# Methodology

Futurum Research surveyed 1,940 technology and risk decision-makers in 28 countries and interviewed 12 senior executives in July and August 2026 to evaluate the state of digital sovereignty today on a global basis. Futurum wrote and owned the questionnaires, oversaw recruitment of respondents, and independently conducted the interviews. Red Hat sponsored this research and was provided an opportunity to review the questionnaires and analysis, but Futurum retained complete final control over all research design, analysis, and content writing.

**Survey firmographics.** Respondents were surveyed across four regions (Asia-Pacific: 979, Europe: 369, US and Canada: 289, Middle East: 101, Latin America: 202) and six industries (financial services 353, manufacturing and energy 334, retail and consumer 334, healthcare and life sciences 308, public sector and defense 306, telecom and digital infrastructure 305). 93% of organizations have 1,000 or more employees, and the average annual cloud, infrastructure, and AI spend is $173M across the sample. Most operate in multiple countries: 93% of respondents' firms generate 10% or more of their revenue from countries outside their home country, with an average of 46% of total revenue generated outside the home country.

**Respondents by Region**
*All respondents*

| Category | Share of respondents |
|--- |--- |
| North America | 15% |
| EMEA | 24% |
| APAC | 51% |
| Latin America | 10% |

*Source: n=1,940 respondents, the achieved sample, unweighted*

**Respondents by Industry**
*All respondents*

| Category | Share of respondents |
|--- |--- |
| Financial Services | 18% |
| Public Sector & Defense | 16% |
| Healthcare & Life Sciences | 16% |
| Telecom & Digital Infrastructure | 16% |
| Manufacturing, Industrial & Energy | 17% |
| Retail, Consumer & Transportation | 17% |

*Source: n=1,940 respondents, the achieved sample, unweighted*

**Survey demographics.** Every respondent confirmed decision-making or strong-influencer involvement in cloud, infrastructure, security, data governance, AI, or regulated-workload strategy in the past 12 months. Of the respondents, 73% are director level or above and the remaining are managers or senior/enterprise architects. At executive levels, 17% are c-level and 24% are VP or SVP. Respondents have long average tenures at their current organization, at 7.1 years, and they each personally influence or own an average annual budget of $125M (with 50% of respondents owning or influencing $20M to $178M of budgets).

**Respondents by Company Size**
*All respondents*

| Category | Share of respondents |
|--- |--- |
| 500–999 | 7% |
| 1,000–4,999 | 24% |
| 5,000–9,999 | 21% |
| 10,000–24,999 | 20% |
| 25,000–49,999 | 14% |
| 50,000–99,999 | 8% |
| 100,000+ | 5% |

*Source: n=1,940 respondents, the achieved sample, unweighted*

**Respondents by Role**
*All respondents*

| Category | Share of respondents |
|--- |--- |
| C-level | 17% |
| VP / SVP-level | 24% |
| Director-level | 31% |
| Senior or Enterprise Architect | 13% |
| Senior Manager | 14% |

*Source: n=1,940 respondents, the achieved sample, unweighted*

**Survey precision and weighting.** Whole-sample margin of error is ±2.2% at the 95% confidence level before weighting. Regional margins range from ±3.1% in Asia-Pacific to ±6.9% in Latin America. Percentages are shown to one decimal where the source supports it and rounded otherwise. The achieved sample is 50.5% Asia-Pacific, so to avoid global results dominated by that region, the global all-respondent analysis weights the four regions equally: each contributes 25% of the result, and nothing from any region is discarded. Every segmented number — for a region, an industry, a company-size band, or a group defined by how it answered a question — is that segment's own and unweighted, with every respondent in it counting once.

**Analyst-led in-depth interviews with senior executives.** Twelve hour-long in-depth interviews with CIOs, CTOs, CISOs, CDIOs, and VP-level technology leaders across EMEA, Asia-Pacific, Latin America, and North America were conducted to augment the analysis with additional depth and context. Quotes and vendor names are anonymized and attributed by role, industry, and region.

**Decision-makers in the final survey sample (unweighted):** 1,940

**Overall margin of error at the 95% confidence level:** ±2.2%

## Frequently Asked Questions

**What does "digital sovereignty" mean in this study?** Digital sovereignty is the ability of an organization, or a country, to run its technology on infrastructure, data, and people it controls, and to keep running if a supplier or a foreign government cuts it off. Futurum treats this as three related concerns that organizations weigh differently by region and industry: where data sits and whose law reaches it, whether the business keeps running under its own control if a supplier or government cuts off software it depends on, and where the AI it uses comes from and where it runs. Most organizations surveyed have already worked out where their data sits; what they are working on now is operational continuity and control over AI. Sections 1 through 5 of the report cover these concerns in turn, with sovereign AI treated separately in Section 5.

