Sovereign Cloud Compass
The independent provider comparison
Independent · Evidence-based · Freely available

Every provider calls itself sovereign. Who can prove it?

The Sovereign Cloud Compass measures 17 European cloud offerings against 43 criteria across six sovereignty axes. Scores rest exclusively on publicly retrievable sources; every score of 4 or higher is individually evidenced. No sponsorships, no paid placements, no overall winner.

17Providers
43Criteria
6Axes
8EU CSF goals
443Sources
Which of your sovereignty claims can I verify today, without an NDA, without a customer portal, at a public URL?”

That single question decides every assessment in the Compass. An attestation that is only visible after signing in to a customer portal does not count as evidence. Hyperscalers and EU-native providers are held to the same standard.

It sounds strict, and it is. But it is the only standard that can be checked from the outside, and that is exactly what a comparison owned by nobody should deliver.

As of 3 October 2026 · SPOT rev23

All 17 providers, at a glance.

Sorted by EU sovereignty score. The Gates column shows how many of the twelve minimum criteria a provider meets. All axis values on the 0 to 5 scale.

ProviderEU scoreGatesDataOpsLegalCryptoTransp.Portab.
1T Cloud PublicCloud Suite69.712/124.02.94.33.52.63.5
2STACKITEU SEAL 3Cloud Suite65.611/123.43.44.13.12.63.3
3OVHcloud Public Cloud (inkl. SecNumCloud)EU SEAL 3IaaS+64.911/123.23.13.82.82.23.5
4SysEleven OpenStack CloudIaaS+63.711/122.92.84.32.52.83.2
5Cloud Temple Trusted CloudCloud Suite63.611/124.33.04.13.12.73.2
6noris Sovereign CloudIaaS+63.211/123.73.04.32.22.03.1
7AWS European Sovereign CloudCloud Suite62.89/123.93.12.13.32.34.4
8ScalewayEU SEAL 3Cloud Suite61.58/123.22.44.12.31.43.7
9IONOS CloudIaaS+59.18/123.22.33.81.82.33.8
10Delos CloudFull Stack58.58/123.72.74.02.81.42.8
11Infomaniak Public CloudIaaS+57.48/123.32.73.52.01.13.3
12Oracle EU Sovereign CloudCloud Suite55.79/123.83.22.12.81.63.3
13Hetzner CloudIaaS53.98/122.42.14.11.82.12.3
14UpCloudIaaS52.09/122.42.34.11.51.12.8
15pluscloud openIaaS+51.110/123.42.92.72.22.13.3
16ExoscaleIaaS+49.88/123.22.12.92.11.93.3
17Microsoft Sovereign CloudFull Stack46.56/123.22.00.92.82.54.1

EU score 0 to 100 per the EU Cloud Sovereignty Framework v1.2.1, with N/A counted conservatively as 0. “EU SEAL 3” marks an official award from the European Commission’s Cloud III procurement, not the Compass approximation. Values are lower than in the May 2026 report because the criteria catalogue has since grown from 31 to 43 criteria, mainly in cryptography and supply chain.

The market’s core problem

Sovereignty washing runs in both directions.

The systematic over-emphasis of a single sovereignty aspect while neglecting other, equally relevant dimensions. Neither variant is confined to one side of the Atlantic.

Variant A US hyperscalers

The GmbH facade.

EU subsidiaries and EU citizens on advisory boards paper over the legal access problem. The technical guardrails are in parts more robust than those of some European competitors. The legal construction changes nothing about extraterritorial reach.

ProviderOwnershipFISA 702Operator access
AWS European Sovereign Cloud114
Oracle EU Sovereign Cloud114
Microsoft Sovereign Cloud013

Five-point scale. The asymmetry between legal and technical protection makes the construction visible.

Variant B EU-native providers

The EU flag as a shield.

EU ownership is placed front and centre as the differentiator. The argument is not wrong, but it is incomplete: for these providers the gap between legal and technical protection is five steps on the five-point scale, and it usually goes unmentioned in marketing.

ProviderOwnershipFISA 702Operator access
Hetzner Cloud550
Scaleway550
Infomaniak Public Cloud450

Five-point scale. The EU flag is no substitute for hardware-backed workload isolation.

Both variants run the same mechanism: an easily measured and well marketed aspect is declared synonymous with sovereignty while other axes stay off the radar. Only the direction of the concealment differs. The largest systemic gap is not with individual providers: 14 of 17 have no documented independent advisory board, and not a single one scores above 3 out of 5 on the hardware supply chain.

Methodology

What is measured, and what is not.

Six sovereignty axes, 43 criteria, fully mapped to the eight goals of the EU Cloud Sovereignty Framework. The Compass assesses the sovereignty properties of individual offerings, not the sovereignty of an IT strategy.

The six axes

Data residencyProcessing in the EU and EEA
Operational sovereigntyOperated by EU actors
Legal & jurisdictionOwnership, FISA 702, EU law
CryptographyKey control, operator exclusion
TransparencyAudit reports, continuous verification
PortabilityOpen standards, no lock-in

Five principles

  • Evidence-based. At least one publicly retrievable source per assessment. Portal access or an NDA does not count.
  • Conservative. Missing evidence is treated as risk; N/A counts as 0 in the EU score.
  • Consistent. All providers, the same criteria, the same standard for hyperscalers and EU-native providers.
  • Transparent. Weightings disclosed and adjustable in the tool, every change traceable in the changelog.
  • Vendor-neutral. Self-funded, freely available, no paid placements and no recommendations.

Methodology in detail

Talks and publications

The methodology is discussed in public.

At conferences, on panels alongside assessed providers, and with specialist editorial teams. Anyone who publishes a comparison should be able to defend it.

All talks and publications

  • IT Summit by heise24 and 25 November 2026 · Munich
  • EuroCloud Summit8 October 2026 · Cologne
  • SITS Sovereign Summit7 October 2026 · Cologne
  • CCX Cloud Computing Conference30 September 2026 · Heidelberg
  • c.m.x channel meets x15 April 2026 · Munich
Behind the Compass

Who is accountable here.

Jörn Petereit is Managing Partner at IT Capital Partners GmbH in Hamburg, previously COO at Cloudflight and Global VP IoT at Deutsche Bahn. The Sovereign Cloud Compass grew out of a practical question: if every provider claims to be “sovereign”, what does a CIO actually decide on?

The Compass is self-funded and freely available. The data is maintained continuously and every change is traceable in the changelog with source and date. Providers can submit corrections; these are checked against public evidence before any value changes.

Disclosure

Through IT Capital Partners GmbH, Jörn Petereit holds a stake in tecRacer, an AWS partner. AWS European Sovereign Cloud is one of the 17 assessed providers.

AWS is therefore held to the same standard as everyone else, and that standard can be checked: AWS meets 9 of the 12 minimum criteria and remains capped at 1 out of 5 on ownership structure and FISA 702.

There are no payments, sponsorships, advertising or commission relationships with assessed providers.

Sovereignty is not a standard product, it is a decision.

Adjust the weighting, set minimum requirements as dealbreakers, see the result for your own use case. No registration.