A government can place critical infrastructure inside its borders and still depend on entities outside its control. A domestic data center, for example, may be operated by a foreign company and rely on technology and supply chains spanning several jurisdictions.
Digital sovereignty is therefore a question of control over critical dependencies. Governments need to identify them, understand how they may change, and preserve options when a supplier, legal regime or security assumption changes.
Digital sovereignty is becoming a question of control
Territorial control does not provide control over every system operating within that territory. Cloud services can depend on operators, technology and supply chains across several jurisdictions.
For governments, this creates an operational test: Which external dependencies affect essential functions? What happens if they change? What options remain if a supplier, jurisdiction or security assumption becomes unacceptable?
Governments can try to reproduce every layer domestically. A control-based approach asks which dependencies matter and what practical options remain when conditions change.
Domestic infrastructure can retain external dependencies
Physical location answers only part of the control question.
A domestic data center can address location requirements while leaving dependencies on operators, technology and cross-border supply chains. Governments need to evaluate these dimensions separately before treating domestic infrastructure as evidence of greater control.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
AI and quantum computing make dependencies change over time
Technical change can alter dependencies. Quantum computing gives governments a concrete example because protected information may remain valuable longer than today’s cryptography remains effective.
The key variable is time. Governments have to compare how long data must remain protected with how long migration could take.
Post-quantum migration makes dependency measurable
Post-quantum migration turns that timing problem into concrete work. Institutions can identify where vulnerable cryptography is used, classify information by its required confidentiality period, set migration priorities, and change procurement requirements.
The useful life of a dependency matters too. A system can meet today’s security requirements yet need a migration plan if its data must remain confidential after its underlying security assumption may change.
Procurement can make sovereignty a control test
Procurement can turn dependency concerns into requirements that buyers can examine before systems become difficult to replace.
The same method can guide technology purchases. A cryptographic inventory can show which systems need migration, while qualification requirements can determine which security products enter government environments. Supply-chain requirements can expose upstream dependencies before purchase.
For a CIO, CISO or procurement leader, this leads to concrete questions. Where is the service operated? Which jurisdiction can compel the operator? Which technologies and suppliers sit upstream? Can cryptographic components be replaced within required deadlines? What evidence demonstrates security and compliance?
Contracts and operating plans can turn those answers into measurable requirements. They can specify jurisdictional constraints, replacement rights, migration deadlines and the evidence buyers require from suppliers. Those controls give institutions a practical way to manage dependencies that cross national borders.
Main highlights
- Control defines digital sovereignty: Governments should assess sovereignty by their ability to manage critical technology dependencies, not simply by where infrastructure is located.
- Domestic infrastructure can still depend on foreign systems: Leaders should evaluate operators, jurisdictions, technologies and supply chains separately before treating local infrastructure as evidence of control.
- AI and quantum change dependencies over time: Governments should plan for technical change by comparing how long critical data and systems must remain protected with how long migration will take.
- Post-quantum migration makes risk measurable: Institutions should inventory vulnerable cryptography, classify data by confidentiality requirements and prioritize systems that need earlier migration.
- Procurement turns sovereignty into enforceable controls: Buyers should set requirements for jurisdiction, suppliers, replacement rights, migration deadlines and compliance evidence before dependencies become difficult to change.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


