European Sovereignty Monitor

Policy and law

Germany's BSI publishes C3A criteria to measure cloud sovereignty

Germany's BSI published C3A (Criteria enabling Cloud Computing Autonomy), a catalogue letting agencies and firms test whether a cloud service can be used self-determinedly, building on its C5 security standard, with optional Germany or EU data-residency requirements.

Verified Editor-read BSI (Bundesamt für Sicherheit in der Informationstechnik) press release, 27 April 2026

What it does not test. Does not itself certify any provider as sovereign or require any agency to use it.

How this item counts. No movement: no answer to who owns, who operates, whose law governs or who made the parts changes. Weight 0. Published measurement catalogue only, certifies no provider and mandates nothing. European Sovereignty Index

How this item was made. Drafted by an AI system (Claude (Anthropic)) from the source cited above; read and approved by the editor on 2026-09-21. How the record is made

Previously in Policy and law

ReportedOpinionAI-drafted CCIA economist says EU's Digital Markets Act bakes in yesterday's market structure VerifiedOpinionAI-drafted ECIPE paper urges EU to reform telecom rules to capture 6G value ReportedOpinionAI-drafted CCIA Europe says Digital Networks Act codifies pathways to network fees

All Policy and law news →