A practical reading of where the regulatory line now sits and what it means for procurement.
For years, "sovereignty" in European defence procurement was treated as a policy preference a nice-to-have when evaluating cloud providers but not something that carried binding weight once it entered a contract. That era closed in 2026. The space within which sovereign defence technology must now operate is defined by two regulatory instruments and these instruments do not merely set direction; they draw a line.
The first is the EU Data Act (Regulation 2023/2854), in force since 12 September 2025. For the first time, it addressed unlawful access by third-country governments to non-personal data stored within the EU at a horizontal level. The second is the Cloud and AI Development Act (CADA), unveiled by the European Commission on 3 June 2026. CADA goes beyond encouraging sovereignty it grades it, turning the assessment of every cloud service against a four-level assurance scale into a de facto procurement threshold for public buyers, defence agencies included.
What actually determines the outcome is the CADA framework itself. It classifies cloud services along five axes: the physical location of data centres, who operates and administers the infrastructure, the provider's ownership and financing structure, the transparency of the software supply chain and whether the provider is exposed to a foreign jurisdiction such as the US CLOUD Act. Level 3, which applies to high-risk defence and justice systems, requires the provider to neutralise third-country legal exposure not through "sovereign region" narratives but through binding legal and technical isolation. Level 4, covering roughly one percent of the most sensitive national security workloads, demands full software transparency and zero third-country influence: no ownership stake, no operational control, no residual legal exposure to a non-EU jurisdiction. If the parent company is incorporated in Delaware, a data centre built on European soil does not change the picture.
For defence procurement, the practical consequence is clear. Every cloud contract must now be classified against these levels, documented and defended where necessary. A foreign order that could compel a provider to disclose software vulnerabilities or cut off service is no longer a theoretical risk heading it is a direct procurement criterion. European defence buyers are already asking suppliers to declare their level, not their logo.
The European Defence Fund's 2026 programme makes this even more concrete: there is a €40 million line allocated to cloud services for military multi-domain operations and the technical requirements are explicitly defined. Military cloud infrastructure must be able to self-form, self-heal, degrade gracefully and sustain redundancy. It must support recovery mechanisms that preserve data consistency after failure, alongside failover capabilities for operations affected by communication disruptions. And it must comply with interfaces agreed with NATO able to interoperate with allies within Federated Mission Networking specifications when the network is available and to continue the mission autonomously and in isolation the moment the network drops.
This is precisely where the regulatory line and operational reality diverge. CADA grades sovereignty along a spectrum; but NATO's Alliance Digital Strategy calls for a federated, multi-classification, scalable and hybrid cloud model integrated with tactical edge computing. That model must provide resilient, high-bandwidth, low-latency connectivity for mission-critical operations in degraded, contested and denied environments.
A Level 3 or Level 4 cloud contract satisfies a compliance officer. It does not, on its own, satisfy a commander whose connectivity has been severed by an adversary.
The perimeter that matters now is not the one drawn by the regulation. It is the one drawn by the operational environment. Air-gapped, post-quantum and proprietary infrastructure that runs without internet connectivity with zero third-party dependencies and no residual exposure to any non-EU legal framework does not merely sit outside the CADA assurance ladder; it fulfils the Level 4 absolute sovereignty threshold the ladder seeks, not through a commitment on paper but directly at the architectural level.
For defence procurement, the practical question is no longer "What level is your cloud?" It is: "What happens to your capability when the cloud is gone?"
The suppliers who can answer that question through architecture rather than assurances will define the next perimeter.
At Lotus Sirius, we answer that question through architecture. The connection-independent structure of ARNOR OS, the accredited supplier network of QUANTUM-CHAIN, the post-quantum encryption layer of ARGUS and the zero-trust architecture of STYX meet the absolute sovereignty threshold of Level 4 not on paper but in the field. If you would like to discuss how this framework can be adapted to your organisation's operational reality, get in touch.
