# Sovereignty Is a Funded Priority Stalled in Planning

**Nearly every technology leader calls sovereignty important and most have money set aside for it; far fewer have built anything yet.** Whether digital sovereignty matters is no longer in question. 66% of technology leaders call it a critical priority, and none of the 1,940 surveyed called it irrelevant. The money has followed. Most expect a major investment within a year, and spending is rising in every region. Delivery, however, is not growing: 46% of organizations have not moved past planning, and only 14.7% actually have sovereignty embedded in operations.

**How Relevant Digital Sovereignty Is Today**
*All respondents*

| Category | All respondents |
|--- |--- |
| Critical priority | 66% |
| Important consideration | 29% |
| Emerging interest | 5% |
| Not relevant | 0% |

*Source: n=1,940 respondents, normalized by region*

**Respondents that consider digital sovereignty a critical priority:** 66%

**Respondents that are likely to make a major sovereignty investment in the next 12 months:** 66.5%

Sovereignty spending is rising at an average of +8.4% over 24 months in every region: Latin America +11.1%, North America +8.1%, Asia-Pacific +8.0%, EMEA +6.6%.

## Regulation puts sovereignty on the agenda; other pressures fund it

Regulation is a major factor for putting sovereignty on the agenda. 47.4% say the regulatory environment in their region drives their roadmap to a great extent and, similarly, 46% describe the cultural pressure around it as high or very high — a board-level concern beyond IT. However, regulation does not, on its own, get the work funded.

What organizations expect back is protection: resilience, compliance, and control over their data lead the list, and every growth outcome trails every protective one. Sovereignty is primarily being funded the way General Data Protection Regulation (GDPR) compliance was funded, as a cost of doing business. The trend is visible across industries, with the manufacturing and energy sectors leading in budget increases (43.1% planning to boost spending by more than 10%), ahead of the public sector and defense at 33.7%. Ultimately, the most successful funding justifications focus on maintaining continuity and control rather than driving expansion.

**Organizations expect protection from sovereignty, and growth trails**
*All respondents (respondents could select more than one)*

| Category | All respondents |
|--- |--- |
| Operational resilience or business continuity | 28% |
| Regulatory compliance | 28% |
| Greater control over data and IP | 26% |
| Long-term technical autonomy or cost predictability | 25% |
| Customer trust or brand differentiation | 23% |
| Independence in AI development | 20% |
| Speed and agility for growth or innovation | 20% |
| Access to new markets or customers | 18% |

*Source: n=1,940 respondents, normalized by region*

Buyers still see upside: 43% call sovereignty a significant competitive differentiator, and 14% call it a compliance cost only.

> It's hard to make time for a project that brings no direct value and is purely about controlling risk.
> — *CIO, retail organization (EMEA)*

## Every additional jurisdiction adds complexity

Sovereignty rarely comes down to one country's rules. Most large organizations operate in several countries, often in several regions, and every jurisdiction they add brings its own rule set, its own conditions for market access, and often its own infrastructure and vendor landscape. Trends run by region, but the countries inside a region can still need very different things; Canada and the United States are the plain example. Local jurisdictions inside a country can add rules of their own. The more distinct sets of rules and requirements an organization has to work around, the more complex sovereignty becomes, and regulation is only part of it. Which markets an organization can serve, what infrastructure exists there, and which vendors can operate there all change from one border to the next. Each added jurisdiction is one more place where vendors must be evaluated, business must be adapted, and readiness must be proven.

## Planning is further along than delivery

46% of organizations have a sovereignty mandate and a budget, but have not yet run anything. Organizations with sovereignty embedded in how systems are chosen, contracted, and run are the target state the rest of the market is working toward — but the gap is significant, and progress is slow.

