Cyso Cloud is an OpenStack-based cloud provider based in the Netherlands. Cyso has a history as a server hoster founded in 1997. The cloud offering was started in 2016, originally under the name Fuga Cloud. In 2025, Fuga cloud was fully integrated in Cyso, now branded as Cyso Cloud.
Features & Services
The Cyso Cloud service portfolio is currently being built up. Basic primitives such as VMs, managed Kubernetes and storage are in place. The Cloud Databases DBaaS service is in Beta phase, starting with PostgreSQL (as of 11/2025).
Cyso Cloud features a managed Transactional Email service and they are building their own IAM.
There is an overview over planned features and services in the public roadmap.
Developer Experience
Since Cyso Cloud is built on OpenStack, it can be accessed via both the OpenStack API and the OpenStack command-line interface (CLI). Cyso Cloud does not (yet) offer its own layer on top of OpenStack, except for the Cyso Cloud Console.

Tutorials and articles to help you get started with Cyso Cloud—such as guides on setting up an Enterprise Managed Kubernetes (EMK) cluster or migrating from another OpenStack-based provider—are available on the Cyso Cloud Documentation page.
Sovereignty Assessment
For the sovereignty assessment, we are following the EU's Cloud Sovereignty Framework. It defines 8 sovereignty objectives and makes sovereignty measurable and quantifiable.
Disclaimer: this assessment is conducted as an outside-in analysis, based on public information and, for some questions, educated guessing. The results may be factually wrong and in no way replace your own due diligence.
Overall Score
70.6 %
SEAL Level
SEAL 1
- Provider
- Cyso Cloud
- Framework
- Initial framework from the Sovereignty assessment calculator annex (v1.0)
- Assessment date
- 29. August 2026
- Overall score
- 70.6 %
- SEAL level
- SEAL 1
SOV-1 — Strategic Sovereignty
Strategic sovereignty captures the degree to which a cloud provider (or technology actor) is anchored within the European Union/EEA legal, financial, and industrial ecosystem. It assesses ownership stability, governance influence, and alignment with EU strategic priorities.
Weight 20%
Selected answer: 4. Entirely within the EU Value 125 SEAL 4
Notes: Cyso Group B.V. is a 100% Dutch private company in Alkmaar; directors Dutch, no foreign ownership; Dutch governing law and Dutch arbitration jurisdiction.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Demonstrates the group's independence, Dutch roots, and long EU-only operating history — no foreign parent or shareholders mentioned. - Cyso Cloud Impressum - Legal Information other 2. September 2026
Official legal entity page: Cyso B.V., KvK 37133395, Alkmaar NL; Directors Paul Bankert, Sven Visser, Tjebbe de Winter.
Relevance: Provides authoritative proof of Cyso Cloud's Dutch legal entity registration, address, directors, and VAT/CC numbers — confirming EU jurisdiction. - Cyso Group B.V. - Creditsafe Business Index other 2. September 2026
Independent credit bureau record: Cyso Group B.V., holding company, incorporated 1997, Alkmaar NL, KVK 33287475.
Relevance: Independent third-party confirmation of Cyso Group B.V.'s Dutch incorporation and holding company structure — supports EU-only control claim.
All possible answer options (4)
- 1. Entirely outside the EU (value 0.00, SEAL 1)
- 2. Mostly outside the EU (value 41.00, SEAL 1)
- 3. Mostly within the EU (value 83.00, SEAL 3)
- 4. Entirely within the EU (value 125.00, SEAL 4) ✓
Selected answer: 4. Unlikely takeover by or transfer to a non-EU sovereign entity Value 93 SEAL 4
Notes: Privately Dutch-owned since 1997, no external investors found. Small size poses theoretical risk, but deep EU anchoring makes takeover unlikely.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Confirms Cyso Group is an independent, privately-owned Dutch entity with no external parent, directly relevant to assessing change-of-control risk. - Cyso Group B.V. - Creditsafe Business Index other 2. September 2026
Independent credit bureau record: Cyso Group B.V., holding company, incorporated 1997, Alkmaar NL, KVK 33287475.
Relevance: Third-party corporate registry validating Cyso Group as a Dutch holding entity with no foreign parent or investor disclosed, supporting ownership stability. - Fuga Cloud Comes of Age and Continues as Cyso Cloud other 2. September 2026
Cyso Group blog (Nov 2024) detailing internal consolidation: Fuga Cloud integrated into Cyso. No external acquisition or investor involvement.
Relevance: Demonstrates corporate restructuring was entirely internal within Cyso Group, with no evidence of outside investment or takeover activity.
All possible answer options (5)
- 1. Very likely (value 0.00, SEAL 4)
- 2. Likely takeover by or transfer to a non-EU sovereign entity (value 31.00, SEAL 4)
- 3. Somewhat likely takeover by or transfer to a non-EU sovereign entity (value 62.00, SEAL 4)
- 4. Unlikely takeover by or transfer to a non-EU sovereign entity (value 93.00, SEAL 4) ✓
- 5. Very unlikely (value 125.00, SEAL 4)
Selected answer: 2. Through "voice of the customer" public channels (e.g. feedback portals, online communities) Value 41 SEAL 2
Notes: Cyso Cloud offers a public feedback roadmap (Canny) for feature requests. No formal governance body exists for EU stakeholders to directly shape its product roadmap.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Existing evidence confirming Cyso co-founded DCC and holds industry memberships — relevant but these bodies don't give EU actors direct roadmap control. - About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Shows open collaboration approach and public roadmap transparency, consistent with voice-of-customer influence rather than formal governance control. - Cyso Cloud Trust Centre other 2. September 2026
Trust Centre listing DCC membership, Linux Foundation Europe, CNCF participation, and security certifications. Shows EU industry body memberships but not roadmap governance.
Relevance: Confirms DCC and LFE memberships but these are advocacy/standards bodies, not governance structures where EU stakeholders shape Cyso's specific product roadmap.
All possible answer options (4)
- 1. No influence possible (value 0.00, SEAL 2)
- 2. Through "voice of the customer" public channels (e.g. feedback portals, online communities) (value 41.00, SEAL 2) ✓
- 3. Governance bodies exist with EU actors participation (value 83.00, SEAL 3)
- 4. Full influence of EU actors (value 125.00, SEAL 4)
Selected answer: 5. Entirely EU-based funding Value 125 SEAL 4
Notes: Cyso Group is 100% Dutch-owned, bootstrapped since 1997, no external funding raised—all capital is EU-origin.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Confirms Cyso is independently owned and operated in Netherlands since 1997 with no indication of non-EU capital involvement. - Cyso Cloud Revenue, Funding & Valuation – Prospeo other 2. September 2026
Business data intelligence listing showing Cyso Cloud has raised no external funding, estimated revenue ~$941K, bootstrapped.
Relevance: Directly supports financial independence assessment: no external funding raised, self-funded Dutch company with no non-EU capital. - Cyso Cloud Review 2026 – European Purpose other 2. September 2026
Independent review describing Cyso Cloud as 100% Dutch, independently owned, not subject to US jurisdiction, self-funded/bootstrapped.
Relevance: Confirms 100% Dutch ownership with no external investors, making it entirely EU-based financing with zero non-EU capital dependence.
All possible answer options (5)
- 1. Almost entirely relying on non-EU funding (value 0.00, SEAL 4)
- 2. Mostly relying on non-EU funding (value 31.00, SEAL 4)
- 3. Balanced mix of EU and non-EU funding (value 62.00, SEAL 4)
- 4. Majority of funding is EU-based (value 93.00, SEAL 4)
- 5. Entirely EU-based funding (value 125.00, SEAL 4) ✓
Selected answer: 5. Fully in the EU Value 125 SEAL 4
Notes: 100% Dutch-owned, ~60 EU-based employees, all data centers in EU, bootstrapped with no external investment. All jobs, investment, and value creation are within EU/EEA.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Confirms all operations, employees, and data centers are in the EU/Netherlands, with no non-EU footprint. Directly addresses EU jobs and value creation. - Cyso Cloud Partner Program other 2. September 2026
Partner page inviting EU-only partners to invest in European digital sovereignty, targeting €50B+ European cloud market with pan-EU expansion.
Relevance: Shows active EU-focused investment strategy and value creation across European markets, requiring 100% EU-owned partners only. - Cyso Cloud Revenue, Funding & Valuation – Prospeo other 2. September 2026
Business intelligence listing showing Cyso Cloud raised no external funding, estimated revenue ~$941K, fully bootstrapped.
Relevance: Confirms all investment is internal EU-based (bootstrapped), meaning all economic activity and value creation remains within the EU.
All possible answer options (5)
- 1. Minimal (value 0.00, SEAL 4)
- 2. Some (value 31.00, SEAL 4)
- 3. Balanced EU/non-EU (value 62.00, SEAL 4)
- 4. Majority in the EU (value 93.00, SEAL 4)
- 5. Fully in the EU (value 125.00, SEAL 4) ✓
Selected answer: 2. Active participant in strategic projects Value 62 SEAL 4
Notes: Cyso Cloud is a partner in CHORYS, a four-year EU-funded IPCEI project, and strongly aligns with Gaia-X principles on its website.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Shows Cyso Cloud's explicit alignment with Gaia-X, a key EU strategic sovereignty initiative, reinforcing participation in European strategic programs. - Cyso Cloud Joins European CHORYS Project to Advance Open Computing Architecture other 2. September 2026
Official Cyso Cloud announcement of participation in CHORYS, an EU IPCEI project led by University of Copenhagen focusing on open accelerators for data-intensive cloud applications.
Relevance: Direct evidence of Cyso Cloud's active participation in an EU IPCEI strategic project, confirming involvement in a flagship European innovation initiative. - TU Dresden Launches EU Horizon Project to Optimize Cloud Performance other 2. September 2026
TU Dresden announcement of the CHORYS project, listing Cyso Cloud as a project partner alongside EU universities and companies, funded with over €4 million from the EU.
Relevance: Independent academic confirmation from a project partner that Cyso Cloud is a named participant in this EU-funded IPCEI research collaboration.
All possible answer options (3)
- 1. No clear participation (value 0.00, SEAL 4)
- 2. Active participant in strategic projects (value 62.00, SEAL 4) ✓
- 3. Strategic projects depend on contractor's involvement (value 125.00, SEAL 4)
Selected answer: Already measured achievement and existing dedicated governance Value 83 SEAL 4
Notes: Cyso Cloud shows measurable EU strategy alignment via CHORYS Horizon participation, Gaia-X commitment, and EU-only partner program embedded in company DNA.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Explicit alignment with Gaia-X, sustainability (green sovereignty), and open-source/no-vendor-lock-in (digital sovereignty) shows consistency with EU strategic priorities as governance principle. - CHORYS – Open and Programmable Accelerators (CORDIS) other 2. September 2026
Official EU CORDIS project page confirming Cyso B.V. as a funded partner (€350K+) in the Horizon Europe CHORYS project on open computing architecture.
