Providers
Cloud, SaaS and platform providers seeking to demonstrate digital sovereignty to buyers and supervisory authorities in an auditable way.
Certification for providersEDSO · European standard · certification across six assessment domains and four maturity levels
EDSO is the European standard for digital sovereignty — with auditable certification across six assessment domains (D1–D6) and four maturity levels (L0, L2, L3, L4). The six domains form a provider's sovereignty profile. The four levels define the depth of the assessment and the strength of the evidence required.
European Digital Sovereignty Standard · Standard development and conformity assessment structurally separated
Why EDSO works in procurement, audits and supervisory contexts
Domains and evidence are mapped to the central EU frameworks.
Standard development and conformity assessment are structurally separated. No self-labelling.
Certificates are machine-readable and can be verified via public key.
Usable as an objective award criterion in European public procurement.
Three paths
EDSO addresses three groups with different entry paths. Select your role for the relevant next steps.
Cloud, SaaS and platform providers seeking to demonstrate digital sovereignty to buyers and supervisory authorities in an auditable way.
Certification for providersPublic sector and regulated industries using EDSO as a reference framework in tenders and supplier assessments.
Use EDSO in procurementAuditors and advisory firms wishing to perform EDSO audits as a recognised conformity assessment body.
Assessor programmeWhy now
Consequence: providers without auditable evidence are increasingly excluded from tenders — broad sovereignty claims no longer satisfy new regulatory and buyer-side requirements.
What EDSO actually assesses
The assessment domains define what is assessed — together they form the sovereignty profile of a provider. The maturity levels define how deep and how binding the assessment is, and thus the strength of the resulting evidence.
Eigentum, Jurisdiktion, Konzernsteuerung, extraterritoriale Zugriffsrechte.
D2Standorte, Subunternehmerkette, Betriebs- und Supportorganisation.
D3Schlüsselhoheit, privilegierte Zugriffe, Log-Integrität, Anbieter-Vertraulichkeit.
D4Hardware- und Software-Lieferkette, geopolitische Choke Points, EU-Alternativen.
D5Offene Standards, dokumentierte und getestete Exit-Pfade, RTO/RPO, Migrationsfähigkeit.
D6Verantwortung auf Leitungsebene, ISMS-Integration, Eskalationswege, Transparenzbericht.
Possible outcome of an external audit. Proven EU anchoring and resilience, but remaining structural dependencies. Use: regulated buyers requiring a sound baseline.
Auf Badge klicken für Details →
Higher outcome of the same external audit. Fundamental EU sovereignty, key authority, demonstrable exit strategy, audited supply chain. Use: critical-infrastructure projects, NIS2/DORA-regulated functions.
Auf Badge klicken für Details →
Highest stage requiring mandatory on-site audit. Resilience, emergency preparedness and real-tested exit/recovery paths at board level. Use: highest protection objectives, critical-infrastructure control, security-related administration.
Auf Badge klicken für Details →
Vorstufe · keine Zertifizierung
Structured self-assessment. EU legal seat, minimum transparency, disclosure of material sub-processors. Use: sensitive standard projects.
L0 ist eine Selbsteinschätzung — nicht auditiert, nicht extern validiert. Kein Zertifikat, kein Badge. Badges und Zertifikate gibt es ab L2.
Zwischenstatus · kein Reifegrad
L1 kennzeichnet Organisationen, die sich auf ein Audit nach L2 oder L3 vorbereiten oder deren Audit begonnen, aber noch nicht abgeschlossen ist — etwa während Nacharbeiten an Dokumentation, Strukturen und Abhängigkeiten.
L1 ist kein Reifegrad und kein Prüfergebnis: kein Zertifikat, kein Badge, keine Vorwegnahme des Audit-Ausgangs. Mit Abschluss des Audits endet L1 und es gilt das erreichte Ergebnis (L2 oder L3). Wer bereits L3 hält und ein L4-Audit durchläuft, behält währenddessen L3.
Statusmatrix und Regeln zu L1 ansehenThe certification path
Structured online questionnaire as the audit mode of base level L0 — the assessed party is the provider organisation, not a single service.
The result profile, L0 confirmation and further evidence documents are available for download in the member account immediately.
Application for an external certification audit. L2 and L3 are two possible outcomes of the same audit; L4 is handled as a separate on-site audit on request.
After a passed audit, the certificate and badges (L2, L3, L4) are available for download directly in the member account; the entry in the public EDSO register is added automatically.
What clients gain
Competitive advantage · Proof, not claim
Buyers, procurement bodies and supervisory authorities require verifiable evidence of digital sovereignty. With EDSO you obtain documents and marks that you can use directly in bids, sales materials and regulatory evidence.
Documents in the member account
EDSO · L0
L0 confirmation (self-assessment)
Result profile and evidence of the structured self-assessment. Not a certification.

Badges for website, bids and tenders



Badges for L2 EU-ALIGNED, L3 EU-SOVEREIGN and L4 CRITICAL EU-SOVEREIGN. For use on websites, in pitch decks, bids and tender documents.
What you gain
Verifiably rateable in public tenders
EDSO can be used as an objective award criterion (MEAT) in European procurement. Your evidence is assessed on the record — not merely asserted.
Head start in sales and account development
Certificate and badge prove digital sovereignty to procurement, IT and compliance without additional rounds of explanation. Shortens sales cycles with security- and regulation-sensitive customers.
Differentiation in the European market
Providers without verifiable sovereignty evidence are increasingly excluded from regulated tenders. With EDSO you position yourself visibly against non-European and unaudited competitors.
Less effort in audits and reviews
The EDSO evidence is increasingly recognised as a reference framework in NIS2, DORA and supplier reviews. Statements on data authority, supply chain and exit capability do not have to be re-substantiated in every audit.
Frequently asked questions