Unified security stack
Why important?
A unified security stack across layers (identity, KMS, logging/monitoring, network security). The coverage of the core building blocks is assessed (security coverage).
How measured?
Scale 0–5 + N/A:
- Derived from security service coverage:
- 0 = Very low (<10% security coverage)
- 1 = Low (10–30%)
- 2 = Medium (30–50%)
- 3 = Good (50–70%)
- 4 = High (70–90%)
- 5 = Very high / unified security suite (>90%)
- N/A = no reliable evidence
Sources / Evidence
Validation questions (RFP)
- Which security building blocks (IAM, KMS, logging/SIEM, WAF, DDoS protection, network security) are native services within the sovereign scope, and which are only available via third parties? Do security events flow into a central, exportable log? Where are security telemetry and threat intelligence processed?
Scores comparison
| Providers | Score | |
|---|---|---|
| AWS European Sovereign Cloud | 5.0 | |
| Oracle EU Sovereign Cloud | 5.0 | |
| Microsoft Sovereign Cloud | 5.0 | |
| Delos Cloud | 4.8 | |
| T Cloud Public | 4.5 | |
| STACKIT | 4.3 | |
| Scaleway | 3.8 | |
| Cloud Temple Trusted Cloud | 3.5 | Stormshield FW (EVA), bastion host, anti-DDoS, IAM/RBAC via console, SecNumCloud baseline. No fully integrated security stack (SIEM/SOAR/CSPM) as self-service. |
| IONOS Cloud | 3.3 | |
| OVHcloud Public Cloud (inkl. SecNumCloud) | 2.8 | |
| Exoscale | 2.3 | |
| SysEleven OpenStack Cloud | 2.3 | |
| Infomaniak Public Cloud | 1.8 | OpenStack security groups (network FW). DDoS protection (anti-DDoS). IAM via Keystone. No KMS/HSM/secrets manager/WAF as a managed service. |
| UpCloud | 1.5 | |
| Hetzner Cloud | 1.5 | |
| noris Sovereign Cloud | 1.0 | |
| pluscloud open | 0.8 |