Sovereign Cloud Compass
EU root CA / trust services

EU root CA / trust services

Why important?

PKI and trust services are central to identity, TLS and signatures.

How measured?

Scale 0–5 + N/A:
  • 0 = Trust anchors / root CA non-EU (or unsuitable) without alternatives
  • 1 = EU trust only claimed, details unclear
  • 2 = EU trust for part of the scope (some services), key paths unclear
  • 3 = EU root CA/trust services for the core scope, but not throughout
  • 4 = EU trust services broadly documented (root CA, signing, possibly HSM) with few gaps
  • 5 = EU trust anchors throughout (root CA/signing/key custody) + verifiably evidenced
  • N/A = no reliable evidence

Validation questions (RFP)

  • Which certificate authorities issue the platform's TLS, signing and identity certificates, and in which jurisdiction are they based? Is there an EU root CA or are there qualified trust services under eIDAS? Can customers integrate their own PKI and root certificates?

Scores comparison

Providers Score
AWS European Sovereign Cloud 4.0
T Cloud Public 4.0
Delos Cloud 3.0
Microsoft Sovereign Cloud 2.0
Cloud Temple Trusted Cloud 2.0 Stormshield EVA (French firewall) integrated. Partnerships with EU security providers. No explicit EU root CA / trust services documentation for cloud PKI.
IONOS Cloud 1.0
STACKIT 1.0
OVHcloud Public Cloud (inkl. SecNumCloud) 1.0
Oracle EU Sovereign Cloud 1.0
pluscloud open 1.0
UpCloud 1.0
Exoscale 1.0
Hetzner Cloud 1.0
Scaleway 1.0
noris Sovereign Cloud 1.0
SysEleven OpenStack Cloud 1.0
Infomaniak Public Cloud 1.0 No explicit EU/CH root CA or trust services documentation. Standard TLS certificates. Let's Encrypt integration.