Webinar replay: Heroku to AWS in one command, with an agent doing the work.

The 10 Best Sovereign Cloud Providers in Europe for Kubernetes (2026 Comparison)

A criteria-first comparison of Europe's leading sovereign cloud providers - Scaleway, OVHcloud, Exoscale, Clever Cloud, Cloud Temple, 3DS Outscale, StackIt, IONOS, Aruba Cloud and T-Systems - covering managed Kubernetes, SecNumCloud and BSI C5 certification, egress pricing, EU Data Act exit rights, and how to stay portable between them.

Romaric Philogene
CEO & Co-founder
SEP 26, 2026 · 11 MIN
The 10 Best Sovereign Cloud Providers in Europe for Kubernetes (2026 Comparison)

Most "sovereign cloud" pages in Europe are marketing pages. Sovereignty is four measurable properties, and only a handful of providers score well on all four. I have spent years helping teams run Kubernetes across AWS, Scaleway, OVHcloud and bare-metal clusters, and the question I get most often now is not "which cloud is cheapest" but "which cloud keeps my data out of reach of foreign law, and can I still ship fast on it." So here is the verdict first, then the evidence.

Key points:

  • The strongest European sovereign cloud providers in 2026 are Scaleway and OVHcloud (France, broad IaaS plus managed Kubernetes), Exoscale (Switzerland/EU, Kubernetes-first), Clever Cloud (France, PaaS on its own infrastructure), Cloud Temple and 3DS Outscale (France, SecNumCloud-qualified for regulated workloads), StackIt and IONOS Cloud (Germany), T-Systems Open Telekom Cloud (Germany, enterprise procurement) and Aruba Cloud (Italy).
  • "Sovereign" is four independent properties, not one label: data residency, operational access control, legal jurisdiction of the operating entity (immunity from the US CLOUD Act), and technical portability. Score every provider on all four. Most sovereignty marketing satisfies two and claims four.
  • For regulated workloads in France, ANSSI SecNumCloud 3.2 is the strictest bar in Europe today because it adds jurisdictional immunity criteria on top of security controls. Qualification is granted per offer and per region, never per company, so check the exact service against the official ANSSI list and ask for the reference number and expiry date.
  • Managed Kubernetes is available from Scaleway (Kapsule), OVHcloud (MKS), Exoscale (SKS), 3DS Outscale (OKS), StackIt (SKE), IONOS Cloud and T-Systems (CCE). They run CNCF-conformant distributions, so Helm, Argo CD, Prometheus, cert-manager and Terraform/OpenTofu run unchanged. The real gap versus AWS, GCP and Azure is the managed-service catalog above Kubernetes, not Kubernetes itself.
  • Sovereign providers are usually cheaper on compute and bandwidth, and several bundle egress that hyperscalers bill per GB, but you pay the difference in platform engineering time. The EU Data Act phases out switching charges from January 2027, which makes an architecture that can actually move the deciding factor, not the contract.
  • Qovery is not a cloud provider and holds no sovereignty certification. It is an internal developer platform that runs inside your own account on AWS, GCP, Azure or Scaleway, or on any existing Kubernetes cluster including OVHcloud, Exoscale, StackIt, IONOS or on-prem, so choosing a sovereign provider does not force you to rebuild how your team ships.
Qovery · Agentic Infrastructure Platform
Kubernetes, operated through one governed API
Learn more

What are the best sovereign cloud providers in Europe in 2026?

The best European sovereign cloud providers in 2026 are Scaleway and OVHcloud for broad IaaS with managed Kubernetes, Exoscale for Kubernetes-first workloads, Cloud Temple and 3DS Outscale for SecNumCloud-regulated workloads, Clever Cloud for developer-first PaaS, and StackIt, IONOS Cloud, T-Systems and Aruba Cloud where German or Italian jurisdiction is the requirement. The pick is decided by jurisdiction and certification scope, not by feature count.