**What is the headline finding of the study?** Futurum's headline finding is a sovereignty readiness gap: organizations have funded sovereignty programs and tightened governance, but few can prove they could keep critical services running if a cloud provider, software supplier, or geopolitical event cut them off. Sovereignty is no longer a question of intent; it is a question of operational readiness, and that gap matters more, not less, as production workloads consolidate onto US-headquartered hyperscalers, the only environment expected to gain share over the next decade. Futurum ties closing the gap to three capabilities: a secondary source of support, enterprise-grade open source, and genuine cross-environment workload portability.

**Who did Futurum survey, and how representative is the sample?** Futurum surveyed 1,940 technology and risk decision-makers in 28 countries, each screened to confirm decision-making or strong-influencer involvement in cloud, infrastructure, security, data governance, AI, or regulated-workload strategy in the past 12 months. The sample is large, internationally exposed enterprises: 93% of respondent organizations have 1,000 or more employees, and 93% of their firms generate 10% or more of revenue outside their home country. Respondents are also senior: 73% are director level or above, including 17% at the C-level and 24% at VP or SVP.

**What is the sovereignty maturity ladder, and what does each stage mean?** It is the six-stage scale Futurum used to place organizations on their sovereignty program's progress: Not on our agenda, Exploring (researching requirements), Planning (building strategy or business case), Piloting (sovereign initiatives in flight to test strategy on a small scale), Deploying (launching sovereign initiatives to full organizational scale), and Deployed (sovereignty embedded in operations). Most organizations sit earlier on that ladder than their budgets suggest: only one in seven organizations has progressed past planning into daily operations, even though nearly every technology leader calls sovereignty important and most have set aside money for it. Program maturity brings governance and money with it, since organizations deploying or with sovereignty embedded are more likely to expect a major investment and to increase spend than earlier-stage organizations are. Section 1 covers the ladder in full, including how maturity varies by region and country.

**What does it mean that the global results are "normalized by region"?** It means each of the four macro-regions Futurum surveyed, North America, EMEA, APAC, and LATAM, contributes an equal 25% share to every global, all-respondent number, regardless of how many respondents each region actually contributed. Futurum weights this way because the achieved sample is 50.5% Asia-Pacific, and without adjustment a global figure would mostly describe Asia-Pacific respondents rather than the world as a whole. Nothing is discarded: every respondent still counts, and any number reported for a single region, industry, company-size band, or answer-based group is that group's own data and is always unweighted. Regional weighting only changes how the four regions combine into one global number; it never changes a figure reported for one region, industry, or segment on its own.

**What do the study's margins of error mean, and where do they apply?** The margin of error describes the range within which the true population value would fall, at a stated confidence level, if the survey were repeated. Before weighting, the whole sample's margin of error is ±2.2% at the 95% confidence level, based on all 1,940 respondents; regional margins are wider because regional samples are smaller, ranging from ±3.1% in Asia-Pacific to ±6.9% in Latin America. These margins are a function of sample size, not of the regional weighting used for global figures, which changes how the four regions combine rather than how precisely each one was measured. A segmented figure, for one industry, company-size band, or answer-based group, carries its own margin of error tied to that group's own respondent count.

**How does the personalized view differ from the global figures?** The personalized view applies the region and industry a reader selects and replaces global findings with that segment's own, unweighted figures, calculated from the same underlying survey data. The global pages, by contrast, use figures that weight the four regions, North America, EMEA, APAC, and LATAM, equally at 25% each so no single region dominates the total. A personalized figure for a region, industry, or company-size band always represents just that group, with every respondent in it counted once and nothing weighted or discarded.

**Did Red Hat, the study's sponsor, influence the findings?** No: Red Hat sponsored the research and was given an opportunity to review the questionnaires and analysis, but Futurum wrote and owned the questionnaires, oversaw respondent recruitment, conducted the analyst interviews independently, and retained complete final control over research design, analysis, and content writing. Futurum discloses this arrangement once, in the Methodology section, rather than restating it throughout the report.

**Where does the underlying data come from, and can it be downloaded?** The findings come from Futurum's own survey of 1,940 technology and risk decision-makers across 28 countries, fielded in July and August 2026, and from 12 analyst-led interviews with senior technology executives conducted the same months. On the study site, the Explorer lets a reader query the survey data by region, industry, company size, country, sovereignty maturity, and respondent role, beyond what the report sections cover. The Downloads menu offers the Executive Summary or the Full Report as a written PDF, a 16:9 presentation PDF, or PowerPoint, each matching the exact scenario, language, and numbers the reader is currently viewing.

**How should this study be cited?** Cite it as Futurum Research, "The Digital Sovereignty Readiness Gap," sponsored by Red Hat, based on a survey of 1,940 technology and risk decision-makers in 28 countries and 12 executive interviews, fielded in July and August 2026. Nick Patience, VP & Practice Lead, AI, and Benjamin Brown, VP, Custom Research, are the study's authors. When citing a specific figure, name the metric together with its section or the Methodology page, since numbers can differ between the global view and any personalized region or industry view a reader has selected.
