Sovereign Cloud Compass
Audit reports / evidence pack

Audit reports / evidence pack

Why important?

Without evidence, audits fail (regulator, internal audit).

How measured?

Scale 0–5 + N/A:
  • 0 = No reports/evidence packs available
  • 1 = Marketing/statements only, no verifiable material
  • 2 = Individual artefacts, but incomplete / scope unclear
  • 3 = Evidence pack available (often via portal/NDA), scope partly clear
  • 4 = Comprehensive artefacts (SOC/C5/ISO/reports), up to date, minor gaps
  • 5 = Comprehensive + current + transparent scope + easily accessible (public/trust centre), evidenced
  • N/A = no reliable evidence

Sources / Evidence

Validation questions (RFP)

  • Is there a standardised evidence pack (SOC reports, C5, pen-test summaries)? How quickly is it available?

Scores comparison

Providers Score
AWS European Sovereign Cloud 5.0
T Cloud Public 5.0
IONOS Cloud 4.0
STACKIT 4.0
pluscloud open 4.0
Exoscale 4.0
Hetzner Cloud 4.0
Scaleway 4.0
Microsoft Sovereign Cloud 4.0
SysEleven OpenStack Cloud 4.0
Cloud Temple Trusted Cloud 4.0 SecNumCloud qualification (ANSSI) = comprehensive audit. ISO 27001 certificate. HDS certificate. Documentation via GitHub (docs). Evidence via the SecNumCloud process.
OVHcloud Public Cloud (inkl. SecNumCloud) 3.0
Oracle EU Sovereign Cloud 3.0
UpCloud 3.0
noris Sovereign Cloud 3.0
Infomaniak Public Cloud 3.0 ISO 27001:2022 certificate (PDF download). ISO 9001/14001/50001. B Corp certification (2025). No SecNumCloud/C5 audit. Certificates publicly referenced.
Delos Cloud 2.0