Digital Sovereignty Checklist
Twelve checks every Swiss company and public body should run before signing with a technology supplier. Free, as a PDF, no fluff.

Who it is for
For those responsible for systems and data that cannot stop: management, IT and security leads in companies, professional firms, healthcare facilities and public bodies. Whoever signs keeps the responsibility; the supplier keeps the contract. This checklist reverses that order.
What is inside
- 1
Where the data lives
- In which country are the data — and the backups — physically stored?
- Who holds the encryption keys?
- Has a restore from backup been tested, and when?
- 2
Who answers when it breaks
- At three in the morning, who do you call? A person or a ticket?
- Are SLAs written, measurable and backed by penalties?
- Who are the subcontractors, and are the certifications their own?
- 3
The dependencies you do not see
- Can you take everything away, in open formats, and at what cost?
- Which licences and which AI models does the service depend on?
- Who provides connectivity, and is there a single point of failure?
- 4
What happens the day after
- Is there a business continuity plan — and who has tested it?
- If the supplier shuts down or is acquired, what happens to your systems?
- Who owns what gets built?
How to use it
- 1.Keep it open during the meeting with your supplier and ask the questions exactly as written.
- 2.Mark each check green, amber or red. Amber is any answer that sounds like «we'll see», «it depends», «usually».
- 3.Count the reds. Three or more and the problem is not the supplier: nobody is accountable for the whole.
Access research, network and SIATI opportunities
Becoming a SIATI member means joining a network dedicated to applied research, technological innovation, advanced training and strategic collaborations. Access expertise, projects, events and opportunities to connect with companies, institutions and technology partners.

