Sovereign-Audit is a structured audit that evaluates your dependency on cloud providers (Microsoft 365 in particular) and your actual ability to retrieve your data and switch provider. We do not certify "sovereignty": we measure, document and prioritize.
Digital dependency is rarely measured, and the topic is becoming regulatory
Regulation (EU) 2023/2854 (Data Act) includes a chapter dedicated to switching between data processing services, with obligations to remove technical and contractual obstacles to changing provider. Few organizations currently know where they stand on this.
Break-glass accounts, identity federation, Copilot, native encryption, custom Teams apps: every technical choice adds a bit more dependency, without any explicit decision ever having been made.
Cloud contracts include data recovery and exit clauses, but they are signed once and never revisited in light of how the tenant is actually used.
The Data Act, SecNumCloud and Gaia-X define vocabulary and portability expectations, but turning that into an operational finding on YOUR tenant takes a method and time that internal IT teams rarely have.
A structured method, built on a catalog of 32 dependency & portability controls
A discussion with leadership or the IT lead to define the scope (M365 tenant, entities, subsidiaries, key providers) and the dependency issues specific to your organization.
Review of the Microsoft 365 configuration (identity, backup, data residence, encryption, applications) and of the reversibility clauses in your provider contracts.
Each control is assessed with a clear status (covered, partial, absent, needs contractual review), mapped to the relevant Microsoft 365 domains.
Findings are connected, where relevant, to the EU Data Act and to the SecNumCloud / Gaia-X reference vocabulary - never presented as a certification obtained.
Delivery of a clear report to leadership, with a prioritized action plan to reduce the most critical dependency points.
A clear set of documents your leadership and IT team can act on
Documented assessment of the 32 controls in the catalog, with a status for each.
An overview of where your dependency on Microsoft is concentrated.
Support for reviewing your existing cloud contracts with your legal team.
Correspondence between your findings and the vocabulary of the reference frameworks.
Recommendations ranked by criticality and ease of implementation.
Documents in formats your teams can use.
Sovereign-Audit relies on existing public frameworks - we deliver no certification
European text with a chapter dedicated to switching between data processing services (cloud portability and interoperability). Sovereign-Audit uses this chapter to structure audit questions, without presenting a specific article as an obligation already enforceable on your organization without legal verification.
Organizational controls on supplier relationships and business continuity structure part of the dependency analysis.
A voluntary qualification framework from the French cybersecurity agency ANSSI. Its contractual reversibility clause is used here as a reading grid, even though standard Microsoft 365 is not SecNumCloud-qualified.
A voluntary, non-binding European framework providing shared vocabulary on sovereignty and interoperability between cloud actors, used here as a reading grid.
Each engagement is scoped on a quote basis, according to the size and complexity of your environment
SME, single M365 tenant
SME/mid-market, multiple entities or subsidiaries
Organizations with a remediation plan
No price is fixed in advance on this page
The exact scope (number of entities, tenant size, depth of contractual review) is defined with you before any quote.
Contact us to receive a quote adapted to your scope.
Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.
contact@syaga.eu See FAQ