Blog #3 – European Digital Sovereignty: From Policy Ambition to Practical Capability


Gaia Anselmi
European Cyber Security Organisation (ECSO)
Manager for Technology, Supply Chain & Strategic Autonomy
European Digital Sovereignty: From Policy Ambition to Practical Capability
In an increasingly connected digital environment, European digital sovereignty is very much dependent on Europe’s ability to develop, operate and govern critical digital technologies in a way that is secure, resilient, and trusted – going beyond the physical location of the digital infrastructure and formal ownership arrangements. This ambition is reflected in the EU’s growing policy and regulatory framework for digital technologies, which seeks to strengthen Europe’s resilience, competitiveness, security and strategic leadership.
In this framework, cybersecurity becomes a core condition for Europe’s digital transformation. Without secure and trusted infrastructures, autonomy, intended as the ability to independently develop, deploy, operate, and maintain critical digital technologies, infrastructures, products and services, remains difficult to exercise in practice. Similarly, sovereignty risks remaining mainly a policy objective rather than an operational capability. The evolution of the EU cybersecurity framework illustrates this increasingly integrated approach. Through instruments such as the NIS2 Directive and the Cyber Resilience Act (CRA), cybersecurity and resilience are becoming embedded across both critical infrastructure and the digital products and services on which the European economy depends: NIS2 strengthens cybersecurity and risk-management requirements for organisations providing critical and important services across the EU; while the CRA complements this by introducing cybersecurity requirements for products with digital elements throughout their lifecycle, from design to maintenance. This shift extends to digital sovereignty itself: the European Commission’s Cloud Sovereignty Framework translates sovereignty into measurable criteria and introduces a Sovereignty Effectiveness Assurance Level (SEAL) for providers, designing a way to assess sovereignty and autonomy in cloud procurement.
Translating security requirements into practice is a crucial part of the equation. For a complex, federated infrastructure such as EURO-3C, demonstrating that security and resilience are achieved and maintained means combining appropriate assurance and certification mechanisms with continuous assessment and testing, covering not only individual components but also the way services are operated and secured throughout their lifecycle.
This is particularly important as telecommunications, cloud, edge computing, artificial intelligence (AI) and high-performance computing become more interconnected. No single provider can deliver alone all the connectivity, computing and data capabilities needed to support Europe’s future digital services, making cooperation and federation between different providers essential. As these technologies increasingly interact across organisational and sectoral boundaries, common European rules are needed to establish the conditions for their secure and responsible use. The Data Act seeks to create fairer and more predictable conditions for accessing and sharing data across the European economy, while the AI Act establishes common requirements for the development and deployment of trustworthy AI systems. Together, these policies contribute to a more coherent digital environment in which data can be shared, and AI can be used across different actors while respecting European standards and safeguards.
Therefore, EURO-3C supports the broader EU strategic agenda by pursuing the objectives of the EU Cybersecurity Strategy on resilience and cooperation, as well as the Digital Compass’ long-term vision for a successful digital transformation. Concretely, the project contributes to the vision of a Connected Collaborative Computing Network (3CN): an open, federated and sovereign European infrastructure in which resources from different providers can work together. It will demonstrate how Telco-Edge-Cloud capabilities can be federated across providers and borders, helping to create a more interoperable and flexible infrastructure that supports European technological sovereignty.
However, connecting infrastructures is only part of the challenge. For federation to be trusted, organisations need confidence that the systems and services they rely on are secure, responsibilities are clear and risks are managed consistently across the ecosystem. Technical interoperability allows platforms to communicate; trust determines whether those connections can support critical services at scale.
The project therefore treats security and sovereignty as testable architectural properties. In Europe’s federated and dynamic environment, where data workloads potentially involve several organisations and technologies simultaneously, EURO-3C aims to establish a trusted environment in which different actors can cooperate while maintaining control over their own security and strategic interests.
Nurturing the required trust calls for common rules, open standards, transparency, clear responsibilities, and assurance mechanisms that security requirements are being met. By linking regulatory alignment with technological development, EURO-3C’s policy dimension can help translate EU objectives into practical implementation, supporting the Union’s ambition to strengthen strategic sovereignty and reduce dependencies in critical digital infrastructure. Ultimately, by embedding security into the foundations of a federated infrastructure, EURO-3C seeks to turn European digital sovereignty from a policy ambition into a practical capability: the ability to connect, cooperate and innovate while maintaining secure and trusted digital infrastructure.

