“More sovereign” is not a useful technology strategy, particularly for organizations that have a mission to fulfil beyond controlling their technology. A simple example illustrates the dilemma.
The German Chancellery operates a pneumatic tube system that moves around 1,000 documents each month through 36 stations for roughly €15,000 a year. It has almost no remote interception surface and no external software provider with a digital kill switch. By many definitions used in today’s debate, it is remarkably sovereign. But would we recommend solutions like this to scale across the tech stack of European organizations?
With the Sovereignty Calculus, cloud ahead aims to make this dilemma manageable. Rather than treating sovereignty as something to maximize, the model treats it as a continuous optimization problem across risk, cost and capability, shaped by an organization’s strategic requirements and technical maturity.
This logic is also reflected in ISO/IEC TS 10866, an internationally agreed Technical Specification on organizational autonomy and digital sovereignty that is now being developed into an ISO/IEC International Standard. It similarly starts with organizational objectives and determines the appropriate degree of autonomy under constraints such as funding, skills and time to market.
Sovereignty is a means, not a goal
The model begins with a simple observation: the value and the risks of the global technology stack come from reusing technology that somebody else has invested in, built and deployed. Organizations gain access to capabilities, reliability and scale without having to recreate the investment behind them. Today’s frontier LLMs are a prime example of this two-sided coin: a company can access a frontier model through an API without investing billions in models and compute, just as it can operate globally on cloud infrastructure without building data centers around the world. Removing such dependencies may reduce sovereignty risks, but it may also destroy the value that made those dependencies attractive in the first place.
There are many ways to mitigate the risks that come with using the global tech stack: open source, multi-cloud, hybrid cloud, insourcing, encryption or even outsourcing to specialist providers. But each comes with trade-offs.
- Risk Trade-Off: Insourcing cloud infrastructure reduces kill-switch exposure, but may increase cyber vulnerability and operational disruption if the necessary internal expertise and redundancy are missing.
- Mitigation Trade-Off: Moving from a specialist cloud to self-operated OpenStack requires additional investment and increases the cost of change, while reducing access to managed services, integration and frontier technologies.
- Moving Baseline: An application considered secure today may become vulnerable to the next generation of LLMs, while one considered deeply vendor-locked may become much easier to replace.
Digital sovereignty is therefore not a goal in itself, but a means to protect an organization’s mission through a continuous optimization of risk, cost and capability.
Three dimensions under permanent tension
Following this insight, the Sovereignty Calculus evaluates every technology posture and proposed change across three dimensions: Risk, Cost and Capability. The triangle makes the trade-offs visible, while each dimension contains a more detailed portfolio.

Related to digital sovereignty, there are six distinct risk categories: cyber vulnerability, operational disruption, loss of expertise, regulatory exposure, kill switch and vendor lock-in.
Cost includes the investment required before a capability can be used, the marginal cost of additional usage, the recurring run cost, the cost of change, and opportunity cost.
Capability describes what the technology stack enables the organization to do: the breadth of services available, their performance and integration, the scale they can support, and how quickly new frontier technologies can be adopted.
Strategic Requirements define where an organization should sit in the triangle to fulfil its mission. They determine which risks matter, which costs are acceptable and which capabilities are essential. Technical Maturity determines how easily an organization can reach and maintain its target position. A degree of maturity comes with the ability to Run the current technology environment reliably and economically, Change it quickly and efficiently, and Adopt emerging technology generations across technology, processes, organization and business models easily.

Together, the three dimensions and two contextual variables make Sovereignty actionable. Strategic Requirements define the target position; Technical Maturity determines which positions and transition paths are realistically accessible; and Risk, Cost and Capability provide the criteria for evaluating the available options.
The same calculus, different answers
There is no universally sovereign technology setup, but there are individually successful degrees of organizational autonomy. What is rational depends on an organization’s Strategic Requirements and Technical Maturity. Four very different organizations illustrate this.
37signals: Make more yourself
37signals is a small, profitable and self-funded SaaS company behind Basecamp and HEY. Its business philosophy emphasizes independence, profitability and deliberately avoiding unnecessary complexity (37signals; Profit). Its workloads are relatively stable and cost discipline is central to its business model (DHH). At the same time, it has exceptionally high Technical Maturity, with the same relatively small engineering team able to operate its applications both in AWS and on its own infrastructure (DHH).
