Across customs, health, tax, public administration and NATO, Europe is converging on a new way to build critical digital systems: an accountable integrator, a reusable platform, sovereign infrastructure and a protected operating model.
The European public-sector sovereign stack is taking shape, but not as a single cloud. Europe spent years debating whether it needed one. In 2026, the market began answering a different question.
The emerging model is not one cloud, one vendor or one “Eurostack.” It is a delivery coalition: a global or national systems integrator that accepts programme accountability; a sector platform or reusable runtime; a sovereign cloud or on-premises substrate; and a security and operating layer that can prove who controls data, keys, software updates and privileged access.
This pattern is emerging first in sectors where a technology failure can quickly become a public crisis—disrupting essential services, compromising security or eroding trust in government. Customs, tax, public health, defence, education and central government have different missions, but they are converging on the same underlying architecture.
The pattern matters because it changes what European public-sector technology buyers are actually procuring. They are moving away from two old extremes: bespoke systems built almost entirely by an integrator, and generic public-cloud capacity bought with a compliance wrapper. The new object of procurement is a governed capability that must remain useful under legal, geopolitical and operational stress.
That is a much bigger shift than “hosting data in Europe.”
It is also the operational sequel to the broader sovereignty argument explored in Why Data Sovereignty, Why Now: once control becomes a requirement, architecture and procurement have to change with it.
Inside the European public-sector sovereign stack
The repeatable model has four layers.
1. The accountable prime
The systems integrator still matters, but its role is changing. It owns programme architecture, migration, integration, sector workflows, governance and long-term operations. It translates a policy requirement into a working service and remains accountable when multiple technology providers are involved.
2. The reusable platform
The programme is no longer only a collection of custom applications. A platform layer provides a common runtime, data services, AI services, developer tooling, orchestration or a domain-specific product. This is where reuse, portability and speed are supposed to come from.
3. The sovereign substrate
The infrastructure may be a European public cloud, a nationally operated region, an on-premises cloud, a customer data centre or a fully disconnected environment. What matters is not geography alone. The buyer increasingly wants evidence of legal control, operational control, supply-chain resilience, encryption-key control and the ability to continue operating if a supplier or jurisdiction becomes unavailable.
4. The protected operating model
Sovereignty is finally becoming operational. Procurement documents and partnerships increasingly specify local or cleared personnel, zero-trust controls, external key management, controlled software updates, auditability, portability and defined exit paths. In classified environments, the same cloud operating model must extend into air-gapped infrastructure.
Put together, the architecture looks like this:
Integrator accountability + reusable platform + sovereign infrastructure + controlled operations
The strongest evidence is no longer in policy papers. It is in contracts.
Germany has already made the pattern explicit
In May 2026, Germany’s Federal Ministry for Digital Affairs and State Modernization awarded a large-scale AI-platform project, valued at approximately €250 million, to a consortium of SVA, Codesphere and STACKIT.
The division of labour could almost be the reference architecture for the emerging market. SVA owns overall architecture, systems integration and governance; Codesphere provides the platform layer; STACKIT supplies the sovereign cloud foundation. Federal and state authorities are expected to use the platform for applications such as intelligent document processing and faster planning and approval procedures.
This is not “an AI project running in a German data centre.” It is an institutional production model. The contract separates accountability, runtime and infrastructure while binding them through common governance.
The wider German GovTech framework reinforces the point. T Cloud Public was added to a cloud-and-AI framework awarded to Bechtle, allowing federal, state and municipal authorities to procure services through a multicloud broker rather than run a new tender for every workload. The same framework supports the Deutschlandplattform and the MEDI:CUS healthcare platform. Both already run as reusable operational and development environments.
The STACKIT–Codesphere cooperation adds another important detail. Codesphere and confidential-computing specialist enclaive won a contract worth up to €30.8 million for the central runtime component of the GovTech framework. STACKIT provides the infrastructure; Codesphere provides a vendor-neutral deployment layer; applications sit above both. The stated goal is portability across administrative and healthcare workloads, not merely local hosting.
This is the pattern in its most legible form: the state is buying a reusable delivery system.
Customs shows where EU procurement is going next
The European Commission’s E-commerce Customs Data Hub is an even more revealing case because its procurement structure describes the future before an award has been announced.
DG TAXUD launched the competitive dialogue in June 2026 with an estimated value of €136.32 million. The winning supplier will be responsible for the design, implementation and operation of the hub and its services, while using foundational cloud and network capacity contracted separately by the Commission. The notice explicitly separates the application and operating responsibility from the underlying infrastructure capacity.
