ICTboard

EU frameworks in plain language

CSF · SOV · SEAL · CADA — and how ICTboard fits.

CSF, SOV, SEAL and CADA are often mixed up. Below: what they are, who sets the score, and how ICTboard relates. Not a calculator — the right words.

Not a sovereignty calculator. ICTboard does not replace CSF, SEAL, CADA, or internal assessments. It is the external sensor when the field pressures your assurance and procurement assumptions — intelligence assist, not a compliance rating.

Cloud Sovereignty Framework (CSF)

Purpose

One official EU yardstick to assess how sovereign a cloud service is (not “how sovereign is our company”).

Value

Buyers and contracting authorities can compare suppliers on the same topics instead of marketing claims.

Who

The buyer / contracting authority applies the framework to a supplier’s service(s) — often at major procurement or reassessment. The supplier provides evidence, but “the score” is not a badge the supplier simply issues.

SOV-1 … SOV-8

Purpose

The eight sovereignty objectives — the chapters of the CSF exam (e.g. strategic, legal, data/AI, operational, supply chain, technology, security/compliance, environment).

Value

You see where weakness sits (e.g. jurisdiction vs certificates), not only one total score.

Who

The same assessment as under the CSF; SOV is not a separate product or mark.

SEAL (Sovereignty Effectiveness Assurance Level)

Purpose

The 0–4 level that comes out of the CSF assessment — the exam scorecard.

How

SEAL works as a weakest link: the overall level is capped by the lowest relevant component; a strong security score does not lift a weak legal score. There is often also a weighted Sovereignty Score (%) to rank bidders that clear the SEAL threshold.

Value

A clear threshold for “good enough for this workload” instead of vague “sovereign cloud” language.

Who

Set in the buyer’s assessment process (optionally with an adviser/auditor) from answers/evidence about the supplier’s service — not a periodic company certificate the supplier “awards” itself.

CADA (Cloud and AI Development Act)

Purpose

EU legislative track with a separate ladder of four assurance levels for cloud/AI (especially where public or sensitive workloads are procured).

Value

Links how sensitive the workload is to which level the service may deliver — sovereignty as a market-access condition, not brochure language alone.

Who

The buyer decides which level the workload requires; providers must demonstrate that level (recognition/audit path per level). Separate from the CSF: not “SEAL and CADA from one exam”.

ICTboard

Purpose and value

The radar between those snapshots — signals when the field (news, regulation, incidents, vendor behaviour) pressures assumptions under a prior assessment.

What it is not

Not a CSF/SEAL/CADA calculator, not a second scorecard, not a replacement for supplier assessment or internal audit. Personalisation stays via the five context questions, not mandatory SEAL/CADA input.

For a typical hyperscaler posture (low SEAL / CADA Level 1), ICTboard signals when the field pressures jurisdiction, supply chain, or identity — relevant before your next assessment. Not a second scorecard.

Also in the senior ICT brochure (appendix). Dutch source text is the Tier C canon; this page is the English product mirror.

← Back to dashboard · About · Plans · NL · © ICTboard · FRISSE BRONNEN