The path to digital sovereignty

Fujitsu / January 6, 2026

Digital sovereignty has become a key topic in recent period, driven by shifts in the geopolitical landscape — from developments in U.S. politics to Europe’s relationship with China and the ongoing war in Ukraine. This topic has now reached IT consultancy firms, and our clients are increasingly asking about it.

At Fujitsu, we organize roundtable discussions where customers can share their perspectives on digital sovereignty. These sessions help us understand their priorities on this topic and ensure that our interpretation of their needs aligns with their expectations.

Digital sovereignty can be complex because it can be approached from different perspectives. From a business perspective: Can we keep our company operational? From a data perspective: Where does it reside, and who can access it? From a legal perspective, which laws apply — U.S. Patriot Act or European legislation? And finally, from a technical perspective: What measures must we take to stay (or get back) in control?

Understanding the landscape

Various industry sources offer guidance. Gartner provides a conceptual view, while cloud providers such as AWS, Microsoft, and Oracle outline their own approaches. The European Commission’s Cloud Sovereignty Framework is particularly insightful, with its sovereignty goals, assurance levels, assessment model, and even a “sovereignty score” for procurement processes. After all this research, here's my take on the matter.
In my view, digital sovereignty isn’t about politics per se — it’s about your architecture. When you analyze the requirements, in many ways, digital sovereignty is an extension of risk management. Geopolitical risks may shift, but the mitigation remains technical: maintaining control over data, networks, and adaptable IT systems to ensure resilience and enable rapid, business- or regulation-driven change.

You can’t buy digital sovereignty, you have to ‘build’ it

As IT capabilities - knowledge, skills and achievements - grow, the organization becomes more resilient and better able to make choices that suit business development. These capabilities span areas such as: software development, security, scalability, availability, licensing strategy, hardware and infrastructure, data residency, and vendor management.
Imagine a ladder: the higher you climb, the more capabilities you gain. At the bottom lies technical debt — outdated systems, limited software-development capacity, rising security risks, manual processes, and proprietary dependencies. In this state, organizations struggle to mitigate even basic risks.

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...