The Commission’s 2026–2027 Customs work programme is even more direct. It calls for a “cloud-native sovereign” E-commerce Customs Data Hub and covers the full lifecycle: business analysis, development, testing, deployment, operations, security and coordination with Member States. More than 90% of the programme budget for 2026 and 2027 is earmarked for digital procurement.
This does not yet prove that Capgemini, Sopra Steria, STACKIT or any other named supplier has won the work. As of 19 July 2026, the official procurement record shows no award. Any claimed consortium would be speculation.
What it does prove is more important: the Commission is deliberately creating a boundary between the integrator-operated sector platform and a pre-contracted sovereign infrastructure layer. The cloud is becoming a replaceable substrate inside a larger public capability.
That is a procurement pattern, not a product announcement.
NATO is applying the same logic to classified operations
In July 2026, NATO’s Communications and Information Agency awarded Accenture a contract for the Protected Business Network programme, with Leonardo as delivery partner. The estimated value is approximately €200 million over seven years.
Accenture and Leonardo will design, implement and operate the core platform across an NCIA-provided multicloud environment for roughly 29,000 users. Leonardo will implement a zero-trust architecture secured by its proprietary Global Cybersec Platform, an AI-enabled, multi-agent cyber-defence platform.
Again, the roles are distinct:
- Accenture brings programme integration, transformation and operating accountability.
- Leonardo contributes the mission-security platform and zero-trust capabilities.
- NCIA provides the multicloud environment and retains institutional control.
- The resulting platform standardises how classified digital services are built, deployed and maintained.
This is not outsourcing in the traditional sense. NATO is using suppliers to construct an internal cloud operating model that the Alliance can govern and extend.
The air-gapped market is moving in the same direction. Capgemini became an authorised operator of Google Distributed Cloud air-gapped in 2026, offering a fully managed model for isolated workloads. Sopra Steria began integrating OVHcloud’s On-Prem Cloud Platform directly into customer facilities, including environments that remain disconnected from the internet. In both cases, the platform vendor supplies a repeatable cloud control plane while the integrator makes it deployable and operable inside a protected domain.
Health is turning sovereignty into a platform requirement
France’s Health Data Hub provides one of the clearest examples of the transition from data residency to strategic control.
In April 2026, the public Health Data Hub selected Scaleway as the future host of its technology platform. The decision followed an assessment of more than 350 technical requirements covering security, resilience, scalability and operational support. The platform expects to manage an autonomous copy of the principal national health-insurance database between the end of 2026 and early 2027.
The important word is autonomous. The project is designed around cloud-native standards and reversibility, not a permanent dependency on a single provider. The public platform owner retains the data mission; the sovereign provider supplies elastic infrastructure and works with the organisation to build the security capabilities still required.
Italy offers an adjacent, earlier-stage signal. Engineering’s One Person One Health project is a five-year, €64.02 million IPCEI programme to build an open and modular ecosystem for certified clinical decision-support modules. It includes a clinical marketplace, personalisation tools, multi-omics capabilities and population-health applications. Engineering is also developing AVANT under IPCEI-CIS, an EU programme intended to create a sovereign cloud-to-edge infrastructure.
OPOH is not a 2026 procurement award and should not be presented as one. It is a publicly funded industrial programme announced in 2025 whose R&D and first industrial deployments run through the period now opening. Its value as evidence is architectural: a major integrator is productising healthcare workflows and executable medical knowledge rather than selling only project labour.
The European Health Data Space will increase the pressure. The Commission is building HealthData@EU as a federated service for dataset discovery and access requests, alongside common testing environments for electronic health-record systems. Once health data must move across governed national and European services, sovereignty, interoperability and platform operations become the same design problem.
Tax and citizen services are following the same route
The United Kingdom sits outside the EU but inside the same European public-sector technology market, and HM Revenue & Customs provides two useful examples.
Capgemini has been named migration delivery partner for HMRC’s Enterprise Tax Management Platform, moving the system toward SAP S/4HANA and SAP Sovereign Cloud in the UK. The platform supports more than 50 tax regimes and processes more than £875 billion annually. In June 2026, Capgemini also announced a separate HMRC customer-service programme with NiCE and Route 101. NiCE CXone will run on a purpose-built UK sovereign cloud, while Capgemini owns design, integration and continuous optimisation.
The repeated formula is visible again: a large integrator, a specialised product platform and a sovereign deployment model.
