Skip to content

Sovereignty explained

BSI C3A for SaaS vendors

On 27 April 2026 the German Federal Office for Information Security (BSI) published C3A, the Criteria enabling Cloud Computing Autonomy. It makes cloud sovereignty assessable and is expected to show up in public procurement as eligibility or award criteria.

Six domains

C3A splits sovereignty into six domains. They match the first six objectives of the EU Cloud Sovereignty Framework.

Strategic sovereigntySOV-1 Strategic
Legal sovereigntySOV-2 Legal & jurisdictional
Data sovereigntySOV-3 Data & AI
Operational sovereigntySOV-4 Operational
Supply-chain sovereigntySOV-5 Supply chain
Technology sovereigntySOV-6 Technology

Each domain has basic and additional criteria, and the catalogue offers an EU level and a stricter German level.

C3A builds on C5

C3A conformity requires BSI C5 conformity first, and C5 is confirmed by an independent auditor. For most small and mid-sized SaaS vendors that is a longer project. Tenders ask sovereignty questions now, though, so vendors need a credible answer before an attestation exists.

What you can do today

  • List every provider in your data path with its controlling company and country. Buyers check this first.
  • Answer the six domains honestly and show evidence where you have it: resource regions, key control, subprocessor list, exit plan.
  • Name the gaps and your next steps. A known SEAL-1 with a plan beats an unverified claim.

The ScanComb Sovereignty Profile does exactly this and maps your answers to the C3A domains. It does not state C3A conformity.

Last reviewed 2026-09-29. Educational summary; the BSI C3A page is authoritative.