With the European technology sovereignty package presented on June 3, 2026, digital sovereignty has finally turned from a buzzword into concrete legislation. The EU Commission has launched a legislative package covering semiconductors, artificial intelligence, cloud services and open source - one that changes the rules of the game for anyone processing data in the cloud. For small and medium-sized enterprises (SMEs) in Leipzig and Saxony, this is more than European high politics: it concerns the question of who actually owns your business data and who controls access when it matters.
The trigger is a clear concern that EU representatives have summed up in the sentence "We want to be sure that nobody has a kill switch." What they mean is the risk that a foreign government could simply shut down critical cloud services or access data. In this article, we put the new framework into context and show which practical steps make sense for SMEs.
What is behind the 2026 EU sovereignty package
The centerpiece of the package is the Cloud and AI Development Act (CADA), which the Commission presented as a draft regulation on June 3, 2026. Its goal is to make it easier to expand data centers in the EU and, for the first time, to create a uniform framework for objectively assessing the sovereignty of cloud and AI services. The background is heavy market concentration: the lion's share of European cloud workloads sits with a few US providers, which creates strategic dependencies.
The political ambition is high. CADA is meant not only to speed up permits for new data centers and lower bureaucratic hurdles, but also to drive targeted investment in European cloud and AI capacity. The law thus joins a whole series of initiatives with which the EU aims to reduce its technological dependence. For SMEs, the signal effect matters most: sovereignty is becoming a selection criterion by which public authorities, corporations and regulated industries evaluate their service providers - and this standard rubs off on the entire supply chain.
The urgency signaled by the market itself is remarkable. In a EuroCloud survey, 45 percent of members name sovereignty as the number one top trend for 2026 - ahead of artificial intelligence. This is accompanied by infrastructure projects such as Deutsche Telekom's Industrial AI Cloud, opened in Munich in early February 2026 and one of Europe's largest AI infrastructures. Flagship projects like these show that capable European alternatives are emerging - and that switching to them is becoming technically realistic.
The four sovereignty levels explained
The heart of CADA is an EU Cloud Sovereignty Framework with four so-called assurance levels. Public bodies are expected to require the appropriate level depending on their risk assessment. The criteria range from control over the service and the supply chain, to data handling and infrastructure location, to cybersecurity.
- Level 1: Baseline level that practically every provider must meet in order to serve the public sector.
- Level 2: Proof of independence from third countries and transparency about the software supply chain.
- Level 3: Ownership and control from within the EU, including additional criteria such as the nationality of key personnel.
- Level 4: Strictest level - no control by a third country, a European cybersecurity certificate at least at level "high" and effective control over all software components.
In practice this means: US hyperscalers such as AWS, Microsoft Azure and Google Cloud will hardly be able to reach the highest levels. The reason is the US Cloud Act of 2018, which allows US authorities to access the data of American companies - regardless of where that data physically resides. This is exactly where the EU draws the line for sensitive government workloads.
Important for understanding: the four levels are not a judgment on a provider's quality but a risk classification. A hyperscaler may be perfectly adequate for a public marketing website, while health, HR or tax data calls for a higher level. This logic also translates to SMEs: they do not need to lift everything to Level 4, but rather choose the appropriate level for each type of data. This turns an abstract EU regulation into a practical grid for your own cloud strategy.
Digital sovereignty is more than a German data center
One widespread misconception deserves special attention: data residency is not the same as data sovereignty. The fact that your data sits in a Frankfurt or Leipzig data center says nothing about who can legally gain access. What counts is the strategic ability to shape and control digital technologies, data and processes on your own terms.
For SMEs, true digital sovereignty therefore means separating three layers: the physical storage location, legal control over the operator and the technical ability to migrate data at any time. A provider that advertises itself with the "sovereign cloud" label but belongs to a US parent company may satisfy residency, but not sovereignty.
It helps to ask yourself concrete test questions. Who owns the company operating the service, and which jurisdiction does it fall under? Who holds the encryption keys - the provider or you? Could the data be exported in an open format within a few days? Only once you can answer these questions do you know how sovereign your cloud usage really is. In SMEs especially, such issues often only become visible in a crisis - for instance when a provider drastically raises prices or discontinues a service.
What SMEs should do now in concrete terms
Even though CADA primarily addresses the public sector, the framework acts as a broad benchmark: anyone supplying the public sector or working with regulated customers will soon find the levels in tender documents. Add to that the German NIS2 implementation act and the EU Data Act, which are building pressure anyway.
- Take stock: Which data sits with which provider, and which jurisdiction does that provider fall under?
- Classify workloads by protection needs - not everything has to sit at the highest sovereignty level.
- Evaluate European and German alternatives for particularly sensitive data.
- Anchor exit capability contractually so that switching remains technically and legally possible.
Treat the topic as a process, not a one-off project. A sensible order: first create transparency, then secure the most sensitive data first, and finally migrate the less critical workloads as needed. This way you avoid falling into blind actionism and trying to rebuild everything at once. It is also important to anchor responsibility clearly - ideally with a person who brings together IT operations, data protection and management.
Practical example: a Leipzig SME sorts out its cloud
Take a typical scenario: a manufacturing company with 80 employees uses a US office suite, a cloud CRM and self-hosted industry software. An inventory shows that HR and engineering data are particularly worthy of protection, while general office communication and public marketing content remain uncritical.
The consequence is not a complete provider switch but a deliberate split. Sensitive data moves to a European provider with verifiable control, while less critical services stay with the familiar provider for now. At the same time, export paths are tested and contractually secured. The result: measurably higher sovereignty for sensitive data without having to overhaul the entire day-to-day business. It is exactly this differentiated approach that makes digital sovereignty affordable and manageable for SMEs.
Conclusion
The EU sovereignty package of June 2026 turns a trend topic into a planning parameter. For the first time, the four assurance levels provide a clear yardstick that SMEs can orient themselves by as well. Anyone who structures their data landscape now avoids expensive rush migrations once the requirements arrive in tenders and supply chains. Sovereignty is not about giving up convenience - it is a conscious decision about which data needs which level of protection.
Unsure which sovereignty level fits your workloads? Cryon from Leipzig analyzes your cloud landscape, classifies your data by protection needs and works with you to develop a sovereign, practical infrastructure. Get in touch - we bring clarity to your cloud strategy.
A cloud with digital sovereignty?
Cryon plans and operates cloud environments that reconcile data protection, EU law and performance.

