Sovereign Cloud Compass
ISO 27001 / ISMS

ISO 27001 / ISMS

Why important?

Baseline certificate for an ISMS; often mandatory in tenders.

How measured?

Scale 0–5 + N/A:
  • 0 = No ISO 27001 evidence
  • 1 = Planned/announced, unclear
  • 2 = ISO 27001 in place, scope very limited/unclear
  • 3 = ISO 27001 for the relevant core scope, but limited transparency on scope/SoA
  • 4 = ISO 27001 broad + scope/SoA well documented
  • 5 = ISO 27001 (accredited) + clear scope (services/regions) + verifiably evidenced
  • N/A = no reliable evidence

Validation questions (RFP)

  • Which sites/services are ISO 27001 certified? What is the statement of applicability? What is the audit frequency?

Scores comparison

Providers Score
AWS European Sovereign Cloud 4.0
STACKIT 4.0
OVHcloud Public Cloud (inkl. SecNumCloud) 4.0
T Cloud Public 4.0
pluscloud open 4.0
UpCloud 4.0
Exoscale 4.0
Hetzner Cloud 4.0
Scaleway 4.0
Delos Cloud 4.0
Microsoft Sovereign Cloud 4.0
SysEleven OpenStack Cloud 4.0
Cloud Temple Trusted Cloud 4.0 ISO 27001 certified (since 2019). HDS-certified (Hébergeur de Données de Santé). Certificates publicly referenced.
Infomaniak Public Cloud 4.0 ISO/IEC 27001:2022 certified (since 2018). Certificate publicly available (PDF). Additionally ISO 9001, ISO 14001, ISO 50001.
IONOS Cloud 3.0
Oracle EU Sovereign Cloud 3.0
noris Sovereign Cloud 3.0