Compliant but Dependent: Why Europe Is Regulating Faster Than It Builds
You can pass every audit on the calendar and still not control your own infrastructure. Compliance and sovereignty are not the same thing. Confusing them is the most expensive mistake in European IT right now.

Part of the pillar series Europe's Digital Dependence, Explained.
Europe has built, in under a decade, the most comprehensive digital rulebook on Earth. NIS2, DORA, the Cyber Resilience Act, the Cyber Solidarity Act, the Data Act, the AI Act, and, in 2026, a tech-sovereignty package on top. If regulation alone produced sovereignty, Europe would already be sovereign.
It isn't. And the reason is a gap most boards never see: Europe is writing rules about its dependencies faster than it is building the substitutes for them. An organization can be fully compliant and still be one foreign legal order, one licensing change, or one provider outage away from losing control of its own operations.
This post is about that gap: what the rulebook does and doesn't buy you, and why "we passed the audit" is the beginning of the sovereignty conversation, not the end.
The rulebook is real, and growing fast
First, credit where due. The European rulebook is not theatre; it has teeth, and it is converging on dependence as a named risk.
| Instrument | Status | What it changes |
|---|---|---|
| NIS2 | Transposition Oct 2024 | Broadens cyber obligations and supply-chain security across essential sectors (EC) |
| DORA | Applies Jan 2025 | Direct EU oversight of critical ICT providers; 19 designated Nov 2025 (ESAs) |
| Cyber Resilience Act | In force Dec 2024 | Security-by-design obligations for products with digital elements |
| Cyber Solidarity Act | In force Feb 2025 | Cross-border detection and emergency response |
| Data Act | Switching rules from 2025; egress ban 12 Jan 2027 | Attacks cloud lock-in and switching costs (Art. 29) |
| Cloud and AI Development Act (CADA) | Proposed 2026 | Demand-side measures and sovereignty rules for cloud/AI (EC) |
Notice what DORA in particular represents. When the European Supervisory Authorities formally designated 19 critical ICT third-party providers (names like AWS, Microsoft, and Google among them), they were, in effect, publishing a list of the dependencies the system cannot yet replace. Regulation has become honest about the problem. It has not yet solved it.
What an audit proves, and what it doesn't
Here is the distinction that matters. A compliance certificate is evidence that you have managed a risk to a defined standard. It is not evidence that you have removed the dependency.
| A passed audit proves you have… | …but it does not prove |
|---|---|
| Documented controls and governance | That your provider is beyond foreign legal compulsion |
| Incident reporting and response plans | That you could actually switch providers if you had to |
| Risk assessments on third parties | That a single provider outage won't halt you |
| Encryption and access controls in place | That you (not the provider) hold the keys |
You can satisfy every line on the left and still be structurally dependent. A US-headquartered "EU region" can be fully GDPR- and NIS2-aligned on paper while remaining reachable under foreign law, a point a hyperscaler conceded under oath in 2025, when Microsoft France told the French Senate it could not guarantee French data would never be passed to US authorities (The Register). The audit was never designed to catch that. (We dig into exactly who can be compelled, and why, in the companion piece, Who Can Actually Compel Your Data?)
Why the gap keeps widening
The deeper problem is one of pace. Rules can be written in months; infrastructure takes years and tens of billions. And the spending gap between Europe's substitutes and the incumbents it depends on is stark.

