Skip to content

For many companies, digital sovereignty sounds like a major strategic goal when it is first mentioned. In reality, the first stage in assessing digital sovereignty is usually much more mundane. It begins with the question of transparency: Which systems are actually business-critical? Where are the real dependencies? Which data is located where? Are there actually any other providers you could switch to? And what will these dependencies cost you in future years?

Many companies today are aware that their technological scope for action has decreased. They are using powerful cloud and platform services and benefiting from rapid innovation and scalability. But at the same time, they are becoming increasingly dependent. Not just technically, but increasingly from a regulatory and economic perspective, too. This is exactly where digital sovereignty comes in – not as an ideological alternative to the cloud. And not as a campaign to move away from all the hyperscalers. But rather as a practical question: Where does a company need more control, more transparency, and more freedom to make decisions? And where does it not?

When dependencies become a risk

The challenge often starts right from the beginning. While many organizations are aware that dependencies exist, they are often unable to assess their actual impact. Which systems pose real lock-in risks? Where do regulatory challenges arise? Which platforms can be replaced, and which ones are now almost impossible to change? And where would greater sovereignty make economic sense because it would reduce risks or allow for better cost control? This is why assessing digital sovereignty and working toward it require a structured approach. An approach that starts with transparency, not ideologies.

We use the ti&m Digital Sovereignty Check to analyze existing IT landscapes systematically. It allows us to identify where organizations stand currently. Instead of focusing solely on technologies, we look at dependencies, risks, cost structures, and scope for action. Our analysis covers platforms, core systems, data flows, operating models, and existing cloud and vendor dependencies, among other things. We also take regulatory requirements into account. This includes issues such as data protection, outsourcing, and foreign authorities being able to access data.

You can’t measure digital sovereignty with just one metric. That is why we evaluate different aspects separately: control and autonomy, portability and interoperability, regulatory requirements, and cost-effectiveness.

Dependence does not necessarily mean risk

Not every dependency is automatically problematic. It becomes critical when it creates risks or costs spiral out of control. In addition, dependency may reduce a company’s scope for action. This is often the real insight that companies gain from the Digital Sovereignty Check: They don’t need to take action everywhere. But where there are risks, there is also often a lack of transparency and clear decision-making bases.

At the moment, dependency risks are particularly acute in cloud computing, data platforms, and AI. In recent years, many companies have built highly integrated platform landscapes. This speeds up innovation, but at the same time, it makes it more difficult to control data, costs, and technological development. When it comes to AI in particular, new dependencies are emerging rapidly: with models, platform services, data storage, and proprietary interfaces.

At the same time, economic pressure is growing. Licensing costs are rising rapidly. Regulatory requirements are also increasing. Plus, geopolitical uncertainties are changing the way many organizations assess risk. It is no longer just governments or operators of critical infrastructure that need to worry about digital sovereignty. It is becoming more and more of a business issue.

Open source offers a realistic solution

Strengthening digital sovereignty is rarely about making a radical fresh start. Today, successful companies typically take a hybrid approach: They use global platforms where scalability and the speed of innovation are critical. In other areas where control, transparency, and independence are more important, they rely on open-source, European, or Swiss solutions.

The technological landscape for this has improved signifi cantly in recent years. In areas such as the workplace solutions, data platforms, security, and AI, there are now highperformance open-source solutions and European alternatives. Organizations can deploy them in a productive and scalable manner. OpenDesk is just one example. At the same time, the European ecosystem for cloud, data, and AI infrastructures continues to grow. With the ti&m Open Source Stack, we bring together proven technologies and operating models designed specifi cally for these scenarios: from workplace and security solutions to data and AI platforms. Instead of advocating technology for technology’s sake, we consciously focus on specifi c opportunities for action: How can you manage your costs better? How can you reduce your risks? And how can you make sure your IT infrastructure remains agile in the long term?

From analysis to a basis for decision-making

The Sovereignty Check doesn’t simply assess the current situation. It also analyzes realistic courses of action. What alternatives do you have? Where do European, Swiss, or open-source solutions offer greater control or better cost-effectiveness? How much would it cost to migrate, and what risks would it involve? Where are the quick wins? And where would migrating completely be neither cost-effective nor practical?

Instead of discussing digital sovereignty in theoretical terms, we provide a concrete basis for decision-making. Companies gain transparency over their risks and dependencies. They are able to assess their technological capacity for action. Above all, they have clear recommendations for their next steps. Time and time again, we have seen the same pattern on projects: The greatest risks rarely stem from individual technologies. They arise where there is a lack of transparency. Where no one knows anymore just how dependent they’ve actually become.

This is why digital sovereignty doesn’t begin with migrating to a new provider. It begins with gaining a clear picture of your own reality.

ti&m Special “Digital Sovereignty”

The economically viable way out of lock-in

How companies and public administrations can reduce technological dependencies, regain control over data and costs, and implement digital sovereignty economically.