Sovereign Cloud Compass
Changelog

Changelog

Version log and changes to the data and the WebApp.

Version log and changes to the dataset & web app.

Changelog entries are provided in German.

Letztes Update: 2026-10-03
rev23
2026-10-03
  • All evidence checked. For the first time, all 506 links in the dataset were checked automatically for availability; pages that block automated requests were checked in a browser. All evidence links that were no longer reachable have been replaced by current, publicly accessible sources or removed where the score has other live evidence; mostly restructured documentation at AWS, Cloud Temple, Exoscale, IONOS, OVHcloud, Oracle, Scaleway, STACKIT and UpCloud. For Cloud Temple, the ANSSI qualification decision of 30 May 2025 has been added as primary evidence. 53 redirected links now point to their current address, duplicate entries have been merged, and every piece of evidence refers to the matching entry in the source directory. All 48 scores of 4 or higher that previously had no individual evidence now have public sources, most of them at SysEleven (ten), Microsoft (nine) and noris (six); at SysEleven these are the freely downloadable certificates and the C5 audit opinion. Every score of 4 or higher now has at least one public source. The source directory has been cleaned up: 18 entries without relation to any score (background articles, duplicates, marketing, dead pages) were removed, 18 previously unused sources now support scores. It comprises 425 sources, 421 of them used as evidence and 4 framework and legal sources.
  • Scores aligned with the evidence. STACKIT energy efficiency from 4 to 3, because only PUE thresholds per site are published. Exoscale and IONOS secure-by-default each from 4 to 3: blocking inbound traffic by default is evidenced, standard blueprints or landing zones are not. Oracle carbon, water and renewables reporting from 3 to 4, because Scope 1 to 3 are reported with external assurance. Microsoft ISO 27001 and audit reports each from 5 to 4: certificates and reports are only available in the Service Trust Portal after signing in, and evidence behind a sign-in does not count as public for any provider. SysEleven metadata in the EU and limits/quotas each from 4 to 3: operation in German data centres and quota increases via support are publicly documented, but not the residency of logs and billing data or a self-service increase. noris metadata in the EU, ISO 27001 and IaC each from 4 to 3: ISO 27001 is listed at company level, a certificate with cloud scope is not published, and public information on metadata and IaC is missing. Cloud Temple BSI C5 from 0 to 4: a C5 attestation (Type 1, May 2025) is publicly stated, the report is available on request, as with IONOS. EU scores change by at most 1.2 points (STACKIT −0.3, IONOS and Exoscale −0.1 each, Oracle +0.5, Microsoft and SysEleven −0.5 each, noris −1.2, Cloud Temple +1.0). Places 4 to 7 of the ranking change: SysEleven (previously 5), Cloud Temple (previously 7), noris (previously 4), AWS European Sovereign Cloud (previously 6); all other places are unchanged.
  • Provider texts corrected. Cloud Temple: the mention of a Tunisian investor referred to a joint venture, not to the assessed company; Cloud Temple is a subsidiary of the French Neurones group, and its IaaS qualification was renewed in 2025. STACKIT: since 2026 the legal entity is Schwarz Digits Cloud GmbH & Co. KG, registered in Bad Friedrichshall. Oracle: information on energy efficiency, emissions and renewable energy is based on the current sustainability report. SysEleven: the ultimate parent is Giesecke+Devrient GmbH, Munich, which holds 75.12% of secunet.
  • Data maintenance and English version. Duplicate sources merged and all evidence linked to the source directory. Methodology, Compass, all 718 provider texts and the notes in the service catalogue are now fully available in English; this English changelog page now shows all entries in English. Saved configurations with earlier settings for handling unknown values are evaluated uniformly conservatively.
rev22 · Addendum
2026-10-02
  • Recalibration of AI processing location and operator access. Statelessness, ephemeral modes, tenant separation, dedicated capacity and organisational operating rules justify at most 3 out of 5. A 4 requires a technical exclusion of operator access that is evidenced for the inference path itself; confidential computing at infrastructure level alone is not sufficient. Seven scores from 4 to 3: STACKIT, pluscloud open, Exoscale, Scaleway, noris Sovereign Cloud, Cloud Temple and Infomaniak. The trigger was the comparison with the infrastructure criterion operator access exclusion, for which six of these seven providers document no confidential computing. The EU scores of the seven providers are 0.2 points lower each; the ranking is unchanged.
