Sovereign Cloud Is No Longer a European Theory — It Is Happening

For quite some time, digital sovereignty has been one of the recurring themes in European technology discussions. Governments, CIOs and policymakers have talked extensively about reducing Europe’s dependency on American hyperscalers, regaining control over data and infrastructure, and creating more room for European and open-source technology.

What struck me during the Nextcloud Enterprise Summit 2026 in Munich, which I attended in June, was how much that discussion has changed. The question is increasingly no longer whether organisations should become more digitally sovereign. The much more practical question is: how do we actually migrate?

I wrote about the event in more detail for Computable. What I saw in Munich convinced me that sovereign cloud is moving beyond policy papers and political ambitions. Real organisations are already making the transition, sometimes at considerable scale.

From discussion to implementation

That is perhaps the most important development. Digital sovereignty used to be discussed primarily in terms of legislation, geopolitical risk and strategic dependency. Those questions remain important, of course, but they are now increasingly accompanied by something much more tangible: migration projects. During the Nextcloud Summit, several organisations explained how they are moving workloads, collaboration environments and digital workplaces towards infrastructure over which they have considerably more control.

One of the most striking examples came from France. The French Ministry of Education operates Nuage, a Nextcloud-based environment that currently has more than 400,000 active accounts and is expected eventually to scale towards 1.2 million users. That immediately changes the nature of the discussion. Sovereign collaboration platforms are clearly no longer limited to small pilots involving a few technically enthusiastic departments. They can operate at genuinely large scale.

Other examples discussed in Munich included organisations and projects involving an Austrian ministry, Amnesty International, Dutch education and research organisation SURF and Deutsche Telekom. The latter has already been operating its Nextcloud-based MagentaCloud for German consumers for years and is also using the technology for large enterprise projects.

Sovereignty also needs a usable workplace

There is, however, an important condition. An alternative to Microsoft 365 or Google Workspace cannot succeed simply because it is European, open source or politically attractive. People actually have to use it every day. That sounds obvious, but it is sometimes overlooked in discussions about digital sovereignty.

Users need to edit documents, share files, organise calendars, communicate with colleagues, participate in video meetings and increasingly also work with AI assistants. If a sovereign alternative makes those everyday activities significantly more difficult, migration becomes a much harder organisational challenge.

This is why many of the relatively modest improvements announced in Nextcloud Hub 26 Spring are actually important. Nextcloud combines file management, collaborative document editing, chat, video conferencing, calendars, workflow automation and AI functionality within one environment. Organisations can operate that environment themselves or obtain it through a European cloud provider.

The latest release also adds Euro-Office as a second standard office option alongside Collabora. Euro-Office focuses strongly on compatibility with Microsoft Office documents and browser performance, while Collabora remains available for organisations that prioritise Open Document Format compatibility. That choice illustrates something that I believe will become increasingly important in the sovereign-cloud market: there probably will not be one single replacement for Microsoft 365. Instead, we are likely to see increasingly modular environments in which organisations select components according to their own requirements.

Migration is not a switch

Another message from the summit was equally important: migration should not be presented as a simple rip and replace operation. Large organisations cannot usually switch thousands of users, documents, calendars, mailboxes, applications and established workflows from one platform to another over a weekend. The transition is much more likely to happen gradually.

Migration specialists such as Germany’s Audriga and Dutch company Sendent demonstrated how important interoperability becomes during that process. Organisations may continue using parts of their existing environment while gradually moving files, calendars, communication and collaboration towards a more open infrastructure.

This approach also makes sovereign cloud much more realistic. The objective does not have to be immediate technological purity. The objective can be progressively reducing dependency while increasing control. That is a very different way of thinking about migration.

Sovereignty is more than data location

The summit also highlighted another issue that is sometimes simplified too much. Storing data in Europe does not automatically make an IT environment sovereign. True digital sovereignty involves questions such as who controls the software, who can access the data, which jurisdiction applies, how easily workloads can be moved, who controls updates, what happens if a supplier changes strategy and whether an organisation can realistically continue operating without that supplier.

Nextcloud’s new Governance functionality reflects that broader view. It introduces enterprise capabilities around areas such as data lifecycle management, access control, sensitivity labels, legal hold and archiving. For governments, healthcare organisations, educational institutions and large companies, this is crucial. Digital sovereignty is not simply about choosing another cloud provider. It is also about being able to demonstrate who controls information and under which rules.

Next is the hardware question

Perhaps one of the most interesting discussions in Munich went even further down the technology stack. Suppose an organisation runs Nextcloud instead of Microsoft 365. Suppose the platform is hosted by a European provider. And suppose the underlying cloud environment uses technologies such as OpenStack and Kubernetes. That certainly reduces dependency.

