🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Amazon Web Services

United States · IaaS/PaaS · https://aws.amazon.com

Sovereignty score44.1%
Global (unweighted)44.4%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty33.4SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty29.3SEAL-1
SOV-3 Data & AI Sovereignty70.0SEAL-1
SOV-4 Operational Sovereignty50.1SEAL-2
SOV-5 Supply Chain Sovereignty18.0SEAL-1
SOV-6 Technology Sovereignty40.0SEAL-2
SOV-7 Security & Compliance Sovereignty64.2SEAL-1
SOV-8 Environmental Sustainability50.0SEAL-2

SOV-1 · Strategic Sovereignty 33.4% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent: the AWS European Sovereign Cloud's German GmbHs are 100% subsidiaries of Amazon.com Inc. (US). Ultimate entity control sits entirely outside the EU -> SOV-1.1 opt1. (src: https://aws.amazon.com/compliance/europe-digital-sovereignty/)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highAmazon is a ~$2T US public company; takeover transferring it to a non-EU sovereign entity is very unlikely (this factor concerns transfer to a non-EU sovereign owner, not realistic for Amazon). Kept at existing all-seal-4 choice.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap set centrally by Amazon in the US; ESC has an EU advisory board but the platform roadmap is foreign-set. EU customers influence only via 'voice of the customer' channels -> opt2.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highAmazon is funded almost entirely by non-EU (US) capital markets/retained earnings; no material EU equity ownership of the parent. Kept at existing all-seal-4 choice.
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumAWS makes substantial EU investments (EUR 7.8B Sovereign Cloud, jobs) but the overwhelming majority of economic value/R&D/profit accrues in the US; EU contribution is 'some'. Kept at existing all-seal-4 choice.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4mediumAWS participates in some EU initiatives (Gaia-X, public-sector frameworks) but is not a core dependency of EU strategic programs; limited participation. Kept at existing all-seal-4 choice.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowAWS publishes EU-facing sovereignty action plans (ESC, EUR 7.8B) showing an existing action plan, but as a US hyperscaler is not a vehicle of EU industrial strategy. Kept at existing all-seal-4 choice.
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2mediumno own_stack but ESC has a contractual continuity design: independent EU governance (German GmbHs, EU advisory board) and a dedicated EU SOC let it continue operating temporarily per contractual agreement on a parent/cut-off event -> opt3 (seal 2). It cannot internalise/replace the Amazon stack, so not opt4/5.

SOV-2 · Legal & Jurisdictional Sovereignty 29.3% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highESC offers German/EU contracting but the parent (Amazon.com Inc.) and CLOUD Act exposure are governed by US law; offer is mixed EU/non-EU law, not exclusively EU -> opt2. (src: https://aws.amazon.com/compliance/europe-digital-sovereignty/)
SOV-2.2Extraterritorial laws exposure3. EU subsidiary with contractual protections84/167SEAL-1highno certified immunity: ESC uses EU corporate structures (German GmbHs, EU advisory board) with contractual data-protection protections, but a US-parented group's EU subsidiary is compellable via the parent and holds no SecNumCloud 3.2/EUCS-High -> EU subsidiary with contractual protections (opt3, seal 1). Normalised to opt3 across the US-hyperscaler cluster (same profile as Azure/GCP/Oracle/IBM). (src: https://aws.amazon.com/compliance/europe-digital-sovereignty/)
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent / CLOUD Act / FISA 702: German GmbHs are 100% Amazon.com Inc. subsidiaries; under 'possession, custody, or control' US courts can compel the US parent to produce data without customer notification in specific gag-ordered cases -> SOV-2.3 opt2 (seal 1). This is the gating cap: SEAL-1. (src: https://aws.amazon.com/compliance/europe-digital-sovereignty/)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowNo EU-Member-State-targeted export restrictions apply; AWS is subject to US EAR but EU revenue share is large with no restrictions toward EU MSs evidenced. Conservatively the >50% EU-revenue tier -> opt3.
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highCore AWS IP (services, Nitro, custom silicon designs, software) originates and is owned in the US (Amazon.com / Annapurna Labs); essentially entirely outside the EU. Kept at existing all-seal-4 choice.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP held by US entities under US law (single jurisdiction) -> opt1.