  • Source directory corrected. 36 source URLs moved to the new hosts of T Cloud Public, Oracle, STACKIT and OVHcloud, 29 source entries added for evidence URLs without title and description. All 443 sources are now bilingual.
  • Question catalogue completed. Validation questions added for 13 criteria that had none so far, including the three AI criteria, the supply chain and key sovereignty. The questions on KMS and HSM were previously attached to the EU root certificate authority; they now belong to the key sovereignty criterion, and the root certificate authority has its own questions on PKI. All 43 questions are now also available in English.
  • Source selection neutralised. For each criterion, the RFP kit showed the first four pieces of evidence of the overall list, which is sorted by provider; as a result, AWS evidence came first in most sections. Now one piece of evidence each from the providers ranked highest in your own configuration is shown, with provider names. A provider's detail window shows its own evidence first.
  • RFP kit revised. Result list with EU score, clickable configuration link, time in local time, printing without browser headers and footers, fixed N/A rule.
  • Start page ranking: provider names left-aligned, the EU score is visible on smartphones without swiping.
  • DORA checkpoints in the RFP kit. For the financial services use case, the kit now contains the contract contents under Art. 30 DORA, with reference and link to the Compass criteria; the wording of the regulation remains authoritative.
  • Next steps reordered. The RFP kit is the main action and can be used without registration. The results walkthrough states who conducts it and includes the disclosure on the publisher's investment.
  • English version: seven criterion names translated that were previously German.
  • English criterion pages: rationale and scoring scale are available in English for all 43 criteria. Previously, the pages showed the German texts at runtime, and for the twelve criteria from rev21 also in the static version.
  • Criterion pages without JavaScript updated. For 24 criteria, the version without JavaScript, which search engines also see, still showed scores from earlier revisions; the interactive view was not affected. Both versions now match.
rev22
2026-10-01
  • Sovereignty Watch CW 38 and CW 39 incorporated. Four scores changed: OVHcloud SecNumCloud from 5 to 3, because on 26.09.2026 ANSSI lists the SNC Cloud Platform as an ongoing procedure and not as a qualified solution. UpCloud ISO 27001 from 3 to 4 after submission of the complete certificate (Kiwa, no. 13851-03, valid until 20.10.2029). IONOS operator access exclusion from 1 to 2 after the launch of confidential VMs. AWS European Sovereign Cloud AI data residency from 3 to 4. Three score proposals from CW 38 were withdrawn.
  • New attribute catalogue version per C5 attestation, filled in for all 17 providers, plus the cut-off rule: C5:2020 applies until 27.02.2027, C5:2026 from 01.06.2027.
  • N/A rule unified. The choice between tolerant, conservative and strict no longer exists; missing information consistently counts as 0. This affects nine of 731 scores, all of them AI criteria for providers without an AI offering.
  • New start page with the ranking of all 17 providers. The configurator is now located at /compass/ and guides you through three instead of six steps: context, requirements, result. The result starts with a score display.
  • Navigation reduced to five destinations. New are /aktuelles/ with talks, publications and data releases and /quellen/ with all evidence. Decision guide, comparison page, Sovereign Cloud, C3A & SEAL and badge have been removed, each with a permanent redirect.
  • 16 sources and 8 evidence URLs added, host changes at T Cloud Public and Oracle, replacement evidence for STACKIT and OVHcloud. Source count now 443.
rev21
2026-06-05
  • 12 new criteria added, from 31 to 43, in four areas: cryptography and key sovereignty (BYOK/HYOK, EU HSM/KMS, crypto agility), supply chain (hardware and chip origin, open-source share and patch sovereignty, severability of all non-EU network connections), AI sovereignty (data residency, model provenance and openness, processing location and operator access) and trust labels and certifications (Gaia-X Trust Label, EU Cloud Code of Conduct, BSI C3A audit status, Climate Neutral Data Centre Pact).
  • All twelve new criteria assessed on an evidence and register basis, backed by public sources.
  • C3A domain mapping: crosswalk of the eight CSF objectives to the BSI C3A domains, plus a conservative C3A readiness per provider.
  • Official EU SEAL (EC award Cloud III, 2026-04-17) shown as calibrating evidence alongside the conservative SCC EU SEAL. STACKIT, Scaleway and OVHcloud reach SEAL-3 for the tendered service or consortium, not automatically for the entire public offering.