But underneath those software layers there are still servers, storage systems, network equipment, racks, firmware, processors, power supplies and management interfaces. In other words: how sovereign is your sovereign cloud if the physical infrastructure remains completely dependent on a handful of proprietary suppliers?

German cloud and datacentre company ScaleUp Technologies used the summit to draw attention to open hardware and the Open Compute Project. Open specifications for servers, racks, storage, networking and power infrastructure can make it easier to avoid dependence on a single hardware supplier or proprietary architecture.

That does not suddenly mean that Europe will manufacture every component itself. Nor does open hardware magically eliminate technological dependencies. But it does broaden the sovereignty discussion. We are moving from discussing individual applications to considering the entire technology stack.

A more mature discussion

That was ultimately my main takeaway from attending the Nextcloud Summit. European digital sovereignty is becoming much less theoretical. There are now organisations running sovereign collaboration environments at hundreds of thousands or even millions of users. There are migration specialists, hosting providers, implementation partners and increasingly mature software platforms. There are also serious discussions about governance, interoperability and even the underlying hardware infrastructure.

None of this means that migrating away from established hyperscaler ecosystems is easy. It is not. But there is an important difference between something being difficult and something being impossible. The cases presented in Munich showed that migration to more sovereign cloud environments is already taking place. Not through one dramatic European departure from American Big Tech, but through hundreds of practical decisions about software, hosting, governance, interoperability and infrastructure.

And perhaps that is exactly how European digital sovereignty will ultimately develop: not as one enormous technological revolution, but as a gradual rebuilding of control, layer by layer.

Moving Away from Microsoft 365: Digital Autonomy Starts with Control

Digital sovereignty and digital autonomy are often discussed in rather abstract terms. We talk about reducing dependence on Big Tech, keeping European data in Europe, choosing open-source technology and creating alternatives to the large American cloud platforms. But eventually, every discussion about digital autonomy runs into a very practical question: how do you actually move away from an environment such as Microsoft 365?

That question is much more complicated than simply installing Nextcloud, copying a few folders and cancelling a number of Microsoft licences. Microsoft 365 has become deeply embedded in the daily operations of many organisations. Documents, e-mail, calendars, identities, permissions and collaboration processes are interconnected in ways that are not always immediately visible.

Frank Dengler

That is why I recently spoke with Frank Dengler, director of German migration specialist Audriga. I wanted to talk to him because of his extensive practical experience with migrations between e-mail, groupware and cloud storage environments. In particular, Audriga has worked extensively on the practical challenges involved in moving organisations from Microsoft 365 towards more open environments based on technologies such as Nextcloud.

The resulting conversation, originally published by Business Meets IT, made one thing particularly clear: migrating away from Microsoft is certainly possible, but the technology itself is rarely the biggest challenge.

First understand what you already have

One of Dengler’s most important observations is that organisations should not start a migration by looking for migration tools. That may sound slightly counterintuitive. After all, when organisations start thinking about moving away from Microsoft 365, some of the first questions are usually technical. How do we migrate Exchange mailboxes? How do we copy SharePoint libraries? Which tool can move OneDrive files into Nextcloud? Those questions matter, but they come later.

The first question should be much simpler: what are we actually using? Microsoft 365 environments tend to grow organically. A SharePoint site created years ago may have become an important repository for a department. A shared mailbox may quietly function as the central workflow for customer enquiries. Teams may provide the user interface, while the actual documents are stored somewhere in SharePoint. Calendars, address books, distribution lists and access rights may have accumulated over many years.

The organisation therefore needs to map those dependencies before moving anything. In other words, migration starts with inventory rather than technology. Which users exist? Which groups? Which SharePoint sites are still active? Where are business-critical files stored? Which mailboxes are personal and which are shared or functional? Which calendars are actually being used? And which permissions have become essential to everyday processes?

Only after answering those questions can an organisation decide what needs to be migrated, redesigned, cleaned up or perhaps simply left behind.

Files are never just files

This is particularly important when migrating documents. At first sight, moving files from OneDrive or SharePoint to Nextcloud sounds relatively straightforward. But Dengler points out that documents always have context. Who owns them? Who is allowed to open them? Which folder structure is relevant? Is version history important? Are there external links? Are particular permissions attached to individual folders or documents?

SharePoint makes this particularly interesting because access rights can exist at several levels: sites, libraries, folders and even individual files. Documents opened through Teams may actually reside in SharePoint in the background. Simply copying the files therefore does not necessarily recreate the way people work. A migration can consequently be an excellent opportunity to clean things up.

Old documents, abandoned accounts, duplicate files and forgotten shared folders do not necessarily have to follow the organisation into its new environment. Moving to another platform can force an organisation to reconsider which information still has value, who owns it and who genuinely needs access to it. That is an interesting aspect of digital autonomy that often receives too little attention. It is not only about where information is stored. It is also about understanding and governing that information.

