Defence dual-use sovereign infrastructure refers to computing environments, data storage systems, and communication networks that are architecturally and legally outside the reach of foreign jurisdiction, designed specifically to protect controlled technical data subject to export control regimes such as the US International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). For European organisations in the defence supply chain, the gap between this definition and current practice is wide and legally consequential.
The Jurisdiction Problem: Why EU-Region US Cloud Is Not Sovereign
The most persistent misconception among European defence contractors is that selecting an EU-region data centre from AWS, Microsoft Azure, or Google Cloud resolves export control and data sovereignty concerns. It does not.
ITAR 22 CFR §120.54, added to Part 120 specifically to address cloud environments, defines the transfer or storage of defence articles and controlled technical data in a cloud system as an export whenever a foreign person could gain access, or whenever the cloud operator is in a position to access the data. The Directorate of Defense Trade Controls (DDTC) has made its position explicit: any cloud service operated by a US person or US-controlled entity is subject to US jurisdiction, regardless of where the data physically resides. The location of servers is legally irrelevant under the CLOUD Act.
The CLOUD Act (18 U.S.C. §2713) reinforces this. It requires US-based providers to comply with lawful orders to produce stored data regardless of the country where that data is located. FISA Section 702 adds a further dimension: US intelligence agencies can compel US providers to hand over communications and stored data of non-US persons without a warrant, without notifying the data owner, and without any EU judicial oversight. Together, these three instruments mean that a European defence contractor storing CAD files, test data, or design documentation in Microsoft Azure or AWS GovCloud EU is operating under US legal exposure by default.
EAR Exposure for Dual-Use Manufacturers
EAR (15 CFR Parts 730-774), administered by the Bureau of Industry and Security (BIS), extends beyond purely military items to dual-use goods, software, and technology listed on the Commerce Control List (CCL). A European manufacturer of precision optics, advanced composites, semiconductor production equipment, or certain encryption products may be subject to EAR controls on re-export and on the cloud transmission of associated technical data, even without a formal defence contract.
The EAR’s deemed export rule (15 CFR §734.13) treats the release of controlled technology to a foreign national, including access via a shared platform, as an export to that person’s country of nationality. A European engineering team using a US SaaS collaboration platform where US employees of that platform could technically access project files is potentially triggering deemed export obligations for every foreign national on their own team.
What Sovereign Infrastructure Actually Eliminates
On-premises infrastructure hosted entirely within the European organisation’s own facilities, or hosted by a Swiss-domiciled provider with no US corporate parent and no US-person access to encryption keys, removes the primary vector of ITAR and EAR cloud-jurisdiction risk.
| Scenario | ITAR/EAR Cloud Risk | CLOUD Act Exposure | FISA 702 Exposure |
|---|---|---|---|
| AWS EU (Frankfurt) or Azure EU Data Boundary | High: US-controlled operator | Yes: US provider subject to §2713 | Yes: US person access possible |
| EU-owned colocation, EU-operated software stack | Low: no US-person access if properly architected | No: non-US provider | No: no US nexus |
| Swiss-hosted, Swiss corporate entity, no US parent | Low: Switzerland is not subject to CLOUD Act | No: Swiss provider outside US jurisdiction | No: no US nexus |
| On-premises, air-gapped for highest classification | Eliminated: no network transmission | None | None |
Switzerland’s revised Federal Act on Data Protection (revFADP, in force September 2023) aligns Swiss data protection standards more closely with GDPR, while Swiss law contains no equivalent to the CLOUD Act. A Swiss-domiciled provider is not compelled by US law to produce data stored in Switzerland, provided it has no US-person employees with access and no US corporate ownership chain.
To demonstrate compliance to a US prime contractor or government customer, a European organisation must produce a Technology Control Plan (TCP) that documents: access control architecture (role-based, with no US-person access to controlled data), encryption key custody (keys held exclusively by the European entity), audit log retention (who accessed what, when, from which endpoint), physical security of servers, and an incident response plan that does not route notifications through US-based SaaS tools.
EUCI, NATO RESTRICTED, and the Private Contractor’s Obligation
Not all defence supply chain organisations hold government security clearances, yet many handle information at classification levels that carry formal handling obligations. Council Decision 2013/488/EU establishes the EU Classified Information (EUCI) framework, which covers RESTREINT UE (the lowest tier), CONFIDENTIEL UE, SECRET UE, and TRÈS SECRET UE. NATO RESTRICTED is the NATO equivalent of RESTREINT UE and is treated as broadly equivalent under bilateral arrangements.
Private contractors handling RESTREINT UE or NATO RESTRICTED information must operate IT systems that have been assessed and approved by the relevant national security authority before contract performance begins. The European Defence Agency (EDA) has stated clearly in its industrial security guidelines that contractors handling EU Classified Information in the defence supply chain must implement information security measures equivalent to those required of public authorities, and must be able to demonstrate this to the contracting authority at any point during contract performance.
This means commercial SaaS platforms that route traffic through foreign jurisdictions, retain telemetry, or are subject to foreign compelled disclosure laws cannot be used for RESTREINT UE or NATO RESTRICTED data, regardless of vendor marketing claims about compliance certifications.
