EDSO · European standard · certification across six assessment domains and four maturity levels

Prove digital sovereignty. Auditable. European.

EDSO is the European standard for digital sovereignty — with auditable certification across six assessment domains (D1–D6) and four maturity levels (L0, L2, L3, L4). The six domains form a provider's sovereignty profile. The four levels define the depth of the assessment and the strength of the evidence required.

European Digital Sovereignty Standard · Standard development and conformity assessment structurally separated

Why EDSO works in procurement, audits and supervisory contexts

Why EDSO works in procurement, audits and supervisory contexts

NIS2 · DORA · EUCS · AI Act
Regulatorily aligned

Domains and evidence are mapped to the central EU frameworks.

Auditable, not declarative
Audit by independent conformity assessment bodies

Standard development and conformity assessment are structurally separated. No self-labelling.

Public register
Verifiable for buyers

Certificates are machine-readable and can be verified via public key.

Procurement-ready
Usable as MEAT award criterion

Usable as an objective award criterion in European public procurement.

Three paths

What is your role?

EDSO addresses three groups with different entry paths. Select your role for the relevant next steps.

Providers

Cloud, SaaS and platform providers seeking to demonstrate digital sovereignty to buyers and supervisory authorities in an auditable way.

Certification for providers

Buyers

Public sector and regulated industries using EDSO as a reference framework in tenders and supplier assessments.

Use EDSO in procurement

Conformity assessment bodies

Auditors and advisory firms wishing to perform EDSO audits as a recognised conformity assessment body.

Assessor programme

Why now

Three forces are converging.

Regulation
NIS2, DORA and the EU AI Act require robust evidence across the IT supply chain.
Geopolitics
The US CLOUD Act and comparable regimes turn third-country dependencies into corporate risk.
Market
Buyers demand demonstrable European sovereignty — a unified standard has been missing.

Consequence: providers without auditable evidence are increasingly excluded from tenders — broad sovereignty claims no longer satisfy new regulatory and buyer-side requirements.

What EDSO actually assesses

Six assessment domains. Four certification tiers.

The assessment domains define what is assessed — together they form the sovereignty profile of a provider. The maturity levels define how deep and how binding the assessment is, and thus the strength of the resulting evidence.

Six assessment domains (D1–D6)

Four maturity levels (L0, L2, L3, L4)

L2 — EU-ALIGNED

Possible outcome of an external audit. Proven EU anchoring and resilience, but remaining structural dependencies. Use: regulated buyers requiring a sound baseline.

Auf Badge klicken für Details →

L3 — EU-SOVEREIGN

Higher outcome of the same external audit. Fundamental EU sovereignty, key authority, demonstrable exit strategy, audited supply chain. Use: critical-infrastructure projects, NIS2/DORA-regulated functions.

Auf Badge klicken für Details →

L4 — CRITICAL EU-SOVEREIGN

Highest stage requiring mandatory on-site audit. Resilience, emergency preparedness and real-tested exit/recovery paths at board level. Use: highest protection objectives, critical-infrastructure control, security-related administration.

Auf Badge klicken für Details →

Vorstufe · keine Zertifizierung

L0Basisstufe

L0

Structured self-assessment. EU legal seat, minimum transparency, disclosure of material sub-processors. Use: sensitive standard projects.

L0 ist eine Selbsteinschätzung — nicht auditiert, nicht extern validiert. Kein Zertifikat, kein Badge. Badges und Zertifikate gibt es ab L2.

Zwischenstatus · kein Reifegrad

L1In Vorbereitung

L1 — Verfahren läuft

L1 kennzeichnet Organisationen, die sich auf ein Audit nach L2 oder L3 vorbereiten oder deren Audit begonnen, aber noch nicht abgeschlossen ist — etwa während Nacharbeiten an Dokumentation, Strukturen und Abhängigkeiten.

L1 ist kein Reifegrad und kein Prüfergebnis: kein Zertifikat, kein Badge, keine Vorwegnahme des Audit-Ausgangs. Mit Abschluss des Audits endet L1 und es gilt das erreichte Ergebnis (L2 oder L3). Wer bereits L3 hält und ein L4-Audit durchläuft, behält währenddessen L3.

