ESG’s contribution to resilience and sovereignty issues
AdVaes spoke about the ESG’s contribution to the challenges of resilience and sovereignty at the start of EuroCloud’s Summer Party, during the session dedicated to market analysis.
During this key session dedicated to market analysis, held at the start of the EuroCloud Summer Party, AdVaes highlighted the contribution of ESG to the challenges of resilience and sovereignty. In particular, it emphasised that dual materiality analysis is a key tool for integrating sovereignty issues (economic, technological, energy, food security, etc.) into organisations’ strategies. It achieves this by drawing on its two dimensions: the organisation’s impact on society and the environment (‘outside-in’ materiality) and the impact of ESG issues on the organisation’s performance (‘inside-out’ materiality).
Double materiality analysis is a requirement under the CSRD (Corporate Sustainability Reporting Directive).
How dual materiality analysis contributes to resilience and sovereignty
1. Identifying dependencies critical to sovereignty
Dual materiality analysis enables the mapping of strategic dependencies (raw materials, technologies, skills, infrastructure) that could threaten the sovereignty, resilience and sustainability of organisations.
The example of energy in the digital sector is particularly telling at present, given the implications of AI usage: a tech company has identified its dependence on imported rare earths. ‘Inside-out’ materiality reveals a risk of supply disruption, whilst ‘outside-in’ materiality highlights the environmental and geopolitical impact of this dependence. This context may encourage investment in local supply chains or technological alternatives, thereby strengthening industrial sovereignty.
The company OVHcloud clearly identified this in its 2024 non-financial report. The acquisition of Qarnot by Scaleway is also part of this trend.

2. Anticipating geopolitical and regulatory risks
Dual materiality takes into account external risks (sanctions, trade tensions, regulations) that affect organisations’ resilience.
Still in the tech sector, and even though data centre operators are not directly affected, an analysis of the impact of the EU’s battery regulation (Regulation 2023/1542) may reveal a risk of non-compliance (‘inside-out’ materiality) and a need to assess the impact on the energy transition (‘outside-in’ materiality). This situation may force them to adapt their value chain to ensure compliance and secure access to strategic resources.
3. Strengthening the resilience of local ecosystems
By cross-referencing the two materialities, organisations can prioritise investments that strengthen both their performance and collective sovereignty.
In the tech sector, an AI infrastructure provider identifies its heavy reliance on certain imported electronic components (“inside-out” risk) and the impact of the associated non-recycled waste on local biodiversity (“outside-in” impact). It could support local alternatives to reduce this reliance and preserve ecosystems.
4. Alignment with public policies on sovereignty
Governments and institutions use dual materiality to direct public funding (grants, calls for proposals) towards critical sectors. France’s national strategy on critical metals (2023) draws on dual materiality analyses to target investments in recycling or responsible mining exploration. Companies can align their ESG strategy with these priorities to benefit from public support.
5. Creating shared value
Dual materiality promotes circular and sovereign economic models. A semiconductor company analyses the impact of its water consumption (‘outside-in’ materiality) and the associated risk of scarcity (‘inside-out’ materiality). It invests in water recycling technologies, reducing its dependence on resources and its environmental footprint.
Examples of how tech companies are using dual materiality analysis
1. Bleu
- ‘Inside-out’ materiality: reducing dependence on US cloud services (risk of vendor lock-in, migration costs, regulatory compliance) and securing the sensitive data of operators of vital importance (OVIs).
- “Outside-in” materiality: contributing to European digital resilience by offering a sovereign, SecNumCloud-certified alternative and by limiting the carbon footprint associated with storing data abroad.
2. S3NS
- “Inside-out” materiality: enabling French businesses and public authorities to store and process sensitive data in compliance with local regulations, without relying exclusively on foreign solutions.
- “Outside-in” materiality: reducing the geopolitical impact of dependence on GAFAM and supporting European technological autonomy.
3. Mistral AI
- “Inside-out” materiality: avoiding dependence on American or Chinese AI models, thereby reducing the risks of data leaks and loss of technological control.
- “Outside-in” materiality: contributing to the European digital transition by offering sovereign alternatives aligned with local values and regulations (GDPR, DSA, etc.).
4. Atos
- “Inside-out” materiality: data localisation and dependence on foreign cloud infrastructure. Some of its clients (public administrations, healthcare, energy) stored their data on servers located outside the EU, posing a risk of sensitive data leaks and non-compliance with the GDPR. The use of foreign data centres also increased the carbon footprint associated with data transport and processing. Action: a gradual migration to sovereign data centres (with SecNumCloud certification in France) for public sector clients and strategic sectors, and investment in hybrid cloud solutions to ensure data is localised in Europe.
- ‘Outside-in’ materiality: regulatory and geopolitical risks linked to dependence on non-sovereign clouds, and sanctions or restrictions on access to public procurement markets in the event of non-compliance with sovereignty requirements (e.g. the French ‘Trusted Cloud’ Act, European directives). Operational risk arising from vendor lock-in (dependence on a single supplier) and high migration costs in the event of regulatory changes. Reputational risk arising from a loss of customer trust (particularly among public authorities and OIVs) in the event of non-compliance with sovereignty standards. Action: developing partnerships with European players (e.g. Bleu, S3NS) to offer sovereign cloud solutions; incorporating reversibility clauses into contracts to limit vendor lock-in; training teams on digital sovereignty issues and SecNumCloud.