That combination made leaving AWS rational. 37signals bought its own Dell servers and moved its applications into two geographically separated colocation data centers (DHH). Its cloud spending had been around $3.2 million per year; after the exit, the remaining cloud bill fell to around $1.3 million, producing savings of almost $2 million per year (DHH). The migration did not require additional operations staff, and all major applications maintained at least 99.99% uptime during the migration year (DHH; Uptime).
Calculus: Moderate risk + strong cost focus + modest capability requirements + very high technical maturity → more independence becomes economically rational.
Sennheiser: Buy infrastructure, own differentiation
Sennheiser is a global professional audio manufacturer whose differentiation increasingly depends on combining hardware, software and connected services (Sennheiser Annual Report; DeviceHub). Its business is already exposed globally, with activities and customers across Europe, the US and China (Sennheiser Global). Reducing US technology dependencies alone would therefore only address one part of its broader international exposure.
Rebuilding generic cloud infrastructure would meanwhile consume money and engineering capacity without differentiating Sennheiser’s products. Instead, Sennheiser uses Microsoft Azure for its DeviceHub infrastructure, including Azure IoT Hub, identity and data services, while retaining responsibility for its products, architecture and security (Sennheiser Cloud Documentation; Security & Data). Its cloud platform supports centralized management of connected devices across locations and regions (DeviceHub Documentation).
Calculus: Broad existing risk exposure + high opportunity cost + high capability requirements + sufficient technical maturity → target sovereignty investments in technical resilience, enterprise architecture and security.
Parloa: Frontier access over independence
Parloa is a Berlin-based AI company building AI agents for enterprise customer service (Parloa; Series C). Its competitive position depends directly on rapid AI development and deployment. Capability requirements are therefore extreme: frontier adoption, enterprise scale, multiple channels and global growth (Platform; Series D). Cost matters, but with more than $560 million raised, investment is primarily directed toward global expansion and product development rather than minimizing infrastructure dependency (Series D).
Its Technical Maturity is correspondingly high. Parloa has repeatedly adapted its architecture as conversational AI evolved, recently replacing channel-specific logic with a shared Conversational Platform across voice and web experiences (Conversational Platform).
Calculus: High operational risk + growth-oriented cost profile + extreme capability requirements + high technical maturity → preserve freedom of action rather than optimize for technological independence.
DRV Bund: Capability with a sovereign fallback
Deutsche Rentenversicherung Bund is Germany’s largest statutory pension insurance institution and operates a large and complex IT environment under a public mandate (DRV Bund; IT Landscape). Operational disruption, cyber vulnerability and geopolitical kill-switch exposure therefore carry much greater strategic weight. Its own digital strategy accordingly emphasizes security, economic efficiency and highly available IT systems (Digital Strategy).
Yet simply replacing its Microsoft environment with openDesk would impose substantial capability and change-cost trade-offs. Instead, DRV Bund has tested openDesk specifically as an emergency workplace for situations in which normal communication and collaboration systems become unavailable. The project operated four independent openDesk instances across different cloud infrastructures, together with IONOS, STACKIT and T-Systems, and successfully tested files, chat, email and videoconferencing under real-world business-continuity scenarios (DRV Bund / ZenDiS). DRV Bund meanwhile continues to use and invest in Microsoft cloud services (Microsoft Cloud). In a crisis, the workplace can therefore degrade in capability rather than becoming unavailable altogether.
Calculus: High risk requirements + constrained cost + substantial capability needs + legacy-shaped technical maturity → use global technology, but protect the critical mission through graceful degradation.
Sovereignty Calculus De-Ideologizes the Debate
The sovereignty debate often treats two positions as ideological opposites. One defines sovereignty as independence: controlling technology and minimizing external reliance. The other defines it as freedom of action: retaining autonomous choices while continuing to use global providers.
The Sovereignty Calculus does not decide which definition is correct. Strategic Requirements determine which degree of autonomy is appropriate for an organization’s mission, while the Risk dimension forces it to specify what it is actually trying to protect against: cyber vulnerability, operational disruption, loss of expertise, regulatory exposure, kill switch or vendor lock-in.
Not every organization needs to apply the model in its full depth. Its main purpose is to take ideology out of technology decisions for organizations whose mission is not simply to maximize control over IT and that operate under real economic and capability constraints. Rather than judging one political understanding of sovereignty as right or wrong, the Calculus asks a more practical question: Given this organization, its mission, its risks and its constraints today, what sovereignty posture is actually rational and achievable?







