All offers
Assessment
Sovereign Cloud
Cloud Sovereignty Readiness Assessment
Within four weeks you get an evidence-based answer: which workloads already satisfy European sovereignty requirements, which fall short, the cost of moving them, and how quickly you could exit if it came to that.
Duration
4 weeks
Usual next step
Sovereign Cloud Landing Zone
The problem
Sovereignty has moved from a policy discussion to a procurement requirement. The EU Cloud Sovereignty Framework has given buyers a shared vocabulary and a scoring model. NIS2 and DORA are in force. Customers, regulators, and increasingly your own board are asking questions that are hard to answer without a workload-level analysis: where does this data actually reside, who can technically access it, what happens if a provider relationship becomes unavailable, and how long would it take us to move.
Most organizations answer these questions with an architecture diagram and a hope. That is not an answer that survives a tender, an audit, or a board meeting.
What the assessment gives you
A workload inventory classified by data sensitivity, regulatory exposure, and sovereignty requirement
An assessment of each workload class against the sovereignty objectives used in European public procurement, with a clear statement of where you stand today and what the gap is
A dependency analysis: the specific technical dependencies (managed services, proprietary APIs, identity, key management, operational tooling) that would make a move slow or expensive, named per workload class
An exit-readiness analysis: realistic time and effort to move each workload class to a European sovereign target, based on the dependencies we actually find rather than a generic estimate
A target architecture recommendation per workload class, including the option of staying where you are where that is genuinely the right answer
A costed, sequenced migration roadmap, with the workloads that give you the most regulatory relief for the least effort placed first
A regulatory mapping to the obligations that apply to you: NIS2, DORA, GDPR, the EU Data Act, and the EU AI Act where AI workloads are in scope
How we work
We are not a cloud provider and we do not resell one. We hold partnerships with European sovereign providers and we build on open source, which means the recommendation you get is the one the evidence supports, including “this workload should stay where it is”.
How it runs
Week | Focus |
|---|---|
1 | Kickoff, workload inventory, regulatory scoping with your compliance and security stakeholders |
2 | Technical dependency analysis, architecture review, provider and contract review |
3 | Target architecture options, migration effort modeling, cost modeling |
4 | Roadmap workshop, findings report, executive presentation |
Who it is for
Regulated and public-sector organizations, and enterprises with European customers who are being asked sovereignty questions in tenders, audits, or board reviews. Typically sponsored by a CISO, a Head of Compliance, or a CIO.
What happens next
Where the roadmap calls for a move, the usual next step is a Sovereign Cloud Landing Zone: the target environment, built and ready to receive workloads, in ten weeks.
Interested?
Let us know where you stand and which decision is ahead of you. We will respond with a scope, a price, and an honest view of whether this assessment fits your situation.