The UK’s Next National Cloud Strategy Is Coming. Are You Ready?

by Sean Giles, Product Evangelist, Rackspace Technology UK

UK Skyline

A delayed cloud strategy launch creates an opportunity to prepare for the evolving role of digital sovereignty, resilience and cloud strategy across the UK public sector.

Over the last few months, I have been keeping tabs on every bit of news related to public and sovereign cloud. Naturally, I was glad to see that Government Digital Service (GDS) was preparing to release the National Cloud Strategy in July 2026.

However, that release has now been pushed to February 2027, meaning we will have to wait a little longer to see what is included in the updated strategy. But the delay doesn't make it any less important. In fact, it gives us more time to think about what the strategy should include and what organisations should be doing now to prepare.

What is the National Could Strategy?

The National Cloud Strategy is the natural successor to the UK government’s Cloud First policy, which was first introduced in 2013. Again, that is 2013, the year when Flappy Bird was the number one game, everyone was doing the Harlem Shake and the red wedding took the world by storm.

Since then, the Cloud First policy has been updated several times. Its main purpose is to ensure that government and public sector organisations consider and fully evaluate cloud solutions before choosing other options, rather than defaulting to on-premises infrastructure.

The focus of the policy was purely on public cloud and not private cloud. But to be fair, at the time of the policy release, private cloud technology technically existed, but it was new, untested and expensive, therefore it wasn't right for what the government was trying to achieve at the time.

The release of the Cloud First policy created a huge shift and many public sector organisations moved onto cloud services to host their systems and data, whether this was the right thing to do or not. The guidance said, thou shalt move to the public cloud, so everyone did. We have all learnt a lot since then and think we can agree that, with the benefit of hindsight, we would all do things very differently.

From what we know so far, the focus of the National Cloud Strategy is going to be on:

  • Cross-sector alignment
  • Economic growth
  • Digital resilience
  • Using cloud adoption as a catalyst for AI (naturally)

The brief history and limited focus of the Cloud First policy

When the policy was launched in 2013, the core purpose was to get government and public sector departments to consider and evaluate public cloud options before anything else. The reason for this was simple: they wanted departments to focus on delivering services, not IT infrastructure.

Then, in 2017, the policy was officially published as a core part of the government's Technology Code of Practice, before a formal review of the policy in 2019 concluded that the original guidance was a success and would remain in use, but no updates were made.

The first update

The first major updates to the policy came in 2023 when:

  • A focus on Software-as-a-Service (SaaS) was added
  • Rules around vendor lock-in were created
  • Any remaining on-premises hosting needed to move into Crown Hosting services
  • Guidance around global and overseas hosting was introduced (this is a big one).

That last point came with some additional criteria and was permitted if it delivered benefits such as better sustainability, lower cost or access to features not yet available in UK data centres.

What about the NCSC's cloud guidance?

It is important to note that there are key things to consider when hosting systems or data outside the UK. The GOV.UK “Cloud guide for the public sector” states, “There is no government policy which directly prevents departments or services from storing or processing cloud-based data in any specific country; however, you need to consider the implications of where you host your data.”

The GOV.UK guidance is followed by other sources to consider when deciding whether to use hosting services outside the UK. One of them is the NCSC Cloud Security Principles, published in 2018. The NCSC’s Cloud Security Principles include guidance that says when hosting data outside the UK, the following need to be taken into consideration:

  • The physical hardware must be protected from tampering, loss, damage
    or seizure.
  • You must be confident that no foreign legal jurisdiction can prevent you from meeting your security goals.
  • Any personnel with admin access to the infrastructure or data must be thoroughly vetted and verified as trustworthy.
  • The cloud provider's entire supply chain must adhere to the same strict security standards as they do.
  • Monitoring, auditing and incident response must be taken into consideration as these can be much more challenging when your data centre resides outside of
    the UK.

All of the above considerations are extremely important when it comes to the security and resilience of hosted systems and data.

The big issue here is that when you lose control of your data, you lose control of your operations. Understanding who has access, governing that access effectively and recovering quickly from cyber incidents are essential to maintaining resilience, security and trust.

The fact that these areas are not included in the GDS Cloud-First policy is quite alarming, although it does make sense based on the evolution of the market — even in the last few years.

What to expect from the National Cloud Strategy announcement

When the National Cloud Strategy is released in February 2027, I would expect to see items like the NCSC’s security guidance addressed and included as standard. I would also expect a larger focus on digital sovereignty, primarily for public sector organisations but also for organisations across the UK, including those in highly regulated industries.

What is true digital sovereignty?

True digital sovereignty still does not have a universal definition in the UK. There is no single owner or official document that sets out exactly what it is. Instead, it is being shaped by several government and defence organisations.