Relevance: Independent EU source verifying Cyso Cloud's formal, funded contribution to EU strategic research in open computing — a measurable achievement under EU industrial policy. - Cyso Cloud Joins European CHORYS Project to Advance Open Computing Architecture other 2. September 2026
Official Cyso Cloud announcement of participation in CHORYS, an EU IPCEI project led by University of Copenhagen focusing on open accelerators for data-intensive cloud applications.
Relevance: Direct participation in an EU-funded Horizon Europe research project demonstrates measurable achievement in aligning with EU digital and industrial sovereignty objectives.
All possible answer options (3)
- Existing Action plan (how to measure ambition? Through means linked to the goals? Relative to the size of the company?) (value 41.00, SEAL 4)
- Already measured achievement and existing dedicated governance (value 83.00, SEAL 4) ✓
- Bold ambition and dedicated means (value 125.00, SEAL 4)
Selected answer: 4. Ability to source alternative suppliers or internalise key functions Value 93 SEAL 2
Notes: OpenStack-based platform with no vendor lock-in enables migration to alternative providers if Cyso support is withdrawn; open APIs ensure workload portability.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Directly addresses resilience to cut-off: open-source OpenStack and no vendor lock-in mean customers can migrate to alternative OpenStack providers or internalise operations if Cyso support is withdrawn. - Cloud Operations – Cyso.com other 2. September 2026
Cyso's CloudOps service page detailing 24/7 monitoring, disaster recovery execution, multi-cloud support, and operational continuity management.
Relevance: Demonstrates operational resilience measures and multi-cloud support, showing customers have pathways to sustain operations through disaster recovery and migration to alternative environments. - How OpenStack Reduces Long-Term Cloud Risks – VEXXHOST other 2. September 2026
Article explaining how OpenStack's vendor-neutral, open-source architecture mitigates vendor lock-in and ensures long-term operational continuity and cost control.
Relevance: Explains why OpenStack-based providers like Cyso Cloud offer inherent resilience to vendor withdrawal: open-source code and vendor-neutral standards mean the platform can be operated by alternative providers.
All possible answer options (4)
- 2. Service would likely stop but with a delay to provide time for customer reaction (value 31.00, SEAL 0)
- 3. Can continue temporarily based on contractual agreement with EC (value 62.00, SEAL 2)
- 4. Ability to source alternative suppliers or internalise key functions (value 93.00, SEAL 2) ✓
- 5. Full autonomy and continuity (value 125.00, SEAL 4)
SOV-2 — Legal & Jurisdictional Sovereignty
Legal & Jurisdictional sovereignty evaluates the legal environment, exposure to foreign authority, and enforceability of rights that govern a technology provider and its services. It determines the extent to which a provider is anchored in European jurisdiction and insulated from external legal claims.
Weight 10%
Selected answer: 3. Exclusively EU law Value 167 SEAL 4
Notes: Cyso Cloud is a 100% Dutch company headquartered in Alkmaar, NL. All contracts governed by Dutch law; no foreign parent or investors. Fully EU jurisdiction.
Evidence
- Cyso Group B.V. - Creditsafe Business Index other 2. September 2026
Independent credit bureau record: Cyso Group B.V., holding company, incorporated 1997, Alkmaar NL, KVK 33287475.
Relevance: Confirms Cyso Group B.V. is a Dutch entity and the top-level parent — no foreign ownership or non-EU jurisdiction exposure. - Cyso Terms and Conditions — Applicable Law & Dispute Resolution other 2. September 2026
Official Cyso T&Cs: Clause 1.12.1 states all agreements governed by Dutch law; CISG excluded. Disputes via Dutch arbitration (SGOA) or courts in Alkmaar, NL.
Relevance: Directly confirms that Cyso's primary legal jurisdiction is exclusively Dutch/EU law, with no foreign jurisdiction clauses. - Why 'European Cloud' means (almost) nothing if your cloud provider is American — Cyso Cloud Blog other 2. September 2026
Cyso Cloud article explaining that as a 100% Dutch-owned provider with no U.S. parent, it is not subject to the U.S. CLOUD Act; all operations under European law.
Relevance: Demonstrates Cyso Cloud's explicit positioning on legal sovereignty: no exposure to non-EU jurisdictional claims such as the U.S. CLOUD Act.
All possible answer options (3)
- 1. Non-EU only (value 0.00, SEAL 1)
- 2. Mixed EU/non-EU (value 84.00, SEAL 1)
- 3. Exclusively EU law (value 167.00, SEAL 4) ✓
Selected answer: Legal structures shielding from foreign law Value 125 SEAL 2
Notes: 100% Dutch-owned, Dutch-law-governed, no US parent — strong legal structures shield from CLOUD Act, but not verified complete immunity from all non-EU laws.
Evidence
- Cyso Terms and Conditions – Applicable Law & Dispute Resolution other 2. September 2026
Official T&Cs: Clause 1.12.1 — Dutch law governs all agreements (CISG excluded). Disputes resolved via Dutch arbitration (SGOA) or courts in Alkmaar, NL.
Relevance: Confirms legal structure anchoring all contracts in Dutch law with CISG excluded, shielding from foreign legal frameworks and cross-border dispute mechanisms. - European Cloud Providers: Verified & Compared other 2. September 2026
Independent quarterly-verified comparison of EU cloud providers flagging CLOUD Act exposure. Notes Cyso is EU-hosted but historically listed US sub-processors.
Relevance: Highlights that while Cyso itself avoids CLOUD Act, sub-processor chain exposure means legal structures shield but do not guarantee full immunity — supporting 'shielding' over 'immunity'. - Why 'European Cloud' means (almost) nothing if your cloud provider is American — Cyso Cloud Blog other 2. September 2026
Cyso Cloud article explaining that as a 100% Dutch-owned provider with no U.S. parent, it is not subject to the U.S. CLOUD Act; all operations under European law.
Relevance: Directly addresses extraterritorial law exposure: Cyso's Dutch ownership structure shields it from US CLOUD Act jurisdiction, a key non-EU law with cross-border reach.
All possible answer options (4)
- Mitigation clauses, exposure remains (value 41.00, SEAL 1)
- EU subsidiary with contractual protections (value 83.00, SEAL 1)
- Legal structures shielding from foreign law (value 125.00, SEAL 2) ✓
- Verified legal immunity, non-EU laws unenforceable (value 167.00, SEAL 4)
Selected answer: 4. Non-EU authorities requests to access data or systems are disputed by the provider and eventually in some cases are accepted with customers being notified Value 125 SEAL 1
Notes: Cyso is 100% Dutch-owned, no US jurisdiction or CLOUD Act exposure. Non-EU data requests would be disputed; only via Dutch court order (MLAT) might disclosure occur, with notification.
Evidence
- Cyso Terms and Conditions — Applicable Law & Dispute Resolution other 2. September 2026
Official Cyso T&Cs: Clause 1.12.1 states all agreements governed by Dutch law; CISG excluded. Disputes via Dutch arbitration (SGOA) or courts in Alkmaar, NL.
Relevance: Confirms that any legal demands—including potential non-EU authority requests—must be validated through Dutch courts, meaning Cyso has legal standing to dispute foreign orders before any disclosure. - European Cloud Providers: Verified & Compared other 2. September 2026
Independent quarterly-verified comparison of EU cloud providers flagging CLOUD Act exposure. Notes Cyso is EU-hosted but historically listed US sub-processors.
Relevance: Provides independent cautionary context: residual non-EU data access pathways could exist via sub-processors, supporting that complete rejection of all non-EU requests (score 5) is not guaranteed. - Why 'European Cloud' means (almost) nothing if your cloud provider is American — Cyso Cloud Blog other 2. September 2026
Cyso Cloud article explaining that as a 100% Dutch-owned provider with no U.S. parent, it is not subject to the U.S. CLOUD Act; all operations under European law.
Relevance: Directly addresses data access pathways: confirms Cyso is not subject to US extraterritorial data demands, supporting the assessment that non-EU requests would be disputed.
All possible answer options (4)
- 2. Non-EU authorities can compel access to data or systems without customers being notified, in specific cases (value 41.00, SEAL 1)
- 3. Non-EU authorities can compel access to data or systems with customers being notified in all cases (value 83.00, SEAL 1)
- 4. Non-EU authorities requests to access data or systems are disputed by the provider and eventually in some cases are accepted with customers being notified (value 125.00, SEAL 1) ✓
- 5. Non-EU authorities requests to access data or systems are always rejected by the provider (value 167.00, SEAL 4)
Selected answer: Part of the offer cannot be exposed to restrictions towards EU MSs or international organisations Value 167 SEAL 4
Notes: 100% Dutch-owned, no US parent, no exposure to ITAR/EAR or CLOUD Act. Open-stack infrastructure fully insulated from US export controls for EU MSs and int'l orgs.
Evidence
- Cyso Cloud Review 2026 – European Purpose other 2. September 2026
Independent review describing Cyso Cloud as 100% Dutch, independently owned, not subject to US jurisdiction, self-funded/bootstrapped.
Relevance: Third-party verification that Cyso is fully European-owned and operated, reinforcing insulation from US export control regimes (ITAR/EAR) for all customers including international organisations. - Defence Dual-Use Sovereign Infrastructure: ITAR, EAR and Export Control other 2. September 2026
Analysis of how US export control laws (ITAR, EAR) apply to cloud providers, concluding non-US providers with no US corporate parent are not subject to these regimes.
Relevance: Explains that ITAR/EAR require a US nexus (US persons, US-origin items, or US corporate parent). Cyso has none of these, so its offer cannot be restricted by these regimes for EU member states or international organisations. - Why 'European Cloud' means (almost) nothing if your cloud provider is American — Cyso Cloud Blog other 2. September 2026
Cyso Cloud article explaining that as a 100% Dutch-owned provider with no U.S. parent, it is not subject to the U.S. CLOUD Act; all operations under European law.
Relevance: Directly establishes Cyso has no US corporate parent, meaning ITAR/EAR export control regimes — which require US-person or US-origin nexus — do not apply to Cyso Cloud's offer for EU MSs or international organisations.
