PLM/ALM sovereignty is more important than ever. I’m probably not the only one wondering how to actually measure it when choosing a suitable IT solution, because so far there has been no common yardstick. That is changing now.
In the last post of this series, I put forward the CIA triad (confidentiality, integrity, availability) from information security as an evaluation framework, one that works quite well for assessing sovereignty at an abstract level.
The EU Cloud Sovereignty Framework (CSF) goes in a similar direction, only more concretely and with eight dimensions instead of three:
- SOV-1 – Strategic sovereignty
- SOV-2 – Legal and jurisdictional sovereignty
- SOV-3 – Data and AI sovereignty
- SOV-4 – Operational sovereignty
- SOV-5 – Supply chain sovereignty
- SOV-6 – Technological sovereignty
- SOV-7 – Security and compliance sovereignty
- SOV-8 – Environmental sustainability
Each dimension is rated individually, with one of five SEAL levels, from SEAL-0 (no sovereignty) to SEAL-4 (full digital sovereignty). These individual ratings then add up to the provider’s overall Sovereignty Score.
In an earlier post, I wrote about Airbus and its digital chief Catherine Jestin. She is asking regulators for a clear statement of when a company is truly immune to external access. The CSF could be a first structured answer to exactly that question. It was created primarily for public-sector tenders, but its logic carries over to private-sector decisions.
In principle, this is a step in the right direction. The CSF creates a shared language for the dimensions in which sovereignty should be assessed in the first place. The SEAL scale at least allows a rough comparison between providers.
What remains open
In the end, a Sovereignty Score is just a number. The framework does not decide what is acceptable and what is not. That is the job of a company’s own sovereignty strategy. Without one, the rating is meaningless.
And that is exactly where the real work lies: not simply comparing providers, but first understanding why, and to what depth, sovereignty matters for your own company at all. Sovereignty is not an end in itself.
For the first time, the EU Cloud Sovereignty Framework provides a shared language and a rough comparison scale for sovereignty. What it does not provide is the answer to how much sovereignty is right for your own company. That strategic work remains the company’s own responsibility.