Skip to content
Cirran

By Michał Puchała · 2026-08-06 · 4 min read

EU cloud news, week of 2026-08-06

European cloud sovereignty moved into procurement, security operations and resilience this week. Dutch municipalities are defining government-cloud needs, STACKIT added a security layer, cloud spending reached a record, and ENISA set new priorities for a more consistent European approach.

This week, European cloud sovereignty became more concrete in procurement, security operations and resilience planning. The common thread is that control needs evidence in contracts and architecture, not just a label in a product name.

Dutch municipalities are asked to shape a sovereign government cloud The Association of Netherlands Municipalities and the Dutch Digitalisation Strategy's cloud team are asking local authorities what they need from a planned government cloud and cloud-services marketplace. The consultation covers software, platform and infrastructure services through 2030, the required level of sovereignty, and conditions around control, security, continuity and funding. Municipalities can respond until 28 August, so the service design is still taking shape. For boards that sell to or work with the public sector, this is an early signal of how sovereignty may appear in future procurement questions: as a set of measurable requirements rather than a general preference.

STACKIT and Zscaler launch a security platform operated from Germany The companies have made Zscaler's Zero Trust security platform, which verifies individual connections rather than trusting their network location, available from German data centres operated by STACKIT. The joint service covers deployment, management, operation and support, and targets regulated sectors including public administration, defence, finance and healthcare. It combines technology from a US-headquartered security company with European infrastructure and local operations, which makes the division of responsibility important. CTOs should establish who can access logs, change the software, administer customer environments and respond to incidents before deciding which sovereignty requirements the arrangement satisfies.

Cloud infrastructure spending reaches $143 billion in one quarter Market figures reported by ITPro put worldwide cloud infrastructure spending at $143 billion in the second quarter of 2026, $43 billion higher than a year earlier. AWS held 28 percent of the market, Microsoft 20 percent and Google 15 percent, giving the three companies a combined 63 percent share, while the US share of worldwide spending increased. Ireland, Norway, Denmark and Finland were among Europe's fastest-growing cloud markets. For management teams, the message is that AI-led growth is increasing both cloud use and concentration, so renewal and AI investment decisions should include an exit route before another layer of dependency is added.

Cloudflare's disruption review shows how concentrated dependencies fail Cloudflare's review records how a routine change to the cryptographic keys that verify .de domain-name records produced invalid signatures on 5 May, causing requests for German websites to fail until service was restored later that night. Users saw websites fail, email bounce and applications time out, even though the fault sat in a shared naming layer rather than their own systems. The report also notes that traffic to an AWS region in the United Arab Emirates remained low after physical damage prevented the region from reliably supporting customer applications. For technical teams, the practical lesson is to map shared dependencies across domain names, networks and cloud regions, then test whether recovery procedures still work when one of those layers is unavailable.

ENISA sets seven objectives for Europe's next cybersecurity phase The EU Agency for Cybersecurity published a new strategy on 6 August centred on cooperation, shared knowledge and preparation for emerging threats. Its operational priorities include more consistent implementation of EU cybersecurity policy, stronger readiness for incidents, greater cybersecurity capacity and trust in secure digital systems. The strategy does not introduce new controls or compliance deadlines by itself. It does indicate the direction in which public authorities are moving, and regulated companies can prepare by making supplier evidence, incident responsibilities and recovery capabilities easier to compare across their cloud estate.

Across the five stories, Europe is moving from broad sovereignty commitments towards requirements that procurement and technical teams can inspect.

Thinking about migration? Book a free consultation to discuss your situation.

See the European equivalent for your stack. Compare AWS, Azure, and GCP services side by side with OVHcloud, Scaleway, STACKIT, IONOS, and Hetzner.

Open the service mapping

Thinking about migration?

Book a free consultation to discuss your situation.

EU cloud news, week of 2026-08-06 | Cirran