All possible answer options (4)
- Restrictions exists towards EU citizens or international organisations (value 41.00, SEAL 1)
- Share of revenues >50% in the EU (value 83.00, SEAL 2)
- Part of the offer cannot be exposed to restrictions towards EU MSs (value 125.00, SEAL 3)
- Part of the offer cannot be exposed to restrictions towards EU MSs or international organisations (value 167.00, SEAL 4) ✓
Selected answer: 5. Fully within the EU Value 167 SEAL 4
Notes: Cyso is a 100% Dutch company. All IP—created, registered, developed in the Netherlands. Founded 1997 in Alkmaar, no foreign IP dependencies.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Independently Dutch-owned since 1997; all cloud platforms (OpenStack/VMware) developed and maintained in-house in the Netherlands—no foreign parent or IP origin. - About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Confirms all cloud platform development (Fuga/Cyso Cloud since 2016) occurred in-house in the Netherlands; Cyso is 100% Dutch-owned with no foreign IP dependencies. - Cyso Terms and Conditions — Applicable Law & Dispute Resolution other 2. September 2026
Official Cyso T&Cs: Clause 1.12.1 states all agreements governed by Dutch law; CISG excluded. Disputes via Dutch arbitration (SGOA) or courts in Alkmaar, NL.
Relevance: Clause 7.1.2 explicitly assigns all IP rights to Cyso (Dutch entity); IP registration and enforcement governed by Dutch law with no foreign jurisdiction exposure.
All possible answer options (4)
- 2. Mostly outside the EU (value 41.00, SEAL 4)
- 3. Mixed within/outside the EU (value 83.00, SEAL 4)
- 4. Mostly within the EU (value 125.00, SEAL 4)
- 5. Fully within the EU (value 167.00, SEAL 4) ✓
Selected answer: fully under EU law Value 167 SEAL 4
Notes: Cyso Group B.V. is a 100% Dutch-owned entity; IP rights retained by Cyso under Dutch law. No foreign parent, investors, or non-EU jurisdiction involvement.
Evidence
- Cyso Group B.V. - Creditsafe Business Index other 2. September 2026
Independent credit bureau record: Cyso Group B.V., holding company, incorporated 1997, Alkmaar NL, KVK 33287475.
Relevance: Confirms the IP-holding parent entity is fully incorporated and domiciled in the Netherlands (EU), with no foreign jurisdiction nexus. - Cyso Terms and Conditions — Applicable Law & Dispute Resolution other 2. September 2026
Official Cyso T&Cs: Clause 1.12.1 states all agreements governed by Dutch law; CISG excluded. Disputes via Dutch arbitration (SGOA) or courts in Alkmaar, NL.
Relevance: Directly confirms IP rights are held by Cyso (Dutch entity) and enforced under Dutch/EU law with no foreign jurisdiction provisions. - Why 'European Cloud' means (almost) nothing if your cloud provider is American — Cyso Cloud Blog other 2. September 2026
Cyso Cloud article explaining that as a 100% Dutch-owned provider with no U.S. parent, it is not subject to the U.S. CLOUD Act; all operations under European law.
Relevance: Confirms no non-EU jurisdiction can claim authority over Cyso's IP or operations; fully insulated from US and other foreign legal claims.
All possible answer options (4)
- non-EU law, mixed non-EU countries (value 41.00, SEAL 3)
- Mixed law, some EU (value 83.00, SEAL 3)
- EU law with exceptions (value 125.00, SEAL 4)
- fully under EU law (value 167.00, SEAL 4) ✓
SOV-3 — Data & AI Sovereignty
Data & AI sovereignty focuses on the protection, control, and independence of data assets and AI services within the EU/EEA. It addresses how data is secured, where it is processed, and the degree of autonomy customers retain over AI capabilities.
Weight 10%
Selected answer: 5. Customer exclusive control - provider can not read the data Value 200 SEAL 4
Notes: Cyso Cloud offers SSE-C: customer-provided keys are never stored; data is unrecoverable without the key, even by support staff.
Evidence
- Cyso Cloud — Customer-Provided Encryption Keys (SSE-C) other 2. September 2026
Official Cyso Cloud docs for SSE-C enabling customer-provided 256-bit AES keys for Object Storage. Keys are never stored; discarded after each request; data unrecoverable without key.
Relevance: Directly proves customer-exclusive key control: Cyso cannot read data encrypted with SSE-C keys since keys are never persisted. - Cyso Cloud — Security Measures other 2. September 2026
Cyso Cloud's security overview detailing ISO 27001/NEN 7510 certifications, encryption, network segmentation, and platform architecture.
Relevance: Confirms encryption is integral to platform security; no provider-managed key overrides documented that would compromise customer-exclusive control. - OpenStack Security Guide — Key Management other 2. September 2026
OpenStack key management guide covering Barbican, HSM support, per-project key isolation, and KMIP interoperability.
Relevance: Cyso Cloud is OpenStack-based; Barbican provides per-project key scoping and RBAC, ensuring tenant keys are isolated — supporting exclusive customer key control.
All possible answer options (4)
- 2. Primarily the provider but not exclusively (value 50.00, SEAL 1)
- 3. Shared - provider has override keys (value 100.00, SEAL 2)
- 4. Customer primary control but provider can read the data or some of the data (value 150.00, SEAL 3)
- 5. Customer exclusive control - provider can not read the data (value 200.00, SEAL 4) ✓
Selected answer: 3. Logs exist but not real-time or controlled by vendor (vendor is replaced by CUSTOMER in the survey) Value 100 SEAL 2
Notes: Provider-side logging exists but no evidence of customer-controlled or real-time log access; no AI model usage auditability documented.
Evidence
- Cloud Operations – Cyso.com other 2. September 2026
Cyso's CloudOps service page detailing 24/7 monitoring, disaster recovery execution, multi-cloud support, and operational continuity management.
Relevance: Monitoring is provider-operated, not customer-controlled. Monthly reports suggest non-real-time delivery. No evidence of AI model usage auditing. - Cyso Cloud — Security Measures other 2. September 2026
Cyso Cloud's security overview detailing ISO 27001/NEN 7510 certifications, encryption, network segmentation, and platform architecture.
Relevance: Confirms logging exists but is described as system-level, with no mention of customer-accessible audit logs or real-time customer visibility. - Cyso Cloud Trust Centre other 2. September 2026
Trust Centre listing DCC membership, Linux Foundation Europe, CNCF participation, and security certifications. Shows EU industry body memberships but not roadmap governance.
Relevance: Audit trails exist but appear provider-managed. No documentation of customer-controlled log access or independent auditability of data/AI usage.
All possible answer options (4)
- 2. Basic logs incomplete (missing date; missing user; missing type of access; missing means of access etc.) (value 50.00, SEAL 1)
- 3. Logs exist but not real-time or controlled by vendor (vendor is replaced by CUSTOMER in the survey) (value 100.00, SEAL 2) ✓
- 4. Full customer controlled visibility of log access but not in real time (value 150.00, SEAL 3)
- 5. Real-time customer oversight and independent auditability (value 200.00, SEAL 4)
Selected answer: 3. Internal validation based on policies - no proof of validation left Value 100 SEAL 1
Notes: ISO 27001 policies cover data handling but OpenStack lacks native secure erasure proof. SSE-C crypto-shredding is opt-in only, not systematically enforced or independently verified.
Evidence
- Assured Deletion in the Cloud: Requirements, Challenges and Future Directions other 2. September 2026
Academic paper analyzing secure deletion in OpenStack, identifying that OpenStack has no native mechanism to confirm or prove deletion after instance termination.
Relevance: Confirms Cyso Cloud's underlying platform (OpenStack) lacks native secure deletion verification, supporting the assessment that no systematic proof of erasure exists. - Cyso Cloud — Customer-Provided Encryption Keys (SSE-C) other 2. September 2026
Official Cyso Cloud docs for SSE-C enabling customer-provided 256-bit AES keys for Object Storage. Keys are never stored; discarded after each request; data unrecoverable without key.
Relevance: SSE-C enables irreversible deletion via key destruction, but only for object storage, opt-in, and not independently verified—doesn't constitute systematic enforced erasure. - Cyso Cloud — Security Measures other 2. September 2026
Cyso Cloud's security overview detailing ISO 27001/NEN 7510 certifications, encryption, network segmentation, and platform architecture.
Relevance: Lists ISO 27001 policies and monitoring which imply internal data handling procedures, but no mention of secure deletion verification or proof of erasure mechanisms.
All possible answer options (4)
- 2. Manual confirmation only (value 50.00, SEAL 1)
- 3. Internal validation based on policies - no proof of validation left (value 100.00, SEAL 1) ✓
- 4. Deletion is technically verified with access logs (value 150.00, SEAL 3)
- 5. Yes, irreversible deletion is systematically enforced and independently verified (value 200.00, SEAL 4)
Selected answer: 5. All data exclusively in the EU with no third-country fallback Value 200 SEAL 4
Notes: Cyso Cloud operates exclusively in Amsterdam & Frankfurt (EU). 100% Dutch-owned, no US parent, no CLOUD Act exposure, no third-country data transfer mechanisms found.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Confirms all infrastructure operates exclusively within EU jurisdictions (Amsterdam, Frankfurt) with no evidence of third-country fallback options. - Cyso Cloud Joins European CHORYS Project to Advance Open Computing Architecture other 2. September 2026
Official Cyso Cloud announcement of participation in CHORYS, an EU IPCEI project led by University of Copenhagen focusing on open accelerators for data-intensive cloud applications.
Relevance: Shows Cyso's deep EU alignment through Horizon Europe project participation reinforcing commitment to EU-based infrastructure and data processing only. - Why 'European Cloud' means (almost) nothing if your cloud provider is American — Cyso Cloud Blog other 2. September 2026
Cyso Cloud article explaining that as a 100% Dutch-owned provider with no U.S. parent, it is not subject to the U.S. CLOUD Act; all operations under European law.
Relevance: Directly addresses data sovereignty and EU jurisdiction. Confirms data centres in Amsterdam and Frankfurt only, full-stack sovereignty, no third-country data access mechanisms.
All possible answer options (4)
- 2. Data partly in the EU, significant reliance on third countries and limited control (value 50.00, SEAL 0)
- 3. Data mainly in the EU, some third-country use with standard safeguards (value 100.00, SEAL 1)
- 4. Data in the EU by default, tightly controlled exceptions (value 150.00, SEAL 1)
- 5. All data exclusively in the EU with no third-country fallback (value 200.00, SEAL 4) ✓
Selected answer: Mixed Control with alternatives: Auditable or open source AI, foreign chips Value 100 SEAL 2
Notes: Open-source infra (OpenStack) and active EU CHORYS RISC-V accelerator development, but no production AI/GPU services yet.
Evidence
- CHORYS – Open and Programmable Accelerators (CORDIS) other 2. September 2026
Official EU CORDIS project page confirming Cyso B.V. as a funded partner (€350K+) in the Horizon Europe CHORYS project on open computing architecture.
