Summary
- TESTA-EIRIS is designed as a three-layer public network in which DG DIGIT integrates the system while Orange Business supplies the Layer 2/Layer 3 backbone.
- The sovereignty claim will be earned through tested migration, continuity, security response and replaceability. The published 99.999% availability figure is an Orange target, not an independently verified end-to-end result.
A supplier selection is the start of the test
Orange Business announced on 29 September that it had been selected as the trusted network partner for TESTA-EIRIS, a private communications backbone for EU institutions and national public administrations. Orange says it will provide the Layer 2 and Layer 3 backbone. That is a material operating role, but it does not by itself show who controls the whole service or whether the system can change suppliers.
The European Commission’s Interoperable Europe Portal describes a wider design. DG DIGIT is the integrator responsible for design, procurement, implementation, operations, monitoring, maintenance, security and compliance. The blueprint divides the network into a telecom connectivity underlay, a services overlay with virtual circuits and encryption in transit, and a security service for monitoring, incident detection and response. Orange’s backbone contract and DG DIGIT’s integration role therefore describe different layers of the same system.
They are not contradictory; the boundary between them is where accountability has to be made testable.
The Commission’s stated goals include continuity for existing TESTA users, an EU-hosted control plane and alternatives for critical functions to limit single-vendor lock-in. Those are useful design commitments. They are not yet evidence that an administration has migrated successfully, that a replacement supplier has been exercised, or that control can be retained during a serious incident.
The network carries public services, not just packets
The transition matters because TESTA is already part of public-sector operations. A July 2026 article on the Interoperable Europe Portal says Eurodac, the EU asylum and migration information system, has long relied on TESTA to exchange sensitive biometric and personal data between Member States and eu-LISA. The article says the new Eurodac system went live in June and names TESTA-EIRIS as the successor under design. It does not say Eurodac has already moved to the successor network.
This distinction matters. A successful procurement is not adoption. The Commission expected migration of current TESTA users to start in the second half of 2026; that schedule is a forecast, not a migration receipt. Each administration and critical application still needs a demonstrated path from old connectivity to the new service, with the same legal authority, access controls and operational contacts continuing through the change.
Five nines need a boundary
Orange says the design will connect at least 12 points of presence across five European regions and target 99.999% availability. The company also describes network and security operating centres, cloud connectivity and VPNs. These are the supplier’s announced scope and performance target; the public materials reviewed here do not provide an independent measurement, service-level definition or a post-migration result.
As arithmetic, 99.999% of a 365-day year leaves about 5.3 minutes outside availability if the figure is measured end to end over that whole year with no exclusions. The announcement does not specify that measurement boundary. A backbone can meet a component target while an institution’s local circuit, overlay, identity service or application is unavailable. Nor does a high uptime percentage show that failover works, that the security team can isolate a compromised segment, or that another supplier can take over.
The evidence that would turn a design into an operating claim
The Commission’s design contains a productive tension: it seeks a single trusted pan-European connectivity service while also limiting dependence on one vendor. A unified service can simplify connection for administrations; a layered supply model can preserve options underneath. The public record does not yet identify which critical functions have qualified alternatives, how quickly they can be activated, or who owns the end-to-end outcome when a boundary fails.
Before the sovereignty claim is treated as an operating fact, readers should be able to see four kinds of evidence: the number and identity of users actually migrated; tested failover across distinct failure domains; published definitions and independent results for availability and incident response; and a supplier-exit exercise showing that a critical function can be replaced without rebuilding every connected service. A control plane hosted in the EU is relevant, but hosting location alone does not establish who holds credentials, approves changes, receives logs or can revoke a supplier’s access.
That is the practical meaning of sovereignty for a shared government network. It is not a label attached to a European vendor or a map of points of presence. It is the continuing ability of the public operator to direct, inspect, repair and replace the service while the administrations that rely on it keep working.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
