🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Cloudflare

United States · PaaS · https://www.cloudflare.com

Sovereignty score36.7%
Global (unweighted)37.5%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty26.1SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty21.0SEAL-1
SOV-3 Data & AI Sovereignty50.0SEAL-1
SOV-4 Operational Sovereignty25.1SEAL-1
SOV-5 Supply Chain Sovereignty21.6SEAL-1
SOV-6 Technology Sovereignty60.0SEAL-3
SOV-7 Security & Compliance Sovereignty46.6SEAL-1
SOV-8 Environmental Sustainability50.0SEAL-2

SOV-1 · Strategic Sovereignty 26.1% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent (Cloudflare, Inc., Delaware/San Francisco, NYSE: NET) -> entity controlling the service is entirely outside the EU -> SOV-1.1 opt1. (src: https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001477333&type=10-K)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumAlready a US-controlled public company; transfer to a non-EU sovereign entity is not a meaningful future risk because control already sits outside the EU. A takeover moving it to EU control is very unlikely.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap set centrally in the US; no EU governance body, only 'voice of the customer' channels (no immunity/EU control) -> SOV-1.3 opt2.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunded via US venture capital (Venrock and others) and US public equity markets; almost entirely non-EU capital.
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumCloudflare has EU offices (e.g., Lisbon, Munich, London) and network presence, but the large majority of R&D, revenue booking and employment is outside the EU; only some EU economic contribution.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo clear participation in EU strategic programs such as Gaia-X or IPCEI-CIS as a core member; it is a US commercial vendor.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of an action plan or dedicated governance aligned with EU industrial sovereignty strategies; alignment is incidental via compliance offerings.
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowNot own_stack (service runs on Cloudflare's US-controlled global network), but a standard PaaS with documented data-export/API access and contractual terms under which dependent services could continue temporarily after a cut-off rather than shutting down immediately -> SOV-1.8 opt3 (seal 2), consistent with US commodity-IaaS/CDN peers.

SOV-2 · Legal & Jurisdictional Sovereignty 21.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highforeign_parent: primary jurisdiction is US law; EU subsidiaries and GDPR contracts add an EU layer, making it mixed EU/non-EU rather than exclusively EU -> SOV-2.1 opt2.
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highNo immunity (US parent): fully exposed to US extraterritorial laws (CLOUD Act, FISA 702); contractual mitigation clauses and SCCs exist but residual exposure remains -> SOV-2.2 opt2.
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent (US CLOUD Act/FISA): US authorities can compel access; policy is to notify and push back, but under gag orders access can be compelled without notification -> SOV-2.3 opt2 (seal 1, caps overall SEAL at 1).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowAs a US entity Cloudflare is subject to US export controls/OFAC sanctions that can restrict service to certain persons or organizations, though not to EU Member States generally -> SOV-2.4 opt2.
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highCore IP (network software, Workers runtime, products) is developed and held in the US, entirely outside the EU.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP is held by Cloudflare, Inc. under US (single-country, non-EU) law -> SOV-2.6 opt1.

SOV-3 · Data & AI Sovereignty 50.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2mediumKeyless SSL/Geo Key Manager let customers control TLS key location, but for most stored data and proxied traffic Cloudflare holds keys and can read data -> shared with provider override -> SOV-3.1 opt3.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2mediumLogs/analytics (Logpush, audit logs) exist but are vendor-controlled and not independently real-time auditable across the global network -> SOV-3.2 opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows internal retention policy with contractual commitments, but no independently verifiable cryptographic proof of irreversible erasure -> SOV-3.3 opt3.
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumNo eu_exclusive sovereign offer; global default product, but the Data Localization Suite makes EU regions selectable (EU-by-default with tightly controlled exceptions) while third-country fallback exists -> SOV-3.4 opt4 (seal 1). (src: https://www.cloudflare.com/data-localization/)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2mediumWorkers AI relies on NVIDIA GPUs (foreign chips) and largely licensed/open models (e.g., Llama); not EU-origin, clear chip dependency -> SOV-3.5 opt2.

SOV-4 · Operational Sovereignty 25.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4highStandard, documented data export and API access exist with broad open-format support; reliance on proprietary features (Workers, WAF rules) limits portability beyond standard export -> SOV-4.1 opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1mediumNo eu_ops: critical operation of the global network, control plane and core engineering is delivered by predominantly US-based teams; EU cannot run the stack independently -> SOV-4.2 opt1.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1lowCloudflare has EU staff (Lisbon, London, Munich) but its engineering/SRE skill base is global with the majority outside the EU -> SOV-4.3 opt2.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2lowSupport is global follow-the-sun with EU presence but the majority of support capacity sits outside the EU -> SOV-4.4 opt2.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowExtensive public documentation exists globally; EU-residency of knowledge repositories is optional/not enforced, with global exposure -> SOV-4.5 opt2.
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowUses non-EU subcontractors/colocation; on disruption the service would stop with delay, with limited ability to internalise within the EU -> SOV-4.6 opt2.