Relevance: Confirms Cyso is actively co-developing EU-origin open accelerator technology (RISC-V, embedded FPGA), reducing future dependence on non-EU chip stacks for AI workloads. - Cyso Cloud Joins European CHORYS Project to Advance Open Computing Architecture other 2. September 2026
Official Cyso Cloud announcement of participation in CHORYS, an EU IPCEI project led by University of Copenhagen focusing on open accelerators for data-intensive cloud applications.
Relevance: Shows Cyso's commitment to EU-developed open computing architecture and its role as the production cloud platform for testing EU-origin accelerator technology. - Sovereign EU Cloud Providers Compared — EU Alternative other 2. September 2026
Feature-by-feature comparison of major EU cloud providers showing Cyso Cloud is the only provider listed that does not offer GPU instances or AI inference APIs.
Relevance: Confirms Cyso Cloud currently has no production AI services or foreign chip dependency, positioning it early in the AI sovereignty maturity curve with alternatives under development via CHORYS.
All possible answer options (4)
- Mostly non-EU dependencies: Licensed AI, chip dependency (value 50.00, SEAL 2)
- Mixed Control with alternatives: Auditable or open source AI, foreign chips (value 100.00, SEAL 2) ✓
- EU-led AI, foreign accelerators (value 150.00, SEAL 3)
- EU-origin models and chips - no dependencies from outside EU (value 200.00, SEAL 4)
SOV-4 — Operational Sovereignty
Operational sovereignty measures the practical ability of EU actors to run, support, and evolve a technology independently of foreign control. It focuses on continuity of operations, skill availability, and resilience against external dependencies.
Weight 15%
Selected answer: 4. Formal migration services are available to assist with moving data and workloads Value 125 SEAL 4
Notes: Cyso offers formal migration services with dedicated architects/engineers plus documented OpenStack-standard data export methods, going beyond self-service documentation.
Evidence
- Cyso Cloud Documentation – Migration Guides & API References other 2. September 2026
Cyso Cloud's docs hub with migration guides for volumes, instances, and object storage, plus OpenStack API references for data export and workload portability.
Relevance: Shows documented, standard OpenStack-based methods for data export and workload migration between providers, including guides for migrating from other OpenStack clouds and DigitalOcean. - Cyso Cloud Product Page – Migration Support other 2. September 2026
Main product page stating Cyso fully supports customers in transitioning to Cyso Cloud with specialized architects and engineers designing and building the platform.
Relevance: Confirms formal migration services with dedicated professional services staff assisting customers in moving data and workloads, going beyond self-service documentation alone. - How OpenStack Reduces Long-Term Cloud Risks – VEXXHOST other 2. September 2026
Article explaining how OpenStack's vendor-neutral, open-source architecture mitigates vendor lock-in and ensures long-term operational continuity and cost control.
Relevance: Supports that Cyso Cloud's OpenStack foundation inherently reduces lock-in and enables interoperability/portability with other OpenStack-based EU-controlled clouds.
All possible answer options (4)
- 2. Data export and workload portability is provided on a "best-effort" basis (value 41.00, SEAL 1)
- 3. Standard documented methods for data export are available (value 83.00, SEAL 4)
- 4. Formal migration services are available to assist with moving data and workloads (value 125.00, SEAL 4) ✓
- 5. Solution already deployed on sovereign infrastructure (value 167.00, SEAL 4)
Selected answer: 5. The entire technology stack is managed and supported by a fully EU-based team Value 167 SEAL 4
Notes: 100% Dutch-owned, in-house EU engineers manage 24/7 operations, OpenStack is vendor-neutral, nothing subcontracted. Full EU operational independence.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Confirms Cyso is a 100% Dutch-owned, independent hosting provider with a long history of EU-based operations — no foreign parent, no dependence on external vendors. - About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Demonstrates Cyso's active role in the OpenStack community; support is provided by Cyso's own EU-based team, eliminating need for non-EU vendor involvement. - Cyso Cloud – Solutions (Managed Cloud Operations, Migration, Cybersecurity) other 2. September 2026
Managed cloud services page noting 24/7 monitoring, disaster recovery, cybersecurity — all by in-house EU engineers, nothing subcontracted.
Relevance: Confirms in-house EU teams manage all Cyso Cloud operations, with open access to OpenStack and no dependency on foreign vendors for maintenance and support.
All possible answer options (4)
- 2. Operational services are partially sourced from within the EU (value 41.00, SEAL 1)
- 3. Operational responsibilities are balanced between EU and non-EU teams (value 83.00, SEAL 3)
- 4. Operational services are predominantly delivered by EU-based teams (value 125.00, SEAL 3)
- 5. The entire technology stack is managed and supported by a fully EU-based team (value 167.00, SEAL 4) ✓
Selected answer: All EU staff Value 125 SEAL 3
Notes: All ~60 staff Netherlands-based; in-house EU engineers, nothing subcontracted. No evidence of formal security clearance.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Confirms entirely EU-based workforce of 50+ certified and screened employees operating the cloud infrastructure with no non-EU staff indicated. - About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Shows EU-based talent pool of ~60 professionals directly operating and sustaining the cloud service from the Netherlands. - Cyso Cloud – LinkedIn other 2. September 2026
LinkedIn company page: 11-50 employees, HQ in Alkmaar, Netherlands; lists staff all Netherlands-based including founders and engineers.
Relevance: Independently verifies all employees are EU-based with no non-EU locations, confirming skill availability within EU.
All possible answer options (4)
- Mixed, majority outside EU (value 41.00, SEAL 1)
- Majority EU, escalation abroad (value 83.00, SEAL 3)
- All EU staff (value 125.00, SEAL 3) ✓
- 100% EU staff + clearance (value 167.00, SEAL 4)
Selected answer: 4. All support staff are located within the EU Value 125 SEAL 3
Notes: All support staff are EU-based. Cyso states operations are performed by Cyso employees in the Netherlands under Dutch/EU law, with 24/7 NOC/SOC. No security clearances mentioned.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Confirms team of ~60 professionals all based in Alkmaar, Netherlands. Tech-to-tech support listed as core principle with no foreign escalation paths mentioned. - Cloud Operations – Cyso.com other 2. September 2026
Cyso's CloudOps service page detailing 24/7 monitoring, disaster recovery execution, multi-cloud support, and operational continuity management.
Relevance: Confirms all support channels (phone, email, 24/7 monitoring) operate from Netherlands HQ. No mention of non-EU escalation teams or outsourced support. - Managed Operations | Cyso Cloud other 2. September 2026
Details Cyso's managed operations: 24/7 NOC/SOC monitoring, all staff in Netherlands, data in EU under Dutch law.
Relevance: Explicitly states operations performed by Cyso employees in the Netherlands under Dutch and European law. Confirms 24/7 support delivered from within the EU exclusively.
All possible answer options (4)
- 2. The team is mixed but the majority of support staff reside outside the EU (value 41.00, SEAL 2)
- 3. The majority of support staff are in the EU but escalations are handled by non-EU teams (value 83.00, SEAL 3)
- 4. All support staff are located within the EU (value 125.00, SEAL 3) ✓
- 5. All support staff are located within the EU and hold relevant security clearances (value 167.00, SEAL 4)
Selected answer: 5. EU-only end-to-end - Content, metadata, and backups/replicas are stored in the EU and privileged administration/support access is restricted to EU-based staff under EU jurisdiction Value 167 SEAL 4
Notes: Full open-source OpenStack docs, EU-hosted docs hub, all staff Netherlands-based, no foreign dependencies for knowledge transfer.
Evidence
- Cloud Operations – Cyso.com other 2. September 2026
Cyso's CloudOps service page detailing 24/7 monitoring, disaster recovery execution, multi-cloud support, and operational continuity management.
Relevance: Confirms operational know-how is held and delivered exclusively by EU-based staff under Dutch jurisdiction, with no subcontracting — critical for knowledge transfer sovereignty. - Cyso Cloud – OpenStack & Automation Documentation other 2. September 2026
Official Cyso Cloud technical documentation page detailing OpenStack API, CLI, Terraform, and Ansible automation with full service endpoint references.
Relevance: Demonstrates availability of full technical documentation on an open-source platform; source code (OpenStack) is publicly available, enabling long-term autonomy independent of any single vendor. - Cyso Cloud Resources & Documentation Hub other 2. September 2026
Central documentation hub with Kubernetes guides, object storage tutorials, migration docs, public roadmap, and community portal for feature requests.
Relevance: Shows comprehensive knowledge repositories hosted on EU infrastructure, publicly accessible, covering all operational aspects needed for long-term autonomy.
All possible answer options (4)
- 2. EU optional, not enforced - EU storage is available as an option, but it is not enforced (value 41.00, SEAL 2)
- 3. EU primary with non-EU fallback - Stored/managed in the EU by default, but some storage/replication/access outside the EU may occur (e.g., disaster recovery/support) (value 83.00, SEAL 4)
- 4. EU-only primary repositories - All primary documentation and knowledge repositories are stored in the EU (no routine non-EU storage/processing) (value 125.00, SEAL 4)
- 5. EU-only end-to-end - Content, metadata, and backups/replicas are stored in the EU and privileged administration/support access is restricted to EU-based staff under EU jurisdiction (value 167.00, SEAL 4) ✓
Selected answer: 4. Ability to source alternative suppliers or internalise key functions Value 125 SEAL 3
Notes: Cyso internalises critical functions (in-house engineering, own AS/network) and uses open-source OpenStack. EU data centers and sub-processors allow sourcing EU alternatives if needed.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Shows Cyso operates its own AS and network infrastructure, reducing dependency on external suppliers and enabling EU-based alternative sourcing. - Cyso Cloud — European Alternatives other 2. September 2026
Independent directory confirming all core services hosted by Cyso Group B.V. (AS25151), self-hosted infrastructure, OpenStack-based platform.
Relevance: Confirms Cyso self-hosts infrastructure under own autonomous system, minimising third-party supplier exposure in service delivery. - Managed Operations | Cyso Cloud other 2. September 2026
Details Cyso's managed operations: 24/7 NOC/SOC monitoring, all staff in Netherlands, data in EU under Dutch law.
Relevance: Confirms in-house engineering by Cyso employees in NL, EU jurisdiction, and a short EU-based sub-processor list — indicating minimal external supplier dependency.
All possible answer options (4)
- 2. Service would likely stop but with a delay to provide time for customer reaction (value 41.00, SEAL 2)
- 3. Can continue temporarily based on contractual agreement with EC (value 83.00, SEAL 3)
- 4. Ability to source alternative suppliers or internalise key functions (value 125.00, SEAL 3) ✓
- 5. Full autonomy and continuity (value 167.00, SEAL 4)
SOV-5 — Supply Chain Sovereignty
Supply chain sovereignty evaluates the geographic origin, transparency, and resilience of the technology supply chain, focusing on the extent to which critical components and processes remain under EU control or exposed to non-EU dependencies.
