🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Contabo

Germany · IaaS · https://contabo.com

Sovereignty score33.4%
Global (unweighted)33.2%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty34.4SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty41.9SEAL-1
SOV-3 Data & AI Sovereignty25.0SEAL-0
SOV-4 Operational Sovereignty29.3SEAL-1
SOV-5 Supply Chain Sovereignty32.4SEAL-1
SOV-6 Technology Sovereignty35.0SEAL-2
SOV-7 Security & Compliance Sovereignty36.0SEAL-1
SOV-8 Environmental Sustainability31.4SEAL-0

SOV-1 · Strategic Sovereignty 34.4% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control3. Mostly within the EU83/125SEAL-3highforeign_parent: Operating entity Contabo GmbH is German (Munich), but since June 2022 the majority shareholder is US PE firm KKR (Oakley Capital/management minority). Ultimate control sits outside the EU -> 'mostly within the EU' (opt3), not entirely. (src: https://www.oakleycapital.com/news-and-insights/oakley-capital-agrees-sale-of-contabo-and-follow-on-investment)
SOV-1.2Change of control risk2. Likely takeover/transfer to non-EU sovereign entity31/125SEAL-4highContabo is a PE portfolio company; KKR acquired it in 2022 as a financial sponsor whose exit path is a further sale/transfer. Change-of-control to a non-EU acquirer is likely (opt2).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap is set by the company and its US PE owners; customers have only voice-of-the-customer feedback channels, with no EU governance body controlling the roadmap (opt2).
SOV-1.4Financial independence from non-EU capital2. Mostly relying on non-EU funding31/125SEAL-4highMajority-owned and capitalised by US fund KKR; funding relies mostly on non-EU capital with EU/UK minority and management stakes (opt2).
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumHeadquarters and main engineering offices (Munich, Cologne, Nuremberg, Prague) plus original German data centres mean a majority of jobs/economic activity are in the EU (opt4). [all-SEAL-4 factor, kept]
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evidence of Contabo participating in EU strategic programs (Gaia-X, IPCEI-CIS); it positions itself as a commercial low-cost global host (opt1). [all-SEAL-4 factor, kept]
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumContabo markets on price/performance globally with no published action plan or governance aligned with EU digital-sovereignty industrial strategy (opt1). [all-SEAL-4 factor, kept]
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowNo own_stack: IaaS on its own German DCs but on commodity non-EU silicon under a US owner; service could continue temporarily per contract if a relationship were cut, but full autonomy is not demonstrated (opt3, seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 41.9% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highContracts are with Contabo GmbH under German law, but the US controlling parent (KKR) and non-EU data-centre footprint create mixed EU/non-EU jurisdictional exposure rather than exclusively EU law (opt2). (src: https://hrnxt.com/news/investment/acquisition/kkr-to-acquire-majority-stake-in-global-cloud-infrastructure-and-hosting-provider-contabo/49691/2022/06/08/)
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highNo immunity: the German entity offers GDPR contractual protections, but its US controlling shareholder (KKR) exposes the group to US extraterritorial pressure; mitigation clauses exist but exposure remains, with no SecNumCloud-style immunity (opt2). (src: https://hrnxt.com/news/investment/acquisition/kkr-to-acquire-majority-stake-in-global-cloud-infrastructure-and-hosting-provider-contabo/49691/2022/06/08/)
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent (US KKR) -> the group is within reach of US CLOUD Act/FISA compelled access for data held by group entities, with no published guarantee of refusal; compelled access without notification in specific cases (opt2, seal 1). (src: https://hrnxt.com/news/investment/acquisition/kkr-to-acquire-majority-stake-in-global-cloud-infrastructure-and-hosting-provider-contabo/49691/2022/06/08/)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowContabo serves ~150 countries; non-EU revenue is large but the German entity is not itself a US sanctions instrument toward EU MSs. Scored conservatively at the >50%-EU threshold given uncertainty (opt3).
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowCore operational IP is a standard hosting/virtualisation (KVM) stack maintained by German teams, but hardware, CPU and hypervisor-adjacent IP originates outside the EU; mixed origin (opt3). [all-SEAL-4 factor, kept]
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowSoftware IP is a mix of in-house/open-source under EU control and third-party components under non-EU law, with the US parent influencing the group; mixed law with some EU (opt3).

SOV-3 · Data & AI Sovereignty 25.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1mediumStandard low-cost VPS/dedicated servers do not offer customer-exclusive key management; encryption is primarily provider/OS-managed and the provider retains infrastructure access (opt2).
SOV-3.2Transparent data flows & access logs2. Basic incomplete logs50/200SEAL-1lowContabo provides a control panel and basic logging, but no comprehensive real-time customer-controlled data-access logs or independent auditability of provider access (opt2).
SOV-3.3Secure deletion & proof of erasure2. Manual confirmation only50/200SEAL-1lowDeletion on cancellation is per policy with at most manual confirmation; no published cryptographic proof or independent verification of irreversible erasure (opt2).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highNo eu_exclusive: customers may opt into an EU region, but Contabo runs a global network of ~23 DCs across Europe, the US and Asia under a US owner. Global default product with significant third-country reliance, not EU-exclusive (opt2, seal 0). (src: https://hrnxt.com/news/investment/acquisition/kkr-to-acquire-majority-stake-in-global-cloud-infrastructure-and-hosting-provider-contabo/49691/2022/06/08/)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2lowContabo offers GPU/AI compute on NVIDIA accelerators with licensed/foreign AI software rather than EU-origin models; mostly non-EU with chip dependency (opt2).

