Which of your sovereignty claims can I verify today, without an NDA, without a customer portal, at a public URL?”
That single question decides every assessment in the Compass. An attestation that is only visible after signing in to a customer portal does not count as evidence. Hyperscalers and EU-native providers are held to the same standard.
It sounds strict, and it is. But it is the only standard that can be checked from the outside, and that is exactly what a comparison owned by nobody should deliver.
All 17 providers, at a glance.
Sorted by EU sovereignty score. The Gates column shows how many of the twelve minimum criteria a provider meets. All axis values on the 0 to 5 scale.
| Provider | EU score | Gates | Data | Ops | Legal | Crypto | Transp. | Portab. | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | T Cloud PublicCloud Suite | 69.7 | 12/12 | 4.0 | 2.9 | 4.3 | 3.5 | 2.6 | 3.5 |
| 2 | STACKITEU SEAL 3Cloud Suite | 65.6 | 11/12 | 3.4 | 3.4 | 4.1 | 3.1 | 2.6 | 3.3 |
| 3 | OVHcloud Public Cloud (inkl. SecNumCloud)EU SEAL 3IaaS+ | 64.9 | 11/12 | 3.2 | 3.1 | 3.8 | 2.8 | 2.2 | 3.5 |
| 4 | SysEleven OpenStack CloudIaaS+ | 63.7 | 11/12 | 2.9 | 2.8 | 4.3 | 2.5 | 2.8 | 3.2 |
| 5 | Cloud Temple Trusted CloudCloud Suite | 63.6 | 11/12 | 4.3 | 3.0 | 4.1 | 3.1 | 2.7 | 3.2 |
| 6 | noris Sovereign CloudIaaS+ | 63.2 | 11/12 | 3.7 | 3.0 | 4.3 | 2.2 | 2.0 | 3.1 |
| 7 | AWS European Sovereign CloudCloud Suite | 62.8 | 9/12 | 3.9 | 3.1 | 2.1 | 3.3 | 2.3 | 4.4 |
| 8 | ScalewayEU SEAL 3Cloud Suite | 61.5 | 8/12 | 3.2 | 2.4 | 4.1 | 2.3 | 1.4 | 3.7 |
| 9 | IONOS CloudIaaS+ | 59.1 | 8/12 | 3.2 | 2.3 | 3.8 | 1.8 | 2.3 | 3.8 |
| 10 | Delos CloudFull Stack | 58.5 | 8/12 | 3.7 | 2.7 | 4.0 | 2.8 | 1.4 | 2.8 |
| 11 | Infomaniak Public CloudIaaS+ | 57.4 | 8/12 | 3.3 | 2.7 | 3.5 | 2.0 | 1.1 | 3.3 |
| 12 | Oracle EU Sovereign CloudCloud Suite | 55.7 | 9/12 | 3.8 | 3.2 | 2.1 | 2.8 | 1.6 | 3.3 |
| 13 | Hetzner CloudIaaS | 53.9 | 8/12 | 2.4 | 2.1 | 4.1 | 1.8 | 2.1 | 2.3 |
| 14 | UpCloudIaaS | 52.0 | 9/12 | 2.4 | 2.3 | 4.1 | 1.5 | 1.1 | 2.8 |
| 15 | pluscloud openIaaS+ | 51.1 | 10/12 | 3.4 | 2.9 | 2.7 | 2.2 | 2.1 | 3.3 |
| 16 | ExoscaleIaaS+ | 49.8 | 8/12 | 3.2 | 2.1 | 2.9 | 2.1 | 1.9 | 3.3 |
| 17 | Microsoft Sovereign CloudFull Stack | 46.5 | 6/12 | 3.2 | 2.0 | 0.9 | 2.8 | 2.5 | 4.1 |
EU score 0 to 100 per the EU Cloud Sovereignty Framework v1.2.1, with N/A counted conservatively as 0. “EU SEAL 3” marks an official award from the European Commission’s Cloud III procurement, not the Compass approximation. Values are lower than in the May 2026 report because the criteria catalogue has since grown from 31 to 43 criteria, mainly in cryptography and supply chain.
