Three US firms hold 65% of Europe’s cloud, and the CLOUD Act means data residency isn’t sovereignty — US authorities can compel disclosure even from EU-located servers. With NIS2 as the accelerant and governments like the Netherlands and Copenhagen steering toward open, self-hosted alternatives, self-hosting has stopped being the harder option and started becoming the European strategic default.
For a decade the only cloud debate worth having was which hyperscaler. In 2026 the question changed shape: not which US cloud, but whether a US cloud is a defensible place for a European business to keep its core at all.
Something is shifting in European technology procurement, and it is happening in the quiet, deliberate way that structural change usually does — not in press releases, but in policy documents, migration plans and the fine print of new regulation. For most of the last fifteen years, the default answer to “where does this run?” was a US hyperscaler. In 2026, a growing number of European operators are asking a harder question first: not where the data physically sits, but who ultimately controls it. Once you ask that question honestly, the comfortable default stops looking so comfortable.
Residency is not sovereignty
The pivot point is a legal contradiction that has been true for years but is only now being priced in. The US CLOUD Act allows US authorities to compel US-owned providers to disclose data even when the servers sit in an EU data centre. This means the reassurance European buyers were sold — “your data stays in Frankfurt, in Dublin, in Paris” — answers the wrong question. Data residency tells you the postcode of the disk. Data sovereignty tells you who can be compelled to reach into it. Under the CLOUD Act, those are not the same thing, and no amount of in-region data centres changes the corporate nationality of the provider.
That contradiction matters more because of how concentrated the market has become. According to analysis cited by the European DIGITAL SME Alliance and others this year, three US-based firms hold roughly 65% of the European cloud market. Concentration of that degree is a strategic dependency in its own right, quite apart from the legal exposure. When two thirds of a continent’s digital infrastructure sits with a handful of foreign providers, “vendor risk” stops being a line item and becomes a matter of economic autonomy.
The public sector is moving first
Governments, which answer to voters rather than shareholders, are leading. The Netherlands public sector now runs a “prefer open” policy, tilting procurement toward open and controllable technology by default rather than by exception. Copenhagen has gone further and drawn up exit plans from its dependence on US cloud services. These are not rhetorical gestures; drafting an exit plan is the moment a dependency becomes a documented risk that someone is accountable for reducing. When capital cities start writing down how they would leave, the private sector tends to follow within a cycle or two.
NIS2 is the accelerant
What turns a slow drift into a decision is regulation, and NIS2 is supplying the pressure. The Directive reached full effect across the EU in 2026, bringing audits and a demanding 24-hour incident-reporting duty. Germany implemented it into national law with no transition period, and its cybersecurity authority has already levied an early fine — reportedly EUR 850,000 — on a cloud provider for inadequate incident detection and late reporting. Crucially, NIS2 attaches accountability to management personally, and fines can reach EUR 10 million or 2% of turnover. That combination forces boards to actually understand their stack: what runs where, who controls it, and how fast the organisation can see and report a problem. A dependency you cannot fully audit is now a liability you cannot fully defend.
Self-hosting stopped being the harder path
For years, “self-host it” was the answer nobody wanted, associated with racks, pagers and heroic operations teams. That framing is out of date. Modern full-stack platforms have absorbed most of the operational heavy lifting that made self-hosting painful. A self-hosted SDK today can offer one backend core driving web, iOS and Android from a single source, with an agnostic core and plug-in modules — payments, subscriptions, catalogue, CMS, booking — that switch on and off without a restart. Because the infrastructure does the hard work, a small digital studio can credibly run a large enterprise’s commerce or booking stack. As one VBWD internal benchmark illustrates, a catalogue of a million complex products can import in around 40 minutes on such infrastructure, against three hours or more on a typical legacy platform. Treat that figure as a scoped benchmark rather than a promise — it varies by platform and workload — but the direction is clear: the operational tax that once made self-hosting the “hard” option has fallen sharply.
Put the pieces together and the strategic calculus inverts. When residency does not equal sovereignty, when two thirds of the market sits under foreign legal reach, when regulators are personally penalising opacity, and when self-hosting is no longer operationally punishing, self-hosting stops being the awkward exception. For a growing set of European operators it is becoming the strategic default. The argument is developed at more length in VBWD’s writing on sovereign-by-default commerce for the NIS2 era.
The honest caveat
None of this makes self-hosting free of trade-offs. It is not a way to shed responsibility — it is a way to own it. Self-hosting means owning patch cadence, monitoring and incident response, and that suits operationally mature organisations, or those working through a capable partner inside their own jurisdiction. A younger platform also trades some accumulated, twenty-year edge-case maturity for architecture, speed and auditability. For many European operators, in this regulatory climate, that is now the better trade. For some it will not be, and the responsible move is to test the claim against your own numbers first.
If this maps to a conversation happening inside your own organisation, the useful next step is specific rather than generic: see your own workload on modern, self-hosted infrastructure. Request an enterprise installation and bring the numbers you’re trying to improve.
Sources: European DIGITAL SME Alliance, OpenVPN, n-ix and elest.io on cloud sovereignty, market concentration and the CLOUD Act; Reed Smith, Freshfields and Lexology on NIS2 and its German implementation.