During the coronavirus pandemic, many organisations discovered just how vulnerable international supply chains could be. It suddenly became clear how dependent businesses were on suppliers on the other side of the world. That experience has permanently changed the way we think about production and supply. Today, a similar shift is taking place in IT. The geopolitical context is prompting organisations to take a more critical look at their dependence on cloud platforms and suppliers based outside the European Union. Cloud sovereignty is, therefore, becoming a strategic priority.
Organisations want to know exactly how much control they have over their digital environment and which dependencies play a role in that. While the technology itself has remained largely the same, the context in which organisations use that technology has fundamentally changed. The central question is actually a simple one: how much control do you really have over your cloud environment? Who has access to your data? Which legislation applies? And will everything keep running if an external supplier were to suddenly shut down operations?
This is why more and more organisations are looking for an objective way to assess their digital independence.
What is the European Cloud Sovereignty Framework?
Organisations often use ‘cloud sovereignty’ as a catch-all term with no true standard. One supplier emphasises the location of the data, for example, while another focuses on legislation, security or operational control.
To provide more clarity and uniformity, the European Commission developed the Cloud Sovereignty Framework. This framework offers an objective assessment methodology that organisations can use to evaluate the digital independence of a cloud environment.
The framework assesses a cloud environment against 48 criteria, spread across eight domains: strategic sovereignty, legal sovereignty, data sovereignty, operational sovereignty, supply chain sovereignty, technology sovereignty, security compliance sovereignty, and environmental sustainability. These criteria assess how much control an organisation retains over its cloud environment. For the first time, this creates a common benchmark that organisations can use to consistently assess their cloud environment.
What does SEAL-2 mean for cloud sovereignty?
Based on that assessment, the framework awards a Sovereignty Effectiveness Assurance Level (SEAL). SEAL-2 is the level at which a cloud environment can operate independently, even when it uses technology from suppliers outside the European Union. Cheops's cloud environment was assessed against this European framework and meets the SEAL-2 requirements.
Meeting the SEAL-2 requirements does not mean that all hardware and software used has to be European. Athough several European alternatives exist for software, they are not equally mature. For hardware, the choice is even more limited. There are few European suppliers that offer a fully-fledged alternative to the major international players. This means organisations will continue to use non-European technology.
The emphasis lies on control over the cloud environment. Where the technology originates plays a smaller role. That control breaks down into two key concepts: data sovereignty and operational sovereignty. Data sovereignty determines where data is stored, which legislation it falls under, and who has access to it. Operational sovereignty defines who manages the infrastructure and whether service delivery continues to function when a supplier is temporarily unavailable. In practice, these two aspects determine the largest part of the score, since full technological independence is not yet achievable today.
Why data residency is only one part of cloud sovereignty
When organisations talk about cloud sovereignty, the conversation often focuses solely on where the data is located. The European framework deliberately takes a much broader view. The following elements also help determine the final score:
- Which legislation does the cloud environment fall under?
- Who has access to the data?
- How dependent are you on suppliers outside the European Union?
- Does your cloud environment remain operational when an external supplier is temporarily unavailable?
This broader approach aligns much better with the challenges organisations face today. Digital independence is, after all, the result of both legal and operational choices.

How Cheops's sovereign cloud meets SEAL-2
Cheops decided to carry out an extensive self-assessment to review its entire cloud environment against the European framework. That exercise confirmed that the environment meets the SEAL-2 requirements. For customers, this provides extra assurance. Organisations that deliberately choose a sovereign cloud know they can turn to Cheops for that.
This score is not the result of recent changes made to comply with the framework. It stems from choices Cheops has consistently made for years.
This approach is further confirmed by external certifications. Cheops has obtained the ISO 27001 certificate for its complete information security, as well as the NIS2 Label for Essential Companies – the highest level within the European NIS2 directive for organisations that are essential to the economy. Both demonstrate that Cheops's operational sovereignty is not based solely on its own assessment, but has also been independently verified.
The cloud runs on Cheops's own hardware in Belgian data centres and falls under Belgian law. Day-to-day management is carried out by Cheops's own staff. Customers do not get an anonymous support platform or an international helpdesk, but direct access to the specialists who manage their environment. When a problem arises, they know exactly who to call. This proximity means Cheops customers never get lost in complex escalation procedures, but can reach specialists directly – in their own language and time zone – who know their environment inside out.
This proximity marks an important distinction compared with larger international cloud environments. Cheops combines the scale and expertise of a managed service provider with local service delivery, giving customers direct contact with the specialists who know their environment.
Like most managed service providers, Cheops also makes use of technology from international suppliers. The difference, however, lies in operational control. That remains entirely in-house. As a result, the cloud environment continues to function independently, even when a supplier is temporarily unable to provide support.
This local approach also appeals to organisations with business-critical IT environments. , for example, has relied on Cheops for its cloud and data centre services for more than fifteen years. This long-standing partnership is built on the same principles that lie at the heart of the European framework: continuity, operational control, and a local partner that knows the environment inside out.

Cloud sovereignty as a strategic choice
The question of SEAL-2 level is increasingly common in tenders. Several recent tenders already included criteria relating to digital independence, particularly among organisations that fall under regulations such as NIS2 and DORA.
For the first time, the European Cloud Sovereignty Framework offers organisations an objective way to assess their digital independence. Cloud sovereignty is shifting from an abstract concept to a concrete strategic consideration in which control and continuity matter just as much as the location of the data.
Would you like to know whether a sovereign cloud would meet your organisation's needs?
Get in touch with our Cheops experts for a no-obligation chat about your cloud strategy and digital independence.