Sovereignty washing runs in both directions.
The systematic over-emphasis of a single sovereignty aspect while neglecting other, equally relevant dimensions. Neither variant is confined to one side of the Atlantic.
The GmbH facade.
EU subsidiaries and EU citizens on advisory boards paper over the legal access problem. The technical guardrails are in parts more robust than those of some European competitors. The legal construction changes nothing about extraterritorial reach.
| Provider | Ownership | FISA 702 | Operator access |
|---|---|---|---|
| AWS European Sovereign Cloud | 1 | 1 | 4 |
| Oracle EU Sovereign Cloud | 1 | 1 | 4 |
| Microsoft Sovereign Cloud | 0 | 1 | 3 |
Five-point scale. The asymmetry between legal and technical protection makes the construction visible.
The EU flag as a shield.
EU ownership is placed front and centre as the differentiator. The argument is not wrong, but it is incomplete: for these providers the gap between legal and technical protection is five steps on the five-point scale, and it usually goes unmentioned in marketing.
| Provider | Ownership | FISA 702 | Operator access |
|---|---|---|---|
| Hetzner Cloud | 5 | 5 | 0 |
| Scaleway | 5 | 5 | 0 |
| Infomaniak Public Cloud | 4 | 5 | 0 |
Five-point scale. The EU flag is no substitute for hardware-backed workload isolation.
Both variants run the same mechanism: an easily measured and well marketed aspect is declared synonymous with sovereignty while other axes stay off the radar. Only the direction of the concealment differs. The largest systemic gap is not with individual providers: 14 of 17 have no documented independent advisory board, and not a single one scores above 3 out of 5 on the hardware supply chain.
What is measured, and what is not.
Six sovereignty axes, 43 criteria, fully mapped to the eight goals of the EU Cloud Sovereignty Framework. The Compass assesses the sovereignty properties of individual offerings, not the sovereignty of an IT strategy.
The six axes
Five principles
- Evidence-based. At least one publicly retrievable source per assessment. Portal access or an NDA does not count.
- Conservative. Missing evidence is treated as risk; N/A counts as 0 in the EU score.
- Consistent. All providers, the same criteria, the same standard for hyperscalers and EU-native providers.
- Transparent. Weightings disclosed and adjustable in the tool, every change traceable in the changelog.
- Vendor-neutral. Self-funded, freely available, no paid placements and no recommendations.
The methodology is discussed in public.
At conferences, on panels alongside assessed providers, and with specialist editorial teams. Anyone who publishes a comparison should be able to defend it.
- IT Summit by heise24 and 25 November 2026 · Munich
- EuroCloud Summit8 October 2026 · Cologne
- SITS Sovereign Summit7 October 2026 · Cologne
- CCX Cloud Computing Conference30 September 2026 · Heidelberg
- c.m.x channel meets x15 April 2026 · Munich
Who is accountable here.
Jörn Petereit is Managing Partner at IT Capital Partners GmbH in Hamburg, previously COO at Cloudflight and Global VP IoT at Deutsche Bahn. The Sovereign Cloud Compass grew out of a practical question: if every provider claims to be “sovereign”, what does a CIO actually decide on?
The Compass is self-funded and freely available. The data is maintained continuously and every change is traceable in the changelog with source and date. Providers can submit corrections; these are checked against public evidence before any value changes.
Disclosure
Through IT Capital Partners GmbH, Jörn Petereit holds a stake in tecRacer, an AWS partner. AWS European Sovereign Cloud is one of the 17 assessed providers.
AWS is therefore held to the same standard as everyone else, and that standard can be checked: AWS meets 9 of the 12 minimum criteria and remains capped at 1 out of 5 on ownership structure and FISA 702.
There are no payments, sponsorships, advertising or commission relationships with assessed providers.
Sovereignty is not a standard product, it is a decision.
Adjust the weighting, set minimum requirements as dealbreakers, see the result for your own use case. No registration.