Weight 10%
Selected answer: Partial disclosure Value 35 SEAL 1
Notes: Cyso discloses data center locations and hardware types (NVMe, Tier 3) but not the geographic origin of physical components like CPUs, servers, or storage devices.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Mentions sustainability and hardware lifecycle practices but does not disclose original provenance or geographic source of physical components, supporting partial disclosure rating. - Cyso Cloud – European Alternatives other 2. September 2026
Independent European hosting directory listing Cyso Cloud as OpenStack-based provider with infrastructure in Amsterdam and Frankfurt.
Relevance: Third-party listing confirms general infrastructure specs but reveals no supplier relationships or component provenance, reinforcing partial disclosure assessment. - Cyso Cloud – Platform Overview other 2. September 2026
Official Cyso Cloud platform page describing enterprise-grade hardware, Tier 3 data centers in Amsterdam and Frankfurt, NVMe storage, and 100% European infrastructure.
Relevance: Discloses hardware types and data center locations but provides no information on geographic origin of physical components like CPUs, servers, or storage devices, indicating partial disclosure.
All possible answer options (4)
- Partial disclosure (value 35.00, SEAL 1) ✓
- Transparent with exceptions (value 71.00, SEAL 3)
- Full transparency (value 107.00, SEAL 3)
- EU-certified provenance (value 143.00, SEAL 4)
Selected answer: Foreign origin, partial disclosure Value 35 SEAL 1
Notes: Cyso Cloud discloses general hardware specs (NVMe, SAN, enterprise-grade) but not component manufacturers or countries of origin. EU lacks chip production capacity.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Mentions 'premium hardware' and 'supply chain transparency' as values, but does not disclose specific hardware suppliers, component manufacturers, or country of origin. - Cyso Cloud – Platform Overview other 2. September 2026
Official Cyso Cloud platform page describing enterprise-grade hardware, Tier 3 data centers in Amsterdam and Frankfurt, NVMe storage, and 100% European infrastructure.
Relevance: Describes hardware specs (NVMe SSDs, compute nodes) without disclosing manufacturers or manufacturing locations of hardware components. - The E.U.'s AI Drive Undermines Its Own Chip Strategy other 2. September 2026
IEEE Spectrum article on EU semiconductor dependency, noting Europe produces under 10% of global chips and relies heavily on US designers and Asian manufacturers.
Relevance: Provides broader context that EU cloud providers sourcing enterprise hardware (CPUs, SSDs, networking gear) depend on non-EU manufacturing, confirming foreign-origin supply chain realities for providers like Cyso.
All possible answer options (4)
- Foreign origin, partial disclosure (value 35.00, SEAL 1) ✓
- Mixed sourcing, EU audit rights (value 71.00, SEAL 3)
- Build by EU Teams, on the basis of a foreign code (value 107.00, SEAL 3)
- Exclusive designed and build by EU Teams (value 143.00, SEAL 4)
Selected answer: Partial disclosure Value 35 SEAL 4
Notes: Open software stack (OpenStack) is transparent but no disclosure on firmware/hardware component provenance; CHORYS participation shows intent, not yet implementation.
Evidence
- About Cyso Cloud – OpenStack Foundation, Gaia-X, '4 Opens' Philosophy other 2. September 2026
Details Cyso Cloud's foundation on OpenStack, Gaia-X alignment, and '4 Opens' philosophy: open development, open standards, open source, open collaboration.
Relevance: Confirms software-layer transparency (OpenStack open source) but does not address firmware or embedded hardware code provenance — the core gap for this assessment question. - Cyso Cloud Blog — Digital Sovereignty Just Grew Teeth: What the 2026 EU Cloud Rules Mean other 2. September 2026
Cyso Cloud's article on EU Cloud Sovereignty Framework covering 48 criteria across 8 areas including supply chain, and 4 sovereignty levels.
Relevance: Directly addresses supply chain sovereignty levels and acknowledges that full component-origin control (Level 4) is aspirational; Cyso positions itself at lower levels. - European Commission — Cloud Sovereignty Framework Implementation Guidance other 2. September 2026
Official EU implementation guidance defining SOV-5: Supply Chain Sovereignty criteria including geographic origin of hardware, jurisdiction of embedded firmware code, and supplier auditability.
Relevance: Defines the assessment criteria for this question: provenance of embedded code controlling hardware and firmware. Notes SEAL-4 (full EU-certified provenance) is 'not today relevant' due to hardware dependencies.
All possible answer options (4)
- Partial disclosure (value 35.00, SEAL 4) ✓
- Transparent with exceptions (value 71.00, SEAL 4)
- Full transparency (value 107.00, SEAL 4)
- EU-certified provenance (value 143.00, SEAL 4)
Selected answer: 3. Core and essential parts of the software are designed and maintained by EU teams Value 71 SEAL 3
Notes: OpenStack core is US-origin (Rackspace/NASA) but Cyso's EU team handles platform customization, DevOps, and ops. Core EU-maintained, base framework foreign.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Shows Cyso's EU-based engineering team handles platform development, customization, and operations — core parts maintained by EU teams. - Cyso Cloud – CloudStack Collaboration Conference other 2. September 2026
Article by Cyso Cloud engineers presenting at CloudStack conference on networking innovations (BGP, EVPN, VXLAN) and evaluating CloudStack alongside OpenStack infrastructure.
Relevance: Demonstrates Cyso's Netherlands-based development team actively engineers platform features and evaluates alternative open-source frameworks. - OpenStack – Wikipedia other 2. September 2026
OpenStack is a free open-source cloud platform founded in 2010 by Rackspace (US) and NASA (US), now governed by the Open Infrastructure Foundation with 540+ contributing companies globally.
Relevance: Establishes that the core software underpinning Cyso Cloud (OpenStack) is of US origin with global development, not EU-designed.
All possible answer options (4)
- 2. Software is of foreign origin with partial disclosure on its development (value 35.00, SEAL 2)
- 3. Core and essential parts of the software are designed and maintained by EU teams (value 71.00, SEAL 3) ✓
- 4. A large majority of the software is designed and maintained by EU teams (value 107.00, SEAL 3)
- 5. The software is exclusively designed and maintained by EU teams (value 143.00, SEAL 4)
Selected answer: 4. EU control & execution - Build/release/deployment is executed by EU teams and governed from within the EU (pipeline administration, signing, approvals) Value 107 SEAL 3
Notes: All Cyso Cloud operations are performed by in-house EU engineers in NL under Dutch jurisdiction. No evidence of automated pipeline policy gates (level 5).
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Confirms full EU ownership and governance of the platform, with all software packaging, distribution, and updates controlled from within the EU under Dutch jurisdiction. - EU Cyber Resilience Act Readiness Means Governing Software Supply Chains other 2. September 2026
Practical roadmap for CRA-preparedness covering software supply chain governance: build identities, signing keys, policy-as-code, binary authorization, and pipeline-enforced compliance controls.
Relevance: Defines the controls needed for level 5 (automated policy gates, binary authorization, signing under EU control). Cyso Cloud shows no evidence of these specific automated pipeline gates. - Managed Operations | Cyso Cloud other 2. September 2026
Details Cyso's managed operations: 24/7 NOC/SOC monitoring, all staff in Netherlands, data in EU under Dutch law.
Relevance: Confirms build/release/deployment operations are executed by EU teams in the Netherlands with pipeline administration and approvals under EU jurisdiction — key evidence for option 4.
All possible answer options (4)
- 2. EU control, non-EU execution - Execution is performed by non-EU teams, but pipeline administration and final release approvals are under EU jurisdiction (value 35.00, SEAL 1)
- 3. Non-EU control, EU execution - Execution is performed by EU teams, but pipeline administration and/or final release approvals (incl. signing) are under non-EU jurisdiction (value 71.00, SEAL 3)
- 4. EU control & execution - Build/release/deployment is executed by EU teams and governed from within the EU (pipeline administration, signing, approvals) (value 107.00, SEAL 3) ✓
- 5. EU control and EU policy gates - As (4), plus EU-based compliance/security gates enforced in the pipeline (e.g., signing under your control, vulnerability checks, segregation of duties, auditable approvals) (value 143.00, SEAL 4)
Selected answer: Few non-EU vendors or facilities involved in non-critical services, documented Value 107 SEAL 3
Notes: Critical cloud infrastructure 100% EU-owned. Non-EU dependency limited to commodity hardware. Dependencies are transparently documented.
Evidence
- Cyso Cloud – Platform Overview other 2. September 2026
Official Cyso Cloud platform page describing enterprise-grade hardware, Tier 3 data centers in Amsterdam and Frankfurt, NVMe storage, and 100% European infrastructure.
Relevance: Confirms critical services — compute, storage, networking — are EU-based and self-hosted, with no reliance on non-EU facilities for core cloud infrastructure. - Cyso Cloud Partner Program other 2. September 2026
Partner page inviting EU-only partners to invest in European digital sovereignty, targeting €50B+ European cloud market with pan-EU expansion.
Relevance: Shows Cyso's explicit policy to exclude non-EU vendors from critical supply chain roles, including hardware and technology partners for sovereign cloud infrastructure. - Cyso Subprocessors other 2. September 2026
Cyso's official sub-processor page transparently listing Microsoft, Amazon, and Google for cloud computing purposes, dated 2018.
Relevance: Demonstrates transparent documentation of non-EU vendor involvement in the supply chain, confirming supply chain dependencies are disclosed rather than undocumented.
All possible answer options (4)
- Mostly non-EU vendors or facilities involved in critical services, non documented (value 35.00, SEAL 1)
- Few non-EU vendors or facilities involved in critical services, non documented, or non-EU vendors/facilities transparently documented (value 71.00, SEAL 2)
- Few non-EU vendors or facilities involved in non-critical services, documented (value 107.00, SEAL 3) ✓
- No depedency on non-EU vendor or facility (value 143.00, SEAL 4)
Selected answer: Critical suppliers and subcontractors can be audited Value 71 SEAL 2
Notes: ISO 27001 requires risk-based supplier audit rights for critical suppliers, but Cyso's subprocessor list is outdated (2018) and no public DPA with full-chain audit rights exists.
Evidence
- Cyso Subprocessors other 2. September 2026
Cyso's official sub-processor page transparently listing Microsoft, Amazon, and Google for cloud computing purposes, dated 2018.
