🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Oracle Cloud Infrastructure

United States · IaaS/PaaS · https://www.oracle.com/cloud

Sovereignty score44.5%
Global (unweighted)45.8%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty33.4SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty33.5SEAL-1
SOV-3 Data & AI Sovereignty70.0SEAL-1
SOV-4 Operational Sovereignty54.3SEAL-2
SOV-5 Supply Chain Sovereignty25.2SEAL-1
SOV-6 Technology Sovereignty40.0SEAL-2
SOV-7 Security & Compliance Sovereignty53.5SEAL-1
SOV-8 Environmental Sustainability56.3SEAL-2

SOV-1 · Strategic Sovereignty 33.4% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent: Oracle Corporation is US-headquartered (Austin, TX). EU Sovereign Cloud is run by EU-incorporated entities but the ultimate controlling parent is entirely non-EU -> entity control entirely outside the EU (opt1). Normalised to opt1 across the US-hyperscaler cluster (US-parented; same as AWS/Azure/GCP/IBM). (src: https://investor.oracle.com/home/default.aspx)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumOracle is a large, stable, publicly traded US corporation; takeover transferring control to another non-EU sovereign entity is very unlikely (kept at existing all-SEAL-4 choice).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumOCI roadmap is set centrally by Oracle US; EU customers have only voice-of-the-customer channels, no EU governance body controls the roadmap -> opt2.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highOracle is funded by US capital markets and a US parent; funding is almost entirely non-EU (opt1).
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumSubstantial EU operations and the EU Sovereign Cloud entities exist, but the bulk of value capture, IP and revenue accrues to the US parent -> some EU contribution (opt2).
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowOracle markets sovereignty offers aligned to EU policy but has no documented Gaia-X / IPCEI-CIS role; participation in EU strategic programs is limited (opt2).
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowOracle has a published EU sovereign-cloud action plan and dedicated EU entities but no EU-governed measured achievement framework -> existing action plan (opt2).
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2mediumNo own_stack (US-parent proprietary core software), so not full autonomy. But EU Sovereign Cloud entities own the EU hardware and data-centre leases and operate with EU-resident staff and processes separated from global Oracle, so the realm can continue temporarily per contractual agreement on a parent cut-off -> opt3 (seal 2). Not the PaaS-on-non-EU-hyperscaler halt case. (src: https://docs.oracle.com/en-us/iaas/Content/sovereign-cloud/eu-sovereign-cloud.htm)

SOV-2 · Legal & Jurisdictional Sovereignty 33.5% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highforeign_parent: contracts/operations involve EU law (EU entities, GDPR) and US law via the parent; jurisdiction is mixed EU/non-EU (opt2). (src: https://www.oracle.com/cloud/eu-sovereign-cloud/faq/)
SOV-2.2Extraterritorial laws exposure3. EU subsidiary with contractual protections84/167SEAL-1highNo certified immunity: US-parented group with EU subsidiaries and contractual/operational protections, but not SecNumCloud/EUCS-High and compellable via the parent -> EU subsidiary with contractual protections (opt3, seal 1). Consistent with the cluster. (src: https://www.oracle.com/cloud/eu-sovereign-cloud/faq/)
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent: as a US company Oracle is subject to CLOUD Act/FISA and could be compelled to provide access without notification in specific cases (opt2, seal 1) -> sets overall SEAL-1. (src: https://www.oracle.com/cloud/eu-sovereign-cloud/faq/)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2mediumSubject to US export controls; very large EU revenue (>50% of EU-region business EU-derived) and no targeted restrictions against EU member states evident -> opt3.
SOV-2.5Origin of IP2. Mostly outside the EU42/167SEAL-4highCore OCI and Oracle software IP is developed and owned in the US -> IP origin mostly outside the EU (opt2).
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP held by Oracle under US law, single country (opt1).

SOV-3 · Data & AI Sovereignty 70.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highOCI Vault customer-managed keys plus External Key Management (Thales HYOK) let customers hold keys/HSMs outside OCI so the provider cannot read data -> customer exclusive control (opt5).
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumOCI Audit/logging give customers full visibility over access and data flows, but logging is vendor-implemented and not independently real-time auditable -> full customer-controlled, not real-time (opt4).
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion performed per documented policy/contract but no independently verified cryptographic proof of irreversible erasure -> internal validation per policy (opt3).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: EU Sovereign Cloud keeps data exclusively in EU data centres (Frankfurt, Madrid) in a separate realm physically and logically isolated from all other Oracle realms, sharing no infrastructure and with no backbone network to other Oracle regions, no third-country fallback (opt5). Genuine differentiator vs Azure/GCP/IBM EU-by-default products. (src: https://docs.oracle.com/en-us/iaas/Content/sovereign-cloud/eu-sovereign-cloud.htm)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2highOCI AI runs on foreign accelerators (NVIDIA/AMD) with licensed/partner foundation models -> mostly non-EU, chip dependency (opt2).

