Cloud sovereignty assessment
Where does your provider sit on the Cloud Sovereignty Framework?
An official framework
This assessment is based on the Cloud Sovereignty Framework (CSF) published by the European Commission.
It evaluates eight objectives, rated on the SEAL scale (Sovereignty Effectiveness Assurance Levels), which runs from SEAL-0 (no sovereignty) to SEAL-4 (a full EU supply chain, from chips to software).
The rule is the weakest link: your overall level is that of your most exposed objective.
Strategic control
Legal and jurisdictional protection
Operational resilience
Supply chain transparency
Technological openness
Security
Compliance with European Union law
Environmental sustainability
Proof from the market
In April 2026, the European Commission awarded its first sovereign cloud contract, scoring each bidder against this same framework. Within the Schengen Cloud Alliance consortium (DEEP (POST Telecom, Luxembourg), OVHcloud and Clever Cloud), Clever Cloud reached SEAL-3, the highest level awarded in this procurement: services and operations deemed immune to a supply disruption caused by a third party outside the European Union. The minimum threshold required to be eligible was only SEAL-2.
Source : European Commission press release, 17 April 2026.
What you get
This assessment is a simplified version of the Cloud Sovereignty Framework. It gives an order of magnitude, an indication of what your actual level might be, and does not constitute an official or certified evaluation.
At the end of the questionnaire, your result appears on screen immediately: you get an estimate of your overall SEAL level, together with an objective-by-objective reading that highlights your most sensitive points of dependency.
Who is it for?
This tool is aimed at IT leaders (CIOs), information security officers (CISOs) and executives (CEOs, general management) who want a quick view of their organization’s level of dependency, without going into technical detail. Two profiles of organization are concerned. On one hand, companies in regulated sectors : finance (DORA), healthcare (HDS), critical infrastructure (NIS2), subject to compliance obligations and to audits of their digital supply chain. On the other, unregulated companies targeting the European public sector, where the sovereignty framework now serves as a contract award criterion. In both cases, a poorly identified dependency becomes a documented risk.
Your data stays with you
No data shared with third parties, no cookies set. The assessment is free and requires no sign-up: you get your result without leaving an email address.