On June 3, 2026, the European Commission unveiled its Technological Sovereignty Package. For CISOs, security architects, and network security leaders operating in or serving the EU, it formalizes a risk they’ve managed informally for years. The package bundles three initiatives that matter well beyond EU policy circles: a Chips Act 2.0 aimed at reducing Europe’s semiconductor dependence, an EU Open Source Strategy to cut reliance on non-EU proprietary software, and the Cloud and AI Development Act (CADA), which targets Europe’s reliance on non-European hyperscalers and aims to triple EU data center capacity over five to seven years. For teams running a SASE or SSE stack, it raises a direct question: is your architecture actually sovereign? Meeting the answer takes more than data residency, and that’s where Versa Sovereign SASE comes in.
Data residency is not data sovereignty
Data residency clauses in vendor contracts, along with GDPR, NIS2, and DORA, have made sovereignty obligations increasingly explicit. Security decision-makers are now fielding questions that go well beyond where the data sits:
Where are identity and policy decisions actually evaluated, and who can reach that decision-making plane under a foreign legal order? Who has administrative and support access to the management plane (logging, configuration, and incident response tooling), and whose compulsion powers apply to that access? And if a platform provider is compelled by an extraterritorial legal order, or simply throttles service during a geopolitical dispute, does the customer’s network and security posture keep functioning independently, or does it degrade?
Most SASE platforms were architected around a single global fabric: shared, multi-tenant points of presence, a centralized cloud control plane, and a vendor-run management layer, often all under one non-EU legal jurisdiction. That architecture is excellent for performance and operational simplicity. It is a poor match for a sovereignty requirement. Collapsing control, data, and management into one externally owned plane is exactly the “kill switch” concentration the EU package is reacting to.
How Versa Sovereign SASE delivers sovereignty
Versa’s answer is to treat sovereignty as an architectural property, not a checkbox on a data-residency form. Versa Sovereign SASE, part of the VersaONE Universal SASE Platform, separates and localizes four operational planes rather than just the data plane:
- Data plane. Traffic inspection and enforcement (FWaaS, SWG, CASB, DLP, threat inspection, and more) run locally at in-EU points of presence, never hairpinned outside the boundary for processing.
- Control plane. Identity validation, policy evaluation, and access decisions run in-region through Versa’s ZTNA policy engine and SD-WAN forwarding, so no access decision depends on an external cloud.
- Management plane. Configuration, logging, and administrative access stay under local authority, with vendor support brokered through an in-jurisdiction privileged access management (PAM) system.
- Jurisdiction. The service runs under local law through a contracting entity legally domiciled in-jurisdiction, so no foreign legal regime can compel access through Versa.
Architecturally, Versa offers three deployment tiers on the same converged software stack: an as-a-service model on Versa’s shared global fabric (90+ PoPs) for organizations without sovereignty constraints, a private model with dedicated gateways inside Versa’s infrastructure, and a sovereign model, delivered on customer- or partner-hosted infrastructure or managed in-region under an EU entity. The same security and networking stack runs across all three, so a sovereignty requirement doesn’t force a rip-and-replace onto different tooling; it’s a deployment decision, not a product switch.
This isn’t hypothetical for European telecom. Swisscom built beem, billed as the world’s first telco-delivered, network-embedded sovereign SASE service, directly on Versa Sovereign SASE. It’s operated, hosted, and governed entirely within Swiss infrastructure, aligned to GDPR and NIS2. beem anchors device identity in the SIM rather than in agents or tunnels, and delivers Zero Trust, SD-WAN, and full-spectrum SSE natively through the carrier network. It’s a concrete answer to the concentration risk the EU’s package targets: connectivity and security that keep functioning without depending on a foreign-controlled control or management plane.
Planning your next architecture review
If your organization operates EU infrastructure, serves EU customers, or falls under NIS2 or DORA scope, sovereignty has moved from a policy question to an architecture requirement. CADA gives that requirement a concrete definition.
Most global SASE and SSE stacks can’t meet the sovereignty test cleanly. A sovereign architecture should name a single jurisdiction that governs all four planes (data, control, management, and jurisdiction). If your vendor’s answer changes from one plane to the next, the gap is architectural, not contractual. A sovereign posture keeps operating even if a primary cloud or connectivity provider is compelled or constrained, because no external plane holds control.
Versa Sovereign SASE is built to that standard, localizing all four planes under EU jurisdiction with no loss of platform capability. To see how Versa delivers fully sovereign SASE for EU enterprises, read the announcement.