🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

netcup

Germany · IaaS · https://www.netcup.com

Sovereignty score61.6%
Global (unweighted)61.7%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty61.6SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty87.4SEAL-2
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty74.9SEAL-3
SOV-5 Supply Chain Sovereignty46.6SEAL-1
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty57.1SEAL-1
SOV-8 Environmental Sustainability56.3SEAL-2

SOV-1 · Strategic Sovereignty 61.6% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (netcup GmbH, Karlsruhe DE, owned by Anexia Holding GmbH, Austria; both EU, no non-EU parent) -> SOV-1.1 opt4. (src: https://www.netcup.com/en/about-netcup/certifications)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumPrivately held by the EU-based Anexia group (founder Alexander Windbichler, Austria) with no external/non-EU capital evident; a non-EU takeover is unlikely though, being part of an acquirable private group, slightly less certain than a founder-locked firm.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap is set internally within the Anexia group with customer feedback channels (support, community), but there is no formal EU-actor co-governance body -> opt2 (key: no governance body).
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumFunded internally within the privately held EU-based Anexia group with no evident external/non-EU investors; financing is entirely EU-based.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4highHQ, workforce and primary data centres are in Germany and Austria; the large majority of economic activity is in the EU though some revenue/colocation arises in the US and Singapore.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4lowPositioned as a GDPR-compliant EU sovereign-hosting alternative but with no documented formal participation in Gaia-X or IPCEI-CIS strategic programs.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets an explicit 'digital sovereignty / European data protection' proposition consistent with EU industrial goals, amounting to an action plan rather than measured, governed achievement.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2mediumown_stack partial: EU-owned/Anexia data centres, EU staff and FOSS allow sourcing alternatives / internalising key functions, but no vertically-integrated full-autonomy claim and residual non-EU hardware -> opt4 (seal 2), not opt5.

SOV-2 · Legal & Jurisdictional Sovereignty 87.4% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highGerman GmbH within an Austrian (EU) group, EU data centres for the core offering; service governed exclusively under EU/German law -> opt3. (src: https://www.netcup.com/en/about-netcup/certifications)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumStructural shielding (no US/non-EU parent) but immunity NOT certified (no SecNumCloud 3.2 / EUCS-High) and parent Anexia has US offices/data centres -> opt4 'legal structures shielding' (seal 2), not opt5 verified immunity. (src: https://www.netcup.com/en/about-netcup/certifications)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent: netcup is German/Austrian (EU)-owned, not subject to US CLOUD Act/FISA/PRC law; commits to refuse foreign-authority access on its EU offer -> opt5. (src: https://www.netcup.com/en/about-netcup/certifications)
SOV-2.4Export control restrictions4. Part of offer shielded from restrictions towards EU MSs125/167SEAL-3lowEU (DE/AT) provider with no export-control restrictions toward EU member states or citizens; consistent with the pure-EU cluster, the offer is shielded from restrictions toward EU MSs -> opt4 (seal 3).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumOperational/control-plane software and IP are EU-controlled in-house; physical hardware/chip IP (AMD EPYC etc.) is foreign, so IP is mostly but not fully EU-origin.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4highThe IP-holding entity is the German GmbH within an Austrian group, fully under EU law -> opt5.

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowCustomers can self-encrypt with their own keys and have full root access; absent confidential-compute/HSM by default, the provider operating the infrastructure could technically read unencrypted data -> opt4.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowAccess/usage logs and audit records exist (ISO 27001/27701 scope) but oversight is vendor-controlled rather than real-time independently auditable by the customer -> opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows documented ISO-certified policy validated internally/by TUV, but without per-request independently verified cryptographic proof of erasure -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1highNo eu_exclusive scoped offer: core is EU-default (Nuremberg, Vienna, Amsterdam) but Manassas (US) and Singapore are customer-selectable within the same product -> opt4 'EU by default, tightly controlled exceptions' (seal 1), not opt5. (src: https://www.netcup.com/en/about-netcup/server-locations)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumNo black-box managed AI service; customers self-deploy open-source/auditable models EU-hosted on rented compute (EU-led/EU-hosted AI), with only the GPU/accelerator hardware being foreign -> opt4 'EU-led AI, foreign accelerators' (consistent with the cluster's open-model-on-foreign-GPU providers).

