The Cloud Strategy Test: Sovereign Multicloud Strategy
What is a sovereign multicloud strategy? It is a risk-based approach to workload placement that balances sovereignty, resilience, cost and innovation while limiting vendor lock-in. This article explains dependency mapping, workload classification and tested cloud-exit planning.
Lino Consulting Research
8/26/20267 min read


Sovereignty Without Isolation. Multicloud Without Ideology.
Cloud strategy has entered a more demanding phase. The question is no longer whether an organisation should use cloud services. The real question is whether the organisation can keep innovating when regulation changes, a provider becomes unavailable, prices move, geopolitical conditions deteriorate, or a critical service must be relocated.
That is why cloud sovereignty and multicloud have moved from architecture discussions into the boardroom. Yet both ideas are frequently oversimplified. Sovereignty is treated as a location choice. Multicloud is treated as a provider count. Neither interpretation is sufficient.
The evidence shows why the issue matters. In 2025, 52.7% of EU enterprises used paid cloud services, up 7.4 percentage points from 2023. In a global 2026 study of 753 cloud decision-makers, 88% of organisations reported using more than one cloud and 73% used a hybrid model. Across Europe, the Middle East and Africa, 82% of organisations said geopolitical or regulatory change was causing them to refine their cloud strategy, while 94% planned to adjust or expand their cloud architecture.
Cloud use is becoming more extensive at exactly the moment when leaders are being asked to prove control, resilience and exit readiness. The strategic challenge is therefore not to choose between global scale and sovereignty. It is to decide where each matters, how much optionality is economically justified, and which dependencies must never become irreversible.
Sovereignty Is A Control Model, Not A Map Pin
Data residency answers one question: where is data stored or processed? Sovereignty asks several more.
Who can legally compel access to the data? Who operates the infrastructure? Who controls encryption keys, identities and privileged administration? Can the software supply chain be inspected? Can the workload continue if a global control plane, support organisation or commercial relationship is disrupted? Can the organisation retrieve its data and operate somewhere else?
This makes sovereignty a spectrum of assurance rather than a binary label. A proposed European framework now describes four assurance levels, ranging from EU-based processing and storage to full software-supply-chain transparency and freedom from third-country interference.The direction is significant: workload placement is likely to become more explicitly risk based.
The economic implications are equally important. Dedicated sovereign services commonly carry a price premium because they require isolated infrastructure, screened personnel and additional compliance controls. Market analysis suggests that the premium often falls in the 15% to 30% range. A 2025 German enterprise study found that 44% of companies would consider paying up to 20% more for sovereign cloud capabilities, while one in ten would consider a surcharge above 30%.
That does not mean every workload should move to the highest-sovereignty environment. It means the strongest controls should be reserved for the workloads whose legal exposure, intellectual property, operational criticality or public-interest role justifies the premium.
Multicloud Is Not A Strategy By Itself
Using several providers can improve bargaining power, access specialised capabilities, support jurisdictional requirements and reduce dependence on a single commercial relationship. But a large provider portfolio does not automatically create portability or resilience.
Many multicloud estates were not deliberately designed. They accumulated through acquisitions, decentralised buying, software-as-a-service growth, regional decisions and teams choosing different tools. The result may be multiple contracts and invoices, but the organisation can still be critically dependent on one identity platform, one data layer, one proprietary managed service, one observability stack or one group of scarce specialists.
This distinction matters in a concentrated market. A major competition investigation found that the two largest providers held a combined 60% to 80% share of the UK and European Economic Area infrastructure-as-a-service market from 2020 through 2024. It also found that most customers raised technical barriers when discussing switching or multicloud, including the coding effort, expertise and resources required.
The correct measure is therefore not the number of providers. It is dependency-weighted exposure:
Dependency exposure = workload criticality x switching difficulty x time to recover
An organisation may use four cloud providers and still have one extreme concentration risk. Another may use one primary provider yet maintain independent backups, portable data, recoverable identity, tested infrastructure definitions and a credible alternative operating environment. The second organisation may have greater practical resilience.
The Cost Of Optionality
Optionality has value, but it is not free. A multicloud operating model can require duplicate skills, security controls, observability, networking, policy engines, commercial management and incident procedures. Data synchronisation may create transfer costs and consistency challenges. Engineers may be forced to work at the lowest common denominator, sacrificing differentiated services that could otherwise accelerate delivery.
The cost problem is already visible. In 2026, 85% of organisations identified cloud-spend management as a leading challenge, and estimated wasted cloud spend increased to 29%.Only one in ten organisations in a large EMEA survey reported fully integrated advanced financial-operations practices.Adding providers without adding governance can multiply waste faster than it reduces risk.
This is why the decision should not be framed as single cloud versus multicloud. The better question is: where is the option to move worth more than the cost of maintaining that option?
For a low-risk digital product, the speed and depth of one provider may be the best decision. For a regulated data platform, regional and cryptographic controls may be essential. For a system that must survive the failure of a provider or jurisdiction, a genuinely independent recovery path may be worth its full cost. For stable workloads with predictable demand, private or regional infrastructure may offer stronger control and better economics.
The Exit Is Part Of The Architecture
Regulation is turning cloud exit from a negotiation topic into an operating requirement. The EU Data Act has applied since 12 September 2025 and establishes a framework for switching between data-processing services.It requires contractual and technical support for switching and phases out switching charges, with those charges eliminated from 12 January 2027.In 2026, the European Commission also published draft standard clauses covering switching, termination, security and business continuity.
