By Michał Puchała · 2026-09-01 · 8 min read
Europe's Cloud Adoption Is Growing. Procurement Quality Is the Next Test
Europe's latest Digital Decade report says 46.7% of EU enterprises now use cloud computing. As adoption grows, the harder question is whether each workload sits with the right provider, under the right controls, with a practical route out when requirements change.

Europe's cloud adoption is still climbing. The European Commission's new State of the Digital Decade 2026 report says 46.7% of EU enterprises now use cloud computing. It also finds that 39.9% use data analytics and nearly 20% use artificial intelligence.
Those figures describe a market moving into the mainstream. The EU's stated objective is for 75% of European businesses to use cloud-edge technologies by 2030. Yet the next phase cannot be measured by adoption alone. A company can use cloud extensively and still have weak contracts, unsuitable dependencies or no tested route to another provider.
For a mid-sized company in a regulated sector, procurement quality is the more useful test. It asks whether each workload sits in an environment that matches its business importance, data obligations and operational needs. It also asks whether the company can change that environment without putting continuity at risk.
Adoption does not describe the quality of the decision
An enterprise counts as a cloud user whether it buys one hosted business application or runs most of its production systems on a cloud platform. The adoption figure does not show which provider it uses, where its data is processed, how concentrated its dependencies are or whether it can recover elsewhere. It records use, not control.
This distinction matters because cloud decisions rarely arrive as a clean infrastructure project. A finance system may be chosen by a department, an application team may adopt a managed database, and a software supplier may introduce its own cloud dependencies. Over time, the company accumulates a portfolio of contracts and technical choices rather than one coherent cloud strategy.
The Commission's 2026 report identifies the same tension at European level. It records rising business adoption while warning that dependence on non-EU suppliers remains significant in cloud services and other strategic technologies. It also says smaller companies continue to face barriers related to skills, data, infrastructure and resources.
The answer is not a blanket requirement to move every workload. A familiar hyperscaler can remain the right choice for systems that depend on its specialist services, while a European provider may offer a better fit for sensitive data, contractual assurance or simpler infrastructure. Procurement quality begins by making that decision explicitly instead of allowing history or a provider label to decide it.
Start with the requirement, then assess the provider
The strongest cloud procurements begin with a business event. A contract is approaching renewal, an auditor has requested evidence, a customer has introduced a data clause, or the board wants to understand reliance on a single supplier. That event determines the question the company needs to answer.
A renewal may create room to compare operating costs and exit terms. An audit may require evidence about administrators, subcontractors and data locations. A customer clause may impose a specific jurisdiction or recovery commitment. A continuity review may focus on how long a critical system can be unavailable and whether the organisation can restore it without help from the affected provider.
These requirements should be written before the shortlist. Otherwise, a procurement exercise tends to reward the longest product catalogue or the most reassuring use of the word "sovereign". Neither tells the buyer whether a particular workload will be safer, easier to operate or more portable.
The requirement also needs to reflect the internal team. A platform with a wide range of managed services can reduce routine operational work, but it may deepen dependence on provider-specific tools. A simpler platform may offer more portability while asking the team to run more components itself. The right balance depends on available skills and the business consequence of getting it wrong.
Assess control across the whole service
Data location is an important procurement field, especially for health, financial and industrial data. It does not answer who administers the service, which legal entities can influence it, where support staff work, who controls encryption keys or which subcontractors are essential to its operation.
The European Commission's Cloud Sovereignty Framework gives buyers a broader vocabulary. It scores cloud offers against 48 criteria grouped into strategic, legal and jurisdictional, data and AI, operational, supply-chain, technological, security and compliance, and environmental objectives. The Commission developed it for public procurement, but it encourages private organisations to use the framework as well.
A mid-sized company does not need to reproduce the Commission's full scoring exercise. It does need evidence for the controls that matter to each workload. That means tracing the service beyond the name on the contract and understanding the organisations, people and technologies required to keep it running.
For a critical application, the assessment should establish who can access production, where logs and backups are held, how security incidents are handled and whether European staff can operate the environment independently. It should also identify proprietary services that would need to be replaced during a move. Unknown answers should be recorded as evidence gaps, not treated as assurances.
This produces a more useful comparison between providers. European ownership may resolve a jurisdictional concern without resolving a service-catalogue gap. An EU region operated by a non-European company may satisfy a data-location requirement without meeting a stronger requirement for operational independence. Procurement quality comes from matching the evidence to the workload rather than forcing both cases into one category.
Technical fit decides whether the choice can work
Provider comparisons often stop at computing capacity, storage and databases. Real applications also depend on identity, network design, deployment tools, systems that pass work between applications, monitoring, encryption keys, backups and support processes. A missing dependency in any of those areas can turn a reasonable provider choice into an expensive engineering programme.
The Commission's August 2026 study on cloud and AI development in the EU identifies lock-in practices within the AI computing stack alongside broader dependence on non-European suppliers. The same principle applies beyond AI. Portability depends on the full chain of services, formats, interfaces and operational knowledge around a workload.
Before signing, the technical team should test the proposed architecture against the target platform. It should confirm which services have direct equivalents, which require redesign, how data will be transferred, how recovery will work and who will operate the result. This is also the point to test whether published regional availability and recovery options match the business requirement.
The outcome may differ by workload. One system may remain where it is with stronger contractual controls. Another may need a database or identity dependency reduced before a later move. A third may already fit a European provider without material redesign.
Treating the estate as a portfolio allows the company to improve control without creating unnecessary disruption.
Put the exit route into the original purchase
An exit plan is easier to write before a provider is selected. The buyer can ask for export formats, interface documentation, transition support, notice periods and continued access during a move while there is still competition for the contract. After several years of technical dependency, the same questions are harder to resolve.
The EU Data Act has improved the contractual position. According to the Commission's Data Act guidance, the rules apply from 12 September 2025 and require cloud and edge providers to remove obstacles to switching or using several services. They also require open interfaces and machine-readable exports in relevant cases, while switching charges, including fees for transferring data out, must be removed from 12 January 2027.
These rights improve the conditions for leaving. They do not export a database, rebuild identity controls or prove that an application will run on the destination. The organisation still needs an inventory, a target, people who understand the move and a test showing that its data and configuration can be recovered.
Using two providers does not by itself create portability. If each holds different systems with separate identities, data and operating procedures, the company may simply have two dependencies. A credible exit route identifies which workloads must move, what can interrupt the move, who owns each step and how the company will confirm that the destination works.
Better procurement creates options
Europe needs broader cloud adoption, particularly among smaller companies that still face gaps in skills and infrastructure. It also needs companies to buy cloud services with a clearer view of control, technical fit and change. Those aims support each other: good procurement makes cloud adoption more durable because the buyer understands what it is accepting.
For management, the result is a defensible answer about why important systems sit where they do. For the technical team, it is an architecture and an exit route that reflect available capacity. For procurement, it is a set of evidence and contract terms that can be tested at renewal rather than a promise that grows harder to examine over time.
The 46.7% adoption figure is evidence of progress. The next useful measure is whether European businesses can place workloads deliberately, operate them confidently and change course when their requirements change.
Thinking about migration? Book a free consultation to discuss your situation.