  • Legal: Data Act, Chapter VII (switching and severability) factored into the non-EU severability assessment.
  • New web app areas: C3A and SEAL, Badge (embeddable provider badge) and a Decision guide (priority shortlist and scenarios).
rev20
2026-02-22 / 2026-03-13
  • 2 new providers: Cloud Temple Trusted Cloud (Cloud Suite, SecNumCloud-qualified, FR) and Infomaniak Public Cloud (IaaS+, OpenStack-based, CH) – full assessment across all 31 criteria + service coverage.
  • Provider count increases from 15 to 17.
  • Data update (2026-03-13): AWS ESC – compliance_bsi_c5 2→4 (C5 Type 1, basic & additional criteria, 69 services), compliance_iso_27001_isms 3→4 (7 ISO certifications ESC-specific), audit_evidence 4→5 (SOC 2 + C5 + 7 ISO via AWS Artifact). Source: AWS Security Blog 2026-03-10.
  • Data update (2026-03-13): STACKIT – compliance_bsi_c5 3→5 (C5 Type 2 confirmed, IaaS stack, all basic/additional criteria). Source: Schwarz Digits press release, STACKIT certificates page.
  • 3 new sources + 5 new evidence URLs added.
rev19
2026-02-22
  • 100% coverage reached for all 15 providers: 68 N/A values replaced by well-founded scores based on official sources.
  • Delos Cloud (65% → 100%, 11 criteria resolved): ISO 27001:2022 confirmed (trust.delos.so) → score 4; D‑Trust (Bundesdruckerei) supplies TLS certificates, an eIDAS-qualified EU trust service provider → score 4 for EU root CA; BSI audit procedure active (C5, IT‑Grundschutz) → score 1 (planned); sovereign boundary + BSI-controlled telemetry → guardrails/default deny score 3.
  • STACKIT (81% → 100%): Confidential Server + Confidential Kubernetes GA (AMD SEV, Intel SGX, Edgeless Constellation) → score 4 for operator access exclusion; Schwarz Group: no non-EU dependencies → score 4.
  • OVHcloud Public Cloud (incl. SecNumCloud) (81% → 100%): Intel SGX/AMD SEV on bare metal + SECURITEE partnership → CC score 3; SecNumCloud + C5 create transparency → black-box score 3.
  • All providers: advisory board consistently score 0 (no board documented), EU root CA mostly score 1 (details unclear), black-box exposure score 2 to 3 depending on certification level.
  • 19 new sources and 21 new evidence URLs added to the corresponding sheets.
  • i18n SPOT: new German columns in 03_Criteria (criterion_de, why_de), 04_Axes (label_de), 13_CSF_Objectives (label_de, description_de), 14_CSF_SEAL_Levels (label_de, description_de). The Excel workbook is now a complete bilingual SPOT for data.js + data-en.js.
  • Data update: T Cloud Public scores updated (including customer content in EU 4→5, BSI C5 4→5, audit evidence 4→5, observability 3→4, physical/logical separation 2→3).
  • Data update: UpCloud scores updated (IaC/Terraform 4→5, limits/quotas 2→3, reference architectures 2→3).
  • Evidence: 53 new evidence URLs + 52 new sources (mainly T Cloud Public & UpCloud).
  • Service coverage: T Cloud Public: Secrets Manager (No→Roadmap), DDoS/WAF (claim→public), Marketplace (No→Yes).
rev18
2026-02-17
  • New: integration of the EU Cloud Sovereignty Framework (CSF v1.2.1): criteria clustered by SOV‑1…SOV‑8 (including objective weights).
  • New: EU Sovereignty Score (0–100) + EU SEAL proxy (minimum) per provider; EU score as a sort option in the results list.
  • Cleanup: ECSF mapping/fields and dimension notes removed from SPOT & WebApp (leaner data source).
  • UX/fix: results: sovereignty profile table without truncated columns; N/A column properly aligned.
  • UX: criteria list: objectives collapsed by default; a single criterion shows the associated CSF objective directly below the title.
  • Fix: "weighting" step: fine weighting (criteria list) visible again.
rev17
2026-02-11
  • New (result): "Executive Matrix" (2D) as a quick overview: Y = control (ownership + operating) vs. X = delivery (tech & guardrails); points clickable → inspector.
