C3SA FIELD GUIDE

DIGITAL SOVEREIGNTY ASSESSMENT GUIDE

Sovereignty is more than where data is stored. This guide helps you assess strategic dependency across data, cloud, identity, cryptography, AI, infrastructure and technology supply chains, one material system at a time.

THE GUIDE

SIX QUESTIONS THAT REVEAL WHO REALLY HAS CONTROL.

A documented dependency chain for each material system is the foundation for every sovereignty decision.

01

Map jurisdictional exposure

For each material system, identify which countries' laws apply to the provider, its parent company and its subcontractors. A service can store data in Canada and still be subject to foreign legal orders through the company that operates it.

Questions to ask

  • Where is each critical provider and its parent incorporated?
  • Which laws could compel them to provide access to our data?
  • What do our contracts say about government access requests?
02

Identify control-plane dependencies

The control plane is the administrative layer that manages a service: consoles, APIs, updates and support access. If it is run from elsewhere, local hosting provides limited control.

Questions to ask

  • Who can administer the service, and from where?
  • Can the provider push changes or updates without our approval?
  • What happens if the control plane becomes unavailable?
03

Assess data and key custody

Encryption only protects sovereignty if you control the keys. Establish who generates, stores and can use each key, and whether the provider can decrypt your data.

Questions to ask

  • Who holds the encryption keys for our most sensitive data?
  • Could the provider decrypt data if compelled?
  • Are keys held in a hardware security module we control?
04

Evaluate identity and cloud concentration

Identity providers and cloud platforms sit underneath almost everything. Dependence on one provider for both creates a single point of failure and control.

Questions to ask

  • Which identity provider do all our systems depend on?
  • How much of our infrastructure runs on one cloud provider?
  • Do we have break-glass access if either fails?
05

Review supplier and AI dependencies

Examine the ownership, subcontractors and software components behind each critical supplier, and where AI services process your prompts, data and outputs.

Questions to ask

  • Who owns our critical suppliers, and has that changed?
  • Where do our AI services process data, and do they retain it?
  • Which suppliers have no realistic alternative?
06

Define sovereign target-state options

For each material system, set out realistic options, from contractual protections and customer-managed keys to migration to a sovereign provider, and document the trade-offs.

Questions to ask

  • What level of control does each system actually need?
  • What are the cost, capability and effort trade-offs of each option?
  • What would we do first if conditions changed tomorrow?

Last reviewed September 24, 2026. This guide is general information, not legal advice. Print or save this page to use it as a workshop handout or pre-engagement checklist.

NEXT STEP

MOVE FROM CHECKLIST TO EVIDENCE.

C3SA can help validate the current state, identify material gaps, define the target state and support implementation, testing and readiness.

UNDER ATTACK? CYBERFIRE →