Statusmatrix und Regeln zu L1 ansehen

The certification path

Four steps. Clearly defined effort.

  1. Step 01

    Self-assessment

    Structured online questionnaire as the audit mode of base level L0 — the assessed party is the provider organisation, not a single service.

    Duration
    approx. 20 min.
    Cost
    EUR 490 net one-off · or from EUR 79/month
  2. Step 02

    Result & confirmation in your account

    The result profile, L0 confirmation and further evidence documents are available for download in the member account immediately.

    Duration
    immediate
    Cost
    included
  3. Step 03

    Apply for an audit for L2/L3 or L4

    Application for an external certification audit. L2 and L3 are two possible outcomes of the same audit; L4 is handled as a separate on-site audit on request.

    Duration
    8–16 weeks (audit)
    Cost
    EUR 2,900 net (L2/L3) · L4 on request
  4. Step 04

    Certificate & badges in your account

    After a passed audit, the certificate and badges (L2, L3, L4) are available for download directly in the member account; the entry in the public EDSO register is added automatically.

    Duration
    immediate
    Cost
    included

What clients gain

Concrete value — precise, auditable, usable.

  • Auditable evidence in EU procurement (MEAT-capable award criterion).
  • Reduction of regulatory audit burden through a recognised reference framework.
  • Listing in the public EDSO register — visibility for buyers.
  • Machine-readable certificate, cryptographically verifiable.
  • SBOM, HYOK and exit guidance as immediate by-products.
  • Clear development path from L0 to L4 — stages instead of blanket verdicts.

EDSO is

  • An assessment framework for digital dependencies
  • A transparency instrument for procurement
  • A governance instrument for the C-level

EDSO is not

  • A political signalling instrument
  • An IT security certification (e.g. ISO 27001)
  • A consulting framework

Competitive advantage · Proof, not claim

Make digital sovereignty visible — in competition, in tenders, in sales.

Buyers, procurement bodies and supervisory authorities require verifiable evidence of digital sovereignty. With EDSO you obtain documents and marks that you can use directly in bids, sales materials and regulatory evidence.

Documents in the member account

EDSO · L0

L0 confirmation (self-assessment)

Result profile and evidence of the structured self-assessment. Not a certification.

Selbsteinschätzung
Certificate L2, L3 or L4

Badges for website, bids and tenders

EDSO L2 EU-ALIGNED BadgeEDSO L3 EU-SOVEREIGN BadgeEDSO L4 CRITICAL EU-SOVEREIGN Badge

Badges for L2 EU-ALIGNED, L3 EU-SOVEREIGN and L4 CRITICAL EU-SOVEREIGN. For use on websites, in pitch decks, bids and tender documents.

What you gain

  • Verifiably rateable in public tenders

    EDSO can be used as an objective award criterion (MEAT) in European procurement. Your evidence is assessed on the record — not merely asserted.

  • Head start in sales and account development

    Certificate and badge prove digital sovereignty to procurement, IT and compliance without additional rounds of explanation. Shortens sales cycles with security- and regulation-sensitive customers.

  • Differentiation in the European market

    Providers without verifiable sovereignty evidence are increasingly excluded from regulated tenders. With EDSO you position yourself visibly against non-European and unaudited competitors.

  • Less effort in audits and reviews

    The EDSO evidence is increasingly recognised as a reference framework in NIS2, DORA and supplier reviews. Statements on data authority, supply chain and exit capability do not have to be re-substantiated in every audit.

Frequently asked questions

What decision-makers want to know first.