  • New (result): toggle matrix ↔ profile + provider filter (display) as a combined block; the filter does not change the scoring.
  • New (result): SEAL badges (heuristic) for control maturity (conservative: N/A = 0).
  • New (weighting): Quick Strategy slider: controls the tech share vs. control (ownership + operating) and synchronises the three layer sliders.
  • Update: category assignment (scope category) is now stored explicitly in the data model (data.providers[].category/scope_category) (source: Excel tab "Provider"), no more heuristics.
  • UX/bug fix: matrix tooltip as a floating overlay (no clipping at the top edge) + labels adjusted ("Control", "Provider").
  • UX: results page: the "next step" block is always shown at the end (regardless of matrix/profile view).
rev16
2026-02-06
  • Evidence/coverage: additional public sources added; scoring N/A → score (evidenced) updated.
  • Update: coverage target >80% for Scaleway, OVHcloud Public Cloud (incl. SecNumCloud), Exoscale, IONOS, Hetzner Cloud, STACKIT, UpCloud, Oracle EU SC by adding evidenced criteria (ops/support, compliance, guardrails, secure by default, verification, logging, confidential computing).
  • Sources: new official documentation/compliance pages added to 'Sources' + evidence URLs in 'Comparison'.
rev15
2026-02-05
  • SEO: "clean" URLs introduced via folder structure (…/index.html) (methodology/providers/criteria/provider detail pages + landing pages).
  • Methodology: changelog as structured data (meta.changelog) + its own /changelog/ page.
  • Personalised RFP kit as a direct PDF (print view), without preview or mandatory e-mail.
  • Bug fix: RFP kit PDF: layer weighting is correctly taken from state.layerPct (no more 0% display).
  • Bug fix/enhancement: RFP kit PDF: evidence coverage (weighted) correct + sovereignty profile (6 axes) added to the PDF.
  • UI: provider profiles: header navigation extended by "Sovereign Cloud" and "Comparison" (consistent with criteria/changelog).
  • UI: provider profiles: provider snapshot + evidence filter (search/categories) + service catalogue as an "Advanced" accordion (progressive disclosure).
  • UI/content: guide updated (focused on usage; details linked via methodology/criteria/providers/changelog).
  • UI: comparison landing page: suffix "| Sovereign Cloud Compass" removed from the header subtitle.
  • UI: provider overview: "Last update" box removed.
  • UI: provider profiles: meta line "Last update · data source …" removed.
  • Bug fix WebApp data export: service stack criteria (service portfolio depth, unified security stack) are now correctly calculated from Service_Catalog/Service_Coverage.
rev14
2026-02-03
  • plusserver: provider name standardised to "pluscloud open".
  • plusserver: certificates/attestations (ISO 27001/9001/50001, PCI DSS, BSI C5/ISAE 3402, IDW PH 9.860.1) added with direct links; scope notes (Dresden/operations) added.
  • plusserver: statements on data residency (metadata), operating/access model, dependencies and guardrails updated in comparison & scoring.
  • IONOS: C5 attestation source (Compute Engine/Cloud Cubes/S3) linked & URLs corrected.
  • Delos Cloud: sources updated and additional context/press sources added.
  • Developer reality: UpCloud "limits/quotas" justified from N/A → partial (sources added) + evidence list extended.
  • Sources: missing sources from evidence lists added (e.g. AWS Service Quotas, Oracle service limits, STACKIT quotas, Hetzner Cloud limits, OVH quota increase etc.).
  • New: Microsoft Sovereign Cloud added to comparison/scoring/service coverage/sources (including research & evidence).
  • New: noris Sovereign Cloud added to comparison/scoring/service coverage/sources (including research & evidence).
  • New: SysEleven OpenStack Cloud added to comparison/scoring/service coverage/sources (including research & evidence).
  • Renamed Open Telekom Cloud → T Cloud Public.
rev13
2026-01-29
  • Sovereignty profile (6 axes): heatmap (provider × axis) including axis score (0–5) + evidence coverage (%) introduced.
  • Axis drill-down per axis ("Why is this axis low?") with top drivers and critical unknowns including a link to criterion details.
  • New sheet "Sovereignty_Profile" (axes → criteria mapping) as the data basis.
rev12
2026-01-28
  • New provider added: Delos Cloud (sources, scoring, service catalogue/portfolio & roadmap).