Relevance: Shows limited public transparency into supplier and sub-supplier chain with no evidence of audit rights extending beyond these named critical suppliers. - EU Vetted — Cyso Cloud Profile other 3. September 2026
Independent EU cloud provider directory listing flagging Cyso Cloud: no public DPA and a 2018 sub-processor list naming AWS, Microsoft, and Google. Recommends requesting current DPA directly.
Relevance: Third-party assessment confirms limited supply chain transparency and absence of public audit rights framework beyond contractual engagement with critical suppliers. - ISO 27001:2022 Annex A.5 — Supplier Management Controls other 3. September 2026
Practical guidance on ISO 27001:2022 controls A.5.19–A.5.23 covering supplier relationships, security agreements, ICT supply chain, monitoring, and cloud service security including audit rights.
Relevance: Explains what ISO 27001 certification (which Cyso holds) mandates for supplier audit rights — focused on risk-based, critical supplier auditing, not blanket coverage of all suppliers.
All possible answer options (4)
- Some suppliers and subcontractors can be audited (value 35.00, SEAL 1)
- Critical suppliers and subcontractors can be audited (value 71.00, SEAL 2) ✓
- Most suppliers and subcontractors can be audited (value 107.00, SEAL 3)
- All suppliers and subcontractors can be audited (value 143.00, SEAL 4)
SOV-6 — Technology Sovereignty
Technology sovereignty evaluates the degree of openness, transparency, and independence in the underlying technological stack, ensuring EU actors can interoperate, audit, and evolve solutions without lock-in to foreign proprietary systems.
Weight 15%
Selected answer: 5. Open-by-default with portability - All critical functions are accessible via open, well-documented, non-proprietary APIs and standard formats, with published specifications and minimal vendor-specific dependencies enabling easy third-party integration Value 200 SEAL 4
Notes: Built on OpenStack; 4 Opens philosophy ensures all APIs are open, documented, and non-proprietary with easy tool integration.
Evidence
- About Cyso Cloud other 3. September 2026
Describes Cyso Cloud's OpenStack foundation, 4 Opens philosophy (open standards, source, development, collaboration), and anti-lock-in approach.
Relevance: Shows explicit commitment to open standards and OpenStack APIs. The 4 Opens philosophy confirms open-by-default approach with minimal vendor dependencies. - Cyso Cloud – OpenStack & Automation Documentation other 2. September 2026
Official Cyso Cloud technical documentation page detailing OpenStack API, CLI, Terraform, and Ansible automation with full service endpoint references.
Relevance: All critical cloud functions accessible via open, non-proprietary OpenStack APIs with full documentation and standard tool integration out of the box. - Cyso Cloud Documentation – Migration Guides & API References other 2. September 2026
Cyso Cloud's docs hub with migration guides for volumes, instances, and object storage, plus OpenStack API references for data export and workload portability.
Relevance: Full documentation of standard OpenStack APIs and open-source tooling confirms well-documented, non-proprietary interfaces enabling easy third-party integration.
All possible answer options (4)
- 2. Restricted proprietary APIs - Some vendor APIs exist, but they are limited/restricted (access, scope, licensing) and interoperability remains vendor-controlled (value 50.00, SEAL 1)
- 3. Mixed (partial openness) - Key interfaces are documented and partly standards-based, but important functions or data formats remain proprietary/vendor-specific (value 100.00, SEAL 2)
- 4. Standards-based and broadly compatible - Interfaces and data formats predominantly follow recognised open standards (e.g., ETSI/CEN/CENELEC, ISO/IEC, IETF/W3C) with stable versioning and full documentation (value 150.00, SEAL 3)
- 5. Open-by-default with portability - All critical functions are accessible via open, well-documented, non-proprietary APIs and standard formats, with published specifications and minimal vendor-specific dependencies enabling easy third-party integration (value 200.00, SEAL 4) ✓
Selected answer: 4. Policy for most core services - A formal policy mandates and documents open standards for most core services, with managed exceptions Value 150 SEAL 3
Notes: Cyso's "4 Opens" philosophy (open standards, source, development, collaboration) mandates open standards for most core services via vanilla OpenStack, but no formal policy covers all services.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Directly evidences Cyso's documented open standards policy covering most core services through the OpenStack foundation and "4 Opens" principle, though not a formal compliance policy for all services. - Cyso Cloud — European Alternatives other 2. September 2026
Independent directory confirming all core services hosted by Cyso Group B.V. (AS25151), self-hosted infrastructure, OpenStack-based platform.
Relevance: Independently verifies that Cyso's core services adhere to OpenStack open standards and are accessible via standard APIs, corroborating the self-declared open standards commitment. - Cyso Cloud Trust Centre other 2. September 2026
Trust Centre listing DCC membership, Linux Foundation Europe, CNCF participation, and security certifications. Shows EU industry body memberships but not roadmap governance.
Relevance: Confirms formal engagement with open standards bodies (CNCF, Linux Foundation Europe) and certifications validating open standards use across security and infrastructure governance.
All possible answer options (4)
- 2. Ad hoc use - Open standards are used inconsistently on a case-by-case basis, without documented rationale or governance (value 50.00, SEAL 0)
- 3. Partial core adoption - Open standards are used and documented for some core services, while other core services remain proprietary/vendor-specific (value 100.00, SEAL 2)
- 4. Policy for most core services - A formal policy mandates and documents open standards for most core services, with managed exceptions (value 150.00, SEAL 3) ✓
- 5. Policy for all core services - A formal policy mandates and documents open standards for all core services (value 200.00, SEAL 4)
Selected answer: 5. Fully open-source software is governed by an independent or EU-based entity, granting full rights to audit, modify, redistribute, and seamlessly transfer stewardship Value 200 SEAL 4
Notes: Platform built on OpenStack (Apache 2.0), governed by independent multi-stakeholder OpenInfra Foundation with democratic elected leadership.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Confirms Cyso Cloud runs vanilla OpenStack and commits to open source, open standards, and anti-lock-in principles as core platform strategy. - OpenStack – Wikipedia other 2. September 2026
OpenStack is a free open-source cloud platform founded in 2010 by Rackspace (US) and NASA (US), now governed by the Open Infrastructure Foundation with 540+ contributing companies globally.
Relevance: Establishes that Cyso Cloud's underlying platform is fully open-source with broad multi-stakeholder governance and Apache 2.0 licensing. - OpenStack Governance – OpenInfra Foundation other 3. September 2026
Official governance hub: elected Technical Committee, multi-stakeholder Governing Board, democratic elections, Four Opens enforcement.
Relevance: Demonstrates OpenInfra Foundation governance is independent, democratic, not controlled by any single entity, enabling stewardship transfer.
All possible answer options (4)
- 2. Source code is available for review but modification and handover rights are under very strict conditions (value 50.00, SEAL 2)
- 3. The software is open source , permitting modification and redistribution, but governance is centralised (e.g., single-company or non-open foundation), limiting strategic autonomy or smooth handover (value 100.00, SEAL 3)
- 4. The software is open source with significant EU contributions but governance is restricted and handover is possible (value 150.00, SEAL 4)
- 5. Fully open-source software is governed by an independent or EU-based entity, granting full rights to audit, modify, redistribute, and seamlessly transfer stewardship (value 200.00, SEAL 4) ✓
Selected answer: Large corpus of public insight exists (all) Value 150 SEAL 3
Notes: Built on OpenStack (fully open-source) with extensive public docs, API refs, architecture principles, and '4 opens' philosophy covering design, data flows, and dependencies.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Publicly articulates service architecture design rationale, technological stack (OpenStack), dependencies, and operational principles — providing full transparency into how the service functions. - Cyso Cloud — European Cloud for Full Control & Compliance other 3. September 2026
Main website showcasing the '4 opens' philosophy (open development, standards, source, collaboration), OpenStack-based architecture, and transparent pricing model.
Relevance: Demonstrates public commitment to open standards and open-source foundation, meaning the underlying architecture is fully auditable and documented publicly via OpenStack's governance model. - Cyso Cloud Documentation – Migration Guides & API References other 2. September 2026
Cyso Cloud's docs hub with migration guides for volumes, instances, and object storage, plus OpenStack API references for data export and workload portability.
Relevance: Comprehensive public architectural documentation covering service design, data flows, dependencies, and APIs — directly demonstrates service architecture transparency across all service components.
All possible answer options (4)
- Insight accessible during audits (value 50.00, SEAL 2)
- Some public insight exists (all) (value 100.00, SEAL 3)
- Large corpus of public insight exists (all) (value 150.00, SEAL 3) ✓
- Customers can contribute to adapt and enhance the service (value 200.00, SEAL 4)
Selected answer: Co-designed or integrated in EU Value 100 SEAL 3
Notes: Active EU co-design in CHORYS (RISC-V accelerators) for cloud integration; current AMD EPYC stack is foreign.
Evidence
- CHORYS – Open and Programmable Accelerators (CORDIS) other 2. September 2026
Official EU CORDIS project page confirming Cyso B.V. as a funded partner (€350K+) in the Horizon Europe CHORYS project on open computing architecture.
Relevance: Confirms Cyso's active co-design role in EU-developed open accelerator technology (RISC-V based), demonstrating EU integration of HPC accelerator IP into its cloud platform. - Cyso Cloud Joins European CHORYS Project to Advance Open Computing Architecture other 2. September 2026
Official Cyso Cloud announcement of participation in CHORYS, an EU IPCEI project led by University of Copenhagen focusing on open accelerators for data-intensive cloud applications.
Relevance: Shows Cyso's direct contribution of cloud infrastructure and engineering resources to EU accelerator R&D, going beyond passive hosting toward active co-design and integration. - Cyso Cloud Product Page – Migration Support other 2. September 2026
Main product page stating Cyso fully supports customers in transitioning to Cyso Cloud with specialized architects and engineers designing and building the platform.
Relevance: Confirms current production infrastructure uses standard enterprise hardware (foreign processors such as AMD EPYC, not EU-designed), providing baseline of EU-hosted, foreign-stack status that CHORYS co-design aims to evolve.
All possible answer options (4)
- EU-hosted, foreign stack (value 50.00, SEAL 3)
- Co-designed or integrated in EU (value 100.00, SEAL 3) ✓
- EU processor IP, non-EU fabs (value 150.00, SEAL 3)
- EU design + EU fab + EU ops (value 200.00, SEAL 4)
SOV-7 — Security & Compliance Sovereignty
Security & Compliance sovereignty measures the extent to which security operations, compliance obligations, and resilience measures are controlled within the EU , ensuring independence from foreign jurisdictions and long-term operational assurance.
Weight 15%
Selected answer: EAL2 Value 71 SEAL 2
Notes: ISO 27001, NEN 7510, SOC 2 Type II attained; lacks broader EU certs like BSI C5 or ENS for higher levels.
