Digital sovereignty for OT security, in practice
Most sovereignty discussions are about jurisdiction. For the team running a plant, the question is more concrete: where does the enforcement run, where does the evidence live, and who else can reach your network.
Last updated:
For an OT operator, digital sovereignty comes down to four questions with checkable answers: where the enforcement decision is made, where the audit evidence is stored, what your security vendor can reach inside your network, and whether the system keeps working if that vendor goes away. A deployment that answers all four on-premise is sovereign in the sense that matters operationally, regardless of which flag is on the box.
Sovereignty is usually argued at the wrong altitude
What to ask about any OT security deployment
Where is the enforcement decision made?
When a user or a device asks to reach a controller, something decides yes or no. If that decision requires a round trip to a vendor's cloud, then your plant floor depends on their availability and their network path. If it is computed on a box in your building, it does not.
Where does the audit evidence live?
Session records, access logs and change history are the artefacts you hand a regulator. If they are stored in a vendor tenant, you are asking a third party to hold your compliance evidence, and your retention is their retention policy. If they are on-premise, the question does not arise.
What can the vendor reach?
Many OT security products maintain a management channel into the environment they protect. That channel is a legitimate design choice and also a real attack path, as the last several supply-chain incidents have shown. Ask what it can reach, who can use it, and whether you can watch or sever it.
What happens if the vendor disappears?
Acquisition, price change, end of life, or an outage. If the answer is that access control stops working, the dependency is not a commercial risk, it is an operational one. A system that keeps enforcing its last known policy without a call home is a different class of thing.
Residency is not the same as encryption
What NIS2 and the member states actually require
See also NIS2 compliance for industry and OT and the secure OT remote access guide, which covers the Article 21(2)(d) supply-chain obligation in detail.
What an on-premise enforcement layer changes
For the mechanism itself, see what is an industrial proxy and agentless Zero Trust for OT.
What on-premise does not solve
Access Gate secures your assets first, then exposes the simple services your teams and vendors actually want, so they run through the sanctioned path, not around it.
OT runs through you, not around you.
Frequently asked questions
Practically, it means you can answer four questions about your own deployment: where the enforcement decision is computed, where the audit evidence is stored, what the vendor can reach inside your network, and whether the system keeps working without them. A deployment that answers all four locally is sovereign in the operational sense.
No. NIS2 does not impose a residency requirement. It makes the operator accountable for supply-chain security under Article 21(2)(d) and for demonstrating the effectiveness of its measures under 21(2)(f), which in practice means being able to show control over the security stack itself. Several member states apply stricter rules in sector-specific regulation and in public procurement.
No, and treating it that way is a mistake. A neglected on-premise appliance is worse than a well-operated cloud service. On-premise changes which risks you own rather than removing risk: you take on patching, backup and failover, and you remove dependency on a third party's availability, retention and jurisdiction.
More than process values. Typically the asset inventory, the network map, the access matrix showing who can reach which controller, and recordings of engineering sessions. Collectively that describes how to attack the plant, which is why where it is stored is worth asking about.
Access does not depend on it. The policy decision is computed on the appliance and the audit trail is written locally, so sessions continue to be brokered and recorded whether or not the appliance can reach us. Software updates are a separate, operator-initiated path.
No. The four questions are architectural, not jurisdictional, and a US utility has the same interest in its audit trail staying on site and its access control surviving a vendor outage. European regulation is what has made the questions explicit, but the answers matter everywhere.