Digital sovereignty · resilience roadmap
Digital sovereignty:
where do you start?
It's not read on a flag — it's in your architecture. CloudCompass maps the services you depend on and hands back a prioritized resilience roadmap: what to act on now, what to make portable, what to switch.
Your sovereignty roadmap
9 dependencies need action
across 14 mapped dependencies
- Act now3
- Build an exit option2
- Switch — easy win4
- Watch5
Start an exit programme now; it will take time, so begin early.
Reachable by the US CLOUD Act (listed on a US market) — authorities can compel disclosure regardless of where the data is hosted.
~70% of Europe's cloud runs on US hyperscalers — the real risk is the sensitive data inside that share
Not a score — a plan
A score tells you where you stand. A roadmap tells you what to do.
Each dependency is weighed on three things: whose law can reach it, how sensitive its data is, and how hard it would be to leave. It's not about ripping out every non-EU service — it's about spotting the ones that carry real risk, and moving just those.
Act now
These run sensitive data under non-EU jurisdiction — the combination that carries real exposure today. Easy-to-leave ones are quick wins; locked-in ones need an exit plan you should start now, even if it takes time.
Build an exit option
Hard to leave, and you may not have a full alternative yet (frontier AI is the classic case). You're not necessarily leaving — but make sure you could: prefer portable formats, agnostic approaches, avoid deepening the lock-in.
Switch — easy win
Low lock-in, and a mature European alternative exists. These are the cheapest sovereignty gains available to you.
Watch
Low stakes and low lock-in. No action needed now — we list them so nothing is invisible.
The goal isn't zero foreign tech — it's informed choices. Keep an exposed tool for public, low-stakes workloads; move the sensitive data to a sovereign option. It's a to-do list, not a score: the four tracks run in parallel, and there's no single finish line.
Identify → Assess → Act
Your roadmap in about five minutes.
No long survey. You recognize your tools from a list; we do the analysis.
Pick what you use
Walk a short list — email, cloud, identity, CRM — and choose your providers. Recognition, not a blank page. Start with the vital few and add more later.
We map the exposure
Each provider's effective jurisdiction and lock-in are derived from our catalogue; you confirm only what's sensitive. We state the facts — like the US CLOUD Act — and never grade a provider; that call is yours.
Get a prioritized roadmap
A board-ready plan: fix first, make portable, switch. Save it, re-assess as you act, and watch your exposure shrink over time.
Shared · tracked · benchmarked
One roadmap, your whole team, tracked over time.
Sovereignty is a journey, not a one-off score. Your assessment is saved to your organization — invite colleagues to work on it together, and re-run it to see progress as you act.
What your roadmap covers
The domains of your stack, mapped for sovereignty.
Nine functional domains — from identity and data to AI and infrastructure. It's inspired by the EU Cloud Sovereignty Framework — the reference the European Commission used to award its €180M sovereign-cloud tender — from which we borrow the category taxonomy, keeping only what an enterprise needs to act.
Learn about the framework