SOV-4 · Operational Sovereignty 54.3% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumOCI provides documented data export and formal migration services/tooling, though not deployed on independent sovereign infrastructure (opt4).
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3higheu_ops: EU Sovereign Cloud operations delivered predominantly by EU-based teams (dedicated EU entities, EU-resident staff), though the broader stack still depends on the US parent -> ops predominantly EU-based (opt4).
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3highEU Sovereign Cloud staffed by EU-resident personnel with engineering/escalation ultimately tied to global Oracle -> majority EU, escalation abroad (opt3).
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3mediumSupport for EU Sovereign Cloud restricted to EU residents, with deeper escalations potentially handled by non-EU engineering -> majority in EU, non-EU escalations (opt3).
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge bases are global Oracle resources; EU-only handling not enforced for docs -> EU optional, not enforced (opt2).
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowEU Sovereign Cloud contracts restrict suppliers/operations to EU entities allowing temporary continuity under contract, but underlying hardware/chip suppliers remain non-EU -> continue temporarily per contract (opt3).

SOV-5 · Supply Chain Sovereignty 25.2% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1mediumServer hardware uses foreign components (US/Asian chips/parts); only partial public disclosure of physical component provenance (opt2).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumHardware manufactured outside the EU with only partial disclosure of manufacturing locations (opt2).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code (BMC, NIC, GPU firmware) from non-EU vendors with only partial disclosure of provenance (opt2).
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2highforeign_core: core OCI software is Oracle US proprietary tech with partial disclosure, not EU-maintained -> foreign origin, partial disclosure (opt2, seal 2).
SOV-5.5Software build/release jurisdiction2. EU control, non-EU execution36/143SEAL-1mediumCore build/release authority and execution sit with the US organisation; EU entities govern only some deployment -> EU control with non-EU execution is the closest fit (opt2).
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1mediumCritical services depend on non-EU vendors (Oracle US software, NVIDIA/AMD chips) with limited documentation of these single points of dependency -> mostly non-EU, undocumented (opt2).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers auditable via Oracle attestations, but the full supply chain (chips/firmware) is not openly auditable by customers -> some suppliers auditable (opt2).

SOV-6 · Technology Sovereignty 40.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumOCI exposes documented APIs and supports some open standards (Kubernetes, SQL) but much remains proprietary -> mixed/partial openness (opt3).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumOCI adopts open standards in parts of its core (Kubernetes, SQL, OCP hardware) but not as policy across all services -> partial core adoption (opt3).
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2highforeign_core: OCI control plane is closed-source US proprietary tech, though Oracle contributes/uses some open source (OpenJDK, Linux); source-available-with-strict-rights best fits -> opt2 (seal 2). Normalised to opt2 with AWS/Azure/GCP (same closed foreign-core profile).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumOracle publishes substantial architecture documentation and reference architectures -> some public insight without full openness (opt3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/AI supercluster capacity in EU regions is EU-hosted but uses a foreign hardware and software stack (NVIDIA/AMD, Oracle US software) -> EU-hosted, foreign stack (opt2).

SOV-7 · Security & Compliance Sovereignty 53.5% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumCerts held: BSI C5 plus ISO 27001 + SOC 1/2/3; no SecNumCloud / EUCS-High. Per key, a high-assurance EU/national cloud certification (BSI C5) maps to EAL3 -> opt4 (seal 3). Normalised across the cluster (all five hold C5). (src: https://www.oracle.com/de/corporate/c5-attestation-for-oracle-cloud-applications-blog/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highStrong GDPR/NIS2/DORA alignment with many independent attestations (ISO 27001, SOC, C5), but not fully independently audited to every regime -> partial compliance to most (opt4).
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1mediumOCI security operations run on a global SOC model; even for EU Sovereign Cloud, incident handling can involve hybrid EU/non-EU teams and global threat intel -> hybrid EU/non-EU (opt2).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get full direct access to security logging via OCI Logging/Audit, and EU Sovereign Cloud stores logs in EU -> full direct access, logs stored in EU (opt4).
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumGDPR/NIS2/DORA-aligned incident disclosure with contractual monitored notification SLAs, but not full real-time CSIRT sharing -> partial compliance, monitored flow, SLAs, opt4 (seal 3). Normalised across the cluster.
SOV-7.6Maintenance autonomy2. Limited autonomy (vendor schedules)36/143SEAL-1lowMaintenance/patching of the managed platform is controlled by Oracle; customers have limited autonomy over the platform maintenance window -> limited autonomy (opt2).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1highNo audit_rights: independent audit limited to third-party certification bodies and access to attestation reports; customers cannot perform fully independent audits -> limited independent access (opt2, seal 1).

SOV-8 · Environmental Sustainability 56.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowOracle pursues PUE improvements (liquid cooling, OCP designs) with a sustainability roadmap, reporting PUE as low as ~1.15 at some sites; conservatively the 'PUE < 1.5 + roadmap' tier (opt3, seal 4). (src: https://www.oracle.com/sustainability/green-cloud/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented hardware reuse/recycling and circular practices program, but not an EU-certified lifecycle -> documented program (opt3).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumOracle publishes annual sustainability/citizenship reporting on emissions/energy, but not under an EU-specific audited methodology -> annual report (opt3).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumOracle reports 100% renewable energy across its European cloud regions -> only EU energy supplies (high renewable) (opt4) (kept at existing all-SEAL-4 choice). (src: https://www.oracle.com/sustainability/green-cloud/)