SOV-5 · Supply Chain Sovereignty 21.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1mediumCloudflare publishes detailed server generation specs (AMD EPYC, Ampere Altra) but full component provenance is only partially disclosed and not EU-certified -> SOV-5.1 opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServers are built by foreign ODMs (e.g., Quanta, Taiwan) to Cloudflare specs; foreign-origin manufacturing with partial public disclosure of design -> SOV-5.2 opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code comes from foreign chip and ODM vendors (AMD, Ampere, NIC vendors); only partial disclosure, no EU-certified provenance.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumCore software (network stack, Workers runtime workerd) is US-developed; some components open-sourced for review but it is foreign-origin with partial disclosure, not EU-maintained -> SOV-5.4 opt2 (seal 2).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumSoftware build and release are controlled and executed by Cloudflare in the US; non-EU control and execution with no EU policy gates -> SOV-5.5 opt1.
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1mediumCritical services depend on non-EU vendors (US/Taiwan chips, ODMs, US control plane) and dependency mapping is mostly undocumented to customers; mostly non-EU dependency -> SOV-5.6 opt2.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers are disclosed via certifications and sub-processor lists, but the full supply chain is not broadly auditable by customers; only some suppliers auditable -> SOV-5.7 opt2.

SOV-6 · Technology Sovereignty 60.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumCloudflare exposes standards-based, well-documented APIs and supports broad protocol standards (HTTP, DNS, TLS, BGP, WebAssembly), making it standards-based and broadly compatible -> SOV-6.1 opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCloudflare actively builds on and contributes to open standards (IETF: TLS 1.3, QUIC/HTTP3, ECH, Privacy Pass) for most core network services as a matter of policy -> SOV-6.2 opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumCloudflare open-sources many significant components (workerd, quiche, BoringTun, CIRCL, gokeyless) under centralised company governance, but the platform itself is not fully open-source -> SOV-6.3 opt3 (open, centralised governance).
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumCloudflare publishes an unusually large corpus of public technical insight (detailed blog posts, research, RFCs), though customers cannot modify the core service -> SOV-6.4 opt4.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/GPU compute (Workers AI inference) runs across Cloudflare's PoPs, including EU locations, on imported NVIDIA accelerators: EU-hosted on a foreign stack rather than imported black-box with no EU footprint -> SOV-6.5 opt2 (seal 3), consistent with US commodity-IaaS/CDN peers.

SOV-7 · Security & Compliance Sovereignty 46.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumBeyond ISO 27001 + SOC 2, Cloudflare holds the German BSI C5 attestation, a high-assurance national cloud-security certification; per the key's cert map (SecNumCloud 3.2 / BSI C5 / EUCS-Substantial / ENS-High -> EAL3) this maps to EAL3 -> SOV-7.1 opt4 (seal 3). This is a genuine differentiator vs the rest of the cluster, which hold only ISO 27001 + SOC 2. (src: https://www.cloudflare.com/trust-hub/compliance-resources/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumCloudflare demonstrates GDPR compliance (ISO 27701, EU Cloud Code of Conduct, EU-US DPF) and supports NIS2/DORA needs, achieving partial compliance to most EU regulations though not a single fully independently audited 'all-regimes' attestation.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowNo eu_ops: SOC and incident response operate globally on a follow-the-sun model spanning US and EU; hybrid EU/non-EU -> SOV-7.3 opt2.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get monitoring via dashboard, audit logs and Logpush (a monitoring portal), but Cloudflare retains primary control of platform-level security logging -> SOV-7.4 opt3.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure is moderate and GDPR/NIS2-aligned with public post-incident reporting, but not full real-time CSIRT integration -> SOV-7.5 opt3.
SOV-7.6Maintenance autonomy2. Limited autonomy (vendor schedules)36/143SEAL-1lowCloudflare controls maintenance and update scheduling of its global network; customers have limited autonomy over when changes are applied -> SOV-7.6 opt2.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNo audit_rights: independent auditing is limited to third-party certification audits (ISO/SOC2/C5); customers and arbitrary entities cannot perform full independent audits -> SOV-7.7 opt2.

SOV-8 · Environmental Sustainability 50.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowCloudflare runs in leased colocation facilities (typically PUE well under 1.5) and reports strong per-watt efficiency gains and an efficiency roadmap -> SOV-8.1 opt3. (src: https://www.cloudflare.com/impact/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowCloudflare runs a documented hardware-sustainability program (use hardware as long as possible, responsible recycling at decommission, plus a customer hardware-decommission/disposal program) -> SOV-8.2 opt3 (documented program), consistent with US commodity-IaaS/CDN peers. (src: https://www.cloudflare.com/impact/)
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumCloudflare publishes an annual Impact Report with Scope 1/2/3 emissions, but it follows global (not EU-specific audited) methodology -> SOV-8.3 opt3. (src: https://www.cloudflare.com/impact/)
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4mediumCloudflare matches 100% of its global network electricity with renewables, but supplies are sourced globally (via RECs), so it is a mix of EU and non-EU energy supplies rather than EU-only. (src: https://www.cloudflare.com/impact/)