Digital sovereignty is not a new challenge. Organisations have long had to manage dependencies on technologies, providers and external infrastructures.
These dependencies can challenge digital sovereignty through six key risks: cyber vulnerability, operational disruption, kill switches, regulatory exposure, vendor lock in, and loss of expertise.
A wide range of governance instruments address different aspects of these risks. The following overview examines relevant regulations, standards, frameworks and assurance schemes and structures them according to whether they primarily address digital systems, organisations or ecosystems.
Governance Instruments for Digital Systems
These instruments focus primarily on individual IT systems, digital products, cloud services and technological infrastructures.
EUCS: European Cybersecurity Certification Scheme for Cloud Services
The EUCS is an assurance scheme targeting cloud security, first published as a draft candidate scheme by the European Union Agency for Cybersecurity (ENISA) in December 2020.
• Purpose: Establish uniform assurance of cloud service security.
• How it works: Defines security requirements and assurance levels for assessing cloud services under the European cybersecurity certification framework.
• Source: https://certification.enisa.europa.eu/publications/candidate-eucs-scheme-v10_en
BSI C5: Cloud Computing Compliance Criteria Catalogue
BSI C5 is an assurance scheme targeting cloud security, published by the German Federal Office for Information Security (BSI). The current major version, C5:2020, was published in 2020.
• Purpose: Provide auditable security criteria for cloud services.
• How it works: Defines criteria for assessing cloud service information security and enables independent assurance reporting on their implementation.
• Source: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/CloudComputing/ComplianceControlsCatalogue-Cloud_Computing-C5.html
BSI C3A: Cloud Computing Compliance Criteria Catalogue for Cloud Service Autonomy
BSI C3A is an assurance scheme targeting digital sovereignty and cloud autonomy, published by the German Federal Office for Information Security (BSI).
• Purpose: Assess cloud autonomy and digital sovereignty.
• How it works: Defines criteria for evaluating cloud service autonomy, dependencies, control capabilities and sovereignty related risks.
• Source: https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cloud-Computing/Kriterienkatalog-C5/C3A/C3A_node.html
CISPE Sovereign & Resilient Cloud Services Framework
The CISPE Sovereign & Resilient Cloud Services Framework is an assurance scheme targeting digital sovereignty and resilience, published by Cloud Infrastructure Services Providers in Europe (CISPE).
• Purpose: Assess and demonstrate cloud sovereignty and resilience.
• How it works: Defines auditable controls for assessing sovereign and resilient cloud services, including independent audit and certification paths.
• Source: https://sovereignty.cispe.cloud/
Sovereign Cloud Stack Scheme
Sovereign Cloud Stack is an assurance scheme targeting digital sovereignty, developed by the Sovereign Cloud Stack community. It combines a set of technical standards with a certification framework for cloud services.
• Purpose: Enable interoperable, open and sovereign cloud infrastructure.
• How it works: Combines technical cloud standards with conformity testing and certification to demonstrate compatibility, openness and sovereignty.
• Source: https://docs.scs.community/standards/
EU Cloud Sovereignty Framework
The EU Cloud Sovereignty Framework is a framework targeting digital sovereignty, developed by the European Commission for the assessment of sovereign cloud providers and used in EU cloud procurement. The Commission published detailed implementation guidance in June 2026.
• Purpose: Assess and compare the sovereignty of cloud services.
• How it works: Assesses providers across eight Sovereignty Objectives, 48 criteria and Sovereignty Effectiveness Assurance Levels from SEAL 0 to SEAL 4.
• Source: https://commission.europa.eu/news-and-media/news/sovereign-cloud-framework-explained-2026-06-01_en
European Sovereign Stack Standard (ES³)
The European Sovereign Stack Standard is an assurance scheme targeting digital sovereignty, introduced by Schwarz Digits in 2026.
• Purpose: Assess and compare the digital sovereignty of IT services.
• How it works: Uses defined sovereignty dimensions, a four stage maturity model and independent audits to assess sovereignty across the technology stack.
• Source: https://schwarz-digits.de/en/presse/archive/2026/european-sovereign-stack-standard
NIST Risk Management Framework
The NIST Risk Management Framework is a framework targeting cybersecurity and risk management, published by the US National Institute of Standards and Technology (NIST).
• Purpose: Manage security and privacy risks of information systems.
• How it works: Defines a lifecycle process for categorising systems and selecting, implementing, assessing, authorising and monitoring controls.