  • AWS European Sovereign Cloud: additional sources integrated (ESCA addendum, initial services, KMS XKS, Nitro; BSI press release); interoperability/portability reclassified.
  • Sources: notes cleaned up (no placeholders/"replaced…"); evidence links without prefixes for correct linking.
  • CTA "Open service catalogue" for hard filters (service portfolio depth & unified security stack).
rev11
2026-01-25
  • Service catalogue (core services) + service coverage per provider added.
  • Service stack: "service portfolio depth" is derived from core service coverage (toggle in Service_Stack_Calc).
  • Evidence links per service added in Service_Coverage.
  • Duplicate criteria cleaned up: developer reality "service catalogue" merged into service stack "service portfolio depth".
  • New criterion "Unified Security Stack" (security coverage from the service catalogue) introduced.
  • Service catalogue view in the criterion modal (core/security/evidence + links) + fix for provider pages (service catalogue visible, not empty, better placed).
  • Service catalogue view with filter bar (core / security stack / all) and table view.
rev10
2026-01-24
  • WebApp: live result count + top exclusion reasons for dealbreakers/filters added.
  • Update: Exoscale: new docs/blog sources added; scoring for BSI C5 and audit reports/evidence pack updated.
rev9
2026-01-21
  • New: providers Exoscale, Hetzner Cloud and Scaleway added (with initial scoring + sources).
  • New: governance criterion "Controlling Interest & FISA 702 Risk" added (jurisdiction ≠ residency) including sources.
  • Update: IT‑Grundschutz: STACKIT certificates/BSI evidence added and scoring updated.
  • Update: lock-in/interoperability refined (API standardisation + IaC provider as indicator).
  • Update: WebApp data updated (Excel → app) including provider/source pages and sitemap.
rev8
2026-01-20
  • New: provider UpCloud added to comparison + scoring.
  • Fix: source links checked for 404/errors and replaced by valid sources (including AWS, IONOS, STACKIT, T Cloud Public).
  • Update: OVHcloud Public Cloud (incl. SecNumCloud): BSI C5 taken into account; additional tooling/DevOps sources added (Terraform provider, CLI, Managed Private Registry, Secret Manager, KCSP).
  • Update: T Cloud Public: certificates link (DE) added.
rev7
2026-01-17
  • Fix: conditional formatting in the scoring consolidated (D5:J32): value colours are correct again; N/A is marked grey.
  • New providers (OTC, Oracle EU SC, pluscloud open) added to the comparison.
  • Governance split into ownership / ultimate parent (EU-owned?) and local contracting entity & EU governance (operational model).
rev6
2026-01-17
  • Coverage penalty introduced in the overall score. Goal: preventing providers with many N/A values from looking "artificially good" in the ranking.
  • Final score is now coverage-adjusted: N/A remains N/A, but acts as a penalty on the final score via reduced weighted coverage.
  • Evidence coverage (weighted %) shown in addition (transparency on how many criteria per provider are actually scored/backed by evidence).
rev5
2026-01-17
  • Scoring transparency: for every criterion in the Scoring tab, the note field now contains "Scored by: …" (specific scoring basis per criterion).
  • Formula/calculation check: N/A is correctly ignored in the weighted calculation (no implicit 0).
rev4
2026-01-17
  • Confidential computing / operator access exclusion integrated (workload scope).
  • Scoring logic extended: attestation, key ownership, admin/debug paths, evidence, production references.
  • Impact level / ex-ante guardrails integrated: policy enforcement, secure by default, independent verification, black-box exposure.
  • Developer reality (DX/operability) integrated into the overall scoring (no longer shown separately).
  • N/A rule introduced: missing robust evidence is recorded as N/A (instead of 0/2) and does not distort the score through arbitrary defaults.
  • ECSF mapping integrated into the overall view.
rev3
2026-01-16
  • Correction interoperability / API portability: AWS no longer flatly 0, but adjusted (better consistency between text and score).
  • Scoring note: interoperability criterion identified as potentially too binary (preparation for a later split).
rev2
2026-01-16
  • Developer reality introduced (service catalogue, IaC, SDLC/DevOps, observability, limits/quotas, reference architectures) including adoption risk score.
  • ECSF mapping added for the first time (crosswalk view/mapping tab).
  • Source list extended (docs for DX/operability + ECSF).