How to Apply the Sovereignty Calculus

 | 
31.08.2026
 | 
6 min read
Featured Image

The Sovereignty Calculus provides a decision model for balancing sovereignty risk, cost and capability. This article turns the model into a practical approach for assessing the current posture, defining a rational sovereignty ambition and translating it into action.

The approach follows the logic of ISO/IEC TS 10866, the internationally agreed Technical Specification on organizational autonomy and digital sovereignty that is now being developed into an ISO/IEC International Standard.

Scope of This Methodology

This approach is made for organizations with these prerequisites: 

  • Brownfield: The actor already has and uses an established technology stack, with accumulated investments, dependencies, skills and processes.
  • Technology is instrumental: The actor’s mission is something other than owning or controlling its technology stack. Technology exists to support that mission.
  • Global stack as starting point: The existing stack reflects ordinary use of globally available technologies and providers, with the capabilities and dependencies that come with them.

The objective is therefore not to design an ideal sovereign stack, but to determine how an existing technology posture should evolve to better protect the actor’s mission without losing sight of cost and capability.

The Sovereignty Loop

The methodology follows an iterative loop. Each step adds information that may require revisiting earlier assumptions until mission, sovereignty requirements and their economic and technological implications form a coherent whole.

Define Mission & Stress Scenarios

Start with the organization’s mission and the capabilities required to fulfil it. Then define the stress scenarios under which these capabilities must remain available. These scenarios translate abstract sovereignty concerns into concrete requirements.

Assess Current Posture & Gaps

Assess the existing technology posture across risk, cost and capability. Test it against the defined stress scenarios to understand where the current setup already meets the requirements and where material gaps remain.

Model Mitigations & Optimize

For each material gap, model alternative ways to close it and assess their effects on risk, cost and capability. Options may include open source, insourcing, architectural changes or investments in technical maturity. The results should make the underlying trade-offs transparent for top management.

The loop continues where the analysis reveals conflicts between sovereignty requirements and their economic or technological consequences. This may require different mitigations, greater investment, changes in technical maturity or a reconsideration of the original mission requirements and stress scenarios.

Setting the Sovereignty Target Posture

The loop ends when top management has enough information to reconcile the desired sovereignty posture with its economic, technological and organizational consequences. For each material gap, management has four basic choices:

  • Accept: Accept the remaining sovereignty risk and continue with the current setup.
  • Invest in Mitigations: Define the required risk reduction and provide RiskOps with the budget and capability guardrails to achieve it.
  • Invest in Maturity: Improve technical or organizational maturity where this makes mitigation more effective or economical.
  • Adapt Mission & Requirements: Adjust business requirements or stress scenarios where the desired level of sovereignty would require disproportionate cost or capability sacrifices.

The result is an agreed Sovereignty Target Posture that defines what the organization wants to achieve, which risks it accepts, and what resources and constraints apply. This becomes the mandate for implementation through RiskOps.

Responsibilities in the Sovereignty Loop

The Sovereignty Calculus deliberately separates strategic accountability from technical analysis. Neither top management nor the working level can run the Calculus alone. Their responsibilities follow the three steps of the Sovereignty Loop.

  • Define Mission & Stress Scenarios. Top management takes the lead. It defines the mission, determines which stress scenarios matter and thereby sets the Strategic Requirements.
  • Assess Current Posture & Gaps. The working level, for example Enterprise Architecture, Product and Security, assesses the existing technology landscape against these requirements. The result is a view of the Sovereignty Posture & Gaps.
  • Model Mitigations & Optimize. The working level then develops and compares mitigation options, involving Finance and Procurement where needed. Its role is not to make the strategic trade-off, but to provide Mitigation Options & Sovereignty Advice that make the consequences transparent.
  • Reconcile & Decide. Top management reviews the mitigation options against business priorities and available resources. It either adjusts the mission requirements, stress scenarios, priorities or resources and starts another iteration of the Sovereignty Loop, or defines the Sovereignty Target Posture once a coherent balance has been reached.

This exchange is deliberately iterative: management must either adapt its sovereignty expectations to technical and economic reality or adapt priorities and resources to meet those expectations.

Operationalizing the Target Posture

Once the Sovereignty Target Posture is agreed, the question shifts from how sovereign the organization wants to be to how the agreed target can be achieved most efficiently. This is where RiskOps takes over. Similar to how DevOps integrates development and operations and FinOps continuously optimizes cloud economics, RiskOps continuously manages sovereignty risks within defined cost and capability constraints.

The Sovereignty Target Posture provides the mandate for RiskOps, defined through four parameters:

  • Risk targets: which exposures need to be reduced
  • Budgets: how much the organization is willing to spend
  • Capability guardrails: which technical capabilities must be preserved
  • Maturity objectives: which organizational and expertise capabilities need to improve

Within these constraints, RiskOps continuously identifies, prioritizes and implements the most efficient mitigations.

Keeping the Sovereignty Target Posture Current

The Sovereignty Calculus is not a one-time exercise. Risks, costs, available technologies, technical maturity and the organization’s mission change over time. The Sovereignty Loop should therefore be repeated periodically, for example as part of the annual technology strategy, and event-driven, when material new risks, regulations, technologies or business requirements emerge.

Each iteration starts from the new current posture, including mitigations implemented and maturity improvements achieved through RiskOps. This may change both what is possible and what is economically reasonable.

The objective is not to reach a final sovereign state, but to maintain and expand an economically viable sovereignty posture over time.

Implementation Remarks

A few practical lessons make the Sovereignty Calculus more useful in practice.

Run the loop at least twice. The first iteration will usually expose inconsistencies between mission, stress scenarios, technological reality and acceptable cost. The second iteration (or subsequent ones) is where these elements start to form a coherent Sovereignty Target.

Constrain scenarios early. Almost anything is technically possible, and almost any risk is imaginable. Unless management narrows down which scenarios actually matter, the analysis quickly becomes endless and economically meaningless.

Do not underestimate technical maturity. Greater technical maturity can make sovereignty substantially cheaper. But achieving it often requires expertise and organizational change beyond IT and therefore needs management attention and investment.

Aim for Sovereignty Consciousness. Doing nothing can be a perfectly rational outcome. The Calculus may confirm that the current posture is appropriate and the remaining risks should be accepted. The important difference is Sovereignty Consciousness: dependencies and risks are understood, assessed and deliberately accepted rather than simply inherited. This may give a decisive advantage as soon as the risks may materially change, for example by geopolitical events.

As sovereignty is often won or lost when technology platforms change, the sovereignty calculus especially recommends to be aware of regularly happening platform changes. Once technologies are mature and deeply embedded, reducing dependencies becomes expensive and capability trade-offs increase. The best economic opportunities therefore arise during technology transitions, when architectures, vendors and standards are still in flux. These transitions provide an opportunity not only to reduce old dependencies, but also to build new businesses and positions of strength.

Toward a Common ISO/IEC Standard

The approach also aligns with ISO/IEC TS 10866:2024, which similarly starts from organizational objectives and balances autonomy and sovereignty requirements with organizational constraints. The technical specification is currently being developed into ISO/IEC 10866, an International Standard.

The resulting standard could provide organizations with a common normative basis for applying approaches such as the Sovereignty Calculus. It may eventually also support conformity assessment or certification, depending on whether the final standard contains auditable requirements and an appropriate certification scheme is established.

Our latest articles in your inbox.

Don’t miss out on any news about the sovereign cloud.

You can find information on the use of the delivery service provider Brevo, the logging of logins and your right of withdrawal in our privacy policy.

Contents
Contact
Social
cloudahead Ki Park Logo