Sovereignty refers to the ability to exercise effective control over one’s data, infrastructure, and technologies, without forced dependency on foreign actors. Strategic autonomy has become a determining criterion for choosing cybersecurity tools, and to protect data, intellectual property, and strategic and technological autonomy.
In an uncertain geopolitical context, companies of all sizes and sectors are reassessing their cybersecurity and IT strategies to include these issues.
This trend may be driven by a growing awareness that dependence on non-European technologies can represent a risk, or it may be imposed by a legal or regulatory framework in sensitive and vital sectors.
What are the legal frameworks in Europe, and which European standards should be prioritized to validate the performance and sovereignty of cybersecurity tools?
Regulatory frameworks for cybersecurity in Europe
NIS 2
The NIS 2 directive (Network and Information Security 2) is a foundational text for European cybersecurity. Entering into force in January 2023 and transposed into member states since October 2024, it expands the scope of NIS 1 by now covering more than 18 critical sectors including public administrations, digital infrastructures, healthcare, energy, and transport.
NIS 2 imposes specific obligations: security governance, cyber risk management, incident notification within 24 hours, and supply chain security. Penalties for non-compliance can reach 10 million euros or 2% of global turnover.
For compliance, organizations must rely on robust and sovereign incident detection and response tools. NIS 2 pushes organizations to rethink their cybersecurity posture in a context where strategic autonomy is becoming an imperative.
Focus: KRITIS
In Germany, KRITIS (Kritische Infrastrukturen) is the regulatory framework for the protection of critical infrastructure, managed by the BSI (Bundesamt für Sicherheit in der Informationstechnik, or Federal Office for Information Security). It identifies the sectors vital to German society: energy, water, food, transport, healthcare, finance, media, and information technology.
KRITIS operators are subject to strict obligations: implementation of state-of-the-art security measures, regular audits, and incident reporting to the BSI.
The IT-Sicherheitsgesetz 2.0 law, adopted in 2021, strengthened this framework by expanding the scope of entities covered and introducing the concept of infrastructures of particular importance to the state.
KRITIS is the German implementation of NIS 2. For the operators concerned, the choice of cybersecurity solutions is strategic, and the BSI certifies and recommends tools that meet its own requirements
A sovereign European workspace detection and protection platform such as HarfangLab ensures that data remains under European jurisdiction, with no dependency on non-European technologies, making it possible to comply with the requirements of NIS 2 and KRITIS.
DORA
The DORA regulation (Digital Operational Resilience Act) came into effect on January 17, 2025. It is specifically addressed to the European financial sector: banks, insurance companies, asset management firms, market infrastructures, and their critical technology service providers.
DORA imposes a unified framework for operational resilience structured around five pillars: IT risk management, incident notification, resilience testing (including advanced pen tests), third-party risk management, and sharing of cyber threat intelligence.
One of DORA’s most impactful requirements concerns supply chain oversight: financial institutions must ensure that their technology providers, including their cybersecurity tools, comply with high security and resilience standards.
HarfangLab, whose code is audited and whose data is hosted in Europe, directly addresses this requirement for traceability and third-party risk management imposed by DORA.
GDPR
The GDPR (General Data Protection Regulation), in force since May 2018, is the legal foundation for the protection of personal data in the European Union. It applies to any organization processing the data of European residents, regardless of its geographical location.
The GDPR is based on fundamental principles: minimization of collected data, purpose limitation, data subject rights (access, rectification, erasure), and the obligation to secure processing operations. In the event of a data breach, organizations have 72 hours to notify the competent local authority.
The link between GDPR and cybersecurity is direct: a security breach is, in many cases, a GDPR violation. Incident detection and response tools therefore play a key role in compliance.
By choosing a sovereign European cyber platform such as HarfangLab, organizations ensure that their sensitive security data, which reveals their internal activity, is processed exclusively under European jurisdiction.
