Every government building a national identity or travel-document system says the word sovereign. It appears in the tender, the ministerial speech and the vendor's response. It is one of the most-used and least-tested words in the whole procurement.
Sovereignty is easy to assert and hard to hold, because it is not established by a clause. It is established by concrete facts about where cryptographic material lives, who can operate it, and what happens to the system if the supplier walks away. A contract can say the state is sovereign while practical control sits with a vendor on another continent. The gap between the two is only discovered at the worst possible moment.
Here is the test, stated plainly: can you keep issuing and verifying credentials if your supplier disappears tomorrow? If the honest answer is no, you do not have sovereignty. You have a dependency with good paperwork.
The keys that actually matter
"Where the keys live" is not one question. A national system has several kinds of cryptographic material, and they carry different consequences.
- The root and signing keys
- The Country Signing Certificate Authority and Document Signer keys for an ePassport programme, or the equivalent trust anchors for a national ID. These sign the credentials the rest of the world trusts. Lose control of them and you lose control of the document's meaning.
- The database encryption keys
- What protects the population's data at rest. Whoever holds these can, in principle, read the register.
- The authentication keys
- What lets relying parties verify a credential against the system. Control here shapes who can build on the identity, and on what terms.
A discussion of sovereignty that does not distinguish these is not a discussion. Each has a different custodian question, and "the vendor manages it" is a different answer for each.
Custody is physical before it is legal
Signing keys of this importance live inside a Hardware Security Module — a tamper-resistant appliance that performs cryptographic operations without ever exposing the private key in the clear. The HSM is where sovereignty becomes physical, and the questions are correspondingly physical.
- Where is the HSM? In a facility the state controls, in the vendor's data centre, or quietly in a cloud region governed by another country's law?
- Who holds the activation material? HSMs are brought into service through a key ceremony that splits custody across several trusted officers. If all of those custodians work for the supplier, the ceremony was theatre.
- Who can invoke a signature? Physical possession is not operational control. If issuing a signature requires a service the vendor hosts, the vendor is in the signing path whatever the asset register says.
Sovereignty is not who owns the HSM. It is who can turn the key in the room, and who they answer to.
The lock-in nobody remembers signing
Most loss of sovereignty is not seized. It is accreted, one convenient default at a time.
- Proprietary template and data formats that only the original vendor's software can read, so migration means re-enrolling the population — which is to say it will never happen.
- Hosted signing or verification that seems efficient until you realise the state cannot issue a passport during a contract dispute.
- Biometric algorithms with no image retention, so when the algorithm reaches end-of-life the templates expire with it and there is nothing to migrate — a permanent lock-in nobody noticed at signing.
None of these appear as a sovereignty clause. All of them are sovereignty decisions.
Clauses that actually protect a state
Contract language cannot manufacture control the architecture does not permit, but the right clauses lock in the control the architecture does allow. The ones that earn their place:
- Key handover and custody — the state holds the activation material, ceremonies are witnessed and documented, and there is a defined procedure to operate without the vendor present.
- Source and build escrow — the state can rebuild and run the system from escrowed source if the supplier fails, with the escrow tested, not merely deposited.
- Open, documented data formats — the register and its biometric records are exportable in a form a successor can ingest, with image retention where templates are algorithm-bound.
- A real exit and transition plan — priced, scheduled and rehearsed at least once, not written as an annex nobody expects to use.
- Data residency and no phone-home — the system does not depend on, or quietly report to, infrastructure outside the state's jurisdiction.
Settle it before procurement, not during
The sovereignty question is cheapest to answer before a supplier is chosen, because it constrains the architecture rather than fighting it. Settled during procurement, it becomes a negotiation the state usually loses, because the leverage has already moved. Settled after go-live, it is not settled at all — it is inherited by whoever holds office when the dependency finally matters.
The useful first conversation is not about the platform. It is about the keys: where they will physically sit, who will hold the custody material, and whether the state could operate the system next week if the vendor stopped answering the phone. If a supplier finds that conversation uncomfortable, that is itself the answer.