Avoid the big bang

For small and relatively simple organisations, migrating everything during one weekend may sometimes be feasible. For larger organisations, Dengler generally favours a phased migration using a period of coexistence. Microsoft 365 and the new open environment temporarily operate alongside each other. Departments, teams or particular data domains are then moved in successive waves.

There is an obvious advantage to this approach: organisations can learn. The first migration wave will almost certainly uncover things that were missed during preparation. Those lessons can then be applied to the next department or user group. Problems remain relatively contained instead of suddenly affecting the entire organisation.

But coexistence should remain temporary. If Microsoft 365 and Nextcloud continue running indefinitely without a clear plan, the organisation risks creating yet another layer of complexity. Users may no longer know which environment contains the authoritative version of a document or which system they should use for a particular task. A phased migration therefore needs an endpoint.

Identity comes first

Another lesson from Dengler’s experience is that identity should be treated as part of the foundation. Before documents, calendars or mailboxes can be moved, users and groups need to exist correctly in the new environment. Nextcloud can work with technologies such as LDAP, SAML-based single sign-on, directory synchronisation, Microsoft Entra ID or an existing Active Directory infrastructure.

This also raises a broader strategic question. An organisation may decide to continue using Microsoft Entra ID as its identity provider while moving documents and collaboration services away from Microsoft. There is nothing inherently wrong with that. A migration towards greater autonomy does not require every dependency to disappear on day one.

But organisations should understand which dependencies are temporary and which ones they intend to retain. That distinction is essential. Otherwise, an organisation may believe it has become independent because its documents have moved to Nextcloud while a critical part of its digital workplace still depends completely on another supplier.

E-mail is where things become serious

Documents are often a sensible starting point. E-mail tends to be considerably more sensitive. A personal mailbox can be relatively straightforward to migrate. Real corporate environments, however, contain shared mailboxes, aliases, distribution lists, delegation rules, functional addresses, calendars and meeting-room resources.

During a phased migration, routing becomes particularly important. Some employees may still use Exchange Online while others have already moved to the new mail and groupware environment. The infrastructure then has to know exactly where a message for each individual user should be delivered.

That sounds like a technical detail, but it is one of the areas where careful planning makes phased migration possible. Rather than switching an entire organisation at once, individual departments or groups can be migrated while mail continues to flow correctly.

Calendars deserve similar attention. Recurring meetings, time zones, attendees, shared calendars and meeting rooms can all introduce unexpected problems.

The important question is therefore not merely whether calendar data has technically been transferred. It is whether the calendar still works as a coordination system for the organisation.

Test whether people can work

That brings us to perhaps the most practical lesson from my conversation with Dengler. Testing should not simply confirm that migration software successfully moved a certain number of gigabytes. It should confirm that people can continue doing their jobs.

Early test migrations should therefore use realistic accounts, large mailboxes, complex folder structures, shared calendars and active collaboration environments. Key users from the organisation should participate as well. IT can verify that files exist, permissions have been transferred and systems respond correctly. But only actual users can determine whether their working environment still makes sense.

The ultimate test is remarkably simple: can this department arrive on Monday morning and work normally? If the answer is no, the migration is not finished.

Digital autonomy also requires an exit

Perhaps the most important point is that moving data into Nextcloud is not the end of the process. If Microsoft 365 remains permanently available as an archive, emergency environment or shadow platform, the organisation has not truly removed the dependency.

That does not mean the old environment needs to disappear immediately. There may be legal, technical or operational reasons for keeping certain services running temporarily. But there should be an exit plan.

At some point Microsoft 365 may become read-only. Licences can be terminated. Remaining information may be archived or deleted. Guest accounts can be removed and obsolete shared environments shut down.

Digital autonomy therefore involves something that organisations do not always associate with technology strategy: the ability to leave.

An organisation is much more autonomous when it knows how to move its information, understands its dependencies and can switch suppliers or platforms when circumstances change.

Control matters more than technology

That was also the central message I took away from my conversation with Frank Dengler. Nextcloud and other open-source technologies make alternatives to Microsoft 365 technically possible. But simply installing different software does not automatically create digital autonomy. Governance, identity, ownership, permissions, migration planning, user acceptance and eventually the ability to shut down the old environment matter just as much.

Digital autonomy is therefore not primarily a debate about replacing Microsoft software with open-source software. It is about regaining control. Control over data. Control over identities. Control over infrastructure. Control over suppliers. And, perhaps most importantly, control over the ability to change direction in the future.

The technology to do this already exists. The more difficult question is whether organisations are prepared to understand their current dependencies well enough to actually use that freedom. That, ultimately, is what makes migration an important part of the wider European discussion about digital sovereignty and autonomy.