Sov levels municipalities

Today, European cities procure cloud services with very real, local administrative concerns. Budgets are tight and regulations like GDPR and NIS2 are mandatory. These organizations deal with everything from emergency infrastructure to the weekly garbage collection schedule.

Because the data is so varied, local governments don't use a "one size fits all" SEAL requirement. Instead, they use a two-tier approach based on the Application Trust Hierarchy to separate Standard Administrative Tasks from Critical Local Infrastructure. ### Tier 1: Standard Public Services (SEAL-2 Requirement) This tier applies to standard applications where the data is important to keep confidential, but it wouldn't pose a threat to public safety if it were temporarily disrupted locally. Workloads involved: Municipal websites, library booking apps, internal office communication tools, waste collection schedules, public park registers. Target Level: SEAL-2 (Data Sovereignty) for all objectives. Key Objectives for Tier 1: * SOV-2 (Legal & Jurisdictional) - SEAL-2: This is crucial to prevent foreign laws, like the U.S. CLOUD Act, from forcing municipalities to share their employee data or address books. * SOV-3 (Data & AI) - SEAL-2: Ensures that local government records and business permits are stored and processed exclusively within the EU, with encryption keys managed locally. * SOV-6 (Technological) - SEAL-2: Focuses on open standards. This allows cities to easily retrieve their data and switch to a new provider if subscription prices increase significantly. ### Tier 2: Critical Local Infrastructure (SEAL-3 Requirement) This tier covers the core functions of a municipality that directly affect public safety, handle sensitive financial transactions, or manage essential city utilities. Workloads involved: Civil status registers (births, marriages, deaths), smart-grid monitoring for water and electricity, traffic light control systems, municipal police routing systems, local tax databases. Target Level: SEAL-3 (Digital Resilience) for technical objectives, with SEAL-2 for governance. Key Objectives for Tier 2: * SOV-4 (Operational) - SEAL-3: In times of geopolitical unrest or supply-chain embargoes, these city systems must remain fully functional. This means local staff must be able to handle all operations, including server patching and tech support, without remote input from a foreign parent company. * SOV-5 (Supply Chain) - SEAL-3: Municipalities need complete transparency from vendors regarding the software components (Software Bill of Materials / SBOM) used in critical utility systems to prevent potential backdoor vulnerabilities. * SOV-7 (Security & Compliance) - SEAL-3: Directly addresses NIS2 infrastructure requirements. Security Operations Centers (SOCs) monitoring city infrastructure must be located in the EU. This ensures that all breach reports and incident responses are handled under local legal authority. ### Summary Matrix for Municipal Procurement | Sovereignty Objective | Standard Municipal Workloads (e.g., HR, Public Info, Libraries) | Critical Municipal Infrastructure (e.g., Utilities, Civil Registry, Traffic) | | :------------------------------ | :---------------------------------------------------------- | :-------------------------------------------------------------------------- | | SOV-1: Strategic | SEAL-1 / SEAL-2 (Standard commercial cloud setups) | SEAL-2 (Requires EU-anchored joint ventures) | | SOV-2: Legal | SEAL-2 (Full GDPR compliance, no CLOUD Act access) | SEAL-2 (Mandatory third-country access blocks) | | SOV-3: Data & AI | SEAL-2 (EU data residency) | SEAL-3 (Decoupled, locally managed encryption keys) | | SOV-4: Operational | SEAL-2 (Global support allowed with EU data boundaries) | SEAL-3 (EU-only support technicians and patching) | | SOV-5: Supply Chain | SEAL-1 (Standard commercial software allowed) | SEAL-3 (Full transparency of software and sub-processors) | | SOV-6: Technological | SEAL-2 (Standard data export features available) | SEAL-3 (Open-source foundations, no vendor lock-in) | | SOV-7: Security | SEAL-2 (Standard EU cloud compliance audits) | SEAL-3 (EU-located SOC / Continuous NIS2 compliance) | | SOV-8: Sustainability | SEAL-1 (Basic reporting) | SEAL-2 (Alignment with local municipal green goals) | ### Why SEAL-4 is Unrealistic for Municipalities Today Municipalities do not need SEAL-4 (Full Digital Sovereignty). This level of sovereignty requires tracing hardware manufacturing all the way down to silicon chip foundries and forbidding any non-EU code. Local governments simply don't have the budgets or the technical teams to manage and audit proprietary hardware stacks to this extent, which makes SEAL-2 and SEAL-3 the practical baselines.

Migration Guidance

Migrate away from
US cloud providers

Our structured guides map AWS, Azure, and GCP services to European equivalents — including compute, managed databases, object storage, CDN, and AI services. Built for CTOs and cloud architects.

Access Migration Guides
1
Audit your current cloud spend & services
2
Identify European service equivalents
3
Plan phased migration with zero downtime
4
Validate compliance & data residency
5
Cut over & decommission legacy infrastructure
Navigating the Rules

How hyperscalers
bypass disqualification

US hyperscalers like AWS, Google Cloud, and Microsoft are strategically developing architectural and organizational solutions to navigate around the legal and structural barriers in the lower levels of the EU's Cloud Sovereignty Framework.

Read more
1
The "Isolated Sovereign Region" Approach
2
Strategic Partnerships with EU "Trusted Partners"
3
Disconnected Key Management & External Encryption
4
Local Governance and "Digital Resilience" Pledges
Sovereignty levels

Sov levels municipalities

Today, European cities procure cloud services with very real, local administrative concerns. Budgets are tight and regulations like GDPR and NIS2 are mandatory. These organizations deal with everything from emergency infrastructure to the weekly garbage collection schedule.

Access Migration Guides
1
Audit your current cloud spend & services
2
Identify European service equivalents
3
Plan phased migration with zero downtime
4
Validate compliance & data residency
5
Cut over & decommission legacy infrastructure