“Our dual materiality analysis revealed that digital sovereignty is a key issue for Atos, both in terms of its impact on our clients’ resilience (impact materiality) and the sustainability of our business model (financial materiality). In 2025, we therefore accelerated the migration of 40 per cent of our cloud infrastructure to sovereign data centres, thereby reducing our exposure to geopolitical risks and strengthening our alignment with the expectations of our stakeholders (clients, regulators and investors).”
Atos follows the ESRS standards (notably ESRS E4 on biodiversity and resources, and ESRS G1 on governance), which require societal impacts to be linked to financial performance. Dual materiality enables investments to be prioritised according to their impact on both society and the business.
5. OVHcloud
- “Inside-out” materiality: data localisation — OVHcloud has assessed that 90 per cent of its data centres are located in Europe (France, Germany, Poland, etc.), but that some customers (particularly SMEs) still use hybrid solutions involving non-European infrastructure. Direct contribution to reducing Europe’s dependence on GAFAM (Google, AWS, Microsoft), by offering a sovereign and certified alternative (SecNumCloud, HDS, ISO 27001). Reduction in the carbon footprint thanks to water-cooled data centres powered by renewable energy (with a target of 100 per cent low-carbon energy by 2030). Job creation in Europe (1,500 direct jobs in France) and support for the local tech ecosystem (partnerships with start-ups, training programmes, etc.). Actions: obtaining SecNumCloud certification for all its French data centres by 2025, guaranteeing a level of security and sovereignty compliant with ANSSI requirements + publication of a sovereignty index for each cloud offering, indicating the percentage of data stored in Europe and the level of compliance with local standards + development of sovereign solutions (OVHcloud Public Cloud Sovereign), with legal guarantees regarding data localisation and access by local authorities.
- “Outside-in” materiality: risk of penalties in the event of non-compliance with European regulations; obligation for operators of vital importance (OIVs) to use sovereign solutions, on pain of exclusion from public procurement contracts. Public authorities and sensitive sectors (health, energy, defence) now prioritise sovereign solutions. OVHcloud has estimated that a “lack of sovereignty” could cause it to lose 20 per cent of its turnover by 2027. Customers using non-sovereign solutions could face high costs when migrating to compliant infrastructure, which could impact customer retention. Dependence on proprietary technologies (e.g. Microsoft or AWS APIs) limits the flexibility and reversibility of solutions. Increased risk of cyberattacks targeting non-sovereign infrastructure. Actions: OVHcloud has anticipated the requirements of the CSRD by integrating digital sovereignty into its ESG strategy and resilience plan. Launch of sovereign cloud solutions with contracts including reversibility clauses and data localisation guarantees. Training campaigns for its customers on sovereignty issues and best practices (webinars, practical guides).
“Our double materiality analysis confirmed that digital sovereignty is a strategic issue for OVHcloud. By 2025, 80 per cent of our revenue will come from sovereign cloud solutions, compared with 60 per cent in 2023. This transition enables us to meet the expectations of our stakeholders (customers, regulators, investors) whilst reducing our exposure to geopolitical risks. For example, our SecNumCloud 3.2 certification enabled us to secure 15 new contracts with OIVs in 2025, representing an additional turnover of €50 million.”
How does the Environment (E) pillar support sovereignty?
The E (Environment) pillar of ESG acts as a catalyst for sovereignty for tech companies through three key mechanisms:
- Reducing energy dependencies: decreasing reliance on fossil fuels or imported energy, achieving energy self-sufficiency, and reducing geopolitical vulnerabilities (e.g. energy crises).
- Eco-design of infrastructure: designing data centres and cloud solutions that are resource-efficient (in terms of energy, water and rare earth elements), and reducing dependence on critical raw materials (rare earth elements, semiconductors).
- Limiting the local environmental footprint (data centres in Europe vs. the United States).
- Managing externalities: reducing legal (GDPR) and geopolitical risks.
→ Result: a company that manages its environmental footprint (E) strengthens its resilience and autonomy by reducing its dependence on foreign resources and securing its value chains.
1. Areas covered by the “E” link → Sovereignty
- Data centres: energy consumption, cooling, water. Data localisation, GDPR/SecNumCloud compliance.
- Supply chain: rare-earth mining, electricity for factories. Dependence on raw materials (China, Congo).
- Software development: carbon footprint of the code (energy-intensive AI). Control over algorithms and infrastructure.
- End-of-life equipment: server recycling, electronic waste. Control over strategic waste streams.
2. Example: measures taken by OVHcloud to link “E” and sovereignty
Energy: 100% renewable energy (PPAs with local producers in France and Germany) + self-generation through data centre projects powered by wind and solar farms in partnership with European players (e.g. TotalEnergies) + reduced dependence on imported fossil fuels (Russian gas).
- Cooling: water cooling, reducing energy consumption by 40% compared to conventional solutions + reuse of waste heat through the sale of residual heat to district heating networks (partnership with the city of Strasbourg). Local energy self-sufficiency and value creation for local areas.
- Location: all data centres in Europe (France, Germany, Poland), with SecNumCloud and HDS (Health Data Hosting) certifications. Compliance with European regulations (GDPR, Cloud Act) and data control.
→ Key message: the Environment (E) pillar is not merely an environmental constraint: it is a strategic lever for strengthening technological sovereignty. By focusing on eco-design, the localisation of infrastructure and circularity, tech companies are reducing their dependencies, securing their value chains and building resilience — whilst meeting the requirements of the CSRD and ESRS standards.
✅ If you’d like to access our support, discuss these issues further and receive our recommendations, please contact us!
If you enjoyed this analysis, please feel free to share it.