SOV-3 · Data & AI Sovereignty 70.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highAWS KMS supports customer-managed keys and External Key Store (XKS/HYOK), letting customers hold keys outside AWS so the provider cannot decrypt when properly configured -> opt5 (best-case exclusive customer control).
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumCloudTrail provides comprehensive customer-controlled access/API logs covering data flows, but delivery is near-real-time rather than guaranteed real-time independent oversight; AWS controls the pipeline -> opt4.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1mediumAWS documents secure decommissioning/deletion per policy (NIST 800-88, attested) but no per-customer cryptographically independent proof of irreversible erasure -> opt3.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4mediumeu_exclusive: ESC is a physically and logically separate partition (aws-eusc) that stores AND processes all data including metadata exclusively within the EU, with infrastructure entirely in the EU, zero operational access from outside EU borders and no critical non-EU dependencies -> SOV-3.4 opt5 (exclusively EU, no third-country fallback). Genuine differentiator vs Azure/GCP/IBM data-boundary products that retain controlled third-country fallback. (src: https://aws.eu/)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2mediumESC AI (Bedrock/SageMaker) is dominated by US-origin models on AWS Trainium/Inferentia accelerators fabbed at TSMC; mostly non-EU AI with chip dependency -> opt2 (seal 2).

SOV-4 · Operational Sovereignty 50.1% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4highAWS provides standard documented export tooling plus formal migration services (Migration Hub, Snow, DataSync), despite managed-service lock-in -> opt4.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops: ESC is operated by EU-resident personnel only and non-EU AWS staff have no access to customer content -> ops predominantly EU-based teams, opt4 (seal 3). Not opt5 (fully EU-built stack) as the platform is US-engineered.
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3mediumeu_ops: ESC day-to-day technical support and operations are staffed by EU residents, with deeper platform engineering escalation to the global (US) pool -> majority EU with escalation abroad, opt3 (seal 3).
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3mediumeu_ops: ESC customer service and technical support are provided by EU-located personnel, with non-EU escalation for the underlying platform -> majority in EU with non-EU escalations, opt3 (seal 3).
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge bases are global (US-hosted, English-primary); EU-only handling is optional/not enforced -> opt2 (seal 2).
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowno own_stack: continuity depends on Amazon (non-EU vendor) and non-EU silicon; on a sustained supplier/parent disruption the service would stop with delay rather than continue autonomously under EU control -> opt2 (seal 2).

SOV-5 · Supply Chain Sovereignty 18.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1mediumAWS discloses some hardware/Nitro detail but not full component provenance; partial disclosure with foreign-origin components -> opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1highServers and custom silicon are built outside the EU (ODMs in Asia/US; chips fabbed at TSMC Taiwan); foreign-origin manufacturing, partial disclosure -> opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4mediumNitro firmware/embedded code designed by AWS/Annapurna (US) with some published architecture but no full open provenance; partial disclosure -> opt2. (All-seal-4 factor; choice kept.)
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2highforeign_core: ESC core platform software is AWS proprietary US-designed/US-maintained technology with only partial architectural disclosure -> SOV-5.4 opt2 (seal 2). This is a SEAL-2 ceiling on software origin.
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1highPlatform software build and release are controlled and executed by AWS in the US (non-EU control and execution) -> opt1.
SOV-5.6Single point of dependency1. Only non-EU vendors/facilities0/143SEAL-1highCritical services depend on Amazon itself as the non-EU vendor plus non-EU silicon (TSMC); fundamental dependency on a single non-EU vendor for the whole stack -> opt1.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1mediumAWS attestation programs expose some supplier/control information to auditors, but the broad supply chain is not openly auditable by customers; some suppliers auditable -> opt2.