SOV-4 · Operational Sovereignty 74.9% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandard documented data export plus full root/SSH/VNC access, KVM-based portable images and a public API/CLI with no proprietary lock-in formats; informal migration assistance available -> opt4.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops: infrastructure operated by netcup's own German/Austrian teams; ops predominantly EU-based though the Anexia group maintains some non-EU (US) offices -> opt4 (seal 3).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering and operations skills are concentrated in Germany and Austria; the majority of staff are EU-based with minor non-EU presence within the group -> opt4 (seal 3).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport is delivered by netcup's own German/Austrian-based staff in German and English; no documented security clearances -> opt4 (seal 3).
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation and help-centre/knowledge repositories are maintained in-house within the EU (Germany/Austria), primarily EU-only -> opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowCore suppliers/facilities for the EU offering are EU-based; non-EU colocation is non-critical to the EU service and the group can source alternatives or internalise functions -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 46.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1mediumServer components rely on foreign chips/parts (AMD EPYC, branded hardware) with only partial public disclosure of component origin -> opt2.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowBranded server hardware integrated by EU teams on foreign chip designs, with EU audit rights via ISO-certified data centres; not documented as building servers fully in-house -> opt3 (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs, NICs and BMCs comes from foreign vendors (AMD etc.) with only partial provenance disclosure -> opt2.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: control/management plane is developed and maintained in-house by the EU-based group with heavy FOSS use; large majority of the stack is EU-maintained -> opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware is developed, built and released under EU control and execution from Germany/Austria -> opt4 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumA few non-EU dependencies are critical (chip vendor AMD with no EU substitute) within an otherwise EU-controlled and documented stack -> opt3 (seal 2).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers are auditable via the ISO 27001 scope, but full critical-supply-chain auditability (especially chip vendors) is not demonstrated -> opt2.

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, broadly compatible interfaces: public API/CLI, KVM-based portable images and standard Linux OS choice with full customer control -> opt4 (seal 3).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumAdopts common open standards/protocols (KVM, standard Linux images, SSH/VNC, DNS) across core services but no all-core policy -> opt3 (seal 2).
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowHeavy FOSS use and customers can run open source, but netcup's own control/management platform is proprietary and not open-sourced (not foreign_core) -> opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public architecture insight via extensive help-centre/docs and status pages, but the core platform internals are kept private -> opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo dedicated sovereign HPC offering; no in-scope HPC -> opt2 (EU-hosted/foreign-stack treated as seal 3 per key, not the imported black-box seal-0 option).

SOV-7 · Security & Compliance Sovereignty 57.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1highCerts held are ISO 27001 (since 2023, annual TUV Nord audit) + ISO 27701 + ISO 9001 + ISO 14001 only; no SecNumCloud/C5/EUCS/Common Criteria EAL -> ISO-only maps to opt2 'EAL1' (seal 1). (src: https://www.netcup.com/en/about-netcup/certifications)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highGDPR-compliant with Art. 28 DPAs and certified to ISO 9001, ISO/IEC 27001 (annual TUV Nord audit) and ISO 27701; aligns with most EU requirements without explicit full NIS2/DORA attestation -> opt4.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and incident response are handled by netcup's own EU-based (Germany/Austria) teams; no documented ENISA/CSIRT real-time sharing -> opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get direct access to their own monitoring/logs with infrastructure logs stored in EU data centres; no claim of immutable tamper-proof customer logging -> opt4 (seal 3).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumAs a GDPR processor it follows GDPR/NIS2-aligned breach-disclosure obligations; not documented as full real-time CSIRT sharing with SLAs -> opt3 (seal 2).
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4lownetcup controls its own maintenance and can deploy patches independently on its own stack without third-party vendor scheduling -> opt4.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNo audit_rights: independent assurance exists only via ISO 27001/27701/9001 TUV certification bodies; no full independent audit of the proprietary platform by any entity -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 56.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowEmphasises energy-efficient hardware and optimised cooling and is ISO 14001 certified, but no specific PUE figure is published; treated as efficient (<1.5) with a roadmap -> opt3. (src: https://www.netcup.com/en/about-netcup/green-electricity-energy-efficiency)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented environmental/efficiency practices including hardware reuse under ISO 14001, amounting to a documented program rather than an EU-certified circular lifecycle -> opt3 (seal 3).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowPublishes sustainability/green-energy information at roughly annual-report level under ISO 14001, but not an independently EU-audited environmental methodology -> opt3 (seal 2).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumPowered by renewable EU energy with own generation (Austrian hydropower covering ~1/3 of the Vienna DC plus ~1 MW solar at Jaidhof); high renewable share from EU supplies -> opt4. (src: https://www.netcup.com/en/about-netcup/green-electricity-energy-efficiency)