Sovereign Cloud Compass
Independent verification (continuous)

Independent verification (continuous)

Why important?

Effect rather than paper: independent, machine-readable checks and continuous compliance reduce blind spots.

How measured?

Scale 0–5 + N/A:
  • 0 = No independent/regular verification
  • 1 = Ad-hoc checks, not systematic
  • 2 = Periodic/partial, limited scope
  • 3 = Continuous monitoring/assessment (tools/reports) for the core scope
  • 4 = Continuous + independent verification (audit/assurance), well documented
  • 5 = Continuous + independent assurance with transparent evidence/reporting
  • N/A = no reliable evidence

Validation questions (RFP)

  • Are there continuous, API-based checks (config/policies) with exportable evidence? Can auditors verify independently (e.g. attestations, logs, API exports)?

Scores comparison

Providers Score
Microsoft Sovereign Cloud 4.0
SysEleven OpenStack Cloud 4.0
AWS European Sovereign Cloud 3.0
T Cloud Public 3.0
pluscloud open 3.0
noris Sovereign Cloud 3.0
Cloud Temple Trusted Cloud 3.0 ANSSI SecNumCloud audits (regular). ISO 27001 annual audits. HDS recertification. Gaia-X Level 3 audit. No continuous automated verification documented.
IONOS Cloud 2.0
STACKIT 2.0
OVHcloud Public Cloud (inkl. SecNumCloud) 2.0
Oracle EU Sovereign Cloud 2.0
UpCloud 2.0
Exoscale 2.0
Hetzner Cloud 2.0
Scaleway 2.0
Delos Cloud 2.0
Infomaniak Public Cloud 2.0 ISO 27001 annual audits. ISO 14001/50001 audits. B Corp recertification. Bug bounty programme. No continuous automated verification.