Sovereign European Cybersecurity Platform

Sovereignty refers to the ability to exercise effective control over one’s data, infrastructure, and technologies, without forced dependency on foreign actors. Strategic autonomy has become a determining criterion for choosing cybersecurity tools, and to protect data, intellectual property, and strategic and technological autonomy.

In an uncertain geopolitical context, companies of all sizes and sectors are reassessing their cybersecurity and IT strategies to include these issues.

This trend may be driven by a growing awareness that dependence on non-European technologies can represent a risk, or it may be imposed by a legal or regulatory framework in sensitive and vital sectors.

What are the legal frameworks in Europe, and which European standards should be prioritized to validate the performance and sovereignty of cybersecurity tools?


Regulatory frameworks for cybersecurity in Europe

NIS 2 

The NIS 2 directive (Network and Information Security 2) is a foundational text for European cybersecurity. Entering into force in January 2023 and transposed into member states since October 2024, it expands the scope of NIS 1 by now covering more than 18 critical sectors including public administrations, digital infrastructures, healthcare, energy, and transport.

NIS 2 imposes specific obligations: security governance, cyber risk management, incident notification within 24 hours, and supply chain security. Penalties for non-compliance can reach 10 million euros or 2% of global turnover.

For compliance, organizations must rely on robust and sovereign incident detection and response tools. NIS 2 pushes organizations to rethink their cybersecurity posture in a context where strategic autonomy is becoming an imperative.


Focus: KRITIS 

In Germany, KRITIS (Kritische Infrastrukturen) is the regulatory framework for the protection of critical infrastructure, managed by the BSI (Bundesamt für Sicherheit in der Informationstechnik, or Federal Office for Information Security). It identifies the sectors vital to German society: energy, water, food, transport, healthcare, finance, media, and information technology. 

KRITIS operators are subject to strict obligations: implementation of state-of-the-art security measures, regular audits, and incident reporting to the BSI.

The IT-Sicherheitsgesetz 2.0 law, adopted in 2021, strengthened this framework by expanding the scope of entities covered and introducing the concept of infrastructures of particular importance to the state. 

KRITIS is the German implementation of NIS 2. For the operators concerned, the choice of cybersecurity solutions is strategic, and the BSI certifies and recommends tools that meet its own requirements 

A sovereign European workspace detection and protection platform such as HarfangLab ensures that data remains under European jurisdiction, with no dependency on non-European technologies, making it possible to comply with the requirements of NIS 2 and KRITIS.


DORA 

The DORA regulation (Digital Operational Resilience Act) came into effect on January 17, 2025. It is specifically addressed to the European financial sector: banks, insurance companies, asset management firms, market infrastructures, and their critical technology service providers.

DORA imposes a unified framework for operational resilience structured around five pillars: IT risk management, incident notification, resilience testing (including advanced pen tests), third-party risk management, and sharing of cyber threat intelligence.

One of DORA’s most impactful requirements concerns supply chain oversight: financial institutions must ensure that their technology providers, including their cybersecurity tools, comply with high security and resilience standards.

HarfangLab, whose code is audited and whose data is hosted in Europe, directly addresses this requirement for traceability and third-party risk management imposed by DORA.


GDPR

The GDPR (General Data Protection Regulation), in force since May 2018, is the legal foundation for the protection of personal data in the European Union. It applies to any organization processing the data of European residents, regardless of its geographical location.

The GDPR is based on fundamental principles: minimization of collected data, purpose limitation, data subject rights (access, rectification, erasure), and the obligation to secure processing operations. In the event of a data breach, organizations have 72 hours to notify the competent local authority.

The link between GDPR and cybersecurity is direct: a security breach is, in many cases, a GDPR violation. Incident detection and response tools therefore play a key role in compliance.

By choosing a sovereign European cyber platform such as HarfangLab, organizations ensure that their sensitive security data, which reveals their internal activity, is processed exclusively under European jurisdiction.


Cyber certifications in Europe

Several groups of cyber certifications exist at the international level depending on the domain concerned, governed by common frameworks: 

  • Product certifications targeting technical security: CSPN (ANSSI in France), BSZ (BSI in Germany), NIAP (USA), JISEC (Japan)… They evaluate the robustness of a product or component
  • Organizational certifications targeting security processes and management (ISMS): ISO 27001, SOC 2 (AICPA in the USA), Cyber Essentials (UK)
  • Cloud/SaaS certifications: FedRAMP (USA), SecNumCloud (ANSSI in France), C5 (BSI in Germany), IRAP (Australia), ENS (Spain)
  • Cryptographic certifications: FIPS 140-3 (USA/Canada), EAL validations

In Europe, different countries have their own bodies and certifications or schemes: 

