Eraneos surveyed leading European IT service providers and system integrators on the state of digital sovereignty in their offerings, roadmaps, and client conversations. The findings confirm that sovereign IT has become a strategic priority across the industry, but they also reveal a structural gap with real consequences for every organization that relies on these providers.
90%
see a clear gap in US hyperscaler
"sovereign" offerings
46%
already have a live or fully
realized sovereign IT offering
64%
offer auditability & data access
guarantees only on request
83%
not yet fully committed to
European sovereignty initiatives
These are our Key Findings:
US hyperscaler sovereign offerings are widely seen as inadequate, yet they remain the default
Sovereign IT services exist, but client demand drives them, not provider strategy
Auditability and data access guarantees exist, but they are not the default
Broad participation in European sovereignty initiatives, but limited real commitment
The barriers are structural, but regulation is removing them
The structural gap: supply versus demand
The survey shows a market in transition, but not yet aligned. IT service providers are responding, but reactively, held back by their dependence on hyperscalers and shaped mainly by client demand. There is still a real gap between what sovereign IT should deliver and what is actually available today.
What the market needs
- Sovereign controls built in by design, not on request
- Independent auditability as a standard part of every contract
- Genuine EU-governed alternatives to hyperscaler infrastructure
- Transparent data access and protection from US CLOUD Act overreach
- Exit assistance and switching support as standard
What is available today
- Sovereignty features available only on request
- Auditability provided reactively, not built in
- Most offerings still built on US hyperscaler infrastructure
- CLOUD Act exposure not systematically addressed
- EU Data Act compliance still being worked out
The core conclusion: the ball is in your court
“IT service providers respond to market demand and to the infrastructure their solutions are built on. If clients do not ask for sovereign controls, these will not become the standard. Responsibility for cloud sovereignty lies with the organizations using these services.”
The takeaway is clear: providers are not holding back out of indifference. They do deliver sovereignty features, but only when specifically asked. Without explicit requirements in procurement, contracts, and governance, providers fall back on business as usual: US hyperscaler infrastructure with sovereignty labels that often do not hold up under scrutiny.
The regulatory landscape is shifting fast. DORA is already in effect. The Data Act’s switching rules are being rolled out. The EU Cloud Sovereignty Framework uses a maturity scale called SEAL to benchmark providers. New rules from the Dutch position paper and CADA are coming. Organizations that wait for providers to raise the bar on their own will find themselves overtaken by compliance requirements, exposed to risks they never managed.
What this means for procurement and governance
Sovereign IT cannot be delegated or assumed to be taken care of. The survey makes it clear that providers respond to explicit demand, not to anticipated needs. If your RFPs do not specify sovereignty requirements, your contracts do not require exit assistance, and your governance does not track concentration risk, you are not sovereign, no matter what your provider claims.
Taking charge: a six-step action plan for sovereignty
Eraneos has developed a practical six-step plan to help organizations move from passive cloud consumers to active owners of their digital sovereignty. Each step adds value whether you plan to migrate, stay, or take a hybrid approach.
Step 1: Map your cloud applications and dependencies
Step 2: Run a scenario-based risk analysis and calculate your total cost of exit
Step 3: Formalize your transition strategy
Step 4: Build a future-proof sourcing strategy
Step 5: Embed sovereignty into ongoing governance
Step 6: Establish and maintain control over where your data lives
Why this plan works
Step 1 closes the visibility gap that lets hyperscaler dependency grow unchecked. Step 2 makes the cost of inaction concrete and easy to bring to the board. Step 4 translates sovereignty requirements into procurement language that providers actually respond to. Step 6 addresses the CLOUD Act exposure that 90% of surveyed providers acknowledge but few are resolving by contract. Together, these six steps give organizations the tools to send the demand signal that changes supplier behavior.
Conclusion
The Eraneos IT sovereignty survey is clear: the market is evolving, but true sovereignty is still not the default. The right capabilities exist and are growing, but they only get deployed when clients ask for them. The initiative lies with client organizations, not with providers.
The good news: proven tools are available, the regulatory direction is clear, and acting early is cheaper than being forced to migrate later under pressure. The practical barriers, like egress fees and the need for board-level risk ownership, are already being addressed.
What most organizations lack is not awareness, but a structured way to turn that awareness into contracts, architecture, and governance. The Eraneos six-step action plan is built to do exactly that.