Capgemini’s partnerships show that the model is substrate-agnostic by design. In 2026 it announced sovereign delivery arrangements across SAP, AWS European Sovereign Cloud, Microsoft Sovereign Cloud and Google Cloud, including air-gapped operations. This is not evidence that every partnership has already produced a public-sector deployment. It is evidence that integrators are building a portfolio of sovereignty levels because buyers will classify workloads differently.
Europe is standardising the demand side
Why is this happening now rather than five years ago?
First, sovereignty has become measurable. The European Commission’s €180 million sovereign-cloud framework, awarded in April 2026, selected four European providers or consortia: Post Telecom with Clever Cloud and OVHcloud; STACKIT; Scaleway; and Proximus with S3NS, Clarence and Mistral AI. The procurement introduced a Cloud Sovereignty Framework with 48 criteria across eight dimensions and assurance levels for data sovereignty, technological autonomy and full sovereignty.
The Proximus consortium is particularly revealing. It combines a trusted telecom and ICT operator, the S3NS sovereign cloud platform, Clarence’s disconnected edge cloud, Mistral AI and Thales security. It is a portfolio of operating modes assembled under one accountable European framework, not a monolithic cloud.
Second, the Commission is turning the framework into a market rule. The proposed Cloud and AI Development Act introduces four sovereignty assurance levels and a common procurement approach for public administrations. The highest levels examine third-country control, ownership, personnel, software supply chains and the ability to operate without outside interference. Portugal’s May 2026 National Plan for Sovereign Cloud already applies a similar risk-classification logic to public-sector data and systems.
Third, AI has made the old compromise untenable. Public bodies want modern models, data platforms and developer services, but their most valuable datasets cannot simply be exported to a generic SaaS control plane. The answer is to bring a repeatable AI and cloud operating model to the data: into a sovereign region, a national provider, the customer’s own data centre or an air-gapped enclave.
Fourth, Europe’s regulation is now colliding with operations. The AI Act, NIS2, the Cyber Resilience Act, the European Health Data Space and sector-specific security regimes do not merely ask where data is stored. They create obligations around risk, traceability, resilience, access, interoperability, incident response and lifecycle governance. A platform plus an operating model can encode those controls once and reuse them. A bespoke project must rediscover them every time.
Finally, geopolitics has turned supplier continuity into a board-level concern. The question is no longer only whether a foreign authority could request data. It is whether a government can patch, operate, recover, migrate and continue a critical service if cross-border support, licensing, updates or control-plane access are disrupted.
This is why “sovereign” increasingly describes an operating condition, not a passport.
The trap: replacing hyperscaler lock-in with integrator lock-in
The coalition model is not automatically sovereign.
A European data centre can still run an opaque stack. A local operator can still depend on a third-country control plane. An open-source platform can still be practically impossible to operate without one supplier. A multivendor consortium can make accountability less clear rather than more resilient.
The next generation of public procurements should therefore test five things:
- Control: Who can access data, keys, logs, updates and the management plane?
- Continuity: What continues to work if an external supplier or network disappears?
- Replaceability: Can infrastructure, models and operational partners be changed without rebuilding the service?
- Evidence: Can the authority audit software provenance, privileged actions, model behaviour and incident response?
- Capability transfer: Does the public body gain the skills and tooling needed to govern the platform, or only a longer outsourcing contract?
Without these tests, “sovereign platform” becomes another premium label. The lock-in simply moves one layer upward—from cloud vendor to prime contractor.
What 2027 will look like
The 2026 evidence points to a clear direction for 2027 and beyond.
Public-sector tenders will increasingly separate the prime integrator from the infrastructure substrate while requiring them to operate as one governed service. Frameworks and brokers will make approved cloud capacity easier to consume. Sector platforms will encode reusable controls for customs, health, tax, defence and citizen services. The same platform will need deployment profiles ranging from ordinary sovereign public cloud to customer-hosted and fully air-gapped environments.
The European public-sector sovereign stack will belong neither to the integrator nor to the cloud provider alone. Its strategic control will belong to the party—or coalition—that owns the repeatable operating architecture: the policies, runtime, deployment patterns, evidence and exit mechanisms that let critical services move across trusted infrastructure without losing governance.
That portability question also reaches into the data layer. The practical choices differ by provider and operating model, as the earlier map of MongoDB in EU sovereign clouds shows.
Europe is not choosing between innovation and sovereignty. It is trying to industrialise the boundary between them.
That boundary is becoming a product.