Country Body Certification / Scheme
Austria ACSC CC, EUCC
Belgium CCB EUCC, Safeonweb
Bulgaria SANS CC
Croatia SOA / CARNET CERT EUCC
Cyprus CSIRT-CY EUCC
Czech Republic NÚKIB CC, EUCC
Denmark CFCS CC
Estonia RIA CC, e-governance
Finland Traficom / NCSC-FI CC
France ANSSI CSPN, CC, SecNumCloud
Germany BSI CC, C5, IT-Grundschutz
Greece ADAE CC
Hungary SZTFH CC
Iceland CERT-IS EUCC (EEA)
Ireland NCSC Ireland CC, EUCC
Italy ACN CC, national cloud scheme
Latvia CERT.lv EUCC
Lithuania NKSC EUCC
Luxembourg CIRCL / HCPN EUCC
Malta MCA EUCC
Netherlands NCSC-NL CC, BIO
Norway NSM CC
Poland CERT Polska / NASK EUCC
Portugal CNCS EUCC
Romania DNSC EUCC
Slovakia NBÚ CC
Slovenia SI-CERT / UKOM EUCC
Spain CCN-CERT CC, ENS
Sweden NCSC-SE / SÄPO CC
Switzerland OFCS CC (EU-aligned)
United Kingdom NCSC Cyber Essentials, CHECK, CC

Some countries such as France, Germany, Spain, and the Netherlands have historically established national schemes, while other smaller countries such as Malta, Cyprus, or Luxembourg rely on the European EUCC scheme managed by ENISA rather than maintaining their own national scheme.

Mutual recognition through the CCRA (Common Criteria Recognition Arrangement) and the SOG-IS MRA (Europe) allows certifications obtained in one member country to be recognized in others, thereby reducing the complexity of assessments.

Outside the EU, NIST, NIAP, and NSA issue certifications in the United States, as does the Canadian Centre for Cyber Security (CCCS), CERT-In (STQC) in India, and IPA (JISEC) in Japan.  

HarfangLab is a sovereign European workspace detection and protection platform certified by ANSSI (CSPN) in France and the BSI (BSZ) in Germany.

HarfangLab’s EDR is the first to have obtained these certifications in Europe, positioning HarfangLab as the leader in the European cybersecurity market,  where performance and certifications are key selection criteria for organizations.

These certifications from ANSSI and the BSI attest to the robustness of the solution, the quality of the platform’s development processes, and the maintenance of requirements over time. 


How to assess the level of European sovereignty of a cybersecurity solution

The European Commission has published the Cloud Sovereignty Framework, which defines several sovereignty criteria and assurance levels for each. It allows the sovereignty of cloud services to be evaluated across the following dimensions:

  • Strategic sovereignty
  • Legal and regulatory sovereignty
  • Data and AI sovereignty
  • Supply chain
  • Technological sovereignty
  • Compliance and security
  • Sustainable development 

Each criterion is scored from 0 to 4 and results in a percentage score. 
  

HarfangLab - Sovereignty score EU framework

HarfangLab’s sovereignty score is 97%

The platform is 100% developed in Europe where all teams are based, and it can ensure full service continuity even in the event of disruption to non-EU services.

Data is 100% hosted within the European Union, contracts are compliant with French legislation, and no data is exposed to the CLOUD Act or non-EU legislation.

Data processing and AI model training are performed internally and stored in the EU for full autonomy over the data lifecycle, avoiding reliance on tools outside the European Union. 

HarfangLab has full visibility and can ensure complete traceability over its suppliers, including international ones, and the platform is independent of proprietary technologies located outside the EU.

They trust us

Proton Head of Security

“We chose HarfangLab for several reasons: it is a high-performance and open solution, and moreover European.”

Proton Head of Security
Molcy IT Manager

“With HarfangLab, we have strengthened our protection with a sovereign and highly performant detection and protection platform.”

Molcy IT Manager
Defense Industry Cybersecurity Architect

“We validated HarfangLab’s performance in terms of detection and remediation; these two parameters tipped the balance in addition to sovereignty, which was a must-have.”

Defense Industry Cybersecurity Architect
Ministry Security Operations Analyst

HarfangLab meets our needs both in terms of performance and the sovereignty imperative. The platform can be deployed On-Premises with the same features as the cloud version. The detection rules are accessible and transparent, and the telemetry is rich.”

Ministry Security Operations Analyst
Startup Newspace MSSP Director

“Interoperability and sovereignty are essential criteria for us, in addition to high requirements for protection and detection. HarfangLab was an obvious choice.”

Startup Newspace MSSP Director
Université Paris Cité CISO

“In addition to fitting our budget framework, HarfangLab perfectly meets our needs in terms of performance, sovereignty, data protection, and availability. The solution also provides strong, close-knit support.”

Université Paris Cité CISO

Try out our platform in your workspace