SOV-4 · Operational Sovereignty 29.3% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard IaaS with documented data export, snapshots/images, SSH/standard OS access and APIs; portability via standard documented methods (opt3, seal 4).
SOV-4.2Ability to operate without foreign dependencies2. Ops partially sourced within EU42/167SEAL-1mediumNo eu_ops: operations rely on globally distributed remote teams and a US owner; some ops are EU-sourced (German DCs/offices) but the team is not predominantly EU-confined (opt2).
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1lowContabo's teams work remotely worldwide alongside EU offices; the skill base is mixed with a meaningful non-EU share rather than majority-EU (opt2).
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2lowSupport is global 24/7 with teams worldwide; a meaningful share sits outside the EU, so support is mixed rather than majority-EU (opt2).
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation and knowledge management serve a global customer base and distributed teams; EU-only handling is not enforced (opt2).
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowReliant on non-EU hardware vendors and a US owner; if a critical supplier relationship were cut, service would degrade/stop with delay rather than continue autonomously (opt2).

SOV-5 · Supply Chain Sovereignty 32.4% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowContabo runs commodity enterprise hardware but does not publish a detailed bill of materials/provenance; only partial disclosure (opt2).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServers use foreign-designed and foreign-manufactured silicon (Intel/AMD CPUs, NVIDIA GPUs); manufacturing is foreign with only partial disclosure (opt2).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs, GPUs, NICs and BMCs comes from non-EU vendors; at most partial disclosure of embedded-code provenance (opt2). [all-SEAL-4 factor, kept]
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3lowNot foreign_core: the hypervisor/management core is KVM and open-source operated by Contabo's German/EU teams (not licensed Google/MS); core/essential parts maintained by EU teams (opt3, seal 3).
SOV-5.5Software build/release jurisdiction3. Non-EU control, EU execution72/143SEAL-3lowContabo's own management/control-panel software is built and operated by its German/EU teams (EU execution) but under a US-owned corporate group rather than independent EU control; EU execution under non-EU control (opt3).
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1lowCritical supply (CPUs, GPUs, network silicon) depends on non-EU vendors with limited documentation; mostly non-EU dependency in the critical hardware path (opt2).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers/processes are auditable under ISO 27001, but Contabo does not publish comprehensive supply-chain auditability covering critical hardware suppliers (opt2).

SOV-6 · Technology Sovereignty 35.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumContabo exposes a documented public API and standard OS/SSH access with broadly compatible tooling, but the control plane is proprietary; partial openness (opt3).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowCore services use open/standard interfaces (standard Linux/Windows images, S3-compatible object storage, standard networking) for many services but without a comprehensive open-standards policy across all (opt3).
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumContabo's control-panel/service software is proprietary and vendor-controlled; while it runs open-source components like KVM, its own service software is source-available/closed rather than openly governed (opt2, seal 2).
SOV-6.4Service architecture transparency2. Insight accessible during audits50/200SEAL-2lowArchitecture details are disclosed mainly through documentation/certification audits rather than rich public insight or customer co-creation (opt2).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo in-scope EU HPC stack: any HPC/GPU compute is EU-hosted on a foreign (NVIDIA/foreign CPU) stack rather than imported black-box with no controls; EU-hosted, foreign stack (opt2, seal 3).

SOV-7 · Security & Compliance Sovereignty 36.0% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumNo Common Criteria EAL or SecNumCloud/EUCS/C5 certification is published for the Contabo platform; security is evidenced via ISO 27001 (German DCs certified) only. Per the key, ISO 27001-only maps to opt2 'EAL1' (seal 1), consistent with the other ISO-only cluster members.
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumContabo offers Art. 28 GDPR DPAs and ISO 27001 certification (moderate compliance), but no comprehensive independently audited NIS2/DORA conformity is published (opt3). [all-SEAL-4 factor, kept]
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowWith a globally distributed team and 24/7 global operations, security operations/incident handling are hybrid EU/non-EU rather than EU-exclusive (opt2).
SOV-7.4Control over security monitoring/logging2. Customers receive periodic reports36/143SEAL-1lowCustomers get basic monitoring via the control panel and periodic information; no full customer-controlled, EU-stored, tamper-proof security logging (opt2).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowAs a German entity Contabo is subject to GDPR/NIS2-aligned breach-notification obligations (moderate disclosure); no published real-time CSIRT sharing (opt3).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowAs operator of its own data centres on commodity hardware, Contabo schedules and applies maintenance/patching with notice to customers; moderate maintenance autonomy (opt3, seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: independent audit access is limited to certification bodies (ISO 27001) rather than full audit by the contracting authority or any independent EU body (opt2, seal 1).

SOV-8 · Environmental Sustainability 31.4% · SEAL-0 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)2. PUE < 363/250SEAL-1mediumContabo targets PUE 1.3 only by 2030 and cites unspecified 'excellent' ratios via free-air/groundwater cooling; no verified current PUE below 1.5 is published (opt2). (src: https://contabo.com/en-us/sustainability/)
SOV-8.2Hardware reuse & recycling2. Basic circular practices63/250SEAL-0lowContabo references energy-efficient hardware choices but publishes no documented hardware reuse/recycling/circular-economy program; basic circular practices at most (opt2, seal 0).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumContabo completed its first GHG inventory in 2023 and commits to repeating it annually with SBTi-aligned targets; an annual report exists but is not yet EU-audited (opt3).
SOV-8.4Energy supplies2. Only EU energy supplies63/250SEAL-4mediumContabo states 100% of procured energy is certified green, but data centres span non-EU regions (US, Asia, UK, Australia), so energy is not exclusively EU-sourced; scored conservatively (opt2). [all-SEAL-4 factor] (src: https://contabo.com/en-us/sustainability/)