Toolbox

All tools in the Toolbox

Appendix E · Interactive tool

Sovereignty assessment

Digital sovereignty is part of resilience: the supply chain security requirement of the Cybersecurity Act assumes you know where your data sits and how dependent you are on individual suppliers. Assess a critical supplier or cloud service on jurisdiction, data localisation, lock in and exit options. Name the supplier and answer the questions. Everything is calculated in your browser.

Jurisdiction and data localisation

Is the supplier subject to EU or EEA jurisdiction (headquarters and parent company)?

Is data stored and processed within the EU or EEA?

Is the supplier shielded from extraterritorial legislation (for example the US CLOUD Act)?

Technical independence

Does the service use open standards and formats that enable data portability?

Are there realistic alternative suppliers for the equivalent function?

Can you switch supplier within a reasonable time and cost?

Operational control

Do you have visibility into the supplier change management and can you verify what happens in your environment?

Are you protected against the supplier unilaterally changing terms, price or function?

Is there a documented and tested exit plan with data extraction and deletion?