At Rackspace, we have used guidance from these organisations over the last five to 10 years to develop our own definition of digital sovereignty. This evolving definition has informed the design of the infrastructure and capabilities behind our UK Sovereign Cloud solution. (For a deeper dive into how we define digital sovereignty, watch my LinkedIn video explainer here.)

Built from the ground up, Rackspace UK Sovereign Cloud includes the core elements of digital sovereignty, including:

  • Operationally isolated environments
  • A team of UK-cleared personnel
  • Compliance-aligned governance
  • Managed sovereign delivery

The reason for the creation of Rackspace UK Sovereign Services in the first place was the clear and growing need for UK-based digital services to be fully managed and hosted within the UK. A global company with a UK region slapping “sovereign” on its solution does not make it truly sovereign overnight.

Ultimately, the new National Cloud Strategy cannot focus on economic growth and AI without also focusing on UK digital sovereignty and resilience. The server infrastructure that will help GDS and the UK achieve these goals must include elements of sovereignty and control to ensure the benefits last long term.

This is especially important in a world with increased geopolitical risk, tightening regulations, escalating cyberthreats and the resilience required for critical national infrastructure. (For a deeper dive, download our e-book, “Cloud and AI Control Digital Sovereignty.”)

What should government and public sector organisations do in preparation for February 2027?

While a six-month delay to the National Cloud Strategy might feel like a reason to put your feet up, the reality is exactly the opposite. February 2027 will be here before you know it and, for public sector bodies, NHS Trusts and highly regulated industries, this breathing space is a rare opportunity to strengthen your digital foundations.

The upcoming strategy is likely to move away from the decade-old Cloud First model toward a framework that treats cloud hosting as a core component of national risk. We can see the industry shifting beyond simple data location toward true legal control, technical independence and localised teams.

To ensure your infrastructure is secure for the long term and ready for the February 2027 announcement, here are four practical, proactive steps your organisation should take right now:

1. Audit for classification drift and map your data

Over the years, many organisations have experienced “classification drift.” This happens when sensitive records, valuable company secrets or private personal data get lumped into standard, everyday cloud storage without anyone noticing.

What to do about it:

Run a complete data audit. Map out your back-end systems to find exactly where your sensitive data and critical system logs are hiding.

Why it matters:

Finding these hidden files lets you isolate and lock down your most important data before automated compliance filters flag them as a major security or legal risk.

2. Check who actually handles your systems (behind the scenes)

True digital sovereignty is about much more than just where your servers are located. Many global cloud companies keep data inside the UK but still rely on support teams working across the world to look after it overnight.

What to do about it:

Check your cloud provider's contracts and ask two key questions:

  • Who can log into your systems in the middle of the night?
  • Is your provider a strictly UK-registered company, or can foreign courts force them to share your data?

Why it matters:

Using isolated systems managed only by UK-based, security-cleared staff helps protect your data from foreign laws and snooping.

3. Move from paper compliance to real technical proof

The era of just ticking boxes on a security form is officially over. UK security rules like GovAssure no longer care about promises on paper. They want hard, continuous proof that your systems are safe.

What to do about it:

Audit your cloud environment to make sure it automatically outputs real-time security logs and creates secure, tamper-proof UK backups.

Why it matters:

Setting up automated security tracking and live audit logs means your systems stay compliant, making official security reviews much less stressful.

4. Design for interoperability to avoid vendor lock-in

Interoperability sounds like a complicated word, but it just means making sure your systems can easily talk to each other.

We think the National Cloud Strategy is likely to reward flexible, hybrid architectures that build on open standards rather than proprietary, locked-down platforms.

What to do about it:

Find out where your systems are heavily tied to one provider or where you are charged huge exit fees just to move or share your own data.

Why it matters:

Building flexible systems keeps you in total control of your data. It gives you the freedom to adopt new tech, like secure, local AI, without your data escaping or getting trapped.

Prepare your strategy with Rackspace

Preparing for February 2027 does not mean waiting around. It means building a digital foundation that you control.

Built from the ground up inside secure, high-protection Crown Hosting datacentres, Rackspace UK Sovereign Services gives you digital sovereignty without slowing down your teams.

How we keep your platform secure:

  • 100% UK-based
    • Run exclusively by UK-resident, security-cleared engineers through an isolated management network
  • Built-in compliance
    • Designed from the ground up to meet strict NCSC 14 Cloud Security Principles and GovAssure standards automatically

Don't wait for the mandate to drop to find out your architecture is on the wrong side of the UK's digital boundaries.

 

Explore Rackspace UK Sovereign Services to see how UK-based operations, security-cleared teams and managed sovereign infrastructure can help you build a more secure, resilient digital foundation.

 

Tags: