Basics
What is the european.cloud definition of a cloud provider?
For the purposes of european.cloud, I define a cloud provider as a platform that offers at least managed Kubernetes, managed databases, storage, networking, and some support for infrastructure-as-code (IaC). A pure server hosting provider does not meet this definition, which is why Hetzner has not been included so far. I am not 100% strict with this definition, but it serves as a useful guideline.
What is a European cloud provider?
A European cloud provider is a cloud provider with it’s headquarter in Europe. Most of the providers listed so far on european.cloud are EU based, plus one provider from Switzerland and one from Iceland. Both Switzerland and Iceland are so closely integrated with the European Union and have more or less aligned laws that I thought it makes sense to include them.
There is a fine line between European cloud providers that have worldwide data centers, especially in the US, and those that don’t. A PoP (Point of Presence) in the US makes the company vulnerable to the US CLOUD Act. A famous case with worldwide attention has been the dispute between a Canadian court and the European cloud provider OVHcloud. OVH has a presence in Canada. Based on this, the court demanded of OVH access to user data stored in France and other countries.
You can filter providers by data center locations on the european.cloud homepage.
There is a fine line between European cloud providers that have worldwide data centers, especially in the US, and those that don’t. A PoP (Point of Presence) in the US makes the company vulnerable to the US CLOUD Act. A famous case with worldwide attention has been the dispute between a Canadian court and the European cloud provider OVHcloud. OVH has a presence in Canada. Based on this, the court demanded of OVH access to user data stored in France and other countries.
You can filter providers by data center locations on the european.cloud homepage.
How can I get listed on european.cloud?
To get listed, contact me and I will provide some details. Please read What is the european.cloud definition of a cloud provider? to get a feeling for who gets listed on european.cloud.
Be aware that I am not making any promises. Both with regards to whether you can appear on european.cloud at all and also with regards to timeline. I am doing this on the side.
Be aware that I am not making any promises. Both with regards to whether you can appear on european.cloud at all and also with regards to timeline. I am doing this on the side.
How are cloud providers ranked on european.cloud?
I am not ranking providers on european.cloud; the order on the home page is arbitrary.
Which one is most suitable depends on your specific requirements and preferences. For instance, if you need providers with certain local certifications – such as European cloud providers with SecNumCloud certification – only a few may qualify, which narrows the selection.
Similarly, if you are looking for an easy-to-use application runtime platform, only a few providers are fulfilling the criteria.
Instead of ranking myself, I want to give you a toolbox to get an overview and narrow down the search for a suitable European cloud provider.
Which one is most suitable depends on your specific requirements and preferences. For instance, if you need providers with certain local certifications – such as European cloud providers with SecNumCloud certification – only a few may qualify, which narrows the selection.
Similarly, if you are looking for an easy-to-use application runtime platform, only a few providers are fulfilling the criteria.
Instead of ranking myself, I want to give you a toolbox to get an overview and narrow down the search for a suitable European cloud provider.
What does cloud sovereignty mean?
To be sovereign means to be in control. As a business, any supplier relationship I cannot walk away from sharply limits my sovereignty and leaves me vulnerable. A textbook example of asymmetric dependency is the relationship many companies have with Microsoft, which can more or less dictate Microsoft 365 prices at will, leaving customers no choice but to accept them.
What was once a purely business concern has intensified in recent years, as the economy has become a political battleground and dependencies on energy, defense, and digital infrastructure are increasingly weaponized.
Sovereignty is of strategic importance in a time when geopolitical players are no longer interested in the rules-based order, the great power competition is the new normal and multilateral institutions face sustained pressure.
What was once a purely business concern has intensified in recent years, as the economy has become a political battleground and dependencies on energy, defense, and digital infrastructure are increasingly weaponized.
Sovereignty is of strategic importance in a time when geopolitical players are no longer interested in the rules-based order, the great power competition is the new normal and multilateral institutions face sustained pressure.
What is the difference between a European cloud and a US cloud?
A European cloud is operated by an EU-headquartered company with data centres in Europe, governed by EU law and the GDPR. A US cloud is run by an American provider subject to US legislation (e.g., CLOUD Act), even when offered as a “sovereign” European variant from EU data centres.
Is AWS / Azure / Google Cloud a European cloud?
No. All three players are offering “sovereign” versions of their platforms. But we should not be mistaken. These constructs are still owned by the US parent company and (generally) are still subject to US CLOUD Act. Needless to say that the money is also flowing to the US parent.
