Sovereign Cloud Compass
EU root CA / trust services

EU root CA / trust services

Why important?

PKI/trust is core for identity, TLS and signatures.

How measured?

Scale 0–5 + N/A:
  • 0 = Trust anchors / root CA non-EU (or unsuitable) without alternatives
  • 1 = EU trust only claimed, details unclear
  • 2 = EU trust for partial scope (some services), key paths unclear
  • 3 = EU root CA/trust services for core scope, but not end-to-end
  • 4 = EU trust services broadly documented (root CA, signing, possibly HSM) with few gaps
  • 5 = End-to-end EU trust anchors (root CA/signing/key custody) + auditably evidenced
  • N/A = no reliable evidence

Validation questions (RFP)

  • Which KMS/HSM options? Bring-your-own-key? Hold-your-own-key? Key custody & audit?

Scores comparison

Providers Score
AWS European Sovereign Cloud 4.0
Delos Cloud 3.0
Microsoft Sovereign Cloud 2.0
SysEleven OpenStack Cloud 1.0
Cloud Temple Trusted Cloud 2.0 Stormshield EVA (FR Firewall) integrated. Partnerships with EU security vendors. No explicit EU Root CA / Trust Services documentation for cloud PKI.
Infomaniak Public Cloud 1.0 No explicit EU/CH Root CA or Trust Services documentation. Standard TLS certificates. Let's Encrypt integration.
noris Sovereign Cloud 1.0
Exoscale N/A
Hetzner Cloud N/A
IONOS Cloud N/A
OVHcloud Public Cloud (inkl. SecNumCloud) N/A
Oracle EU Sovereign Cloud N/A
STACKIT N/A
Scaleway N/A
T Cloud Public N/A
UpCloud N/A
pluscloud open N/A