Sovereignty explained
The EU Cloud Sovereignty Framework, for SaaS vendors
The European Commission uses the Cloud Sovereignty Framework to compare cloud offers in its own procurement. It scores eight sovereignty objectives on an assurance scale called SEAL. Public buyers are starting to ask their SaaS vendors the same questions.
The eight objectives and their weights
Supply chain weighs most: control over the providers and components you depend on is the hardest dependency to replace.
SEAL levels 0 to 4
SEAL stands for Sovereignty Effective Assurance Level. Each objective gets a level.
- SEAL-0 · No sovereignty
- The service or technology is under exclusive non-EU control.
- SEAL-1 · Jurisdictional
- EU law applies, but non-EU control or access remains possible.
- SEAL-2 · Data sovereignty
- EU law applies and is enforceable; material non-EU dependencies remain.
- SEAL-3 · Digital resilience
- EU actors hold strong influence; non-EU dependencies are limited.
- SEAL-4 · Full digital sovereignty
- Technology and operations are under full EU control.
What it means for a SaaS product
- Your level is mostly inherited from your stack. A US-controlled hyperscaler, CDN or email service keeps the legal and supply-chain objectives low, even in an EU region.
- Data residency alone does not reach the top levels. Key control, EU-based operations and a tested exit plan do.
- Buyers look at the weakest objective as well as the average. One open door is enough to fail a requirement.
How ScanComb applies it
The Sovereignty Profile asks 18 questions across the eight objectives. Each answer maps to a SEAL level, an objective takes its weakest answer, and the score uses the weights above. Public signals and WardBee cloud evidence lower answers they contradict. The result is a self-assessment with checked claims, not an official rating.
Last reviewed 2026-09-29. Educational summary; the Commission's framework document is authoritative.