A European cloud is one that is headquartered in Europe, under European jurisdiction, and where the revenue stays in Europe.
A European cloud is one that is headquartered in Europe, under European jurisdiction, and where the revenue stays in Europe.
Comparison & Selection
Which is the best European cloud provider?
There is no single best provider — it depends on your needs. To give an impression, for broad portfolios and managed AI, consider Scaleway or OVHcloud. For the DACH enterprise market, STACKIT and IONOS are strong choices. UpCloud has great coverage in the Nordics and excels in developer tooling.
Consider also how cloud providers are ranked on european.cloud.
Consider also how cloud providers are ranked on european.cloud.
What is the cheapest European cloud provider?
There is no single cheapest provider, as pricing depends on the services, region, and workload. For entry-level VMs, Aruba, OVHcloud, and IONOS typically offer competitive pricing.
In general, European cloud providers offer competitive pricing. They are neither generally more expensive nor generally less costly than their US counterparts. One thing that is fair to say on a general level is that pricing with European providers is more transparent with less hidden or not immediately visible cost, e.g. for traffic.
Always compare total cost — including egress, storage, and support — rather than headline compute prices alone.
In general, European cloud providers offer competitive pricing. They are neither generally more expensive nor generally less costly than their US counterparts. One thing that is fair to say on a general level is that pricing with European providers is more transparent with less hidden or not immediately visible cost, e.g. for traffic.
Always compare total cost — including egress, storage, and support — rather than headline compute prices alone.
Which European cloud provider is best for AI / GPU workloads?
Scaleway stands out with managed LLMs, generative APIs, and GPU instances, making it a top pick for AI workloads. OVHcloud and STACKIT also offer GPU servers and AI services. IONOS added an AI Model Hub, while T Cloud Public (Deutsche Telekom) provides managed AI. Compare GPU availability, pricing, and managed model offerings for your specific use case.
To find out which European cloud providers are offering GPU instances and managed LLMs, just set a respective filter.
To find out which European cloud providers are offering GPU instances and managed LLMs, just set a respective filter.
Which European cloud provider is best for serverless?
Scaleway is the strongest pick, offering serverless containers, serverless functions, and a serverless database – one of the broadest serverless portfolios in Europe. T Cloud Public (Open Telekom Cloud) provides serverless functions as well. Scalingo offers a PaaS-style managed runtime that abstracts infrastructure. Nine has a similar product and STACKIT has the CloudFoundry runtime. Compare supported runtimes, cold-start performance, and pricing model before choosing.
You can filter providers by services, e.g. European Cloud Providers with Serverless Containers and Serverless Functions.
You can filter providers by services, e.g. European Cloud Providers with Serverless Containers and Serverless Functions.
What are the alternatives to AWS / Azure in Europe?
This is the point of european.cloud. All providers listed on european.cloud are alternatives to AWS / Google / Azure in Europe. While no European provider can fully match the breadth of the big three’s service portfolio, 80% of use cases require only a small subset. As the famous saying about Microsoft Word goes: “Everybody is using only 20% of Word functionality. But everybody is using different 20%”. The point of european.cloud is to help you find the best european cloud provider that matches your 20%.
Compliance & Certifications
What is the EU Cloud Sovereignty Framework?
The EU Cloud Sovereignty Framework (CSF) is a binding framework introduced by the European Commission in October 2025. It turns the abstract concept of “digital sovereignty” into concrete, measurable requirements for cloud service providers.
The CSF is already shaping public procurement — in a 2025 tender worth up to €180 million, the European Commission required bidders to meet minimum SEAL levels across all eight objectives, effectively creating a “digital sovereignty gate.” It is expected to influence private-sector contracts as well and to evolve alongside other EU digital initiatives such as the forthcoming EU Cloud and AI Development Act and the Data Act.
For a deeper dive, read the full article: What is the EU’s Cloud Sovereignty Framework?.
The CSF is already shaping public procurement — in a 2025 tender worth up to €180 million, the European Commission required bidders to meet minimum SEAL levels across all eight objectives, effectively creating a “digital sovereignty gate.” It is expected to influence private-sector contracts as well and to evolve alongside other EU digital initiatives such as the forthcoming EU Cloud and AI Development Act and the Data Act.
For a deeper dive, read the full article: What is the EU’s Cloud Sovereignty Framework?.
What is SecNumCloud and why does it matter?
SecNumCloud is a security certification issued by ANSSI, the French national cybersecurity agency. It is one of the strictest sovereign cloud qualifications in Europe and is mandatory for cloud services that process sensitive or classified French public-sector data.
It matters because a SecNumCloud-qualified service is operated under French jurisdiction, and the law expressly shields qualified providers from foreign data-access requests — including the US CLOUD Act. This is a key difference from “sovereign” offerings of US hyperscalers, which remain under US parent-company control. Furthermore, the certification audits data centre security, encryption, access control, isolation between tenants, personnel vetting, and incident response — far beyond a generic ISO 27001. Lastly, SecNumCloud has become a de facto benchmark for cloud sovereignty across Europe, often cited as a model within the broader EU cloud sovereignty framework.
Currently, only a handful of European cloud providers hold SecNumCloud qualification – all of them French-headquartered. On european.cloud, these are OVHcloud, Scaleway, and Scalingo. You can filter providers by this certification here.
It matters because a SecNumCloud-qualified service is operated under French jurisdiction, and the law expressly shields qualified providers from foreign data-access requests — including the US CLOUD Act. This is a key difference from “sovereign” offerings of US hyperscalers, which remain under US parent-company control. Furthermore, the certification audits data centre security, encryption, access control, isolation between tenants, personnel vetting, and incident response — far beyond a generic ISO 27001. Lastly, SecNumCloud has become a de facto benchmark for cloud sovereignty across Europe, often cited as a model within the broader EU cloud sovereignty framework.
Currently, only a handful of European cloud providers hold SecNumCloud qualification – all of them French-headquartered. On european.cloud, these are OVHcloud, Scaleway, and Scalingo. You can filter providers by this certification here.
What is the EU Cloud Certification Scheme (EUCS)?
The EUCS — European Cybersecurity Certification Scheme for Cloud Services — is a planned EU-wide certification scheme that assesses the cybersecurity of cloud services. It sits under the European Cybersecurity Certification Framework established by the EU Cybersecurity Act of 2019.
The goal of EUCS is to create a single, harmonised cybersecurity certification that is recognised across all member states, replacing the patchwork of national schemes.
As of now, EUCS is still a draft scheme and has not yet been formally adopted, so no cloud provider currently holds an EUCS certificate. Until it is finalised, look to existing certifications such as ISO 27001, BSI C5, and SecNumCloud as practical benchmarks.
The goal of EUCS is to create a single, harmonised cybersecurity certification that is recognised across all member states, replacing the patchwork of national schemes.
As of now, EUCS is still a draft scheme and has not yet been formally adopted, so no cloud provider currently holds an EUCS certificate. Until it is finalised, look to existing certifications such as ISO 27001, BSI C5, and SecNumCloud as practical benchmarks.
Are European cloud providers GDPR compliant?
Yes — European cloud providers are generally well-positioned for GDPR compliance, since they are headquartered in the EU/EEA and operate data centres under EU jurisdiction, which means they fall directly under the GDPR as data controllers or processors.
However, GDPR compliance is shared responsibility. A provider may offer a fully compliant infrastructure, but compliance also depends on how you configure the service, process data, and manage access. A misconfigured bucket or over-permissive IAM policy can still cause a breach for which you are liable.
Additionally, some European providers operate data centres outside the EU (e.g. in the US, Canada, or Singapore). If you use those regions, cross-border transfer rules apply again — so pay attention to where your data actually lands.
However, GDPR compliance is shared responsibility. A provider may offer a fully compliant infrastructure, but compliance also depends on how you configure the service, process data, and manage access. A misconfigured bucket or over-permissive IAM policy can still cause a breach for which you are liable.
Additionally, some European providers operate data centres outside the EU (e.g. in the US, Canada, or Singapore). If you use those regions, cross-border transfer rules apply again — so pay attention to where your data actually lands.
Which certifications should I look for?
The certifications that matter depend on your industry, the data you process, and your regulatory environment.
A general security baseline is established with ISO 27001, ISO 27017, ISO 27018, and ISO 27701.
SecNumCloud is the strictest sovereignty & classified data certification.
PCI DSS, HDS, NEN 7510, and TISAX are popular examples of industry-specific certifications that you know better than anybody else.
SOC 2 is a compliance and audit report typically required for general enterprise assurance. BSI C5 is often a necessity for DACH enterprises.
