Executive summary

Everyone is telling European managed service providers (MSPs) that sovereign cloud is a growth engine. The numbers agree. Gartner forecasts $80 billion in worldwide sovereign cloud infrastructure spending in 2026, with European spending growing 83% this year and more than tripling by 2027.

Nobody, however, is telling MSPs where the commercial bottleneck sits. It is not in the data centre. It is in the catalogue, and closing it is a sovereign cloud CPQ problem.

Here is the idea in one line: sovereignty is not a new SKU, it is a multiplier on your existing catalogue complexity. The moment you offer a sovereign variant, your services fork. Two cost bases.

Eligibility constraints that arrive through policy, tenders, and contracts, not discount conversations. Jurisdiction as a configuration attribute that must be accurate, because a quote is a commitment. And mixed bundles, because most real deals are partly sovereign and partly not.

Sovereign cloud CPQ means quoting sovereign offers with those rules built in. This piece explains why the catalogue is the choke point and what the EU Cloud Sovereignty Framework and SecNumCloud mean for anyone quoting in France and across Europe. It also covers what to fix before the deals arrive.

 

The advice every European MSP is getting, and the part it leaves out

The sovereign cloud pitch now writes itself. An analyst deck shows the market curve. A hyperscaler announces another sovereign region. A board asks its MSP leadership team the obvious question: what is our sovereign offer? That sequence is playing out across Europe right now, and almost every version of it skips the same step.

The market curve is real

In its 9 February 2026 forecast, Gartner projects worldwide sovereign cloud infrastructure as a service (IaaS) spending of $80 billion in 2026, up 35.6% from 2025. As Computerworld reported, European investment grows from $6.9 billion in 2025 to $12.6 billion in 2026, then to $23.1 billion in 2027. That is a tripling of European spend in two years.

Rene Buest, Senior Director Analyst at Gartner, frames the driver in the same release: “organizations outside the U.S. and China are investing more in sovereign cloud IaaS to gain digital and technological independence.”

Demand and supply agree

Gartner survey of 241 Western European CIOs and IT leaders found 61% want to increase their use of local cloud providers. Kyndryl’s 2025 Cloud Readiness Report found three quarters of business leaders concerned about the geopolitical risks of storing data in global clouds.

 

The supply side has noticed. AWS launched its European Sovereign Cloud in January, already expanding to Belgium, the Netherlands, and Portugal.

CEO Matt Garman told CNBC that removing the sovereignty trade off “unlocks a huge amount of business.” Each of the major hyperscalers now has a sovereign offering.

So the advice is: build the offer, ride the curve. Here is the part it leaves out. Between the sovereign infrastructure you stand up and the revenue you book sits a document. A quote. And the system that produces it, your catalogue and configuration logic, was never designed to answer the questions sovereignty asks.

Why sovereignty forks the services you sell

Think about what happens the day you launch a sovereign variant. Four things change at once, and each one lands in the catalogue, an asset we have made the case for modernising before. Sovereignty is about to raise the stakes on it.

1. Two cost bases: sovereign versus standard pricing

Sovereign infrastructure does not price like hyperscale. Qualified facilities, cleared staff, audited supply chains, and jurisdiction constrained sub processors all cost money. The margin profile of the sovereign variant differs from the standard one, and differs again by service and region.

One cost model per service becomes at least two, each needing true cost to serve visibility at the moment of quoting, not at month end when the deal is signed.

2. Eligibility rules, not preferences

Some customers cannot accept certain configurations. The constraint arrives through different doors: statutory rules for some, government policy for others, and tender terms, sector regulation, or the customer’s own contract and risk policies for the rest.

France’s “Cloud au centre” doctrine, for instance, requires SecNumCloud or equivalent protection for state digital services involving particularly sensitive data. That is not a universal mandate, and I will not pretend otherwise. But at quote time the distinction hardly matters. If this buyer, on this deal, cannot accept that configuration, quoting it is a compliance incident waiting for a signature.

