New: AI Workspace – Secure AI for Organizations With Sensitive Data. Learn more.

Fact Sheet

EU Cloud Sovereignty Framework

The EU Cloud Sovereignty Framework defines clear criteria for digital sovereignty in the cloud and helps IT decision-makers to make critical dependencies in their own IT landscape transparent and reduce them.

  • What sovereignty goals does the EU Cloud Sovereignty Framework define?

  • How does Myra implement sovereignty goals in areas such as law, technology, and security?

  • How does Myra help you make your cybersecurity more digitally independent?

What is the EU Cloud Sovereignty Framework?

The EU Cloud Sovereignty Framework is a reference framework developed by the European Commission that enables companies and public authorities to systematically assess the digital sovereignty of cloud services. Among other things, it describes requirements for data locations, legal control over data access, and the technological and operational independence of cloud providers. This transforms the abstract concept of “cloud sovereignty” into a concrete, measurable criterion that can serve as a basis for strategic decisions and tenders.

  • Eight clearly defined sovereignty objectives, for example for strategy, law, data, technology, and operations.

  • Five-level assessment model (SEAL) to classify the level of sovereignty achieved by a provider.

  • Decision-making aid for selecting cloud services that meet EU requirements for data protection, security, and digital sovereignty.

Myra compared

Myra meets almost all sovereignty criteria of the EU Cloud Sovereignty Framework

Methodology:

  • The eight sub-goals (SOV-1 to SOV-8) were evaluated individually based on the influencing factors defined in the EU Cloud Sovereignty Framework v1.2.1.

  • The objectives were assessed using the SEAL system, which distinguishes between five different levels of sovereignty.

  • Non-European competitors were assessed to the best of our knowledge based on publicly available information, without claiming to be exhaustive or absolutely accurate.

For providers outside the European Union, some of the criteria required by the Cloud Sovereignty Framework are simply impossible to meet—particularly with regard to legal and jurisdictional sovereignty.
Dennis-Kenji Kipker
Professor of IT Security Law & Head of Research at cyberintelligence.institute

Where Myra sets itself apart from non-EU providers

(Download the report now for the entire table.)

sovereignty goal
Implementation by Myra

Strategic Sovereignty (SOV-1)

  • Myra is an owner-managed company with exclusively European shareholders from the DACH region

  • Headquarters and seat of the entire management in Germany

  • No critical dependencies on customers or partners outside the EU

  • Development and operation of the protection services are carried out independently from Germany on our own hardware, independently of service providers

Legal & Jurisdictional Sovereignty (SOV-2)

  • Myra is subject solely to German and European law

  • No possibility for non-EU authorities to force access to data or systems

  • No risk of usage restrictions due to international regulations

  • Creation of intellectual property, development, and operation exclusively in Germany in accordance with EU law

Strategic Sovereignty (SOV-1)

  • Myra is an owner-managed company with exclusively European shareholders from the DACH region

  • Headquarters and seat of the entire management in Germany

  • No critical dependencies on customers or partners outside the EU

  • Development and operation of the protection services are carried out independently from Germany on our own hardware, independently of service providers

Legal & Jurisdictional Sovereignty (SOV-2)

  • Myra is subject solely to German and European law

  • No possibility for non-EU authorities to force access to data or systems

  • No risk of usage restrictions due to international regulations

  • Creation of intellectual property, development, and operation exclusively in Germany in accordance with EU law

How you can benefit from digitally confident cybersecurity with Myra

Icon DDoS Schutz

Reliable cyber resilience

Fail-safe availability and data security in accordance with European laws and values – without risks from political influence or foreign law

Protection in Secure Hands

Preservation of data sovereignty

Compliance with EU data protection standards builds trust and protects both customer and business data, for example thanks to GDPR-compliant TLS termination.

Less regulatory effort

More efficient implementation and verifiable compliance with national or European cybersecurity requirements such as NIS-2, DORA, or the Cyber Resilience Act (CRA)

Icon relocation

Robust supply chain

No abrupt price increases or access restrictions due to tariff wars, trade barriers, or other geopolitical developments

secure now

Protect yourself effectively against cyber attacks

We would be happy to show you how Myra improves your digital sovereignty in a free demo and answer all your questions.