CSF, SOV, SEAL and CADA are often mixed up. Below: what they are, who sets the score,
and how ICTboard relates. Not a calculator — the right words.
Not a sovereignty calculator.ICTboard does not replace CSF, SEAL, CADA, or internal assessments. It is the external sensor when the field pressures your assurance and procurement assumptions — intelligence assist, not a compliance rating.
Cloud Sovereignty Framework (CSF)
Purpose
One official EU yardstick to assess how sovereign a cloud service is (not “how sovereign is our company”).
Value
Buyers and contracting authorities can compare suppliers on the same topics instead of marketing claims.
Who
The buyer / contracting authority applies the framework to a supplier’s service(s) — often at major procurement or reassessment. The supplier provides evidence, but “the score” is not a badge the supplier simply issues.
SOV-1 … SOV-8
Purpose
The eight sovereignty objectives — the chapters of the CSF exam (e.g. strategic, legal, data/AI, operational, supply chain, technology, security/compliance, environment).
Value
You see where weakness sits (e.g. jurisdiction vs certificates), not only one total score.
Who
The same assessment as under the CSF; SOV is not a separate product or mark.
SEAL (Sovereignty Effectiveness Assurance Level)
Purpose
The 0–4 level that comes out of the CSF assessment — the exam scorecard.
How
SEAL works as a weakest link: the overall level is capped by the lowest relevant component; a strong security score does not lift a weak legal score. There is often also a weighted Sovereignty Score (%) to rank bidders that clear the SEAL threshold.
Value
A clear threshold for “good enough for this workload” instead of vague “sovereign cloud” language.
Who
Set in the buyer’s assessment process (optionally with an adviser/auditor) from answers/evidence about the supplier’s service — not a periodic company certificate the supplier “awards” itself.
CADA (Cloud and AI Development Act)
Purpose
EU legislative track with a separate ladder of four assurance levels for cloud/AI (especially where public or sensitive workloads are procured).
Value
Links how sensitive the workload is to which level the service may deliver — sovereignty as a market-access condition, not brochure language alone.
Who
The buyer decides which level the workload requires; providers must demonstrate that level (recognition/audit path per level). Separate from the CSF: not “SEAL and CADA from one exam”.
ICTboard
Purpose and value
The radar between those snapshots — signals when the field (news, regulation, incidents, vendor behaviour) pressures assumptions under a prior assessment.
What it is not
Not a CSF/SEAL/CADA calculator, not a second scorecard, not a replacement for supplier assessment or internal audit. Personalisation stays via the five context questions, not mandatory SEAL/CADA input.
For a typical hyperscaler posture (low SEAL / CADA Level 1), ICTboard signals when the field pressures jurisdiction, supply chain, or identity — relevant before your next assessment. Not a second scorecard.
Also in the senior ICT brochure (appendix). Dutch source text is the Tier C canon; this page is the English product mirror.