3. Jurisdiction as a configuration attribute

Where data rests. Which entity operates the service. Who can compel access under which law. Which sub processors sit in the chain. These used to be appendix material. In a sovereign deal they are quotable attributes that must be accurate, because the quote document is a commitment.

The exposure is not hypothetical. The EU’s own sovereignty assessment methodology measures exposure to foreign legislation such as the US CLOUD Act, which can compel a US controlled provider to produce data regardless of where it is stored. If your quote promises French residency under a French entity and your delivery reality is subtly different, you have not made a sales error. You have made a legal representation you cannot honour.

4. Mixed bundles, because real deals are hybrid

Most real deals are partly sovereign and partly not. A regulated workload goes to the qualified environment. The development estate stays on standard public cloud. Managed services wrap around both.

Gartner’s forecast notes that 80% of sovereign cloud spend comes from new solutions or migrating legacy workloads, sitting alongside estates that remain on global platforms. Expressing that in one quote, with correct pricing, margin, and compliance attributes per line, is exactly where spreadsheet and hope quoting collapses.

Sovereignty is not a new SKU. It is a multiplier on your existing catalogue complexity: every service, times every jurisdiction, times every eligibility class.

The tempting workaround is cloning a second “sovereign catalogue.” That doubles the maintenance surface and guarantees the two drift apart, which is how a quote ends up promising last quarter’s compliance posture. The MSPs who win will carry the multiplication inside one governed catalogue. The ones who lose will discover it in their error rate.

Approval alone cannot enforce sovereignty

There is a tempting shortcut, and it deserves to be closed off directly: “we will add an approval step.”

Approval workflows are sequenced wrong for this problem. By the time a quote reaches an approver, the ineligible configuration has been assembled, priced, and often discussed with the customer.

The approver now chooses between blocking a deal the customer has seen, or waving through a configuration that should never have existed. It is the failure pattern we documented in the Missing Mile: commercial intent degrading in the gaps between systems.

To be precise: approval remains a legitimate secondary control, and it should stay. But sovereignty has to be enforced first at the point of configuration.

The catalogue itself must know that this customer class cannot receive that variant, and that this margin floor differs on sovereign infrastructure. That is governed autonomy: speed for the seller, control for the business, and approval reserved for genuine judgement calls.

France made sovereignty measurable. Then Brussels gave it a score.

SecNumCloud made it precise

The first development is SecNumCloud, the qualification issued by ANSSI, France’s national cybersecurity agency, and the strictest French security baseline for cloud services. The current version, 3.2 from the 2022 revision, runs to more than 360 criteria and, as Legiscope documents, requires demonstrable immunity from extraterritorial laws such as the US CLOUD Act and FISA 702.

Two details matter for anyone building an offer. First, supply is scarce. Per the current ANSSI qualified catalogue, roughly eleven providers hold qualified services, with more candidates in the pipeline, including Bleu, the Capgemini and Orange venture delivering Microsoft Azure under French control. The list moves, so check it on the day you quote.

Second, and this catches people out, SecNumCloud qualifies a specific cloud offer, not a provider or its infrastructure generally. A service hosted on qualified infrastructure does not automatically inherit the qualification.

“Our provider is qualified” and “this line item is qualified” are different statements, and only one belongs on a quote. That is exactly the kind of attribute a catalogue must carry at service level.

Then Brussels gave it a score

The second development is the EU Cloud Sovereignty Framework, published by the European Commission on 20 October 2025 and explained on the Commission’s own site. It grades cloud services against eight sovereignty objectives, each scored 0 to 4 on the SEAL scale, producing a weighted sovereignty score. Sovereignty now has a number.

The framework was built for EU institutional procurement, not as a binding commercial standard, and honesty about that scope matters. But watch the trajectory. In April 2026 the Commission used it to award contracts worth up to EUR 180 million to four providers. Per the Commission’s own account, bidders needed at least SEAL-2 to be eligible, and most winners reached SEAL-3.

