EU Sovereignty Score

Independent · evidence-based · free

How sovereign is your software stack?

Assess your dependencies and find European alternatives, each scored on transparent, traceable evidence.

6,800+ vendors in 96 categories, each one scored and checked by us. Try the demo · How we verify

Example resultDemo stack
49 / 1000 = high exposure
100 = sovereign
Jurisdiction31
Data residency67
Key management49
Lock-in54
Source code42

17 vendors · 8 categoriesOpen this demo assessment →

What you get in three minutes

01

A score from 0 to 100

Broken down into jurisdiction, data residency, key management, lock-in and source code.

02

A heatmap per category

Shows where your dependencies are concentrated.

03

Risks and alternatives

Your main risk factors, with European alternatives for each vendor.

The tool stays free. The report is for the boardroom.

You pay only to keep, forward or rebrand a report. No account, no subscription.

Free assessment

€0
  • Total score and a score per dimension
  • Heatmap per category
  • Your main risk factors
  • Two European alternatives per vendor
Assess your stack →

Report

€39 incl. VAT
  • Everything in the free assessment
  • Discussion questions for the board per dimension, most exposed first
  • Migration path in three phases: now, soon, later
  • Printable, to keep and forward

Advising clients? A whitelabel report without our branding is €99. Business licence and API from €499 per year.

How our data is built

A score, not a list

Every vendor is rated on five dimensions with a published model.

Evidence labels on every fact

Vendor-statedConfirmed in registryTechnically measured

Ownership to the top

We follow ownership chains to ultimate control, not just the head office.

Checked and dated

Every record carries a review date, and ownership changes are reviewed monthly by a human.

Sources you can follow

5,957 of 6,877 records link to the public sources behind them, so you can check a fact yourself.

Open to correction

Every vendor page has a correction link, and changes are listed in a public changelog.

Independent by design

No paid listings or positions, no paid badges, no affiliate links. A listing or a score cannot be bought.

Funded by donations, report sales and a small number of self-sold sponsor banners without tracking. Sponsorship never affects a score or a position.

Support this project →

Explore scored alternatives

Browse 715 curated lists of alternatives to widely used software.

vendors scored
6,877
categories
96
countries
74
alternative links
13,078

Why this matters now

NIS2

Requires you to manage supply chain risk, starting with knowing your software stack.

DORA

Requires financial institutions to know their ICT third-party and concentration risk.

CLOUD Act · FISA 702

US vendors can be compelled to hand over data, even from a European data centre.

GDPR · Data Act

Transfers outside the EU need a legal basis, and switching cloud services is regulated.

Cyber Resilience Act

Sets security requirements for software and connected products, so it matters which vendors can meet them.

AI Act

Puts obligations on organisations that deploy AI systems, starting with knowing which AI vendors you rely on.

Is your product missing?

Submit it for review. Every submission is checked by hand before it appears.

Submit a vendor →