Brussels Publishes Its First Sovereignty Scorecard

The European Commission awarded the first contracts under its new Cloud Sovereignty Framework on 17 April 2026, a EUR 180 million procurement framework running six years under the Commission's Cloud III Dynamic Purchasing System, launched in October 2025 according to Help Net Security's reporting. The award introduced a graded rating scale called SEAL, for Sovereignty Effectiveness Assurance Level, running from SEAL-0 to SEAL-4, where SEAL-0 marks a complete lack of sovereignty and SEAL-4 requires a full EU supply chain from chips to software.

Providers had to clear SEAL-2, described by the Commission as a Data Sovereignty level, simply to qualify for a contract at all. That floor matters because it replaces a vague, self-declared claim of being sovereign with a specific bar every bidder had to clear before Brussels would even consider its bid, evaluated across eight weighted objectives spanning strategy, legal protection, operational control, environmental responsibility, supply chain transparency, technological openness, security and compliance with EU law.

Four Winners, Two Different Sovereignty Tiers

Four consortia cleared the bar and now hold contracts under the framework, each anchored in a different EU country and each landing at a different SEAL level. Post Telecom, based in Luxembourg, won together with France's OVHcloud and CleverCloud; Germany's STACKIT, owned by the Schwarz Group that also owns Lidl and Kaufland, won on its own; France's Scaleway, owned by Iliad, won on its own; and a Belgian-led consortium built around Proximus, S3NS, Clarence and the French AI company Mistral AI won the fourth contract.

ConsortiumHome countrySEAL level reached
Post Telecom with OVHcloud and CleverCloudLuxembourg / FranceSEAL-3
STACKIT (Schwarz Group)GermanySEAL-3
Scaleway (Iliad)FranceSEAL-3
Proximus with S3NS, Clarence and Mistral AIBelgium / FranceSEAL-2

Post Telecom, STACKIT and Scaleway all reached SEAL-3, the level the Commission defines as immune from disruption in a non-EU supply chain. The Proximus-led consortium reached SEAL-2, the qualifying floor itself, reflecting that its underlying technical environment draws on Google Cloud infrastructure even though every operating company in the chain is EU-based.

A Shortlist to Buy From Today, Not a Promise for Later

Most EU sovereignty policy up to this point has stayed at the level of a target date or a strategy paper. This framework is different: it names four specific vendors, tells you which sovereignty tier each cleared, and lets any EU business currently evaluating exposure to the US CLOUD Act or a future geopolitical disruption to cloud access shop from a graded, citable shortlist starting now.

That immediacy is the real story here, not the procurement mechanics. A business worried about a foreign government compelling access to its cloud data no longer has to wait for a future compliance regime to tell it who qualifies; it can point at STACKIT, Scaleway, the OVHcloud-led Post Telecom consortium or the Mistral-AI-linked Proximus group and ask each one, directly, which SEAL level it can actually document.

The SEAL-2/SEAL-3 Gap Is the Real Procurement Signal

Three of the four winners cleared SEAL-3 while one cleared only SEAL-2, and the Commission drew that line itself rather than leaving it to marketing copy. A vendor calling itself sovereign is now making a claim at one specific level on a five-step scale, and the gap between SEAL-2 and SEAL-3 marks the difference between data sovereignty and genuine immunity from non-EU supply-chain disruption.

Any procurement team weighing a cloud contract should treat that gap as a question to put to its own vendor, sovereign-labeled or not: which SEAL level would you actually clear, and against which of the eight weighted objectives would you fall short. The Commission has now shown that question has a concrete, gradable answer, not a marketing one.