The Commission then published implementation guidance for other public entities, and its June 2026 Cloud and AI Development Act proposal extends the idea with a four level sovereignty framework for sensitive public sector workloads. Scoring is spreading from one tender towards a market convention.

What the catalogue controls, and what it does not

Here is the boundary my own headline risks blurring, so let me draw it myself. The EU framework assesses eight dimensions, including ownership, supply chain, personnel, and environmental factors. Most of that evidence cannot originate in a CPQ system, and a quote cannot prove runtime residency or key custody by itself. Infrastructure creates sovereign capability.

Legal, security, and operational systems validate it.

What the catalogue does is make validated capability commercially selectable and quotable, and it stops sales promising what delivery cannot support.

That is sovereign cloud CPQ in one sentence. The catalogue is the commercial control surface of sovereignty, not the whole evidence system. That is a narrower claim than my headline, and a stronger one.

Get this architecture right and the output is more than a quote. It is a sovereignty evidence pack: the per line configuration record a buyer scoring you can actually assess. In a market learning to score sovereignty, the provider who attaches evidence beats the provider who attaches adjectives.

Sovereign cloud CPQ: the five tests of readiness

The practical question for your quote to cash motion is narrow. A French public sector prospect or a pan European bank asks for a proposal next month.

Can you produce a quote that is fast, priced on the right cost base, and accurate in every sovereignty attribute? This holds whether you resell a hyperscaler’s sovereign regions or operate your own qualified stack. Only the attributes differ, not the discipline.

Run them against your own environment. If you pass more than two, you are ahead of the market, because the tooling that makes all five routine has never been standard in provider quoting stacks.

The questions to take upstairs

Then take four questions into your next leadership meeting.

How much faster could we launch a sovereign variant if the catalogue carried the rules?

How many tenders would an ungoverned catalogue quietly disqualify us from?

What margin risk does a second cost base create at our current discounting habits?

And who owns the answer?

Your numbers will make the case better than mine ever could.

Ninety days to close the gap

Closing the gap is bounded work, and it needs a single owner with authority across product and revenue operations. Thirty days to inventory which services carry a sovereign variant and document each cost base. Thirty to define the eligibility classes your markets impose.

Thirty to move those rules into the quoting system itself, the approach we describe as governed revenue architecture. Treat this as a recommended operating model, not a guaranteed timeline. But a provider who starts now will meet the tenders with an asset late movers will assemble under deadline pressure.

And the market will not wait.

Gartner’s John-David Lovelock put it plainly in the firm’s European IT spending forecast: “Cloud investments in Europe will be more turbulent in 2026 as CIOs focus on digital sovereignty and move their cloud services closer to home.”

Funded sovereign procurements are already running: Brussels has awarded its EUR 180 million framework, and France’s qualified pipeline keeps growing. The buyers behind them have a scoring rubric in hand.

Why servicePath™

servicePath™ is a Configure, Price, Quote (CPQ) and Revenue Lifecycle Management platform built for complex technology sales.

It has been named a Visionary in the Gartner Magic Quadrant for CPQ for four consecutive years, 2023 to 2026, and the sole Visionary for the last three. The sovereign fork is exactly the class of problem its architecture exists to govern.

Map the platform’s documented capabilities onto the five tests. Rule based configuration prevents incompatible selections and enforces pricing and compliance policies at the moment a quote is built: the mechanism an eligibility constraint needs.

Cost to serve analytics give per line margin visibility, which two cost bases demand. Multi tier catalogues with global compliance rules let sovereign and standard variants live side by side, and shadow quote testing means a new variant can be modelled before it touches a customer.

Finally, version history, audit trails, and Service Contracts keep the configuration evidence retrievable through renewal and revision.

Proof from providers like you

telent, which operates critical national infrastructure in the UK across rail, public safety, defence, and the public sector, quotes £50 to £60 million in annual costs. The team moved that off spreadsheets and onto servicePath™ in an eight week deployment, after a failed CPQ implementation elsewhere.

