Digital transformation has created new dependencies across cloud, software, infrastructure, data, and AI. As geopolitical tensions rise, regulations proliferate, and cyber threats intensify, organisations are increasingly exposed to risks beyond their direct control.

As a result, digital sovereignty is moving from a policy discussion to a business priority. Organisations are seeking to strengthen resilience, retain control over critical assets, and manage dependencies without compromising innovation or competitiveness.

This report draws on a global survey of 1,300 executives and interviews with leaders across industry, technology, and policy to examine how organisations are approaching digital sovereignty in a rapidly changing environment.

The defining shifts in digital sovereignty

Digital sovereignty has become a boardroom issue
Ninety-three percent of organisations have discussed digital sovereignty at board level, while half have appointed, or are considering appointing, a chief sovereignty officer.

Strategic autonomy matters more than full independence
Most organisations recognise that complete control across the technology stack is neither realistic nor desirable. Instead, they focus on managing dependencies while maintaining flexibility and control over critical assets.

Dependency on external technology providers remains high
Reliance on global suppliers across cloud, software, hardware, and connectivity continues to expose organisations to concentration risk, limited visibility, and lengthy switching timelines.

Organisations are taking a pragmatic approach
According to 59% of organisations, full digital sovereignty is unrealistic. Many are pursuing hybrid models built on federated control and managed interdependence to protect critical operations while maintaining access to innovation.

Digital sovereignty requires balancing resilience and competitiveness
Just over half of organisations (54%) believe they can strengthen digital sovereignty without sacrificing competitiveness, highlighting the need for practical, risk-based strategies.

Five actions for business and technology leaders

Organisations should:

  • Elevate digital sovereignty to a board-level priority
  • Assess exposure across critical operations and dependencies
  • Prioritise interventions based on business impact and risk
  • Build resilience and control into operating models and governance
  • Foster innovation through managed interdependence

This report is essential for CIOs, CTOs, CDOs, chief data and security officers, and executives responsible for risk, compliance, and digital strategy. It provides practical insights into balancing control, resilience, and innovation in an increasingly complex digital ecosystem.