Sovereign computing is infrastructure you control - running on hardware you own or trust, built entirely from open source components, sovereign by design rather than by policy.

It is not a cloud service with a data residency guarantee. It is not a vendor's managed platform with a sovereignty label. It is foundation infrastructure - the layer beneath your applications - that operates on your terms, in your jurisdiction, under your control.

This page covers both halves of the question: what the category is, and why it matters. If you already know the case and want the definition, start below. If you want the argument first, skip to why it matters.

The definition

Sovereign computing infrastructure, as defined by this initiative, is a coherent, integrated set of open source components that together deliver the foundation services any organisation needs to run digital workloads independently.

Core capabilities

Compute, Storage, and Network as a Service
Elastic, programmable infrastructure equivalent to what a hyperscaler provides, running on commodity hardware under your control.
High Availability and Business Continuity
Redundancy and disaster recovery built in, not bolted on. Backup is a means to an end.
Identity and Access Management
Single sign-on and machine-to-machine authentication. Whoever controls identity controls the stack - so identity must be yours.
Zero Trust Security
Encryption in motion and at rest as a baseline. Secrets management. Perimeter and segmentation controls.
Centralised Logging
For diagnostics, performance, security audit, and compliance - in one place, from day one.
Automated Operations
Programmatic install, upgrade, and update. Operable without deep specialist expertise.
Portable Workloads
No lock-in to proprietary formats or interfaces. Data and workloads move freely.

How it fits together

The core capabilities are not a checklist - they form a single, coherent architecture. Compute, storage and network as a service are the base layers; identity and centralised logging are component blocks above them; high availability and automated operations run as dimensions across every layer; zero trust wraps the whole; and portable workloads are the outcome.

Sovereign computing architecture. Compute, Storage and Network, delivered as a service, form the base layers. Identity and Access Management and Centralised Logging sit above them as component blocks. High Availability and Business Continuity and Automated Operations run vertically as a dimension and a concept spanning every layer. Zero Trust Security wraps everything. Portable Workloads are the outcome at the top.
How the core capabilities fit together: base layers delivered as a service, component blocks above them, high availability and automated operations spanning all, zero trust across everything, and portable workloads as the outcome.

What it is not

Sovereign computing infrastructure explicitly excludes hardware, end-user applications (productivity, collaboration, office tools), traditional platform services such as database-as-a-service, and any single vendor's proprietary solution. These sit above or below the category, not within it.

Sovereign by design

The word sovereign carries specific meaning here. Infrastructure is sovereign when:

  • it runs on hardware you own or that is dedicated to you
  • your environment is not shared with others at the hardware level
  • zero trust is a design principle, not a configuration option
  • data is encrypted at rest and in transit as a baseline
  • data can be freely exported and imported in standardised formats

Sovereignty is an architectural property, not a contractual one.

The conformance framework

A coherent category requires agreed conformance criteria - a shared definition of what qualifies and what does not. The Sovereign Computing Initiative is developing that framework collaboratively, drawing on existing standards including the Sovereign Cloud Stack, OpenSSF best practices, NIS2, and the Cyber Resilience Act.

The conformance framework will be open, community-governed, and usable directly in procurement. See how conformance works, the support model it tests, and the Mark it produces.

Optional capability extensions

Beyond the core, the category accommodates optional capability stacks for organisations with specific needs: an AI Stack for inference and model serving, a DevOps Stack for CI/CD and development tooling, a Software Platform for Kubernetes and runtime services, and a Productivity Stack for office and collaboration tools.

These extensions are additive. The core remains minimal, coherent, and independently operable.

Why it matters

Every organisation that runs on someone else's infrastructure is making a bet: that the price, the terms, the availability, and the access will not change in ways that harm it. For years that bet felt safe. It no longer does.

The dependency you did not quite choose

Hyperscale cloud became the default for good reasons - it is convenient, capable, and quick to adopt. But convenience accumulates into dependency. Over time, critical workloads, data, and institutional knowledge settle onto a single provider's platform, using that provider's proprietary services, priced on that provider's terms, governed by that provider's jurisdiction.

None of that is a problem until it is. A pricing change, a policy shift, a regulatory ruling, or a geopolitical event can turn a convenient arrangement into a strategic liability - and by then, moving is expensive, slow, or practically impossible.

What sovereignty actually buys you

Sovereign computing is not about distrusting every supplier or running everything yourself. It is about keeping control of the decisions that matter:

  • where your data physically sits, and under whose laws
  • whether you can leave a provider without rebuilding from scratch
  • whether your infrastructure keeps working if a supplier relationship ends
  • who holds the keys, the identity system, and the logs

These are architectural properties. Sovereign infrastructure is built so that control stays with you by design, rather than being promised in a contract.

Exit as a design principle

The clearest test of sovereignty is whether you can leave. Hyperscalers are increasingly subject to switching rules - in the EU, customers have the right to move within defined periods, and further unbundling obligations are expected. But a legal right to switch is worth little if the architecture makes switching impractical.

Sovereign computing puts the exit plan into the design: data and workloads in standard, portable formats; open interfaces between every layer; no single proprietary service that cannot be replaced. The ability to walk away is what gives you leverage, even if you never use it.

The regulatory tailwind

The direction of travel in Europe is clear. The EU Cloud Sovereignty Framework sets out what sovereignty should mean. NIS2 raises the bar on operational resilience and supply-chain accountability. The Cyber Resilience Act places obligations on the software in your stack. Data-residency rules constrain where regulated data may live.

Meeting these obligations is far easier on infrastructure that was sovereign by design than on a platform retrofitted with a sovereignty label. What European law already requires, and where it lands on the conformance checklist, is set out in trust and conformance.

Three strands, one word

None of this works in isolation. Technology without policy is unaccountable; policy without technology is unenforceable; and neither holds without governance. Sovereignty is what the three become when they pull in the same direction.

Three strands - technology, policy and governance - converge into one line pointing at the word sovereignty
One purpose, where three disciplines meet - open source, verifiable, procurable.

Being honest about the trade-offs

Sovereign computing is not free and not effortless. Convenience is the single biggest reason organisations choose hyperscalers, and that convenience is real. The perception that running your own foundation means taking on unmanageable risk is widespread - even where it is not true.

This initiative exists partly to close that gap: to make sovereign computing well-defined, conformance-tested, and genuinely procurable, so that choosing it is a sound, low-drama decision rather than a leap of faith. The aim is to remove the excuses for not choosing an open, sovereign, European option - by making the open option the easy one.

Where to start

If you are weighing your own exposure, take the buyer self-assessment - it takes about five minutes and gives you a tailored view of where you stand - then read for buyers.

If you build or operate infrastructure, check your platform with the provider self-assessment, then read for providers.

If your organisation wants to shape the category or offer conformant services, see community.