At Dell EMC, the platform made complex proposal changes 98% faster, as little as 15 minutes instead of a day, with partners generating their own quotes and configurations.

I will be straight about what this proves.

Neither engagement was a sovereign cloud build. What they demonstrate is the underlying discipline: governing complex, fast changing, rule bound configurations at quote time. Sovereignty is that same discipline with a legal edge, and we would rather show you than assert it.

That is governed autonomy in practice: sellers move at deal speed, and the business never signs a promise it cannot keep.

The window is open, briefly

Every structural shift in our industry has had a short period where operational readiness, not marketing, decided who captured the value. Sovereign cloud in Europe is in that period now, and sovereign cloud CPQ is the readiness that decides it.

My bet: within two tender cycles, a sovereignty score will sit beside price in most regulated European evaluations. Providers who treat sovereignty as a data centre story will build capacity and lose deals on paperwork. Providers who treat the catalogue as the commercial control surface will quote accurately and take the business.

Fix the catalogue.

See it against your own catalogue

The five tests are a working diagnostic. Run them, and if any test fails, the fastest way to see what governed sovereign quoting looks like is to watch it happen in a demo: sovereign and standard variants, separate cost bases, and eligibility rules applied before a quote is ever assembled.

Book a demo

Meet us at Big Data & AI Paris, 15 to 16 September

Find servicePath™ on the Ontario Stand (RX France) at Paris Expo Porte de Versailles, Pavilion 7.2, across both days.

 

Frequently asked questions

What is sovereign cloud CPQ?

Sovereign cloud CPQ is the ability to configure, price, and quote sovereign cloud services with jurisdiction, eligibility, and cost rules enforced inside the quoting system itself. A quote is a commitment: sovereignty attributes such as data residency and operating entity must be accurate on the document, and eligibility constraints must be applied before a configuration is assembled.

How big is the European sovereign cloud opportunity for MSPs?

Gartner forecasts worldwide sovereign cloud IaaS spending of $80 billion in 2026, up 35.6% from 2025. European spending grows 83% this year to $12.6 billion, then to $23.1 billion in 2027. Sovereign deals need local operation, qualified environments, and managed services, so MSPs sit at the natural point of delivery.

What are SEAL levels in the EU Cloud Sovereignty Framework?

It is a methodology published by the European Commission on 20 October 2025 for its own procurement. It grades cloud services against eight sovereignty objectives, each scored 0 to 4 on the SEAL scale, producing a weighted sovereignty score. The Commission used it to award a EUR 180 million procurement in April 2026, and the June 2026 Cloud and AI Development Act proposal extends the scoring approach.

Why is an approval workflow alone not enough to enforce sovereignty?

Because approval happens after configuration. By the time a quote reaches an approver, the ineligible configuration has been assembled, priced, and often shared with the customer. Eligibility rules must be enforced first in the catalogue at the moment of configuration, which prevents non compliant quotes from existing. Approval then remains a useful secondary control for genuine judgement calls.

For definitions of the terms used in this piece, from CPQ AI to composable revenue architecture, visit the servicePath™ glossary. For more analysis like this, explore our Insight library.

 

About the author

Daniel Kube is the CEO of servicePath™, the Configure, Price, Quote (CPQ) and Revenue Lifecycle Management platform for complex technology sales, recognised as a Visionary in the Gartner Magic Quadrant for four consecutive years.

His writing for revenue leaders includes the Missing Mile, on the gap between CRM and the general ledger where commercial intent gets lost, and the Revenue Brain, on the governed architecture layer that closes it. He publishes regularly through the servicePath™ Executive Conversations  series. Connect with Daniel on LinkedIn, or explore more of his thinking in the Insight library.

Revolutionize Your Sales Operations With Our Gartner Recognized CPQ+ Solution. Book A Demo.