You can filter European cloud providers by certification directly on the european.cloud homepage or via dedicated pages such as SecNumCloud-qualified providers.
A general security baseline is established with ISO 27001, ISO 27017, ISO 27018, and ISO 27701.
SecNumCloud is the strictest sovereignty & classified data certification.
PCI DSS, HDS, NEN 7510, and TISAX are popular examples of industry-specific certifications that you know better than anybody else.
SOC 2 is a compliance and audit report typically required for general enterprise assurance. BSI C5 is often a necessity for DACH enterprises.
You can filter European cloud providers by certification directly on the european.cloud homepage or via dedicated pages such as SecNumCloud-qualified providers.
Practical
Can I migrate from AWS/Azure to a European cloud?
Yes.
First, a thorough due diligence should be conducted to determine which European cloud provider best fits the given use case, regulatory requirements, and other constraints.
Since European cloud providers typically rely on popular open-source products, the learning curve is generally not steep. Anyone who has worked with other clouds and is familiar with the relevant open-source tools in their domain will feel at home right away.
How difficult a migration will be depends largely on how heavily proprietary services are used. To illustrate the spectrum: moving from one PostgreSQL database to another is straightforward, unless there are very specific scale or performance requirements. Migrating away from AWS Step Functions or Azure Functions, on the other hand, can require a complete rewrite of the respective logic.
A key difference between European cloud providers and the big hyperscalers is that services tend to be less tightly integrated. When migrating, this can mean extra effort and a few rough edges that must be tolerated.
The european.cloud How-To section contains useful articles on typical challenges when getting started with European cloud providers.
First, a thorough due diligence should be conducted to determine which European cloud provider best fits the given use case, regulatory requirements, and other constraints.
Since European cloud providers typically rely on popular open-source products, the learning curve is generally not steep. Anyone who has worked with other clouds and is familiar with the relevant open-source tools in their domain will feel at home right away.
How difficult a migration will be depends largely on how heavily proprietary services are used. To illustrate the spectrum: moving from one PostgreSQL database to another is straightforward, unless there are very specific scale or performance requirements. Migrating away from AWS Step Functions or Azure Functions, on the other hand, can require a complete rewrite of the respective logic.
A key difference between European cloud providers and the big hyperscalers is that services tend to be less tightly integrated. When migrating, this can mean extra effort and a few rough edges that must be tolerated.
The european.cloud How-To section contains useful articles on typical challenges when getting started with European cloud providers.
Do European clouds offer Terraform/OpenTofu support?
Yes.
Infrastructure-as-code (IaC) support is part of the european.cloud definition of a cloud provider, therefore all providers featured here have some IaC support. Terraform is the de facto IaC standard across the European cloud market.
Most European cloud providers maintain their own Terraform providers, and the open-source fork OpenTofu is compatible as well. If you have worked with Terraform on AWS, Azure, or Google Cloud, you will find the workflow familiar: define your resources in HCL, run plan and apply, and manage state remotely.
Coverage and maturity vary between providers, though. Core resources like compute instances, networks, storage, and databases are typically well-supported, while newer or more specialized services may lag behind. It is worth checking the respective provider’s Terraform registry entry and documentation.
For practical examples, the european.cloud How-To section includes guides such as How to use the STACKIT Secrets Manager with Terraform.
Infrastructure-as-code (IaC) support is part of the european.cloud definition of a cloud provider, therefore all providers featured here have some IaC support. Terraform is the de facto IaC standard across the European cloud market.
Most European cloud providers maintain their own Terraform providers, and the open-source fork OpenTofu is compatible as well. If you have worked with Terraform on AWS, Azure, or Google Cloud, you will find the workflow familiar: define your resources in HCL, run plan and apply, and manage state remotely.
Coverage and maturity vary between providers, though. Core resources like compute instances, networks, storage, and databases are typically well-supported, while newer or more specialized services may lag behind. It is worth checking the respective provider’s Terraform registry entry and documentation.
For practical examples, the european.cloud How-To section includes guides such as How to use the STACKIT Secrets Manager with Terraform.
Where are the European cloud data centres located?
European cloud providers operate data centres across the European Union and closely integrated regions. Most providers are EU-based, with coverage stretching from the Nordics (e.g. UpCloud in Finland and Norway) to Western Europe (e.g. OVHcloud and Scaleway in France, STACKIT and IONOS in Germany) and Southern Europe (e.g. Aruba in Italy). Some providers, such as UpCloud and Delska, also extend into the Nordics and the Baltics.