Here is the one-line verdict for each, so you can lift the entity you care about:

  • Scaleway (France, iliad Group). Broadest EU-owned IaaS with a free managed Kubernetes control plane (Kapsule); best for breadth and pricing.
  • OVHcloud (France, OVH Groupe SA, listed on Euronext Paris). The scale player, strong on bare metal and included bandwidth; best where you want reach and raw price.
  • Exoscale (Switzerland/EU, Akenes SA, part of the A1 Group). A clean Kubernetes-first cloud with a Swiss plus EU footprint; best for teams that want Swiss jurisdiction.
  • Clever Cloud (France). A PaaS that runs on its own infrastructure and competes on developer experience rather than IaaS breadth; best for teams who want one French vendor to do the shipping for them.
  • Cloud Temple (France). SecNumCloud 3.2-qualified sovereign cloud; best for regulated workloads that need documented immunity from non-EU law.
  • 3DS Outscale (France, a Dassault Systèmes brand). SecNumCloud 3.2-qualified with its own managed Kubernetes (OKS); best for regulated and industrial workloads.
  • StackIt (Germany, Schwarz Group, parent of Lidl and Kaufland). German-owned IaaS with managed Kubernetes; best for German sovereign backing outside the telecom incumbents.
  • IONOS Cloud (Germany, IONOS SE, listed). German hosting with a free Kubernetes control plane; best for straightforward German jurisdiction on a budget.
  • T-Systems Open Telekom Cloud (Germany, Deutsche Telekom). Enterprise procurement and BSI C5; best for large German enterprises that buy through Telekom.
  • Aruba Cloud (Italy, Aruba S.p.A.). Italy's largest hoster with its own datacenter campuses; best where Italian jurisdiction is the requirement.

Two honest flags. Civo offers low-cost, CNCF-conformant managed Kubernetes with EU regions, but it is UK-headquartered, so its post-Brexit jurisdictional profile is different from an EU-headquartered provider. Hetzner is excellent value with a German footprint, but it does not position itself on sovereignty certification and ships no first-party managed Kubernetes, so treat it as a cost play, not a sovereignty play.

Three questions decide the choice: which regulation applies to you, which certification scope you actually need, and whether you want raw IaaS or a managed platform. Everything else is detail.

For scale: in 2025, 52.7% of EU enterprises paid for cloud computing services (Eurostat), yet three US companies (Amazon, Microsoft and Google) still held roughly 70% of European cloud infrastructure spend in the first half of 2025, with European providers holding steady at about 15% (Synergy Research Group). The sovereign providers below are the credible answer to that gap.

ProviderCountry / jurisdictionOwnershipModelManaged KubernetesBest for
ScalewayFranceiliad GroupIaaS + K8sYes (Kapsule)Breadth and pricing
OVHcloudFranceOVH Groupe SAIaaS + bare metalYes (MKS)Scale and bare metal
ExoscaleSwitzerland / EUAkenes SA (A1 Group)IaaS + K8sYes (SKS)Kubernetes-first, Swiss footprint
Clever CloudFranceIndependentPaaSBeta (CKE)Developer-first shipping
Cloud TempleFranceIndependentIaaS + K8sYesSecNumCloud workloads
3DS OutscaleFranceDassault SystèmesIaaS + K8sYes (OKS)Regulated / industrial
StackItGermanySchwarz GroupIaaS + K8sYes (SKE)German sovereign backing
IONOS CloudGermanyIONOS SEIaaS + K8sYesGerman jurisdiction on a budget
T-Systems (OTC)GermanyDeutsche TelekomIaaS + K8sYes (CCE)Enterprise procurement + C5
Aruba CloudItalyAruba S.p.A.IaaS + K8sYesItalian jurisdiction

What actually makes a cloud provider "sovereign" in Europe?

A cloud is sovereign only when four independent properties hold at once: data residency, operational access control, legal jurisdiction of the operating entity, and technical portability. Most sovereign cloud marketing satisfies one or two of them and claims all four, so score every provider on each property separately.