SOV-6 · Technology Sovereignty 40.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumMany standards-based APIs and open protocols, but a large share of differentiated value sits in proprietary managed-service APIs; mixed/partial openness -> opt3.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumOpen standards adopted across many core services (S3 API, POSIX, SQL engines, EKS/Kubernetes) but no blanket policy mandating open standards for all; partial core adoption -> opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumforeign_core: the ESC platform substrate is closed-source and vendor-controlled (AWS contributes OSS like Firecracker/Bottlerocket but the service is not open); source-available-with-strict-rights best fits -> opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumAWS publishes extensive architecture/whitepaper material (Well-Architected, Nitro, ESC overview) giving substantial public insight, with deepest internals only under audit -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumESC offers HPC capacity in the EU but the stack (chips, schedulers, accelerators) is foreign-designed and foreign-fabbed; EU-hosted with a foreign HPC stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 64.2% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumcerts: ESC holds C5 (BSI) plus SOC 2 and seven ISO certifications, and AWS components (Nitro, KMS HSMs) hold Common Criteria/FIPS 140; per key high-assurance EU cloud cert (BSI C5) maps to EAL3 -> opt4 (seal 3). No platform-wide EAL4-5/EUCS-High. (src: https://aws.amazon.com/blogs/security/aws-european-sovereign-cloud-achieves-first-compliance-milestone-soc-2-and-c5-reports-plus-seven-iso-certifications)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highAWS supports GDPR (DPA, SCCs), NIS2 and DORA frameworks and is independently audited, but full end-to-end compliance is shared-responsibility; partial compliance to most. Kept at existing all-seal-4 choice.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumeu_ops: ESC has a dedicated EU Security Operations Centre staffed exclusively by EU residents handling the incident lifecycle within the EU -> entire lifecycle by EU teams, opt4 (seal 3). Genuine differentiator vs peers' hybrid global SOCs. Not opt5 (no evidenced ENISA/CSIRT-network sharing). (src: https://aws.eu/)
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get full direct access to security logs (CloudTrail, GuardDuty, Security Lake) and can store them in EU Regions; immutability depends on customer config -> full direct access, EU log storage, opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumAWS provides GDPR/NIS2/DORA-aligned breach/incident notification with contractual monitored SLAs, though not full real-time CSIRT-network sharing -> partial compliance, monitored flow, SLAs, opt4 (seal 3). Normalised across the cluster (all five offer NIS2/DORA-aligned SLAs).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4mediumCustomers have moderate maintenance autonomy over workloads (patch/maintenance windows, advance notice, testing) while AWS controls platform maintenance except emergency/zero-day fixes -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumno certified audit_rights: independent audit limited to AWS-defined attestation programs (C5/SOC2/ISO) and auditor access under NDA; customers/independent EU bodies cannot freely audit -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 50.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4highAWS reports a global average PUE of ~1.15 (2023)/1.14 (2024) with an efficiency roadmap; falls in the 'PUE < 1.5 + roadmap' tier (lower tiers require verified per-facility figures) -> opt3 (seal 4). (src: https://sustainability.aboutamazon.com/products-services/aws-cloud)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3mediumAWS runs a documented hardware reuse/refurbishment/recycling program reported in Amazon's sustainability disclosures -> documented program, opt3 (seal 3).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2highAmazon publishes a detailed annual sustainability report with AWS data-centre metrics (PUE, WUE, renewables) but self-reported, not independently EU-methodology-audited -> annual report, opt3.
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4mediumAWS matches 100% of electricity with renewables globally and procures EU renewable capacity, but supply is a mix of EU and non-EU sources -> opt3. Kept at existing all-seal-4 choice. (src: https://sustainability.aboutamazon.com/products-services/aws-cloud)