Cyber certifications in Europe
Several groups of cyber certifications exist at the international level depending on the domain concerned, governed by common frameworks:
Product certifications targeting technical security: CSPN (ANSSI in France), BSZ (BSI in Germany), NIAP (USA), JISEC (Japan)… They evaluate the robustness of a product or component
Organizational certifications targeting security processes and management (ISMS): ISO 27001, SOC 2 (AICPA in the USA), Cyber Essentials (UK)
Cloud/SaaS certifications: FedRAMP (USA), SecNumCloud (ANSSI in France), C5 (BSI in Germany), IRAP (Australia), ENS (Spain)
Cryptographic certifications: FIPS 140-3 (USA/Canada), EAL validations
In Europe, different countries have their own bodies and certifications or schemes:
Country
Body
Certification / Scheme
Austria
ACSC
CC, EUCC
Belgium
CCB
EUCC, Safeonweb
Bulgaria
SANS
CC
Croatia
SOA / CARNET CERT
EUCC
Cyprus
CSIRT-CY
EUCC
Czech Republic
NÚKIB
CC, EUCC
Denmark
CFCS
CC
Estonia
RIA
CC, e-governance
Finland
Traficom / NCSC-FI
CC
France
ANSSI
CSPN, CC, SecNumCloud
Germany
BSI
CC, C5, IT-Grundschutz
Greece
ADAE
CC
Hungary
SZTFH
CC
Iceland
CERT-IS
EUCC (EEA)
Ireland
NCSC Ireland
CC, EUCC
Italy
ACN
CC, national cloud scheme
Latvia
CERT.lv
EUCC
Lithuania
NKSC
EUCC
Luxembourg
CIRCL / HCPN
EUCC
Malta
MCA
EUCC
Netherlands
NCSC-NL
CC, BIO
Norway
NSM
CC
Poland
CERT Polska / NASK
EUCC
Portugal
CNCS
EUCC
Romania
DNSC
EUCC
Slovakia
NBÚ
CC
Slovenia
SI-CERT / UKOM
EUCC
Spain
CCN-CERT
CC, ENS
Sweden
NCSC-SE / SÄPO
CC
Switzerland
OFCS
CC (EU-aligned)
United Kingdom
NCSC
Cyber Essentials, CHECK, CC
Some countries such as France, Germany, Spain, and the Netherlands have historically established national schemes, while other smaller countries such as Malta, Cyprus, or Luxembourg rely on the European EUCC scheme managed by ENISA rather than maintaining their own national scheme.
Mutual recognition through the CCRA (Common Criteria Recognition Arrangement) and the SOG-IS MRA (Europe) allows certifications obtained in one member country to be recognized in others, thereby reducing the complexity of assessments.
Outside the EU, NIST, NIAP, and NSA issue certifications in the United States, as does the Canadian Centre for Cyber Security (CCCS), CERT-In (STQC) in India, and IPA (JISEC) in Japan.
HarfangLab is a sovereign European workspace detection and protection platform certified by ANSSI (CSPN) in France and the BSI (BSZ) in Germany.
HarfangLab’s EDR is the first to have obtained these certifications in Europe, positioning HarfangLab as the leader in the European cybersecurity market, where performance and certifications are key selection criteria for organizations.
These certifications from ANSSI and the BSI attest to the robustness of the solution, the quality of the platform’s development processes, and the maintenance of requirements over time.
How to assess the level of Europeansovereignty of a cybersecuritysolution
The European Commission has published the Cloud Sovereignty Framework, which defines several sovereignty criteria and assurance levels for each. It allows the sovereignty of cloud services to be evaluated across the following dimensions:
Strategic sovereignty
Legal and regulatory sovereignty
Data and AI sovereignty
Supply chain
Technological sovereignty
Compliance and security
Sustainable development
Each criterion is scored from 0 to 4 and results in a percentage score.
The platform is 100% developed in Europe where all teams are based, and it can ensure full service continuity even in the event of disruption to non-EU services.
Data is 100% hosted within the European Union, contracts are compliant with French legislation, and no data is exposed to the CLOUD Act or non-EU legislation.
Data processing and AI model training are performed internally and stored in the EU for full autonomy over the data lifecycle, avoiding reliance on tools outside the European Union.
HarfangLab has full visibility and can ensure complete traceability over its suppliers, including international ones, and the platform is independent of proprietary technologies located outside the EU.
They trust us
ProtonHead of Security
“We chose HarfangLab for several reasons: it is a high-performance and open solution, and moreover European.”
ProtonHead of Security
MolcyIT Manager
“With HarfangLab, we have strengthened our protection with a sovereign and highly performant detection and protection platform.”
MolcyIT Manager
Defense IndustryCybersecurity Architect
“We validated HarfangLab’s performance in terms of detection and remediation; these two parameters tipped the balance in addition to sovereignty, which was a must-have.”
Defense IndustryCybersecurity Architect
MinistrySecurity Operations Analyst
“HarfangLab meets our needs both in terms of performance and the sovereignty imperative. The platform can be deployed On-Premises with the same features as the cloud version. The detection rules are accessible and transparent, and the telemetry is rich.”
MinistrySecurity Operations Analyst
Startup NewspaceMSSP Director
“Interoperability and sovereignty are essential criteria for us, in addition to high requirements for protection and detection. HarfangLab was an obvious choice.”
Startup NewspaceMSSP Director
Université Paris CitéCISO
“In addition to fitting our budget framework, HarfangLab perfectly meets our needs in terms of performance, sovereignty, data protection, and availability. The solution also provides strong, close-knit support.”
Université Paris CitéCISO
Try out our platform in your workspace
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.