🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

plusserver

Germany · IaaS/PaaS · https://www.plusserver.com

Sovereignty score67.4%
Global (unweighted)66.2%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty73.0SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty75.0SEAL-2
SOV-3 Data & AI Sovereignty70.0SEAL-1
SOV-4 Operational Sovereignty66.7SEAL-3
SOV-5 Supply Chain Sovereignty43.1SEAL-1
SOV-6 Technology Sovereignty75.0SEAL-3
SOV-7 Security & Compliance Sovereignty64.3SEAL-1
SOV-8 Environmental Sustainability62.5SEAL-2

SOV-1 · Strategic Sovereignty 73.0% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: plusserver GmbH is incorporated and headquartered in Cologne, Germany (HRB 84977), operating entirely within the EU -> opt4. (src: https://www.plusserver.com/en/company/)
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4mediumOwned by UK-based PE firm BC Partners (non-EU) since 2017 and actively shopped for sale (Jefferies mandate, loan maturity); a transfer to a non-EU sovereign owner is a realistic possibility -> opt3.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumFounding member of Gaia-X and SCS contributor with open governance via the Sovereign Cloud Stack community; EU actors participate in roadmap governance bodies -> opt3.
SOV-1.4Financial independence from non-EU capital3. Balanced mix of EU and non-EU funding63/125SEAL-4mediumFinancial sponsor is UK PE firm BC Partners (non-EU), while operating business, revenues and reinvestment are German; effectively a balanced mix of EU and non-EU capital -> opt3.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, data centers, employees and revenue base are fully in Germany; economic contribution is overwhelmingly within the EU -> opt5.
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4highFounding member of Gaia-X and delivered the first Gaia-X-compatible cloud (pluscloud open) on the Sovereign Cloud Stack; strong participation in EU strategic programs -> opt4.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumClear, sustained alignment with EU digital-sovereignty industrial strategy (Gaia-X, SCS, 'made in Germany' sovereign cloud) with dedicated governance and measured delivery -> opt3.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2mediumown_stack partial: German-operated, built on open-source SCS/OpenStack so plusserver can source alternatives or internalise functions, but a real non-EU hardware dependency prevents full autonomy -> opt4 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 75.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highA German GmbH with German data centers operating fully in the German legal space; contractual and operational jurisdiction is exclusively EU law -> opt3. (src: https://www.plusserver.com/en/company/data-centers/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with structural shielding (German GmbH, German DCs) but no certified immunity (no SecNumCloud/EUCS-High) and a non-EU UK parent owner -> legal structures shielding, opt4 (seal 2).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo US/CN parent; not subject to CLOUD Act/FISA/PRC law (UK PE owner cannot compel German-held data); plusserver states data is not subject to the CLOUD Act and responds only under EU/German legal process -> opt5. (src: https://www.plusserver.com/en/company/certificates-and-attestations/)
SOV-2.4Export control restrictions4. Part of offer shielded from restrictions towards EU MSs125/167SEAL-3lowGerman provider with the large majority of revenue in the EU and no evident export-control restrictions toward EU member states; sovereign offer shielded toward EU MSs -> opt4.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumCore platform leans on open-source software (OpenStack, Kubernetes, SCS) with EU contributions, but underlying hardware and some component IP originate outside the EU; mixed within/outside -> opt3.
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowSoftware stack is largely open-source/community-governed and operated under German law, but foreign hardware/firmware IP sits under non-EU jurisdictions; mixed law with some EU -> opt3.

SOV-3 · Data & AI Sovereignty 70.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowOpenStack-based platform supports customer-managed keys (Barbican/KMS) giving customers primary control, but as managed infrastructure the provider can technically still reach data; no end-to-end zero-access guarantee -> opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowOpenStack and BSI C5 controls provide customer-accessible logging and audit evidence, but real-time independent auditability of all provider data flows is not documented -> opt4.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowBSI C5 and ISO 27001 mandate documented deletion procedures validated by policy, but no published cryptographic proof-of-erasure offered to customers -> opt3.
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1highNo eu_exclusive guarantee: data resides by default in four certified German data centers (GDPR-compliant) but this is EU-by-default with tightly controlled exceptions, not a contractual no-third-country-fallback exclusivity -> opt4 (seal 1). (src: https://www.plusserver.com/en/company/data-centers/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumplusAI is an open-source, German-hosted sovereign AI platform under German law, but it runs on foreign accelerators (Nvidia/AMD GPUs); EU-led AI on foreign accelerators -> opt4.

