All articles
SovereigntyCompliance

Compliant but Dependent: Why Europe Is Regulating Faster Than It Builds

You can pass every audit on the calendar and still not control your own infrastructure. Compliance and sovereignty are not the same thing. Confusing them is the most expensive mistake in European IT right now.

Ilke Tosunoğlu
Ilke TosunoğluMay 21, 20268 min readUpdated July 20, 2026
Infographic contrasting an "Audit Passed" shield with a system still wired to a foreign-controlled cloud. "What an audit proves" (documented controls, incident response, risk assessments, encryption in place) versus "what it doesn't" (foreign legal exposure, vendor lock-in, provider outage risk, external key control). Caption: compliance checks the box; sovereignty removes the dependency.

Part of the pillar series Europe's Digital Dependence, Explained.

Europe has built, in under a decade, the most comprehensive digital rulebook on Earth. NIS2, DORA, the Cyber Resilience Act, the Cyber Solidarity Act, the Data Act, the AI Act, and, in 2026, a tech-sovereignty package on top. If regulation alone produced sovereignty, Europe would already be sovereign.

It isn't. And the reason is a gap most boards never see: Europe is writing rules about its dependencies faster than it is building the substitutes for them. An organization can be fully compliant and still be one foreign legal order, one licensing change, or one provider outage away from losing control of its own operations.

This post is about that gap: what the rulebook does and doesn't buy you, and why "we passed the audit" is the beginning of the sovereignty conversation, not the end.

The rulebook is real, and growing fast

First, credit where due. The European rulebook is not theatre; it has teeth, and it is converging on dependence as a named risk.

Instrument Status What it changes
NIS2 Transposition Oct 2024 Broadens cyber obligations and supply-chain security across essential sectors (EC)
DORA Applies Jan 2025 Direct EU oversight of critical ICT providers; 19 designated Nov 2025 (ESAs)
Cyber Resilience Act In force Dec 2024 Security-by-design obligations for products with digital elements
Cyber Solidarity Act In force Feb 2025 Cross-border detection and emergency response
Data Act Switching rules from 2025; egress ban 12 Jan 2027 Attacks cloud lock-in and switching costs (Art. 29)
Cloud and AI Development Act (CADA) Proposed 2026 Demand-side measures and sovereignty rules for cloud/AI (EC)

Notice what DORA in particular represents. When the European Supervisory Authorities formally designated 19 critical ICT third-party providers (names like AWS, Microsoft, and Google among them), they were, in effect, publishing a list of the dependencies the system cannot yet replace. Regulation has become honest about the problem. It has not yet solved it.

What an audit proves, and what it doesn't

Here is the distinction that matters. A compliance certificate is evidence that you have managed a risk to a defined standard. It is not evidence that you have removed the dependency.

A passed audit proves you have… …but it does not prove
Documented controls and governance That your provider is beyond foreign legal compulsion
Incident reporting and response plans That you could actually switch providers if you had to
Risk assessments on third parties That a single provider outage won't halt you
Encryption and access controls in place That you (not the provider) hold the keys

You can satisfy every line on the left and still be structurally dependent. A US-headquartered "EU region" can be fully GDPR- and NIS2-aligned on paper while remaining reachable under foreign law, a point a hyperscaler conceded under oath in 2025, when Microsoft France told the French Senate it could not guarantee French data would never be passed to US authorities (The Register). The audit was never designed to catch that. (We dig into exactly who can be compelled, and why, in the companion piece, Who Can Actually Compel Your Data?)

Why the gap keeps widening

The deeper problem is one of pace. Rules can be written in months; infrastructure takes years and tens of billions. And the spending gap between Europe's substitutes and the incumbents it depends on is stark.

Two-column comparison. "The rulebook": NIS2 (2024), DORA (2025), CRA (2024), Cyber Solidarity Act (2025), Data Act (2025/2027 egress ban), CADA (2026), Chips Act 2.0 (2026). "The toolbox": a €180M sovereign-cloud tender and EuroHPC AI Factories (important building blocks, but small in scale) dwarfed by hyperscaler capex such as AWS's €15.7bn in Spain. Caption: Europe regulates dependency faster than it builds substitutes.

On the build side, the EU's flagship sovereign-cloud procurement (a tender awarded to four European providers in April 2026) was worth €180 million (European Commission). In the same period, a single hyperscaler committed €15.7 billion to data centers in Spain alone (Amazon), with Microsoft and Google each committing billions more across the continent. Europe's own auditors concluded the Chips Act will likely reach only 11.7% of the global chip value chain by 2030, against a 20% target (European Court of Auditors).

The rulebook is a powerful lever. But you cannot regulate a substitute into existence as fast as a competitor can build the thing you depend on. That is the gap.

What to do while the gap exists

The pragmatic move is not to wait for Europe to "win," and not to treat compliance as the finish line. It is to turn the same effort you already spend on compliance into a genuine reduction in dependence.

  1. Tier your workloads. Decide which functions truly need sovereign treatment and which don't. Not everything has to move; the crown jewels do. (We make the full case for this in Sovereignty Is Not Autarky.)
  2. Make "can we leave?" an audit question. A tested exit plan is worth more than a binder of policies. DORA already requires it for critical functions. Apply it everywhere that matters.
  3. Control the keys. The single highest-leverage step: hold your own encryption keys, so compliance with "encryption at rest" also reduces who can be compelled.
  4. Do the compliance once, across frameworks. Evidence collected for NIS2 should count toward DORA and ISO 27001, and should map to controls that genuinely lower dependence, not just satisfy an auditor.

This last point is where compliance and sovereignty stop being in tension. Command turns the frameworks that apply to you into controls that are drafted, mapped, and continuously evidenced across NIS2, DORA, and ISO 27001, so the work you do to pass an audit is the same work that maps and reduces your real dependencies. And because it runs on the Soveryne Cloud Foundation (EU-hosted, operated by an EU entity with no US-jurisdiction subprocessor in the data path and no US-held keys), passing the audit and reducing the dependency become the same motion rather than two competing ones. If DORA is your driver, the Growth plan covers unlimited frameworks with continuous validation.

FAQ

Can you be NIS2 or DORA compliant and still be dependent on US tech? Yes. Compliance proves you have managed a risk to a standard; it does not prove you have removed the underlying dependency or that your provider is beyond foreign legal compulsion.

What's the difference between compliance and sovereignty? Compliance is meeting a defined regulatory standard. Sovereignty is the operational capacity to control, operate, and switch your infrastructure without unacceptable foreign exposure. You can have the first without the second.

Does DORA solve cloud concentration risk? DORA brings critical ICT providers under direct EU oversight and requires exit strategies (important steps), but oversight is not substitution. The dependence remains until alternatives exist and are adopted.

How can compliance work also reduce dependence? By mapping each control to the framework and to the dependency it addresses, and by holding your own keys and testing your exits. So audit evidence doubles as a sovereignty measure.


Passing the audit is necessary. It is not sufficient. The next post shows exactly who can be compelled to hand over your data, and the architecture that takes the question off the table. To make compliance and sovereignty the same motion, explore Command or see the Growth plan for DORA.

Sources