How does EDSO differ from the European Sovereign Stack Standard (ES³)?
ES³ was issued by Schwarz Digits — a cloud provider that itself operates in the market being assessed. EDSO is designed as an independent organisation with a multi-stakeholder supervisory board from industry, civil society, academia and the public sector. In substance both refer to the EU Cloud Sovereignty Framework and use a four-stage maturity model with a minimum principle; EDSO assesses across six management-grade domains (D1–D6) instead of nine dimensions, publishes the full methodology openly and does not exclude any provider — including hyperscalers — by definition, but rather makes differences visible. ES³ is therefore a possible certification candidate under EDSO, just like SecNumCloud, BSI C5 or DigiD.
How does EDSO differ from ISO 27001, BSI C5 or EUCS?
ISO 27001, C5 and EUCS address IT security. EDSO addresses digital sovereignty — i.e. data authority, supply chain, legal jurisdiction and exit capability. The two are complementary.
How long does a certification take?
Self-assessment in around 20 minutes. From application to issued certificate typically 3–6 months, depending on maturity level and scoping.
Who performs the audit?
Accredited conformity assessment bodies that are structurally independent from the sponsoring organisation. Standard development and assessment are organisationally separated.
What happens if a maturity level is not reached?
You receive a detailed report with gaps and concrete remediation actions. Re-certification is possible without a full repeat of the audit effort.
What does a certification cost?
L0 (base level / self-assessment / register listing) costs EUR 490 net one-off, EUR 790 net per year or EUR 79 net per month and is not a certification. The external certification audit resulting in L2 (EU-ALIGNED) or L3 (EU-SOVEREIGN) is priced jointly (EUR 2,900 net audit fee, EUR 3,900 net per year, EUR 390 net per month) — L2 and L3 are two possible results of the same audit. L4 (CRITICAL EU-SOVEREIGN) is handled separately and priced on request. Audits are carried out exclusively by accredited assessment bodies.
Wie lange ist ein EDSO-Zertifikat gültig?
Ein EDSO-Zertifikat ist zwölf Monate gültig; danach erfolgt eine verkürzte Re-Zertifizierung. Bei strukturellen Änderungen — etwa Eigentümerwechsel, Verlagerung von Hosting-Standorten oder neuen Subunternehmern — besteht eine sofortige Meldepflicht, damit das ausgewiesene Level jederzeit belastbar bleibt.
Gibt es K.-o.-Kriterien, die eine Zertifizierung ausschließen?
Ja. In D1 (Juristische Verortung) führen ein fehlender EU/EWR-Rechtssitz, eine intransparente Eigentümerstruktur oder ein nachweisbarer Drittstaat-Kontrollzugriff zur Ablehnung. In D5 (Resilienz und Exit-Fähigkeit) begrenzt eine fehlende oder nicht dokumentierte Exit-Strategie das erreichbare Level — unabhängig vom Ergebnis in anderen Domänen. Diese Kriterien sind nicht durch hohe Werte an anderer Stelle kompensierbar.
Welche Reifegrade gibt es — und wann ist welcher relevant?
L0 ist die strukturierte Selbsteinschätzung der anbietenden Organisation und ausdrücklich keine Zertifizierung. L1 ist kein eigener Reifegrad, sondern der Zwischenstatus einer Organisation, die sich auf ein Audit vorbereitet oder sich in einem laufenden Auditverfahren befindet; er endet mit Abschluss des Audits und begründet weder Zertifikat noch Badge. L2 EU-ALIGNED und L3 EU-SOVEREIGN sind zwei mögliche Ergebnisse desselben externen EDSO-Audits (remote oder vor Ort) durch eine akkreditierte Prüfstelle: L2 belegt eine belastbare Aufstellung mit offen benannten Restrisiken, L3 die belastbare EU-Souveränität. L4 CRITICAL EU-SOVEREIGN ist die höchste Stufe und wird als eigenständiges Audit mit zwingender Vor-Ort-Prüfung und real getesteten Exit-Szenarien durchgeführt. L2, L3 und L4 werden ausschließlich durch akkreditierte Prüfstellen ausgestellt.
Strebt EDSO eine offizielle Normierung an?
Ja. EDSO ist als privatwirtschaftlicher Standard gestartet, mit dem Entwicklungspfad zur DIN-SPEC als Vorstufe zu einer offiziellen Norm. Der Einreichungsprozess ist für 2026/2027 vorgesehen. Spezifikation und Methodik werden öffentlich gepflegt, damit sie institutionell anschlussfähig bleiben.
View all FAQs