The long-running debate about digital sovereignty has finally moved to practical implementation. Gaia-X and CISPE introduced the first catalogue allowing organizations to quickly evaluate whether a cloud service truly protects them from foreign jurisdiction.
Simultaneously, NATO and Google Cloud announced a landmark agreement to deploy highly secure, sovereign-grade cloud environment. It’s an unexpected yet strategically important moment for the global cybersecurity landscape.
Gaia-X Level 3: Europe’s Tightest Standard for Data Sovereignty
The headline announcement at the Gaia-X Summit in Porto was the release of the CISPE sovereign cloud catalogue. Europe’s first fully operational system for identifying cloud services based on clear sovereignty guarantees.
The framework evaluates providers along three levels, but Level 3 stands out as a breakthrough, because it requires:
- the provider to be headquartered in the EU,
- independence from extraterritorial laws such as the U.S. CLOUD Act, and
- verified procedures ensuring that foreign entities can’t compel access to customer data.
This is the first time European CIOs can instantly verify whether a cloud service is fully shielded from non-EU legal interference. The first wave of certified providers is intentionally small. Only those capable of meeting the strictest requirements made the list, e.g. Cloud Temple, Opiquad, OVHcloud or Seeweb.
Sebastien Lescop, CEO of Cloud Temple, captured the significance of this shift: “We talk too much about trust. The time has come to show things”.
Why Gaia-X Level 3 Matters for European Businesses?
For enterprises handling sensitive data, this catalogue radically simplifies risk assessment. Instead of navigating vague claims of “European cloud,” companies can rely on a transparent, standardized mechanism.
Furthermore, Europe has also managed something notable. Gaia-X has produced a sovereignty standard faster than the EU’s own developing assessment framework. Both systems are expected to overlap significantly, which gives early adopters a head start in compliance and strategic planning.
For organizations facing complex cloud integration challenges, this shift underscores the importance of designing resilient, well-structured architectures from the outset.
To explore common challenges and best practices, see our conversation: How to Handle Cloud Integration Challenges and Best Practices
What the New CISPE Catalogue Changes in Cloud Security Practices?
Beyond sovereignty ratings, the CISPE catalogue introduces a new level of transparency in cloud security verification.
Historically, assessing a provider’s security posture required lengthy audits, vendor questionnaires, and trust in self-reported compliance. The new CISPE catalog standardizes and simplifies this process by offering:
- verified identity and registration checks (Level 1),
- enhanced manual validation (Level 2),
- explicit independence from foreign jurisdiction (Level 3).
This eliminates ambiguity at a time when security models and cloud dependency risks are becoming more complex. It also supports companies adopting DevSecOps or SecDevOps approaches, where security is integrated throughout the entire application lifecycle.
If you want to dive deeper into modern approaches to application-level security, read our piece about Security as a Service: Security Throughout the Application Lifecycle: Is Security as a Service the Future?
NATO’s Multi-Million Deal with Google Cloud
Only days after the Gaia-X Summit, another major development hit the European security landscape. NATO’s Communications and Information Agency (NCIA) signed a multi-million-euro contract with Google Cloud. The scope of the agreement focuses on implementing Google Distributed Cloud (GDC) air-gapped – one of the most secure cloud environments available today.
GDC air-gapped is part of Google’s sovereign cloud portfolio and is specifically designed for organizations with the highest security requirements. Its core characteristics include:
- complete physical and logical isolation from the public internet,
- strict control over data location and access,
- compliance with rigorous national and international security standards.
This means NATO can process classified and strategic information without exposing it to external networks.
Why NATO Chose This Approach?
NATO will deploy the solution at its Joint Analysis, Training and Education Centre (JATEC) to strengthen operational readiness and provide AI-driven insights while maintaining total control over sensitive data.
As Antonio Calderon, CTO at NCIA, emphasized: “Through this collaboration, we will deliver a secure, resilient and scalable cloud environment for JATEC that meets the highest standards required to protect highly sensitive data”.
This partnership demonstrates a growing trend: global defense organizations increasingly rely on sovereign cloud solutions. Not to replace public clouds, but to complement them where the highest level of assurance is required.
A New Strategic Reality for Europe’s Cloud Landscape
The Gaia-X Level 3 certifications and the NATO–Google Cloud agreement may seem unrelated at first, but together they signal a profound shift in Europe’s digital strategy.
Do you need support navigating cloud sovereignty, security requirements, or integration challenges?
Get in touch with our experts and we’ll help you design a secure and future-ready cloud architecture.

Tomasz Michalik