• Source: https://csrc.nist.gov/projects/risk-management/about-rmf
EU AI Act
The EU AI Act is a regulation targeting artificial intelligence, adopted by the European Union in 2024.
• Purpose: Manage AI risks and support trustworthy AI.
• How it works: Establishes risk based requirements for AI systems and obligations for providers, deployers and other actors.
• Source: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Cyber Resilience Act (CRA)
The Cyber Resilience Act is an EU regulation targeting cybersecurity, adopted in 2024.
• Purpose: Ensure cybersecurity throughout the lifecycle of products with digital elements.
• How it works: Establishes cybersecurity requirements for products and obligations for manufacturers and other economic operators.
• Source: https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Cybersecurity Act
The Cybersecurity Act is an EU regulation targeting cybersecurity, adopted in 2019.
• Purpose: Establish an EU wide cybersecurity certification framework.
• How it works: Creates the European framework for cybersecurity certification of ICT products, services and processes.
• Source: https://eur-lex.europa.eu/eli/reg/2019/881/oj
Governance Instruments for Organisations
These instruments focus primarily on the organisation itself.
BSI IT Grundschutz
BSI IT Grundschutz is an information security framework published by the German Federal Office for Information Security (BSI). Its methodology has been developed and continuously updated since the 1990s.
• Purpose: Systematically establish and maintain information security.
• How it works: Combines methodology, standards and safeguards for identifying and implementing appropriate security measures.
• Source: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html
NIST Cybersecurity Framework
The NIST Cybersecurity Framework is a cybersecurity framework published by the US National Institute of Standards and Technology. The first version was published in 2014.
• Purpose: Manage cybersecurity risks.
• How it works: Provides a common structure for understanding, assessing, prioritising and communicating cybersecurity activities and risks.
• Source: https://www.nist.gov/cyberframework
COBIT
COBIT is an IT governance framework developed by ISACA, first released in 1996.
• Purpose: Align and govern enterprise IT according to organisational objectives.
• How it works: Provides governance and management objectives for aligning information and technology with organisational goals.
• Source: https://www.isaca.org/resources/cobit
FAIR
FAIR is a risk management framework maintained by The Open Group and focused on quantitative information risk analysis.
• Purpose: Quantify information and cyber risks.
• How it works: Analyses risk through the frequency and magnitude of potential loss events, enabling financial comparison of risk scenarios.
• Source: https://www.opengroup.org/openfair
CIS Controls
The CIS Controls are a cybersecurity framework maintained by the Center for Internet Security.
• Purpose: Prioritise cybersecurity safeguards.
• How it works: Provides a prioritised set of practical safeguards designed to reduce common and significant cybersecurity risks.
• Source: https://www.cisecurity.org/controls
COSO Enterprise Risk Management
COSO ERM is an enterprise risk management framework published by the Committee of Sponsoring Organizations of the Treadway Commission. The original ERM framework was published in 2004 and substantially updated in 2017.
• Purpose: Integrate enterprise risk with strategy and performance.
• How it works: Provides principles for integrating risk management into governance, strategy and organisational decision making.
• Source: https://www.coso.org/enterprise-risk-management
OCTAVE
OCTAVE is an information security risk assessment methodology developed by Carnegie Mellon University's Software Engineering Institute, originally introduced around the turn of the 2000s.
• Purpose: Identify and prioritise information security risks.
• How it works: Uses an organisation centred assessment of critical assets, threats, vulnerabilities and potential risk responses.
• Source: https://www.sei.cmu.edu/library/octave-allegro-improving-the-information-security-risk-assessment-process/
GDPR: General Data Protection Regulation
The GDPR is an EU regulation targeting data protection, adopted in 2016 and applicable since May 2018.
• Purpose: Protect personal data and the rights of data subjects.
• How it works: Establishes rules, rights and obligations for the lawful and secure processing of personal data.
• Source: https://eur-lex.europa.eu/eli/reg/2016/679/oj
NIS2 Directive
NIS2 is an EU directive targeting cybersecurity and resilience, adopted in 2022.
• Purpose: Increase cybersecurity and resilience across important and essential sectors.
• How it works: Requires relevant organisations to implement cybersecurity risk management, governance and incident reporting measures.
• Source: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
DORA: Digital Operational Resilience Act
DORA is an EU regulation targeting digital operational resilience in the financial sector, adopted in 2022 and applicable since January 2025.