**The sovereignty maturity ladder: where organizations stand on sovereignty**
*All respondents*

| Category | All respondents |
|--- |--- |
| Not on our agenda | 4% |
| Exploring — researching requirements | 16% |
| Planning — building strategy or business case | 26% |
| Piloting — sovereign initiatives in flight to test strategy on a small scale | 21% |
| Deploying — launching sovereign initiatives to full organizational scale | 18% |
| Deployed — sovereignty is embedded in operations | 15% |

*Source: n=1,940 respondents, normalized by region*

Program maturity brings governance and money with it: organizations deploying sovereignty or with sovereignty embedded are more likely to expect a major investment and to increase spend. For a leader, the useful question is which program maturity stage an organization is in. Organizations still planning should know that their current planning will dictate how fast they overcome this gap. Organizations piloting or deploying should check whether their pilots include a tested exit and a second source of support. Section 3 shows how few pilots include the exit.

**Mature organizations are accelerating.** 81% of organizations that are deploying or have embedded sovereignty expect to make a major investment within 12 months, versus only 60% of all other organizations; 72% of mature organizations are increasing spend over 24 months, against 62%.

**Organizations that have sovereignty embedded in operations:** 14.7%

## Ownership is split; security holds it nearly as often as infrastructure

Sovereignty is a board-level decision about which vendor dependencies an organization accepts. Some dependence is unavoidable, but a dependency with no tested way to migrate is different, and for critical systems and customer-facing services it is one the board should approve knowingly. Those systems cannot degrade because a supplier or government changes terms, and identifying them is leadership's job, beyond IT alone.

Ownership in practice is less settled than that. While nearly every respondent indicated a primary owner exists for digital sovereignty, 21% report active internal disagreement about direction or ownership. Where it is settled, the CIO or CTO holds it most often and the CISO or chief risk officer nearly as often, so security owns sovereignty almost as often as infrastructure does. Interestingly, chief-level survey respondents were significantly more likely to attribute sovereignty ownership to the CIO or CTO (45%) than any other respondent levels from managers and architects through SVPs (27%–37%), indicating that senior executives disagree with the rest of their business on who actually owns sovereignty responsibility.

21% report active internal disagreement about direction or ownership for sovereignty.

**Who Owns Sovereignty**
*All respondents*

| Category | All respondents |
|--- |--- |
| CIO / CTO | 35% |
| CISO / Chief Risk Officer | 29% |
| Shared across IT, risk and legal | 11% |
| Chief Data or AI Officer | 10% |
| Legal or compliance | 8% |
| Business unit leader | 7% |
| No clear owner | 0% |

*Source: n=1,940 respondents, normalized by region*

> [The statutory information-risk role] responsibility for location of data and control of assets from a tech point of view is generally in one person… it's very clear that's my responsibility to advise the board on.
> — *CDIO, Healthcare (EMEA)*

## Maturity splits sharply by region, but not industry or size

North America is furthest along, building sovereignty inside a familiar jurisdiction, with only 33% of organizations not yet piloting sovereignty programs. Asia-Pacific and Latin America both sit in the middle (46% and 43% not yet started with pilots).

**Regional maturity: North America leads, EMEA lags**
*All respondents*

| Category | Piloting or beyond | Regulation drives to a great extent |
|--- |--- |--- |
| North America | 67% | 56% |
| EMEA | 38% | 31% |
| APAC | 54% | 49% |
| LATAM | 57% | 54% |
| All respondents | 54% | 47% |

*Source: n=289 / 470 / 979 / 202 / 1,940 respondents*

Surprisingly, EMEA has the longest regulatory history but the fewest projects past planning: it solved where data sits under GDPR but has not addressed whether the business survives a vendor being cut off. Its low scores on the ability to move workloads, on wanting a second source of support, and on treating sovereignty as decisive at renewal all point the same way. Within the region, Mainland Europe is furthest behind — only 34% have started piloting sovereignty programs — while 43% in the United Kingdom and 46% in the Middle East (Saudi Arabia, UAE, Qatar) have at least started pilots.

Drilling deeper, maturity veers sharply by country across the 28 countries surveyed: only 23% have started pilots in Italy and 29% in the Netherlands, Belgium, and Luxembourg. Japan (34%), South Korea (35%), Germany (38%), and Spain (38%) are only somewhat further along. Meanwhile, some are far ahead: 70% of organizations in Hong Kong and 69% in Singapore have at least started piloting, with Thailand and the United States almost as far along.

Interestingly, neither the respondents' industry, role, nor organization size have any consistent, meaningful effect on sovereignty maturity as reported in the survey.