These rules improve the contractual environment, but they cannot remove application complexity. A legal right to export data does not guarantee that another environment can interpret it. An infrastructure template does not make a proprietary database portable. A container does not carry identity, policy, network behaviour, observability, service dependencies or operating knowledge with it.
Exit readiness must therefore be designed and tested across four layers:
Contractual exit: termination rights, assistance, timelines, cost treatment, data retrieval, deletion evidence and continuity obligations.
Data exit: complete inventories, documented formats, metadata, lineage, encryption keys, transfer capacity and reconciliation procedures.
Technical exit: reproducible infrastructure, dependency maps, replaceable interfaces, target capacity and tested recovery automation.
Operational exit: trained people, decision rights, runbooks, communications, security monitoring and an agreed minimum viable service.
The first time an organisation tests these layers should not be during a crisis. Exit exercises should be treated like disaster-recovery tests: scoped, timed, evidenced and improved.
A Selective Cloud-Placement Model
The strongest strategy begins with workload classification, not provider comparison. A practical model uses four placement patterns.
Open and elastic workloads can use a primary global cloud where innovation speed, scale and advanced services create the most value. Portability should focus on data access, interfaces and recoverability rather than avoiding every differentiated capability.
Regulated workloads need stronger controls over region, encryption, identity, auditability and legal access. A sovereign or trusted environment may be appropriate, but the required assurance level should be defined explicitly.
Business-critical workloads need an independent recovery design. This may involve a second provider, private infrastructure or a regional operator. The deciding test is whether the alternative can restore the minimum viable business within the required time.
Strategic and nationally sensitive workloads require the highest level of control over data, operations, software dependencies and jurisdiction. For these workloads, local operations, customer-held keys, inspectable components or isolation may be more important than access to the broadest service catalogue.
This selective approach avoids two expensive extremes: putting everything into a premium sovereign environment, or forcing every application to run identically on several clouds.
Five Questions For The Executive Team
What must remain under our control?
Define the data, keys, identities, software components, operations and decision rights that cannot be delegated without unacceptable risk.
Where are we concentrated?
Map critical dependencies across providers, managed services, identity, data, network, software licences, operational skills and support channels. Measure concentration by business impact, not spend alone.
What is our minimum viable business?
Identify the smallest set of capabilities that must continue during a provider, regional, legal or commercial disruption. Design recovery around this set first.
Can we leave within the required time?
Set recovery and exit objectives, then run a practical test. Track the amount of data moved, services restored, manual work required, residual dependencies and total cost.
Are we paying for useful optionality?
Make the cost of resilience visible. Include duplicate platforms, talent, data movement, testing, contractual commitments and the innovation value forgone by standardising too aggressively.
Control Is The New Cloud Kpi
Cloud strategy should not be ideological. A single provider is not automatically reckless. Multicloud is not automatically resilient. A sovereign service is not automatically independent. The right architecture is the one that matches control to risk, preserves valuable choices and makes the cost of those choices transparent.
The most important cloud metric is becoming the organisation's ability to act when circumstances change. Can it move critical data? Can it restore the minimum viable business? Can it operate under the required jurisdiction? Can it replace a dependency without rebuilding the company around it?
The future belongs to organisations that use cloud scale without surrendering strategic control. Sovereignty without isolation. Multicloud without ideology. And no critical dependency without a tested exit.
References
Eurostat. (2026, February 3). 53% of EU enterprises used paid cloud services in 2025. https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20260203-1
Flexera. (2026, March 18). 2026 State of the Cloud Report: The convergence of cloud and value. https://www.flexera.com/blog/finops/flexera-2026-state-of-the-cloud-report-the-convergence-of-cloud-and-value/
PwC. (2025, November 7). The new age of cloud: Responding to a shifting paradigm—2025 EMEA Cloud Business Survey. https://www.pwc.com/gx/en/services/consulting/cloud-transformation/emea-cloud-survey-tech-leaders.html
European Commission. (2026, June 3). Cloud and AI Development Act. https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act
Boston Consulting Group. (2025, July 29). Cloud cover: Price swings, sovereignty demands, and wasted resources. https://www.bcg.com/publications/2025/cloud-cover-price-sovereignty-demands-waste
KPMG AG Wirtschaftsprüfungsgesellschaft. (2025, September). Cloud Monitor 2025: Digital sovereignty begins in the cloud. https://assets.kpmg.com/content/dam/kpmgsites/tr/pdf/2025/10/kpmg-cloud-monitor-2025-consulting.pdf
Competition and Markets Authority. (2025, July 31). Cloud services market investigation: Final decision report. https://assets.publishing.service.gov.uk/media/688b8891fdde2b8f73469544/final_decision_report_31.7.25.pdf
European Commission. (2026, July 2). Data Act. https://digital-strategy.ec.europa.eu/en/policies/data-act
European Parliament & Council of the European Union. (2023). Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng
European Commission. (2026). Draft recommendation on non-binding model contractual terms on data access and use and non-binding standard contractual clauses for cloud computing contracts. https://digital-strategy.ec.europa.eu/en/library/draft-recommendation-non-binding-model-contractual-terms-data-access-and-use-and-non-binding
McKinsey & Company. (2025, November 19). Boards are calling for more digital autonomy: How CIOs can deliver. https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/boards-are-calling-for-more-digital-autonomy-how-cios-can-deliver
Deloitte. (2026, June 17). Digital sovereignty: Nachfrage nach europäischen Cloud-Lösungen wächst. https://www.deloitte.com/de/de/Industries/tmt/research/digital-sovereignty-nachfrage-nach-europaeischen-cloud-loesungen-waechst.html
We turn market complexity into executive decisions
Get in Touch
© 2026. All rights reserved.