On the build side, the EU's flagship sovereign-cloud procurement (a tender awarded to four European providers in April 2026) was worth €180 million (European Commission). In the same period, a single hyperscaler committed €15.7 billion to data centers in Spain alone (Amazon), with Microsoft and Google each committing billions more across the continent. Europe's own auditors concluded the Chips Act will likely reach only 11.7% of the global chip value chain by 2030, against a 20% target (European Court of Auditors).
The rulebook is a powerful lever. But you cannot regulate a substitute into existence as fast as a competitor can build the thing you depend on. That is the gap.
What to do while the gap exists
The pragmatic move is not to wait for Europe to "win," and not to treat compliance as the finish line. It is to turn the same effort you already spend on compliance into a genuine reduction in dependence.
- Tier your workloads. Decide which functions truly need sovereign treatment and which don't. Not everything has to move; the crown jewels do. (We make the full case for this in Sovereignty Is Not Autarky.)
- Make "can we leave?" an audit question. A tested exit plan is worth more than a binder of policies. DORA already requires it for critical functions. Apply it everywhere that matters.
- Control the keys. The single highest-leverage step: hold your own encryption keys, so compliance with "encryption at rest" also reduces who can be compelled.
- Do the compliance once, across frameworks. Evidence collected for NIS2 should count toward DORA and ISO 27001, and should map to controls that genuinely lower dependence, not just satisfy an auditor.
This last point is where compliance and sovereignty stop being in tension. Command turns the frameworks that apply to you into controls that are drafted, mapped, and continuously evidenced across NIS2, DORA, and ISO 27001, so the work you do to pass an audit is the same work that maps and reduces your real dependencies. And because it runs on the Soveryne Cloud Foundation (EU-hosted, operated by an EU entity with no US-jurisdiction subprocessor in the data path and no US-held keys), passing the audit and reducing the dependency become the same motion rather than two competing ones. If DORA is your driver, the Growth plan covers unlimited frameworks with continuous validation.
FAQ
Can you be NIS2 or DORA compliant and still be dependent on US tech? Yes. Compliance proves you have managed a risk to a standard; it does not prove you have removed the underlying dependency or that your provider is beyond foreign legal compulsion.
What's the difference between compliance and sovereignty? Compliance is meeting a defined regulatory standard. Sovereignty is the operational capacity to control, operate, and switch your infrastructure without unacceptable foreign exposure. You can have the first without the second.
Does DORA solve cloud concentration risk? DORA brings critical ICT providers under direct EU oversight and requires exit strategies (important steps), but oversight is not substitution. The dependence remains until alternatives exist and are adopted.
How can compliance work also reduce dependence? By mapping each control to the framework and to the dependency it addresses, and by holding your own keys and testing your exits. So audit evidence doubles as a sovereignty measure.
Passing the audit is necessary. It is not sufficient. The next post shows exactly who can be compelled to hand over your data, and the architecture that takes the question off the table. To make compliance and sovereignty the same motion, explore Command or see the Growth plan for DORA.
Sources
- European Commission, NIS2 Directive: https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
- ESAs, first 19 critical ICT third-party providers under DORA (2025): https://www.eiopa.europa.eu/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital-2025-11-18_en
- EU Data Act, Article 29 (switching/egress charges): https://www.eu-data-act.com/Data_Act_Article_29.html
- European Commission, Cloud and AI Development Act: https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act
- European Commission, €180M sovereign-cloud procurement (2026): https://commission.europa.eu/news-and-media/news/commission-advances-cloud-sovereignty-through-strategic-procurement-2026-04-17_en
- Amazon, AWS €15.7bn investment in Spain: https://www.aboutamazon.eu/news/job-creation-and-investment/aws-plans-to-invest-15-7-billion-in-spain-supporting-the-creation-of-17-500-jobs-annually-in-local-businesses
- European Court of Auditors, The EU's strategy for microchips (SR 12/2025): https://www.eca.europa.eu/ECAPublications/SR-2025-12/SR-2025-12_EN.pdf
- The Register, Microsoft "cannot guarantee" data sovereignty (2025): https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/

The sovereignty debate keeps offering a false choice: cut yourself off from the world's best technology, or accept permanent dependence. There is a third option, and it's the only realistic one.
Read the next part
"Encrypted at rest" is the most reassuring phrase in enterprise IT, and one of the least informative. The question that actually decides your exposure is simpler and harder: who holds the keys, and who can be compelled to use them?
Read the companion piece