• Purpose: Strengthen digital operational resilience in financial services.
• How it works: Establishes requirements for ICT risk management, resilience testing, incident management and ICT third party risk.
• Source: https://eur-lex.europa.eu/eli/reg/2022/2554/oj
ISO/IEC 27001
ISO/IEC 27001 is an information security management standard published jointly by ISO and IEC. The current edition was published in 2022.
• Purpose: Establish an information security management system.
• How it works: Defines requirements for establishing, implementing, maintaining and continually improving an ISMS.
• Source: https://www.iso.org/standard/27001
ISO/IEC 27005
ISO/IEC 27005 is a risk management standard published jointly by ISO and IEC. The current edition was published in 2022.
• Purpose: Manage information security risks systematically.
• How it works: Provides guidance for identifying, analysing, evaluating, treating and monitoring information security risks.
• Source: https://www.iso.org/standard/80585.html
ISO 31000
ISO 31000 is a general risk management standard published by ISO. The current edition was published in 2018.
• Purpose: Manage organisational risks systematically.
• How it works: Provides principles and guidelines for integrating risk management into governance, strategy and decision making.
• Source: https://www.iso.org/standard/65694.html
ISO/IEC 42001
ISO/IEC 42001 is an AI governance standard published jointly by ISO and IEC in 2023.
• Purpose: Establish a management system for responsible AI.
• How it works: Defines requirements for establishing, implementing, maintaining and continually improving an AI management system.
• Source: https://www.iso.org/standard/42001
ISO/IEC TS 10866:2024
ISO/IEC TS 10866 is a technical specification targeting digital sovereignty and organisational autonomy, published jointly by ISO and IEC in 2024.
• Purpose: Address organisational autonomy and digital sovereignty systematically.
• How it works: Provides concepts and a framework for examining digital sovereignty, organisational autonomy and the use of digital platforms.
• Source: https://www.iso.org/standard/83757.html
Governance Instruments for Ecosystems
Gaia X Trust Framework
The Gaia X Trust Framework is a framework for trust, interoperability and digital sovereignty in data and cloud ecosystems, published and maintained by Gaia X.
• Purpose: Enable trustworthy and interoperable digital ecosystems.
• How it works: Defines trust and compliance requirements for participants, services and resources using common rules and machine readable descriptions.
• Source: https://docs.gaia-x.eu/technical-committee/architecture-document/latest/trust_framework_architecture/
Data Act
The Data Act is an EU regulation targeting access to and use of data, adopted in 2023 and applicable from September 2025.
• Purpose: Enable fair data access, use and switching.
• How it works: Establishes rights and obligations for accessing and using data and introduces requirements facilitating switching between data processing services.
• Source: https://eur-lex.europa.eu/eli/reg/2023/2854/oj
Data Governance Act
The Data Governance Act is an EU regulation targeting data sharing and data governance, adopted in 2022 and applicable since September 2023.
• Purpose: Promote trustworthy data sharing.
• How it works: Establishes governance mechanisms for data intermediation, data altruism and the reuse of certain protected public sector data.
• Source: https://eur-lex.europa.eu/eli/reg/2022/868/oj
What Does the Governance Landscape Tell Us?
We identified 29 governance instruments relevant to digital sovereignty and its underlying risks. Of these, 15 primarily address organisations, 11 digital systems and 3 ecosystems. The landscape consists of 10 frameworks, 8 regulations, 6 assurance schemes and 5 standards or specifications.
Only 7 of them explicitly address digital sovereignty in the narrower sense. Most deal instead with individual aspects of the problem, such as cybersecurity, resilience, data protection, risk management or IT governance.
Among the instruments that explicitly address digital sovereignty, however, a pattern emerges: control dominates. Sovereignty is typically strengthened by increasing control over data, technology, operations and jurisdiction, reducing external dependencies, improving portability and preserving the ability to switch providers.
This is a particular understanding of digital sovereignty: more control and fewer dependencies mean more sovereignty. As discussed in our analysis of the control problem of digital sovereignty, this can conflict with how organisations actually make technology decisions. They do not optimise for sovereignty alone, but balance control against capabilities, costs and other risks.
One instrument stands out: ISO/IEC TS 10866:2024. Rather than starting with maximum control, it starts with organisational objectives, risks and risk appetite and derives the required degree of autonomy from them. This makes sovereignty a risk based trade off rather than an objective to maximise.






