How Versa Sovereign SASE Answers the EU Technological Sovereignty Package

Data residency isn't sovereignty. See how Versa Sovereign SASE keeps inspection, access decisions, and management under EU law and jurisdiction. Learn more.

Dhiraj Sehgal
Senior Director,Product Marketing
  • Read Time: 4 min read
  • Published: September 29, 2026
  • Modified: September 29, 2026
  • 4 min read read
  • September 29, 2026
  • September 29, 2026

Summary

Versa Sovereign SASE answers the EU Technological Sovereignty Package by localizing all four operational planes, data, control, management, and jurisdiction, under EU law, rather than stopping at data residency.

  • Data residency answers where data sits. Sovereignty answers who evaluates policy, who can reach the management plane, and whose law applies.
  • The EU Technological Sovereignty Package bundles Chips Act 2.0, an EU Open Source Strategy, and the Cloud and AI Development Act (CADA), making sovereignty an architecture requirement.
  • A sovereign architecture names a single jurisdiction governing all four planes, data, control, management, and jurisdiction. If the answer changes from one plane to the next, the gap is architectural, not contractual.
  • Versa Sovereign SASE localizes all four planes: inspection at in-EU points of presence, access decisions in-region, management under local authority, and a contracting entity domiciled in jurisdiction.
  • Versa's three deployment tiers run the same converged stack, so sovereignty is a deployment decision, not a rip-and-replace. Swisscom's beem is built on Versa Sovereign SASE.

On June 3, 2026, the European Commission unveiled its Technological Sovereignty Package. For CISOs, security architects, and network security leaders operating in or serving the EU, it formalizes a risk they’ve managed informally for years. The package bundles three initiatives that matter well beyond EU policy circles: a Chips Act 2.0 aimed at reducing Europe’s semiconductor dependence, an EU Open Source Strategy to cut reliance on non-EU proprietary software, and the Cloud and AI Development Act (CADA), which targets Europe’s reliance on non-European hyperscalers and aims to triple EU data center capacity over five to seven years. For teams running a SASE or SSE stack, it raises a direct question: is your architecture actually sovereign? Meeting the answer takes more than data residency, and that’s where Versa Sovereign SASE comes in.

Data residency is not data sovereignty

Data residency clauses in vendor contracts, along with GDPR, NIS2, and DORA, have made sovereignty obligations increasingly explicit. Security decision-makers are now fielding questions that go well beyond where the data sits:

Where are identity and policy decisions actually evaluated, and who can reach that decision-making plane under a foreign legal order? Who has administrative and support access to the management plane (logging, configuration, and incident response tooling), and whose compulsion powers apply to that access? And if a platform provider is compelled by an extraterritorial legal order, or simply throttles service during a geopolitical dispute, does the customer’s network and security posture keep functioning independently, or does it degrade?

Most SASE platforms were architected around a single global fabric: shared, multi-tenant points of presence, a centralized cloud control plane, and a vendor-run management layer, often all under one non-EU legal jurisdiction. That architecture is excellent for performance and operational simplicity. It is a poor match for a sovereignty requirement. Collapsing control, data, and management into one externally owned plane is exactly the “kill switch” concentration the EU package is reacting to.

How Versa Sovereign SASE delivers sovereignty

Versa’s answer is to treat sovereignty as an architectural property, not a checkbox on a data-residency form. Versa Sovereign SASE, part of the VersaONE Universal SASE Platform, separates and localizes four operational planes rather than just the data plane:

  • Data plane. Traffic inspection and enforcement (FWaaS, SWG, CASB, DLP, threat inspection, and more) run locally at in-EU points of presence, never hairpinned outside the boundary for processing.
  • Control plane. Identity validation, policy evaluation, and access decisions run in-region through Versa’s ZTNA policy engine and SD-WAN forwarding, so no access decision depends on an external cloud.
  • Management plane. Configuration, logging, and administrative access stay under local authority, with vendor support brokered through an in-jurisdiction privileged access management (PAM) system.
  • Jurisdiction. The service runs under local law through a contracting entity legally domiciled in-jurisdiction, so no foreign legal regime can compel access through Versa.

