Sovereign Cloud Compass
No critical non-EU dependencies

No critical non-EU dependencies

Why important?

Important for crisis scenarios and geopolitical risk.

How measured?

Scale 0–5 + N/A:
  • 0 = Critical non-EU dependencies (DNS/PKI/identity/control plane or similar)
  • 1 = Several critical dependencies, only partly mitigated
  • 2 = Individual critical dependencies, or scope heavily restricted
  • 3 = Predominantly EU-based, but individual critical dependencies/uncertainties
  • 4 = Only a few non-critical non-EU dependencies + clear mitigations
  • 5 = No critical non-EU dependencies (trust anchors/control plane), evidenced
  • N/A = no reliable evidence

Validation questions (RFP)

  • Which critical control-plane services depend on non-EU infrastructure (DNS, PKI, updates, identity, monitoring)?

Scores comparison

Providers Score
AWS European Sovereign Cloud 4.0
STACKIT 4.0
OVHcloud Public Cloud (inkl. SecNumCloud) 4.0
Oracle EU Sovereign Cloud 4.0
Hetzner Cloud 4.0
Scaleway 4.0
noris Sovereign Cloud 4.0
SysEleven OpenStack Cloud 4.0
Cloud Temple Trusted Cloud 4.0 French company (SAS). Own DCs in FR. Open source focus (XEN hypervisor, OpenShift). Emphasises no dependencies on non-EU software for critical infrastructure. SecNumCloud qualification requires immunity from extraterritorial laws.
Infomaniak Public Cloud 4.0 Swiss company (employee-owned). Own DCs. OpenStack (open source) as basis. In-house development. No non-EU dependencies for critical infrastructure documented. Hardware: European components preferred.
IONOS Cloud 3.0
T Cloud Public 3.0
pluscloud open 3.0
UpCloud 3.0
Exoscale 3.0
Delos Cloud 3.0
Microsoft Sovereign Cloud 1.0