer the six underlying questions concretely; that unblocks deals now.
- Verify certification scheme status before contractual commitments.