🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

iomart

United Kingdom · IaaS/PaaS · https://www.iomart.com

Sovereignty score30.6%
Global (unweighted)31.3%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty26.2SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty40.0SEAL-0
SOV-4 Operational Sovereignty29.3SEAL-0
SOV-5 Supply Chain Sovereignty25.2SEAL-1
SOV-6 Technology Sovereignty30.0SEAL-2
SOV-7 Security & Compliance Sovereignty43.1SEAL-1
SOV-8 Environmental Sustainability43.8SEAL-1

SOV-1 · Strategic Sovereignty 26.2% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highiomart Group plc is headquartered in Glasgow, Scotland and incorporated in the UK, operating wholly-owned UK data centres only (no EU/EEA footprint); the UK is a third country (not EU/EEA), so the legal entity is entirely outside the EU -> SOV-1.1 opt1 (seal 1). (src: https://www.iomart.com/our-data-centres)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumAn LSE/AIM-listed independent plc could in principle be acquired, but there is no current evidence of an imminent non-EU sovereign takeover; takeover to a non-EU sovereign entity is unlikely rather than very unlikely.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowAs a commercial UK provider, roadmap influence is via standard customer feedback channels; no EU-actor governance bodies exist.
SOV-1.4Financial independence from non-EU capital3. Balanced mix of EU and non-EU funding63/125SEAL-4lowFunding comes from UK public-market equity and UK banking facilities (non-EU); investor base is global, so neither clearly EU- nor clearly non-EU-dominated. Treated as a balanced/indeterminate mix, but the funding is structurally non-EU.
SOV-1.5EU economic contribution1. Minimal0/125SEAL-4mediumiomart's operations, data centres, employment and revenue are concentrated in the UK with no EU footprint; EU economic contribution is minimal.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4highNo evidence of participation in EU strategic programs such as Gaia-X or IPCEI-CIS.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4highA UK provider aligned with UK government targets shows no evidence of alignment with EU industrial strategies.
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowforeign_core (VMware/Microsoft/NVIDIA core, no own_stack): iomart owns its UK data centres and dark-fibre network so under contract workloads could continue temporarily, but the platform depends on non-EU VMware/Broadcom + Microsoft software supply chains -> not fully autonomous, SOV-1.8 opt3 (seal 2). Normalised with the VMware-core cluster members (Pulsant). (src: https://www.iomart.com/our-data-centres)

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highno EU jurisdiction: contract under UK (third-country) law only -> SOV-2.1 opt1 (seal 1); EU law does not exclusively govern the service. (src: https://www.iomart.com/about-us/our-accreditations)
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1mediumno immunity (UK entity, no SecNumCloud/EUCS-High, exposed to UK Investigatory Powers Act + India processing via Atech) -> SOV-2.2 opt2 (mitigation clauses, exposure remains, seal 1).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1mediumno immunity: subject to non-EU compelled access under the UK Investigatory Powers Act (compelled access without notification in specific cases) -> SOV-2.3 opt2 (seal 1); cannot commit to always reject. Normalised across the UK cluster (all subject to UK IPA).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowno eu_exclusive: as a non-EU (UK) provider with UK-majority revenue (<50% in the EU) the offer is not shielded from non-EU export controls affecting EU citizens/orgs; no EU-MS-specific restriction identified -> SOV-2.4 opt2 (seal 1). Normalised with the UK cluster.
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4mediumCore platform IP is foreign: VMware Cloud Foundation (US/Broadcom), Microsoft Azure, NVIDIA; iomart's own IP is UK (non-EU). Origin of IP is entirely outside the EU.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3mediumIP holders (Broadcom/VMware, Microsoft, NVIDIA in the US; iomart in the UK) are governed by non-EU law, predominantly a single country (US) plus UK.

SOV-3 · Data & AI Sovereignty 40.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowAs a managed VMware/private-cloud provider, encryption is typically available with provider involvement; customer-managed keys are not the default and the provider generally retains override capability.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowEnterprise managed-hosting provides access logs and reporting, but visibility is largely vendor-controlled and not real-time independently auditable by the customer.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001-certified operations imply documented deletion per policy, but no published independently verifiable proof-of-erasure mechanism.
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highno eu_exclusive: data sits in UK data centres (third country vs EU/EEA) plus offshore Atech/India -> SOV-3.4 opt2 (partly EU, significant third-country reliance, seal 0). This is the decisive SEAL-0 gate. (src: https://www.iomart.com/our-data-centres)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2mediumforeign AI stack: Private AI Cloud on VMware + NVIDIA (licensed models, foreign chips) -> SOV-3.5 opt2 (seal 2).

