On 3 June, the European Commission presented a package of measures aimed at reducing the Union's technological dependence on the United States and China. The package covers cloud computing infrastructure, artificial intelligence services, open-source software and semiconductors.
For those following the debate on digital sovereignty in Portugal, one element stands out from all the others for its practical application: the proposal introduces four levels of digital sovereignty that public authorities will have to consider when procuring cloud services, depending on the sensitivity of each use. At the highest level, which covers sectors such as defence and health, non-European companies are in practice excluded from public contracts.
The stated aim is to avoid the scenario that European documents call a "kill switch": the risk that a foreign government could, from one moment to the next, cut off hospitals or critical systems from the services they depend on.
The starting point
The figures behind the initiative are well known, but their scale is still striking. Amazon, Microsoft and Google account for around 80% of the European cloud computing market, leaving providers based in the Union in a marginal position. According to the Commission's Executive Vice-President responsible for the portfolio, approximately 80% of the technology used in Europe comes from outside the continent.
She highlighted the political dimension of the problem, noting that geopolitics and technology have become inseparable and that Europe must secure a leading role in innovation. The stated goal is to achieve visible results by 2030.
The episode that accelerated the debate
The package did not come out of an abstract debate. One of the strongest warnings for European decision-makers came when the International Criminal Court, after issuing an arrest warrant against the Israeli prime minister, saw its officials targeted by US sanctions, losing access to everyday services provided by American companies.
It was the clearest possible demonstration of an argument that until then had circulated mainly in technical papers: dependence on foreign infrastructure is not just a market issue, it is a question of the ability to function.
What this means for Portuguese organisations
The proposal now goes through the European legislative process and will take time to have an effect. But the direction is unequivocal, and it converges with what is already under way in Portugal. The National Sovereign Cloud Plan, approved in May 2026, rests on exactly the same logic: classify processes and data by criticality, and require different levels of sovereignty according to that classification.
For a Portuguese public body, the practical reading is simple. Classifying data by criticality and requiring sovereignty in procurement are no longer a matter of principle: they are now the direction set in Brussels and in Lisbon. Those who structure their procedures accordingly now will be aligned with a framework that is on its way, instead of having to adapt to it later.
For Sooma, whose infrastructure is entirely within the European Union, with its servers in Portugal and its backups in Germany, and beyond the reach of third-country laws, the package confirms the framework in which the company has operated since 2018. A debate that for years was treated as an ideological preference is now treated as a procurement requirement.
Critical voices
Not all the reactions were enthusiastic, and that is worth noting. The European Parliament produced both support for the approach, described as bold and pragmatic by some MEPs, and reservations about whether it goes far enough. The most frequent criticism is that regulation alone does not create capacity: without investment in Europe's own infrastructure, European preference in tenders risks having nowhere to materialise.
It is a legitimate objection, and it applies equally to Portugal. A sovereignty requirement in tender specifications is only useful if there are national and European providers able to meet it with an equivalent service.
