MD · Infrastructure Sovereignty · 2026
Module MD — Digital Sovereignty
Controlling
your technical
foundation.
On-premise · Cloud · Edge · DORA Art. 28 · Resilience plan
Fundamental Rights #1 & #3 — ORBii Framework

"Choose your technologies and retain the ability to switch: infrastructure sovereignty ensures the organization maintains control over its technical foundation, can evolve it, and can exit without excessive damage."

What this module covers

Infrastructure dependency mapping, cloud/on-premise/edge decision criteria, operational DORA, resilience planning and exit strategy.

Target audience

CIO, enterprise architects, infrastructure & cloud managers, CISO, resilience and continuity teams, CDO office.

Core regulation

DORA Art. 28-30 (ICT concentration), NIS 2 Art. 21 (technical measures), Data Act Art. 23-35 (portability), BCBS 239 (continuity).

Recommended duration

Half day (3h30) — 2 theoretical sessions + 1 dependency mapping workshop.

ORBii.Academy — Digital Sovereignty & AIMD · P.01
MD · Infrastructure Sovereignty
Dependency mapping

Anatomy of a sovereign infrastructure.

Infrastructure sovereignty relies on the ability to precisely map dependencies, classify them by DORA criticality, and maintain a continuity strategy without excessive reliance on any single third party.

Tier 1 — On-premise

Own infrastructure, internal or co-located datacenter. Full control. High CAPEX investment.

Use cases: critical data, encryption keys, core banking, DORA-critical
Maximum sovereignty
Tier 2 — Sovereign cloud

SecNumCloud or HDS-certified cloud, EU operator, no foreign jurisdiction exposure.

Use cases: confidential data, data platforms, AI workloads, business applications
Strong sovereignty
Tier 3 — Hyperscaler cloud

International public cloud. Maximum agility. Cloud Act exposure depending on provider. DORA concentration risk.

Use cases: public/internal data, dev/test, collaboration tools, non-critical
Risk to manage

Workload classification matrix

WorkloadDORA CriticalityData ClassificationRecommended TierRequired Certification
Core banking & payments CriticalCriticalOn-premise / Tier 1PCI-DSS, ISO 27001
Data platform & BCBS reporting CriticalCriticalOn-premise or SecNumCloudHDS if healthcare, ISO 27001
High-risk AI systems (scoring) CriticalConfidentialSovereign cloud / Tier 1SecNumCloud or equiv.
Fraud detection & AML ImportantConfidentialEU sovereign cloudISO 27001, SOC2
Internal analytics & BI StandardInternalEU cloud (hyperscaler)GDPR + DPA
Collaboration & productivity tools LowInternalInternational cloudInternal security policy
ORBii.Academy — Digital Sovereignty & AIMD · P.02
Protected content

You have viewed the preview of this module (first 2 pages).
To access the full content, enter your access code or request access.

8 remaining pages Personal link · Valid 24h