A few providers are headquartered outside the EU but are closely integrated — e.g. in Switzerland and Iceland — which european.cloud includes due to their largely aligned legal frameworks.
Notably, some European providers operate data centres outside Europe as well. This is worth paying attention to: a Point of Presence (PoP) in the US, for example, can expose the provider to the US CLOUD Act, as illustrated by the OVHcloud vs. Canada dispute.
You can explore the exact data centre locations of each provider on the european.cloud Data Centre Map, and filter providers by region on the homepage.
A few providers are headquartered outside the EU but are closely integrated — e.g. in Switzerland and Iceland — which european.cloud includes due to their largely aligned legal frameworks.
Notably, some European providers operate data centres outside Europe as well. This is worth paying attention to: a Point of Presence (PoP) in the US, for example, can expose the provider to the US CLOUD Act, as illustrated by the OVHcloud vs. Canada dispute.
You can explore the exact data centre locations of each provider on the european.cloud Data Centre Map, and filter providers by region on the homepage.
Sovereign US Cloud
What is the AWS European Sovereign Cloud?
The AWS European Sovereign Cloud is a dedicated, separately operated cloud environment from Amazon Web Services, designed in an attempt to address European data sovereignty requirements. It launched in January 2026.
Despite the “sovereign” label, the AWS European Sovereign Cloud remains owned by the US parent company and is still subject to the US CLOUD Act. It does not reduce strategic dependency on AWS as a provider. It is effectively a “sovereign washing” attempt — it addresses data-residency concerns but does not solve the fundamental sovereignty problem.
For the full overview and a critical commentary on the launch, see the AWS European Sovereign Cloud page and the article On the AWS European Sovereign Cloud.
Despite the “sovereign” label, the AWS European Sovereign Cloud remains owned by the US parent company and is still subject to the US CLOUD Act. It does not reduce strategic dependency on AWS as a provider. It is effectively a “sovereign washing” attempt — it addresses data-residency concerns but does not solve the fundamental sovereignty problem.
For the full overview and a critical commentary on the launch, see the AWS European Sovereign Cloud page and the article On the AWS European Sovereign Cloud.
What is Microsoft Cloud for Sovereignty?
Microsoft Cloud for Sovereignty is Microsoft’s offering to address European data sovereignty requirements within its Azure cloud. It is the successor to the discontinued Microsoft Cloud Deutschland (2015–2021), which used a physical data-trustee model with T-Systems but was phased out due to low demand and operational complexity.
Unlike a fully separate cloud instance, Microsoft Cloud for Sovereignty keeps sovereign areas within the broader Azure platform. The boundaries and isolation are enforced through policies rather than physical separation.
For the full overview, see the Microsoft Cloud for Sovereignty page.
Unlike a fully separate cloud instance, Microsoft Cloud for Sovereignty keeps sovereign areas within the broader Azure platform. The boundaries and isolation are enforced through policies rather than physical separation.
For the full overview, see the Microsoft Cloud for Sovereignty page.
Are sovereign US clouds really sovereign?
No.
While the “sovereign” offerings from AWS, Microsoft, Google, and Oracle address data residency, they do not deliver true sovereignty.
Not all approaches are identical. AWS built a separate instance with its own governance – yielding strong technical separation. Microsoft uses a policy-based boundary within the broader Azure platform – the most technically demanding and trust-dependent model. Google partners with T-Systems as a data trustee. But none of them change the underlying ownership, jurisdiction, or dependency equation.
In short, “sovereign” US clouds are better understood as data-residency solutions than as sovereignty solutions. They address a real compliance concern but do not deliver the strategic autonomy that European-headquartered providers offer.
For more, see the “Sovereign” US Cloud section.
While the “sovereign” offerings from AWS, Microsoft, Google, and Oracle address data residency, they do not deliver true sovereignty.
Not all approaches are identical. AWS built a separate instance with its own governance – yielding strong technical separation. Microsoft uses a policy-based boundary within the broader Azure platform – the most technically demanding and trust-dependent model. Google partners with T-Systems as a data trustee. But none of them change the underlying ownership, jurisdiction, or dependency equation.
In short, “sovereign” US clouds are better understood as data-residency solutions than as sovereignty solutions. They address a real compliance concern but do not deliver the strategic autonomy that European-headquartered providers offer.
For more, see the “Sovereign” US Cloud section.