NIS-2 and the Supply Chain Security Obligation
NIS-2 (Directive (EU) 2022/2555, transposed by member states by October 2024) extends mandatory cybersecurity obligations to entities classified as “important” or “essential” based on their sector and size. Defence supply chain participants, including subcontractors supplying components or engineering services to prime defence contractors, may fall within scope even without holding a security clearance. The average cost of a data breach in the industrial and manufacturing sector reached $4.73 million in 2023 (IBM Security, Cost of a Data Breach Report 2023), a figure that does not include ITAR penalty exposure or contract termination costs.
NIS-2 requires risk-based cybersecurity measures, supply chain security assessments (Article 21), and significant incident reporting within 24 hours of detection. Non-compliance carries administrative fines of up to €10 million or 2% of global annual turnover, whichever is higher.
Architecting a Sovereign Dual-Use Workspace
A sovereign workspace for a dual-use organisation must separate ITAR-controlled data flows from general business workflows at the infrastructure level, not just at the policy level. Logical separation enforced only by configuration settings in a shared SaaS platform does not satisfy ITAR requirements because the platform operator retains potential access.
A practical architecture uses a dedicated on-premises server cluster, running an open-source collaboration platform such as Nextcloud hosted on European hardware, with network segmentation that prevents ITAR-tagged project folders from being accessible from devices or accounts used for non-controlled workflows. Data Loss Prevention (DLP) policies must run on-premises: any DLP engine that sends telemetry to a US-based vendor for analysis is itself a potential transmission channel for controlled data.
Remote and travelling staff present a specific risk vector. Connecting to on-premises controlled-data repositories over public internet without a quantum-safe VPN gateway is increasingly inadequate as nation-state actors with access to quantum computing capability advance. Post-quantum cryptographic algorithms standardised by NIST in 2024 (FIPS 203, 204, 205) should be the baseline for any new gateway procurement, because data intercepted today can be decrypted retroactively once quantum capability matures, a risk profile directly relevant to classified technical data with a 10-to-20-year sensitivity window.
Directive 2009/81/EC and Security-of-Supply Requirements
EU Directive 2009/81/EC, which governs procurement of defence and security equipment and services, requires contracting authorities to include security-of-supply and security-of-information clauses in covered contracts. Security-of-information clauses obligate the contractor to protect classified information and to ensure that subcontractors are bound by equivalent obligations. Security-of-supply clauses address continuity: the contracting authority must have assurance that the contractor’s ability to deliver will not be disrupted by a foreign government’s legal action against the contractor’s infrastructure provider.
An on-premises or European-sovereign-hosted deployment directly satisfies security-of-supply clauses in a way that a US-cloud-dependent architecture cannot, because it eliminates the scenario in which a US government order to a cloud provider could interrupt access to the contractor’s own project data. Eurostat data from 2023 indicates that approximately 42% of EU enterprises in the defence and advanced manufacturing sectors were using at least one public cloud service managed by a non-EU provider, suggesting that a significant portion of the European defence industrial base currently operates with unresolved security-of-supply exposure (Eurostat, Cloud Computing Statistics, 2023).
FAQ
Does storing data on AWS or Azure servers physically located in the EU protect a European defence contractor from ITAR exposure?
No. Under ITAR 22 CFR §120.54 and the CLOUD Act (18 U.S.C. §2713), the controlling factor is whether the cloud operator is a US person or US-controlled entity, not where servers sit physically. AWS and Microsoft are US companies, so their EU-region infrastructure remains subject to US jurisdiction and compelled disclosure requests.
What is the difference between ITAR and EAR exposure for a European dual-use manufacturer?
ITAR (22 CFR Parts 120-130) covers items and technical data on the US Munitions List, which includes defence articles with primarily military applications. EAR (15 CFR Parts 730-774) covers dual-use goods and technology that have both civil and military uses. A European manufacturer of precision optics or advanced composites may fall under EAR even without a direct defence contract, because the technology appears on the Commerce Control List. Both regimes can be triggered by cloud transmission of associated technical data.
What contractual evidence must a European contractor provide to a US prime contractor to demonstrate ITAR-compliant infrastructure?
A US prime will typically require a Technology Control Plan (TCP) describing access controls, physical security, encryption key custody, audit logging, and personnel authorisation. For cloud or hosted infrastructure, the TCP must demonstrate that no US-controlled service provider has technical access to the controlled data. On-premises or Swiss-hosted infrastructure with end-to-end encryption under keys held exclusively by the European entity, combined with independent audit reports and access logs, satisfies this requirement more cleanly than any hyperscaler arrangement.
How does NATO RESTRICTED differ from RESTREINT UE in terms of handling requirements for private contractors?
NATO RESTRICTED and RESTREINT UE are broadly equivalent classification levels under their respective frameworks and are treated as mutually recognised under bilateral arrangements. Both require that information systems used to process the data be assessed and approved by the relevant national security authority, that access be limited to cleared or need-to-know personnel, and that audit logs be maintained. Commercial SaaS platforms subject to foreign jurisdiction cannot be used for either classification level.
How does NIS-2 apply to a private defence subcontractor that does not itself hold a security clearance?
NIS-2 (Directive (EU) 2022/2555) classifies entities based on their role in critical infrastructure and their sector, not on whether they hold a government clearance. Subcontractors in the defence supply chain may be in scope as “important entities” and must implement risk-based cybersecurity measures, supply chain security controls, and significant incident reporting within 24 hours. Non-compliance carries fines of up to €10 million or 2% of global turnover. The obligation is independent of classification status.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
