Sovereign Cloud Compass
Unified security stack

Unified security stack

Why important?

A unified security stack across layers (identity, KMS, logging/monitoring, network security). The coverage of the core building blocks is assessed (security coverage).

How measured?

Scale 0–5 + N/A:
  • Derived from security service coverage:
  • 0 = Very low (<10% security coverage)
  • 1 = Low (10–30%)
  • 2 = Medium (30–50%)
  • 3 = Good (50–70%)
  • 4 = High (70–90%)
  • 5 = Very high / unified security suite (>90%)
  • N/A = no reliable evidence

Validation questions (RFP)

  • Which security building blocks (IAM, KMS, logging/SIEM, WAF, DDoS protection, network security) are native services within the sovereign scope, and which are only available via third parties? Do security events flow into a central, exportable log? Where are security telemetry and threat intelligence processed?

Scores comparison

Providers Score
AWS European Sovereign Cloud 5.0
Oracle EU Sovereign Cloud 5.0
Microsoft Sovereign Cloud 5.0
Delos Cloud 4.8
T Cloud Public 4.5
STACKIT 4.3
Scaleway 3.8
Cloud Temple Trusted Cloud 3.5 Stormshield FW (EVA), bastion host, anti-DDoS, IAM/RBAC via console, SecNumCloud baseline. No fully integrated security stack (SIEM/SOAR/CSPM) as self-service.
IONOS Cloud 3.3
OVHcloud Public Cloud (inkl. SecNumCloud) 2.8
Exoscale 2.3
SysEleven OpenStack Cloud 2.3
Infomaniak Public Cloud 1.8 OpenStack security groups (network FW). DDoS protection (anti-DDoS). IAM via Keystone. No KMS/HSM/secrets manager/WAF as a managed service.
UpCloud 1.5
Hetzner Cloud 1.5
noris Sovereign Cloud 1.0
pluscloud open 0.8