Evidence
- Cyso Certifications Page other 3. September 2026
Official Cyso page listing ISO/IEC 27001, NEN 7510, and SOC 2 Type II certifications with validity dates.
Relevance: Directly confirms which EU and international security certifications Cyso has attained, central to the assessment question. - Cyso Cloud Trust Centre other 2. September 2026
Trust Centre listing DCC membership, Linux Foundation Europe, CNCF participation, and security certifications. Shows EU industry body memberships but not roadmap governance.
Relevance: Confirms security certifications and compliance posture from the cloud provider's own trust centre.
All possible answer options (4)
- ELA1 (value 35.00, SEAL 1)
- EAL2 (value 71.00, SEAL 2) ✓
- ELA3 (value 107.00, SEAL 3)
- EAL4-5 (value 143.00, SEAL 4)
Selected answer: 3. Moderate compliance to some well-know EU Regulations (controls exist but gaps remain; compliance not fully demonstrated) Value 71 SEAL 4
Notes: GDPR compliance and ISO 27001/NEN 7510/SOC 2 certifications exist, but no evidence of NIS2 or DORA compliance. Gaps remain for full EU regulatory adherence.
Evidence
- Cloud Certifications Explained: ISO 27001, BSI C5, HDS & More other 3. September 2026
Industry article explaining cloud compliance certifications and their legal significance, comparing European cloud providers' certification portfolios.
Relevance: Provides context on what EU regulatory certifications (BSI C5, HDS, SecNumCloud, DORA) serious cloud providers should hold, highlighting Cyso's absence of DORA/NIS2-specific certifications. - Cyso Certifications Page other 3. September 2026
Official Cyso page listing ISO/IEC 27001, NEN 7510, and SOC 2 Type II certifications with validity dates.
Relevance: Confirms independently audited ISO 27001 and SOC 2 Type II, but no NIS2/DORA-specific certifications or audit evidence listed. - Cyso Cloud Trust Centre other 2. September 2026
Trust Centre listing DCC membership, Linux Foundation Europe, CNCF participation, and security certifications. Shows EU industry body memberships but not roadmap governance.
Relevance: Shows GDPR compliance and security certifications (ISO 27001, SOC 2) but no mention of NIS2 or DORA compliance, indicating partial coverage of EU frameworks.
All possible answer options (4)
- 2. Limited compliance to some well-known EU Regulations (basic practices exist but informal, incomplete, or non-systematic) (value 35.00, SEAL 4)
- 3. Moderate compliance to some well-know EU Regulations (controls exist but gaps remain; compliance not fully demonstrated) (value 71.00, SEAL 4) ✓
- 4. Partial compliance to most of the well-known EU Regulations (requirements implemented and operational with minor exceptions) (value 107.00, SEAL 4)
- 5. Fully compliant to all well-know EU regulations (verified compliance, independently audited) (value 143.00, SEAL 4)
Selected answer: 4. The entire incident lifecycle is handled by teams operating exclusively within the EU. Threat intelligence and incident data obtained mostly via EU sources Value 107 SEAL 3
Notes: Cyso's 24/7 SOC and incident response are fully EU-based. No evidence of non-EU escalation. No ENISA ISAC participation found, ruling out option 5.
Evidence
- About Cyso - Cyso.com other 2. September 2026
Cyso Group corporate page: describes itself as the oldest independent Dutch hosting provider, part of Cyso Group since 1997, all data centers on European soil.
Relevance: Confirms cybersecurity operations are fully Dutch/EU-based. Lists SIEM and threat detection capabilities but no evidence of ENISA information sharing framework participation. - Cyso Cloud Trust Centre other 2. September 2026
Trust Centre listing DCC membership, Linux Foundation Europe, CNCF participation, and security certifications. Shows EU industry body memberships but not roadmap governance.
Relevance: Confirms entire incident lifecycle handled by EU-based SOC teams with dedicated incident response. No mention of non-EU escalation or hybrid operations. - ENISA – Information Sharing and Analysis Centers (ISACs) other 3. September 2026
ENISA's page on ISACs as trusted hubs for sharing threat intelligence across EU sectors, supported under the NIS2 Directive.
Relevance: Provides context on ENISA information sharing frameworks. No evidence found of Cyso's participation in ENISA ISACs, which rules out answer option 5.
All possible answer options (4)
- 2. A hybrid model is used with SOC functions split between EU and non-EU locations (value 35.00, SEAL 1)
- 3. The primary SOC is in the EU but incidents may be escalated to non-EU teams (value 71.00, SEAL 1)
- 4. The entire incident lifecycle is handled by teams operating exclusively within the EU. Threat intelligence and incident data obtained mostly via EU sources (value 107.00, SEAL 3) ✓
- 5. The full incident lifecycle is handled by EU-based teams with active participation in ENISA's information sharing frameworks. Threat intelligence and incident data are gathered worldwide (value 143.00, SEAL 4)
Selected answer: 4. Customers have full direct access to their security monitoring and logs which are stored in the EU Value 107 SEAL 3
Notes: Observe platform gives real-time monitoring, log aggregation, and custom dashboards. Audit logs via IAM. All data within EU. No immutability mentioned.
Evidence
- Cyso Cloud — Security Measures other 2. September 2026
Cyso Cloud's security overview detailing ISO 27001/NEN 7510 certifications, encryption, network segmentation, and platform architecture.
Relevance: Confirms active monitoring and logging of systems, but does not mention immutability or tamper-proof logs, ruling out option 5. - Cyso Cloud IAM – Identity and Access Management other 3. September 2026
European IAM platform with comprehensive audit logs, real-time compliance dashboards, automated reporting, and full GDPR compliance with data within EU borders.
Relevance: Confirms audit logging and real-time compliance dashboards accessible to customers, with all data stored exclusively within the EU. - Observe by Cyso – Advanced Monitoring Platform other 3. September 2026
Cyso's observability platform offering real-time monitoring with custom dashboards, extensive log aggregation without storage limits, and full data access and control.
Relevance: Demonstrates customers have direct access to real-time monitoring and log aggregation rather than periodic reports, supporting direct oversight of security logs.
All possible answer options (4)
- 2. Customers receive periodic reports based on security logs (value 35.00, SEAL 1)
- 3. Customers have access to a basic portal for monitoring (value 71.00, SEAL 1)
- 4. Customers have full direct access to their security monitoring and logs which are stored in the EU (value 107.00, SEAL 3) ✓
- 5. Customers have full access to immutable tamper-proof logs stored exclusively within the EU (value 143.00, SEAL 4)
Selected answer: 3. Moderate compliance - GDPR/NIS2-aligned reporting procedures in place with vulnerabilities and breaches communicated within mandated timelines; CSIRT cooperation available but not real-time Value 71 SEAL 2
Notes: ISO 27001/SOC 2-backed incident response with NIS2/GDPR alignment and responsible disclosure policy. No evidence of real-time CSIRT data sharing or contractual EU investigation readiness.
Evidence
- Cybersecurity Solutions | Cyso Cloud other 3. September 2026
Describes 24/7 SOC monitoring, incident response procedures (detect, contain, investigate, report), post-incident reports, and NIS2/GDPR compliance support.
Relevance: Directly confirms GDPR/NIS2-aligned incident reporting procedures with structured detection-to-report workflow and post-incident root cause analysis. - Cyso Cloud Trust Centre other 2. September 2026
Trust Centre listing DCC membership, Linux Foundation Europe, CNCF participation, and security certifications. Shows EU industry body memberships but not roadmap governance.
Relevance: Confirms certified incident management framework with ISO 27001 controls and 24/7 response, but no mention of CSIRT real-time data sharing or audit-backed EU investigation readiness. - Responsible Disclosure — Cyso.com other 3. September 2026
Cyso's vulnerability disclosure policy with 3-day response SLA, Wall of Fame, and rewards for serious findings reported by researchers.
Relevance: Demonstrates proactive vulnerability disclosure with defined timelines, meeting part of the disclosure transparency criteria for EU sovereignty assessment.
All possible answer options (4)
- 2. Limited compliance - reporting is reactive with limited transparency and unguaranteed timelines; CSIRT cooperation possible on best-effort basis (value 35.00, SEAL 1)
- 3. Moderate compliance - GDPR/NIS2-aligned reporting procedures in place with vulnerabilities and breaches communicated within mandated timelines; CSIRT cooperation available but not real-time (value 71.00, SEAL 2) ✓
- 4. Partial compliance - there is a monitored reporting flow with internal SLAs equal or below regulatory maximums; contractually prepared to support EU-directed investigations; data sharing with EU CSIRTs available but not in real-time (value 107.00, SEAL 3)
- 5. Full compliance - full EU-compliant breach disclosure with real-time data sharing to EU CSIRTs with audit-backed processes, proactive vulnerability disclosure and threat intel sharing; proven readiness for investigations (value 143.00, SEAL 4)
Selected answer: 3. Moderate Autonomy - security patches are deployed with sufficient notice to the customer and testing is possible, except for zero-day patching Value 71 SEAL 4
Notes: Cyso deploys monthly patches via maintenance windows with notice; customers control VM patching independently, but platform-layer patching remains provider-managed, including zero-days.
Evidence
- Cloud Operations – Cyso.com other 2. September 2026
Cyso's CloudOps service page detailing 24/7 monitoring, disaster recovery execution, multi-cloud support, and operational continuity management.
Relevance: Shows security patches deployed on vendor schedule with maintenance windows and notice to customers; zero-day patching is handled by Cyso, not customer-controlled. - Cyso Cloud — Security Measures other 2. September 2026
Cyso Cloud's security overview detailing ISO 27001/NEN 7510 certifications, encryption, network segmentation, and platform architecture.
Relevance: Confirms Cyso autonomously patches firmware and OS of infrastructure to mitigate critical risks, but does not offer customer-controlled platform-layer patching. - OpenStack vs Proprietary Clouds: A Digital Sovereignty Comparison Guide — OpenInfra Foundation other 3. September 2026
Compares OpenStack vs proprietary clouds on sovereignty: operator-controlled patching cadence, immediate critical vulnerability patching without vendor wait.
Relevance: As an OpenStack provider, Cyso can patch platform independently without waiting for vendor release cycles, but customers cannot patch the platform layer themselves.
All possible answer options (4)
- 2. Limited Autonomy - security patches are deployed according to vendor schedules; basic testing is possible (value 35.00, SEAL 1)
- 3. Moderate Autonomy - security patches are deployed with sufficient notice to the customer and testing is possible, except for zero-day patching (value 71.00, SEAL 4) ✓
- 4. High Autonomy - security patches can be deployed independently by the customer, without customers' checks (value 107.00, SEAL 4)
- 5. Full Autonomy - security patches can be deployed independently by the customer, with customers' checks (value 143.00, SEAL 4)
Selected answer: 4. High control by independent entities to request data from the vendor Value 107 SEAL 1
Notes: Cyso holds ISO 27001, NEN 7510, SOC 2 Type II certifications and provides audit-ready logs, configs & documentation on request. No evidence of unrestricted system access for arbitrary independent auditors.
