EU DATA ACT - CLOUD SWITCHING OBLIGATIONS

Measure your digital
dependency before it costs you

Sovereign-Audit is a structured audit that evaluates your dependency on cloud providers (Microsoft 365 in particular) and your actual ability to retrieve your data and switch provider. We do not certify "sovereignty": we measure, document and prioritize.

32
Dependency & portability controls audited
7
Microsoft 365 domains covered
3
Reference frameworks used
2009
SYAGA has run IT security audits since

The problem

Digital dependency is rarely measured, and the topic is becoming regulatory

The EU Data Act now regulates switching cloud providers

Regulation (EU) 2023/2854 (Data Act) includes a chapter dedicated to switching between data processing services, with obligations to remove technical and contractual obstacles to changing provider. Few organizations currently know where they stand on this.

🔒

Vendor lock-in builds up without ever being decided

Break-glass accounts, identity federation, Copilot, native encryption, custom Teams apps: every technical choice adds a bit more dependency, without any explicit decision ever having been made.

📋

Reversibility clauses are rarely reviewed

Cloud contracts include data recovery and exit clauses, but they are signed once and never revisited in light of how the tenant is actually used.

🧭

The frameworks exist but stay theoretical

The Data Act, SecNumCloud and Gaia-X define vocabulary and portability expectations, but turning that into an operational finding on YOUR tenant takes a method and time that internal IT teams rarely have.

Our approach: Sovereign-Audit

A structured method, built on a catalog of 32 dependency & portability controls

01
Scoping

Scoping interview

A discussion with leadership or the IT lead to define the scope (M365 tenant, entities, subsidiaries, key providers) and the dependency issues specific to your organization.

02
Collection

Structured collection of technical and contractual elements

Review of the Microsoft 365 configuration (identity, backup, data residence, encryption, applications) and of the reversibility clauses in your provider contracts.

03
Analysis

Assessment against the 32 controls in the catalog

Each control is assessed with a clear status (covered, partial, absent, needs contractual review), mapped to the relevant Microsoft 365 domains.

04
Perspective

Cross-reference with the Data Act, SecNumCloud and Gaia-X

Findings are connected, where relevant, to the EU Data Act and to the SecNumCloud / Gaia-X reference vocabulary - never presented as a certification obtained.

05
Delivery

Report and prioritized action plan

Delivery of a clear report to leadership, with a prioritized action plan to reduce the most critical dependency points.

What you receive

A clear set of documents your leadership and IT team can act on

📝

Dependency & portability report

Documented assessment of the 32 controls in the catalog, with a status for each.

  • Map of the 7 M365 domains involved
  • Status per control (covered / partial / absent / to verify)
  • Findings illustrated with configuration extracts
  • Executive summary on the first page
🗺

Vendor lock-in map

An overview of where your dependency on Microsoft is concentrated.

  • Identity and federation
  • Backup and data residence
  • Encryption and key management
  • Proprietary applications and automations

Reversibility clause reading grid

Support for reviewing your existing cloud contracts with your legal team.

  • Points of attention identified by the catalog
  • Questions to ask your providers
  • Not legal advice - a working aid
🎯

Regulatory perspective

Correspondence between your findings and the vocabulary of the reference frameworks.

  • Data Act (EU) 2023/2854 - provider switching chapter
  • SecNumCloud (ANSSI) - reversibility clause
  • Gaia-X - portability / interoperability vocabulary
  • ISO/IEC 27001 Annex A - supplier relationships
📈

Prioritized action plan

Recommendations ranked by criticality and ease of implementation.

  • Quick wins
  • Deeper contractual / technical workstreams
  • No action implemented without your validation
📄

Delivery and files

Documents in formats your teams can use.

  • Report in PDF format
  • Summary for leadership
  • Delivery session with questions and answers

Reference frameworks

Sovereign-Audit relies on existing public frameworks - we deliver no certification

DA

Data Act - Regulation (EU) 2023/2854

European text with a chapter dedicated to switching between data processing services (cloud portability and interoperability). Sovereign-Audit uses this chapter to structure audit questions, without presenting a specific article as an obligation already enforceable on your organization without legal verification.

ISO

ISO/IEC 27001 - Annex A

Organizational controls on supplier relationships and business continuity structure part of the dependency analysis.

SNC

SecNumCloud v3.2 (ANSSI)

A voluntary qualification framework from the French cybersecurity agency ANSSI. Its contractual reversibility clause is used here as a reading grid, even though standard Microsoft 365 is not SecNumCloud-qualified.

GX

Gaia-X (Trust Framework)

A voluntary, non-binding European framework providing shared vocabulary on sovereignty and interoperability between cloud actors, used here as a reading grid.

Scope & quote

Each engagement is scoped on a quote basis, according to the size and complexity of your environment

Diagnostic

SME, single M365 tenant

Quote on request
Scoped with you beforehand
  • Assessment of the 32 controls in the catalog
  • Summary report
  • Restitution to leadership
Request a quote

Follow-up

Organizations with a remediation plan

Quote on request
Scoped with you beforehand
  • Everything in In-depth, plus
  • Detailed prioritized action plan
  • Follow-up review after actions are implemented
  • Report refresh
Request a quote

No price is fixed in advance on this page

The exact scope (number of entities, tenant size, depth of contractual review) is defined with you before any quote.

Frequently asked questions

Is my organization concerned by the EU Data Act?
The Data Act (Regulation (EU) 2023/2854) broadly applies to cloud service providers and users within the European Union, with specific provisions on switching provider. Sovereign-Audit helps you understand concretely where you stand, but does not replace a legal analysis specific to your situation.
Is Sovereign-Audit related to SYAGA's automated M365 audit?
No. Sovereign-Audit is an engagement carried out by our auditors, based on the same control catalog as our other work, but performed manually, without an automated collection extension. It is not the same product as SYAGA's zero-knowledge M365 audit solution.
Does the report constitute legal advice?
No. Sovereign-Audit is an operational and technical support tool. It does not constitute legal advice and does not replace a review of your contracts by a lawyer or your legal department.
How much time do I need to free up on my team?
The scoping interview and the final restitution involve your leadership or IT lead. The rest of the collection and analysis is carried out by our auditors. The exact volume depends on the scope chosen and will be detailed in the quote.
What makes SYAGA legitimate to run this audit?
SYAGA Consulting has run IT security audits since 2009, for clients from 50 to 5,000 employees across several sectors. The control catalog used for Sovereign-Audit builds on that same audit work.
Does Sovereign-Audit certify that my organization is sovereign?
No. Sovereign-Audit measures your dependency and portability at a given point in time, based on verifiable findings. We issue no sovereignty label or certification.

Want to know where you really stand?

Contact us to receive a quote adapted to your scope.

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu See FAQ