keystoneDetect · Remediate · Prove

Sovereignty · September 2026

On 12 January 2027, switching your cloud provider becomes free. Nobody can prove they can do it.

EU Data Act Article 29 takes egress and switching charges to zero. Article 30 requires functional equivalence at the destination. DORA Article 28(8) requires exit strategies that are tested, not documented. An exit plan in Confluence is not a test report.

10 September 2026 · Kenio Shirley


The date, and the clause

From 12 January 2027, EU Data Act Article 29 removes switching charges entirely.

Since 12 September 2025, every cloud contract with an EU customer has had to carry the Article 25 terms: notice of at most two months, a transition window of at most 30 days, a retrieval window of at least 30 days, and defined exit assistance. Article 30 requires functional equivalence for IaaS at the destination.

The obligations already exist. What changes in January is that the last commercial excuse for never testing them disappears.

The question a regulator asks

DORA Article 28(8) requires exit strategies that are tested.

A tested exit produces a test report: date executed, volume moved, elapsed time, what failed, RTO and RPO achieved, cost incurred.

Almost nobody has one. What most organisations have is a document describing an intention, reviewed annually by the person who wrote it.

What the market has published — and what it has not

This is research, not an accusation. Each row records what a vendor has published. The finding is the silence, and it should be read as silence rather than as incapacity.

Vendor / projectPublishedNot published
IBM Cloud Sovereignty Risk ProfileAnnounced 28 May 2026. Monitors residency, encryption, resilience, concentration and operational independence, and emits audit-ready evidence.No published GA status, no published multicloud scope, no published price.
Google Cloud Assured WorkloadsContinuously monitors residency and data-boundary controls.Only inside Google Cloud, and only against Google's own control packages.
EscapeCloud / ExitCloudQuantifies an exit score against DORA, EBA, FCA and FINMA.Explicitly does not cover sovereignty or jurisdiction. Exit without jurisdiction.
WizOne blog post committing to AWS European Sovereign Cloud support, dated 13 November 2024 — fourteen months before ESC existed.No sovereignty framework and no residency scoring published since.
Vanta, Drata, OneTrust, LogicGate, ServiceNowExtensive published GRC coverage.No published sovereignty or data-residency module at any of them.
ProwlerAdded aws-eusc partition detection on 16 January 2026, one day after GA.Runs generic NIS2/CIS/GDPR/ISO frameworks rather than a sovereignty framework.

The honest reading: the point-in-time questionnaire tier is crowded and mostly free. The continuous, computed, evidence-generating tier — a live estate assessed against the Commission's framework, producing a per-objective score with drift alerts — has IBM in it, thinly, and essentially nobody else.

The questions are about your estate. The answers are in your estate.

Every sovereignty assessment on the market asks you questions. A questionnaire asks a human to self-report the location of resources that a cloud API will simply tell you.

And the scoring mechanic that most tools get wrong: the EU Cloud Sovereignty Framework's SEAL levels have per-objective floors. A single number is the wrong answer to the actual procurement mechanic. The useful output is "you fail this objective's floor, therefore you are disqualified," not "you scored 68%."

Sovereignty posture is not a certificate. It is a state.

A new region enabled, a new sub-processor added, a support role assumed from outside the EU — each changes the answer, and today nobody notices until an audit.

That is the whole argument for continuous over point-in-time, and it is why an annual assessment is structurally the wrong instrument.

For context on the destination side: AWS's European Sovereign Cloud runs in the aws-eusc partition, region eusc-de-east-1, GA January 2026. The migration detail lives on the sovereign cloud page.

These are regulatory dates and clause references, not legal advice. Your counsel interprets them.

Where Keystone sits — and where it would fail its own scan

Keystone reads the estate rather than asking about it — every resource, its region and partition, and what fraction of the estate is under governance at all. It holds hash-chained evidence, so a drill that ran in March is provable in November.

To be clear about what that is not: Keystone has no shipping sovereignty module, no SEAL scoring engine, no exit-testing feature and no European Sovereign Cloud support. This piece is about the gap, and about what a discovery and evidence engine can already read.

If Keystone held European customers' infrastructure metadata in a US-operated SaaS, Keystone would be a sovereignty finding in its own customers' assessments. We would fail our own scan.

So for EU customers Keystone runs inside your own account, in your own region, and we never hold your data.

Kenio Shirley is the founder of Keystone and runs hireken.io. CISSP, CISM. Seventeen years in enterprise technology across 50+ audits covering SOC 2, HITRUST, FedRAMP, PCI DSS, SOX and IRAP.

Read the estate, not the questionnaire

What sovereignty looks like when it is computed from your own accounts.