Evidence
- Cybersecurity Solutions | Cyso Cloud other 3. September 2026
Describes 24/7 SOC monitoring, incident response procedures (detect, contain, investigate, report), post-incident reports, and NIS2/GDPR compliance support.
Relevance: Directly addresses auditability: Cyso provides audit evidence and documentation on request, with independently audited certifications, but evidence is vendor-provided rather than granting full independent audit access. - Cyso Cloud IAM – Identity and Access Management other 3. September 2026
European IAM platform with comprehensive audit logs, real-time compliance dashboards, automated reporting, and full GDPR compliance with data within EU borders.
Relevance: Demonstrates robust audit logging and compliance reporting capabilities EU entities can request, but access is managed by vendor with no evidence of granting independent auditors full unrestricted system access. - Managed Operations | Cyso Cloud other 2. September 2026
Details Cyso's managed operations: 24/7 NOC/SOC monitoring, all staff in Netherlands, data in EU under Dutch law.
Relevance: Shows Cyso maintains continuous audit-ready evidence and a Trust Centre for certification documents, supporting high auditability but via vendor-provided data rather than unrestricted independent audit access.
All possible answer options (4)
- 2. Limited access to independent entities to the data provided by the vendor (value 35.00, SEAL 1)
- 3. Partial control by independent entities on the data provided by the vendor (value 71.00, SEAL 1)
- 4. High control by independent entities to request data from the vendor (value 107.00, SEAL 1) ✓
- 5. Full control by any idependent entity to perform security and compliance audits (value 143.00, SEAL 4)
SOV-8 — Environmental Sustainability
Environmental sustainability assesses autonomy and resilience of cloud services over the long term in relation to energy usage, dependency and raw material scarcity.
Weight 5%
Selected answer: PUE < 3 Value 62 SEAL 1
Notes: No public PUE data or measurable efficiency targets found. CSR exists but lacks data center energy metrics or roadmap. PUE likely below 3.
Evidence
- Corporate Social Responsibility – Cyso.com other 3. September 2026
Cyso's CSR page details hardware lifecycle management, CO₂-neutral fleet, and social initiatives but no data center PUE targets or energy efficiency roadmap.
Relevance: Directly shows Cyso's sustainability efforts omit measurable data center energy efficiency (PUE) targets, supporting lowest-tier assessment. - Cyso Cloud — Security Measures other 2. September 2026
Cyso Cloud's security overview detailing ISO 27001/NEN 7510 certifications, encryption, network segmentation, and platform architecture.
Relevance: Confirms ISO 14001 environmental management exists but no published PUE figures or measurable improvement targets for energy efficiency. - Data centres: Hungry for power – ICIS other 3. September 2026
ICIS report on European data centre power demand; notes European average PUE ~1.6, new facilities should reach 1.3, and Germany's 2026 requirement of PUE ≤1.2.
Relevance: Provides industry context: Cyso operates in Amsterdam (NL) and Frankfurt (DE) where PUE ≤1.2 may soon be mandatory, yet Cyso publishes no PUE data.
All possible answer options (5)
- PUE > 0 (value 0.00, SEAL 1)
- PUE < 3 (value 62.00, SEAL 1) ✓
- PUE < 1.5 + roadmap (value 125.00, SEAL 4)
- PUE < 1.3 (value 187.00, SEAL 4)
- PUE < 1.2 EU verified (value 250.00, SEAL 4)
Selected answer: Documented program Value 125 SEAL 3
Notes: Cyso has a documented CSR program with hardware lifecycle reuse/donation, but no formal EU circular economy certification or framework alignment.
Evidence
- Corporate Social Responsibility – Cyso.com other 3. September 2026
Cyso's CSR page details hardware lifecycle management, CO₂-neutral fleet, and social initiatives but no data center PUE targets or energy efficiency roadmap.
Relevance: Directly documents Cyso's hardware reuse and lifecycle practices — a documented but informal program without EU certification or formal circular economy framework alignment. - Use the Data Center Circular Economy for Sustainability – TechTarget other 3. September 2026
Practical guide on circular economy in data centers with examples from Microsoft (90% reuse target), Amazon (reverse logistics hubs), and Google (zero-waste goals, 32.6M components resold).
Relevance: Benchmark showing what a fully circular economy-aligned or EU-certified lifecycle program looks like; Cyso's CSR program falls short of these standards. - Waste from Electrical and Electronic Equipment (WEEE) – European Commission other 3. September 2026
EU WEEE Directive (2012/19/EU) sets mandatory collection, reuse, and recycling targets for IT and telecom equipment including data center hardware across EU member states.
Relevance: Establishes the EU regulatory baseline Cyso must comply with as a Dutch company, but compliance is obligatory rather than a voluntary circular economy certification.
All possible answer options (5)
- No policy (value 0.00, SEAL 0)
- Circular economy EU-aligned (value 62.00, SEAL 0)
- Documented program (value 125.00, SEAL 3) ✓
- Circular economy EU-aligned (value 187.00, SEAL 4)
- EU-certified lifecycle (value 250.00, SEAL 4)
Selected answer: No reporting Value 0 SEAL 1
Notes: Cyso's CSR page outlines qualitative initiatives (hardware reuse, electric fleet) but publishes no measured carbon, water, or energy metrics for its data centers.
Evidence
- About Cyso Cloud other 2. September 2026
Official about page outlining mission, OpenStack foundation, Gaia-X alignment, and '4 Opens' philosophy (open development, standards, source, collaboration).
Relevance: Demonstrates Cyso treats sustainability as aspirational rather than measured, with no formal environmental impact reporting or quantified data disclosure. - Corporate Social Responsibility – Cyso.com other 3. September 2026
Cyso's CSR page details hardware lifecycle management, CO₂-neutral fleet, and social initiatives but no data center PUE targets or energy efficiency roadmap.
Relevance: Shows Cyso provides qualitative sustainability statements but no transparent measurement or disclosure of carbon emissions, water usage, or sustainability indicators. - ESG Reporting: Carbon in the Cloud – CIO.com other 3. September 2026
Article exploring complexities of cloud computing carbon emissions, ESG reporting gaps, and greenwashing risks; notes Scope 3 cloud emissions reporting is voluntary.
Relevance: Industry benchmark showing what proper environmental reporting requires — highlighting Cyso's complete absence of carbon, water, or energy data disclosure by comparison.
All possible answer options (5)
- No reporting (value 0.00, SEAL 1) ✓
- Detailed EU methodology (value 62.00, SEAL 1)
- Annual report (value 125.00, SEAL 2)
- Detailed EU methodology (value 187.00, SEAL 3)
- EU-audited reporting (value 250.00, SEAL 4)
Selected answer: Only EU energy supplies Value 62 SEAL 4
Notes: Cyso operates data centers in Amsterdam and Frankfurt (EU only), so energy is sourced from EU grids. No public evidence of green-only or renewable energy sourcing.
Evidence
- Corporate Social Responsibility – Cyso.com other 3. September 2026
Cyso's CSR page details hardware lifecycle management, CO₂-neutral fleet, and social initiatives but no data center PUE targets or energy efficiency roadmap.
Relevance: Confirms Cyso has sustainability efforts but explicitly lacks disclosure of renewable energy sourcing for data center operations — key gap for this assessment question. - Energy & Sustainability – Dutch Data Center Association other 3. September 2026
DDA reports 88% of affiliated Dutch data centers use renewable power and the sector targets climate neutrality by 2030 under the CNDCP. Notes insufficient domestic renewable generation capacity.
Relevance: Provides context on Dutch data center energy sourcing; shows high renewable penetration in the Netherlands where Cyso's Amsterdam data center is located, supporting EU-only energy supply. - Network – Cyso.com other 3. September 2026
Cyso's official network page confirms carrier-neutral data centers in Amsterdam and Frankfurt with their own RIPE IP space and fiber network, both within the EU.
Relevance: Confirms Cyso's data centers are exclusively in the EU, meaning energy supplies are drawn from EU grids. No non-EU infrastructure or energy dependency indicated.
All possible answer options (4)
- Only EU energy supplies (value 62.00, SEAL 4) ✓
- Mix of EU and non-EU supplies (value 125.00, SEAL 4)
- Only EU energy supplies (value 187.00, SEAL 4)
- Only green EU energy supplies (value 250.00, SEAL 4)
Data Centres
At the moment, Cyso Cloud is operating from 3 data centers in two locations: Amsterdam and Frankfurt. Both locations are very popular data center locations with direct backbone access. All US hyperscalers and many European cloud providers are hosting their services in Amsterdam and Frankfurt.
| Country | City | Name |
|---|---|---|
| Frankfurt | Cyso Cloud FFM | |
| Amsterdam | Cyso Cloud AMS |
Environmental Policy
In the Cyso Corporate Social Responsibility statement, Cyso are stating “the ultimate goal of achieving a positive climate effect”. Concrete measures towards this goal are:
- Hardware lifecycle management, where decomissioned hardware is repurposed or donated to educational institutions.
- CO2 neutral fleet of company cars.
There are no statements about energy efficiency of data centres and about the energy sources to power Cyso Cloud.
Certifications
At the moment (11/2025), Cyso Cloud holds the ISO/IEC 27001 certification, which testifies that Cyso has all the processes in place that have to do with the security, availability and integrity of data and applications.
Building on the ISO/IEC 27001 certification, Cyso Cloud also holds the NEN 7510 certification. This certification was developed by the Dutch Standards Institute for Information security for the healthcare sector in the Netherlands and is based on ISO 27001. It adds to ISO 27001 specific regulations for handling patient data in the electronic health record.
Details about the Cyso Cloud certificates are listed on the Cyso Cloud certifications page.
Conclusion
Cyso Cloud is a regional dutch OpenStack based cloud provider. Once the Cloud Databases managed database service is out of beta, the service portfolio encompasses the minimum set of services that should be expected of a cloud provider (compute, Kubernetes, storage, managed databases, and networking).
With its data centres in North Holland and in Frankfurt, Cyso Cloud can fulfill geo-redundancy requirements. The NEN 7510 certification for the Dutch healthcare sector can make Cyso Cloud a good choice for respective Dutch companies.
Resources
- HeadquartersAlkmaar, Netherlands
- Parent companyCyso Group
- Cloud since2025
- Websitecyso.cloud
ISO 27001
NEN 7510
SOC 2