Architecturally, Versa offers three deployment tiers on the same converged software stack: an as-a-service model on Versa’s shared global fabric (90+ PoPs) for organizations without sovereignty constraints, a private model with dedicated gateways inside Versa’s infrastructure, and a sovereign model, delivered on customer- or partner-hosted infrastructure or managed in-region under an EU entity. The same security and networking stack runs across all three, so a sovereignty requirement doesn’t force a rip-and-replace onto different tooling; it’s a deployment decision, not a product switch.

This isn’t hypothetical for European telecom. Swisscom built beem, billed as the world’s first telco-delivered, network-embedded sovereign SASE service, directly on Versa Sovereign SASE. It’s operated, hosted, and governed entirely within Swiss infrastructure, aligned to GDPR and NIS2. beem anchors device identity in the SIM rather than in agents or tunnels, and delivers Zero Trust, SD-WAN, and full-spectrum SSE natively through the carrier network. It’s a concrete answer to the concentration risk the EU’s package targets: connectivity and security that keep functioning without depending on a foreign-controlled control or management plane.

Planning your next architecture review

If your organization operates EU infrastructure, serves EU customers, or falls under NIS2 or DORA scope, sovereignty has moved from a policy question to an architecture requirement. CADA gives that requirement a concrete definition.

Most global SASE and SSE stacks can’t meet the sovereignty test cleanly. A sovereign architecture should name a single jurisdiction that governs all four planes (data, control, management, and jurisdiction). If your vendor’s answer changes from one plane to the next, the gap is architectural, not contractual. A sovereign posture keeps operating even if a primary cloud or connectivity provider is compelled or constrained, because no external plane holds control.

Versa Sovereign SASE is built to that standard, localizing all four planes under EU jurisdiction with no loss of platform capability. To see how Versa delivers fully sovereign SASE for EU enterprises, read the announcement.

Dhiraj Sehgal

By Dhiraj Sehgal

Senior Director,
Product Marketing

Dhiraj Sehgal leads product marketing for the VersaONE Universal SASE Platform, translating advanced security for CISOs and architects. His writing spans generative AI security, post-quantum cryptography, and the shift from legacy VPNs to Zero Trust Network Access. He holds a degree from the Wharton School at the University of Pennsylvania.

FAQs

Sovereign SASE is an architecture in which traffic inspection, policy decisions, management access, and legal jurisdiction all stay inside one defined territory. Versa Sovereign SASE, part of the VersaONE Universal SASE Platform, localizes all four planes so no external provider or foreign legal order holds control.

Data residency defines where data is stored. Data sovereignty defines whose law governs it and who can reach it. A platform can store data in the EU while evaluating identity and policy decisions elsewhere, with a management plane under non-EU jurisdiction. Sovereignty requires all four planes in-region.

The package bundles Chips Act 2.0, an EU Open Source Strategy, and the Cloud and AI Development Act (CADA), which targets reliance on non-European hyperscalers. For security teams, it gives sovereignty a concrete definition and makes it a question for architecture reviews, not just procurement.

No. Versa offers three deployment tiers on the same converged software stack: as-a-service on Versa's shared global fabric, private with dedicated gateways, and sovereign on customer- or partner-hosted infrastructure or managed in-region under an EU entity. Sovereignty is a deployment decision, not a product switch.

NIS2 and DORA have made sovereignty obligations explicit for critical infrastructure and financial services. Versa Sovereign SASE addresses them architecturally: inspection and enforcement run at in-EU points of presence, access decisions run through Versa's ZTNA policy engine in-region, and vendor support is brokered through an in-jurisdiction PAM system.

Subscribe to the Versa Blog

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Related Posts