SOV-4 · Operational Sovereignty 66.7% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumBuilt on open standards (OpenStack APIs, Kubernetes) with documented export methods, and plusserver markets migration/onboarding services reducing lock-in -> opt4.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops: operations are predominantly delivered by German/EU teams from German data centers; foreign hardware vendors remain a dependency but not for day-to-day operation -> opt4.
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3lowEngineering and operations skills are based in Germany (majority EU), with foreign-vendor escalation for hardware-specific issues; no published security-clearance regime -> opt3.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport is delivered from Germany via German phone lines and German-language support; effectively all support staff in the EU, no published clearance program -> opt4.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation (docs.plusserver.com) is German/EU-primary, with some upstream open-source/vendor materials hosted abroad; EU-primary with non-EU fallback -> opt3.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowOpen-source stack and EU operations mean plusserver can source alternatives or internalise critical functions if a non-EU supplier is cut off, though hardware substitution would take time -> opt4.

SOV-5 · Supply Chain Sovereignty 43.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1mediumHardware vendors (HPE, NetApp, Intel, Nvidia, AMD, Juniper) are disclosed at a high level, but detailed component provenance is only partially disclosed -> opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServers, storage, networking and chips are manufactured by non-EU OEMs (US/Asian origin); German assembly/operation does not change the foreign manufacturing origin -> opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode for the foreign hardware (BIOS, NIC, GPU, storage controllers) is vendor-controlled with only partial disclosure -> opt2.
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNo foreign_core: core platform software is open-source (OpenStack, Kubernetes, SCS) with plusserver/EU teams maintaining and integrating the essential parts -> opt3 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowAs a German operator deploying the SCS/OpenStack stack, build and release of the operated platform are controlled and executed within the EU, though upstream open-source releases originate globally -> opt4.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumA few non-EU vendors (chip/server OEMs) sit in critical infrastructure paths; dependencies are documented but cannot be fully removed -> opt3.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowBSI C5 and ISO 27001 audits cover critical suppliers, providing audit rights over the most important parts of the supply chain, but not all suppliers -> opt3.

SOV-6 · Technology Sovereignty 75.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highpluscloud open is open-by-default on OpenStack/Kubernetes/SCS standard APIs, explicitly designed for portability and avoiding vendor lock-in -> opt5.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3highOpen standards (OpenStack, Kubernetes, S3-compatible, SCS reference standards) underpin most core services as a deliberate policy -> opt4.
SOV-6.3Open source availability5. Fully open-source, independent/EU governance200/200SEAL-4highNo foreign_core: pluscloud open is fully open source on the community-governed Sovereign Cloud Stack with a public GitHub (pluscloudopen) and EU/independent governance -> opt5.
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumOpen-source codebase, public documentation and SCS reference architecture provide a large corpus of public insight into the service architecture -> opt4.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/GPU capacity is EU-hosted in German data centers but runs on foreign (Nvidia/AMD/Intel) hardware and stack; EU-hosted foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 64.3% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumCerts held are BSI C5 Type II + ISO 27001 + ISAE 3000/IDW PS 9.860.1; per the key, BSI C5 is a high-assurance EU/national cloud certification mapping to EAL3 -> opt4 (seal 3). (src: https://www.plusserver.com/en/company/certificates-and-attestations/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumDemonstrably GDPR-compliant with BSI C5 Type II, ISO 27001 and ISAE 3000/IDW PS 9.860.1 attestations; as an EU critical provider subject to NIS2, though full DORA conformance is not separately evidenced -> opt4.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and incident handling are run by German teams from German data centers under EU regulation; EU lifecycle, though formal ENISA/CSIRT real-time sharing is not explicitly documented -> opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowBSI C5/ISO 27001 controls give customers direct access to monitoring and logs stored in German (EU) data centers; tamper-proof immutability not explicitly published -> opt4.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure aligns with GDPR and NIS2 obligations applicable to the German entity; moderate GDPR/NIS2-aligned -> opt3.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperating an open-source stack in its own data centers, plusserver has moderate maintenance autonomy with notice and testing windows, constrained by upstream/vendor patches -> opt3 (seal 4).
SOV-7.7Auditability3. Partial independent control72/143SEAL-1lowNo tender-grade audit_rights: independent audits exist via BSI C5/ISO 27001 bodies and customers get partial independent control, but full audit by any entity is not offered (no SecNumCloud) -> opt3 (seal 1).

SOV-8 · Environmental Sustainability 62.5% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern certified German data centers with an energy-efficiency program (DIN EN 16247 audit) indicate PUE below ~1.5 with an improvement roadmap, though no audited sub-1.3 figure is published -> opt3. (src: https://www.plusserver.com/en/perspektiven/nachhaltige-it)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowSustainability program implies a documented hardware reuse/recycling approach, but no EU-certified circular-economy lifecycle is evidenced -> opt3.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowplusserver publishes sustainability/environmental information (CO2 savings, energy audits) consistent with regular reporting, but not independently EU-audited per a detailed methodology -> opt3.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highplusserver states it relies 100% on renewable (green) electricity in its German data centers, saving ~8,000 tons of CO2 per year -> opt5. (src: https://www.plusserver.com/en/perspektiven/nachhaltige-it)