Independent verification (continuous)
Why important?
Effect rather than paper: independent, machine-readable checks and continuous compliance reduce blind spots.
How measured?
Scale 0–5 + N/A:
- 0 = No independent/regular verification
- 1 = Ad-hoc checks, not systematic
- 2 = Periodic/partial, limited scope
- 3 = Continuous monitoring/assessment (tools/reports) for the core scope
- 4 = Continuous + independent verification (audit/assurance), well documented
- 5 = Continuous + independent assurance with transparent evidence/reporting
- N/A = no reliable evidence
Sources / Evidence
Validation questions (RFP)
- Are there continuous, API-based checks (config/policies) with exportable evidence? Can auditors verify independently (e.g. attestations, logs, API exports)?
Scores comparison
| Providers | Score | |
|---|---|---|
| Microsoft Sovereign Cloud | 4.0 | |
| SysEleven OpenStack Cloud | 4.0 | |
| AWS European Sovereign Cloud | 3.0 | |
| T Cloud Public | 3.0 | |
| pluscloud open | 3.0 | |
| noris Sovereign Cloud | 3.0 | |
| Cloud Temple Trusted Cloud | 3.0 | ANSSI SecNumCloud audits (regular). ISO 27001 annual audits. HDS recertification. Gaia-X Level 3 audit. No continuous automated verification documented. |
| IONOS Cloud | 2.0 | |
| STACKIT | 2.0 | |
| OVHcloud Public Cloud (inkl. SecNumCloud) | 2.0 | |
| Oracle EU Sovereign Cloud | 2.0 | |
| UpCloud | 2.0 | |
| Exoscale | 2.0 | |
| Hetzner Cloud | 2.0 | |
| Scaleway | 2.0 | |
| Delos Cloud | 2.0 | |
| Infomaniak Public Cloud | 2.0 | ISO 27001 annual audits. ISO 14001/50001 audits. B Corp recertification. Bug bounty programme. No continuous automated verification. |