Skip to content

Sovereign cloud, managed services: how French providers are rewriting the rules for European mid-market IT

New EU rules are making cloud sovereignty a practical procurement test for mid-market CIOs. The question is no longer simply where data is hosted, but who operates, secures, restores, and can help move critical workloads.

Key takeaways

  • NIS2, DORA and the EU's Cloud and AI Development Act are turning cloud sovereignty from a compliance topic into a procurement criterion.
  • A sovereign managed cloud service covers operations, security, and recovery, not just hosting under European jurisdiction.
  • French providers such as Jiliti are building multi-country European networks to compete with hyperscalers on mid-market workloads.

For years, European mid-market companies treated cloud sovereignty as a concern for banks and governments. 2026 has changed that. Between new cybersecurity obligations, financial-sector resilience rules, and Brussels' push for a European cloud infrastructure, the question facing CIOs is no longer whether jurisdiction matters, but how to act on it without rebuilding their entire IT estate.

The 2026 regulatory shift and what it means for CIOs

Three texts now shape cloud decisions in Europe: NIS2, DORA, and the newly proposed Cloud and AI Development Act. NIS2 extends strict cybersecurity requirements to thousands of mid-sized companies that were previously out of scope. DORA imposes resilience and exit-strategy obligations on financial entities and, indirectly, on their IT providers. And in June 2026, the European Commission presented the Cloud and AI Development Act (CADA), part of a broader technology sovereignty package, a political answer to a market where Amazon, Microsoft and Google hold around 70% of European cloud spending, while European providers' share has been stuck at 15% since 2022, down from 29% in 2017 (Synergy Research Group, 2025). A market that is anything but marginal: European cloud infrastructure revenues reached €61 billion in 2024 and were on track to exceed €75 billion in 2025, according to Synergy Research Group.

For a CIO, the practical consequences are concrete: knowing where data physically sits, demonstrating auditability to regulators, and proving that workloads can be moved out of a provider if needed. Reversibility, long buried in contract annexes, has become a selection criterion in its own right.

What a sovereign managed cloud service actually covers

Sovereignty alone does not run workloads. A European data center answers the jurisdiction question, but mid-market IT teams, often a handful of people, still need someone to operate what sits inside it. That is the difference between sovereign hosting and sovereign managed cloud services: the latter bundles infrastructure with day-to-day operations, monitoring, backup, disaster recovery, patching, and security under a shared responsibility model where the provider is contractually accountable for defined service levels.

That distinction matters under the new rules. NIS2 and DORA do not ask companies where their servers are; they ask who detects an incident at 3 a.m., how fast systems are restored, and who signs off on the audit trail. For organizations that cannot staff those functions internally, a managed model is what turns compliance from a document into an operating reality.

The Jiliti example, at European scale

French group Jiliti illustrates how local providers are positioning against hyperscalers. After integrating Naitways, a French sovereign cloud operator, in 2025, the group extended its footprint beyond France, opening points of presence in Frankfurt and Milan in March 2026 to deliver cloud services under local jurisdiction across markets. The group is certified ISO 9001, ISO/IEC 27001 and ISO 14001, and holds an EcoVadis Platinum rating (2025), placing it in the top 1% of companies assessed. Its analysis of private cloud as the foundation of digital sovereignty reflects a broader European conviction: control over sensitive data starts with controlling the platform it runs on.

The bet of European IT infrastructure services group Jiliti is that mid-market companies will choose providers able to combine proximity, regulatory alignment, and industrial-grade operations.

For CIOs evaluating that promise, three criteria stand out. First, jurisdiction: is the entire chain, from infrastructure to operator to support, subject to European law? Second, scope: does the contract cover operations and recovery, with measurable SLAs, or only hosting? Third, reversibility: can data and workloads be repatriated or moved, and has that exit actually been tested? In 2026, those three questions separate a sovereignty label from a sovereignty strategy.

Comments

Latest