SOV-4 · Operational Sovereignty 29.3% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4lowBuilt on VMware/standard virtualization with documented data-export methods and managed-migration services typical of enterprise hosting.
SOV-4.2Ability to operate without foreign dependencies2. Ops partially sourced within EU42/167SEAL-1mediumOperations are predominantly UK-based (non-EU) with offshore delivery in India and Poland via Atech; from an EU perspective ops are only partially within the EU (Poland) and not EU-controlled.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumEngineering and support staff are mainly UK-based (non-EU) plus offshore India/Poland; the EU-resident skilled workforce is a minority.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2mediumSupport is UK-centric with offshore (India) escalation; the majority of support staff sit outside the EU/EEA.
SOV-4.5Documentation & knowledge transfer1. Global/non-EU exposure0/167SEAL-0lowDocumentation and knowledge are managed in the UK with global/offshore exposure; no EU-only knowledge-transfer guarantee.
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowiomart owns its facilities and could continue temporarily, but it depends on subcontracted suppliers (VMware/Broadcom, Microsoft) under contractual terms rather than full autonomy.

SOV-5 · Supply Chain Sovereignty 25.2% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware component provenance is only partially disclosed; servers and chips are foreign-sourced (e.g. NVIDIA, x86) with no EU-certified provenance.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowCompute hardware is of foreign origin with limited disclosure; not built or designed by EU teams.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code provenance is at best partially disclosed and originates from foreign hardware vendors.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumforeign_core: core platform is licensed VMware Cloud Foundation + Microsoft Azure (US tech) with UK management layered on -> SOV-5.4 opt2 (foreign origin, partial disclosure, seal 2 ceiling).
SOV-5.5Software build/release jurisdiction2. EU control, non-EU execution36/143SEAL-1lowSoftware build/release of the underlying platform is controlled and executed by non-EU vendors (US); iomart's own UK builds are also non-EU. Best fit is non-EU control with limited EU execution.
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1mediumCritical services depend heavily on non-EU vendors (Broadcom/VMware, Microsoft, NVIDIA) with limited public documentation of mitigations; mostly non-EU dependency.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers/certifications are auditable via ISO frameworks, but the full critical supply chain is not independently auditable.

SOV-6 · Technology Sovereignty 30.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2lowVMware-based platform offers standard APIs and partial openness, but is not open-by-default; portability is partial.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowPartial adoption of open/industry standards (VMware, common virtualization and storage formats) rather than a policy across all core services.
SOV-6.3Open source availability1. Fully closed-source, vendor-controlled0/200SEAL-2mediumforeign_core: core platform (VMware, Microsoft Azure) is closed-source vendor-controlled tech -> SOV-6.3 opt1 (fully closed-source, seal 2 ceiling); iomart is not open-source-centric.
SOV-6.4Service architecture transparency2. Insight accessible during audits50/200SEAL-2lowArchitecture insight is provided mainly under audit/customer engagement (ISO-certified) rather than broadly published.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumAI/HPC is EU-region-absent and built on foreign (NVIDIA) accelerators and VMware stack hosted in the UK; the closest fit is hosted-but-foreign-stack, noting hosting is UK not EU.

SOV-7 · Security & Compliance Sovereignty 43.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumcerts = ISO 27001 (+ISO 20000/9001/14001/50001, PCI DSS L1, Cyber Essentials), no SecNumCloud/EUCS/C5/ENS-High -> below the 'ISO 27001 + SOC 2 + C5 = EAL2' bar; maps to ISO-27001-only -> SOV-7.1 opt2 EAL1 (seal 1). (src: https://www.iomart.com/about-us/our-accreditations)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumStrong compliance posture (ISO 27001, PCI DSS L1, UK GDPR) but as a UK entity it is not within the EU NIS2/DORA regime; partial compliance to most EU regulations.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSOC and incident handling are UK-based with offshore (India) security operations via Atech; hybrid EU/non-EU at best, and UK is non-EU.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get monitoring portals/reports typical of managed hosting, but logs are stored in UK (non-EU) and control is partly provider-retained.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowIncident disclosure aligns with UK GDPR / ISO 27001 breach-notification practices (GDPR/NIS2-aligned in substance) without real-time CSIRT sharing.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowAs operator of its own infrastructure iomart has moderate maintenance autonomy (scheduled with notice/testing), though dependent on vendor patch cycles for VMware/Microsoft.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowno audit_rights (no sovereign-tender commitment): auditability only via ISO/PCI certification bodies, not full audit by the contracting authority or independent EU bodies -> SOV-7.7 opt2 (seal 1).

SOV-8 · Environmental Sustainability 43.8% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)2. PUE < 363/250SEAL-1highReported average PUE is around 1.9 across sites, which is below 3 but well above the 1.5 efficiency threshold -> SOV-8.1 opt2 (seal 1). (src: https://www.iomart.com/katrick-technologies)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowISO 14001/50001 certified with carbon-reduction plan implies a documented hardware lifecycle/recycling program, but not an EU-certified circular-economy program.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumiomart publishes a Carbon Reduction Plan and ESG reporting annually; not audited to a detailed EU methodology.
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4mediumData centres run on 100% REGO-certified renewable energy plus onsite solar, but the supply is UK (non-EU); treated as a traceable mix of EU/non-EU supplies since the high-renewable EU-only options do not apply to a UK grid. (src: https://www.iomart.com/katrick-technologies)