For most of the last decade, enterprise procurement has run on autopilot. A requirement comes up, a shortlist forms, and one of a handful of familiar names, often Microsoft, usually wins by default. Familiarity and perceived low risk have done a lot of the deciding.
That’s starting to change. In a recent piece for IT Europa, Zimbra CRO Anthony Chadd pointed to a real shift underway: procurement teams are asking harder questions about flexibility, data residency, and long-term control, not just cost and functionality. France’s move to reduce reliance on proprietary desktop software and Schleswig-Holstein’s push toward digital independence are two visible public-sector signals. Wire’s State of Digital Sovereignty 2025 report backs this up with numbers: 63.2% of respondents now consider open-source software critical to their sovereignty strategy, 47.4% see reducing dependency on US technology vendors as a strategic imperative, and 36.8% now treat EU data hosting as a real procurement factor.
Why email is the flashpoint
Email is usually the last thing anyone questions. It’s treated as a utility, not a decision. That’s exactly why it’s become such a clear test case for this shift. The questions procurement teams are now asking, where does our data actually sit, does our hosting align with sovereignty requirements we’re on the hook for, are we locked into one vendor’s ecosystem by default, didn’t used to come up in an email RFP. Now they do.
For organizations in the EU, this isn’t an abstract compliance exercise. The US CLOUD Act allows US jurisdiction to reach data stored by US-headquartered providers regardless of where that data physically sits. That’s a real gap for any organization relying on Microsoft 365’s EU data-residency options as a sovereignty answer. Data residency and data sovereignty are not the same thing, and the difference matters most in exactly the systems, like email, that everyone assumed were settled.
A live example, not a hypothetical
SITIV, the French public IT services operator, is a case in point. Rather than defaulting to Microsoft, SITIV reassessed its messaging platform against sovereignty and governance requirements for a user base north of 30,000 across the public sector. The result: full control over data jurisdiction, resilience at scale, and lower licensing and maintenance costs as a byproduct, not the starting point.
Where this leaves procurement teams
Nobody’s arguing for a return to fragmented, best-of-breed chaos. What’s changing is the assumption that one integrated ecosystem should own every workload by default. The organizations getting this right are the ones preserving choice deliberately, on jurisdiction, on deployment model, on which vendor sits behind a system as foundational as email, rather than inheriting that choice from whichever platform won everything else.
That’s the case for evaluating deployment flexibility, data sovereignty, and privacy as procurement criteria in their own right, not nice-to-haves bundled into a bigger platform decision.
Source: Anthony Chadd, “Are customers more willing to challenge ‘Microsoft by default’ procurement?”, IT Europa, July 2026.

No comments yet.