  • Data residency. Where data is stored, replicated and backed up, including metadata, logs and support tickets. The backup bucket and the log pipeline are the usual leak, not the primary database. "Frankfurt region" says nothing about where the snapshot replicates.
  • Operational sovereignty. Who can technically access systems, from which country, under which support model and follow-the-sun rotation, and whether break-glass access is auditable.
  • Legal sovereignty. Whether the operating entity is subject to the US CLOUD Act and FISA Section 702. The CLOUD Act, signed into law in March 2018 as part of the Consolidated Appropriations Act (Congress.gov, H.R.4943 / Public Law 115-141), lets US authorities compel US-controlled providers to disclose data regardless of where it is physically stored. FISA Section 702 is the separate surveillance authority the Court of Justice of the EU cited when it struck down Privacy Shield in Schrems II (Case C-311/18, 16 July 2020).
  • Technical sovereignty. Open standards, portable formats, a documented exit plan, and no hard dependency on a proprietary control plane. A "sovereign" cluster sitting behind a US CI system, registry, identity provider and observability vendor is not a sovereign system.

An EU subsidiary of a US parent is not legally sovereign, no matter how many datacenters it runs in Frankfurt or Paris. The European Data Protection Board and the EDPS reached the same conclusion in their joint response on the CLOUD Act: a US-controlled provider can be compelled to hand over data, and a US warrant alone is not a valid basis for disclosure under GDPR (EDPB-EDPS joint response). Physical location does not change who controls the entity.

Certifications are proxies for these properties, and each proves something different. ANSSI SecNumCloud 3.2 (France) is the strictest because it ties qualification to protection from non-EU law, not just security controls; it is granted per offer and per region (ANSSI qualified providers). BSI C5 (Germany) is a criteria catalogue verified by auditor attestation, which is a Type 1 or Type 2 report, not a certification (BSI C5). ISO/IEC 27001 covers a management system, not sovereignty. HDS is required for hosting French health data, with an official register at esante.gouv.fr. And two regimes now change the third-party risk calculus directly: NIS2 (Directive (EU) 2022/2555) put cloud and managed service providers in scope as essential or important entities, with a transposition deadline of 17 October 2024 (EUR-Lex), and DORA (Regulation (EU) 2022/2554), applicable since 17 January 2025, holds financial entities responsible for ICT third-party risk under its Chapter V (EUR-Lex).

Two things to clear up. EUCS, the EU-wide cloud certification scheme, is still a candidate, and it has been stuck precisely on whether the highest assurance level should require immunity from non-EU law; the sovereignty requirements were removed in a 2024 draft and the matter is unresolved (ENISA). And Gaia-X is a Belgian non-profit association running a framework and labelling initiative with over 340 members (Gaia-X); it is not a cloud provider and never was.

The US hyperscalers' own sovereign offerings belong on the map, described fairly rather than dismissed. AWS European Sovereign Cloud launched on 14 January 2026 in Brandenburg, Germany, backed by a stated 7.8 billion euro investment and run through dedicated German legal entities with EU-resident leadership (AWS). Microsoft Sovereign Cloud offers a Sovereign Public Cloud and a Sovereign Private Cloud plus a Data Guardian control under which only Microsoft personnel resident in Europe approve remote access (Microsoft). S3NS, a French company majority-owned by Thales in partnership with Google Cloud, took its PREMI3NS trusted cloud through SecNumCloud 3.2 qualification in December 2025 (Thales). These offerings address data residency and operational access seriously. The layer where they still differ from an EU-owned provider is legal ownership: AWS and Microsoft keep a US-headquartered ultimate parent, while S3NS is structured as a French entity precisely to close that gap.

Sovereignty propertyEU-owned independent providerUS hyperscaler, EU regionUS hyperscaler sovereign offeringEU joint venture (e.g. S3NS)Self-managed K8s on EU infra
Data residencyEU / national by designEU region available; verify backupsEU-only by designEU / national by designYou decide
Operational accessEU / national staffOften global supportEU-staffed, EU-controlledEU-staffedYou control
Legal jurisdictionEU entity, no US parentUS parent, CLOUD Act exposureUS parent; ownership question persistsFrench entity (Thales majority)Depends on host
Technical portabilityVerify per providerProprietary stackProprietary stack, EU-operatedGoogle tech, EU-operatedFully portable

How do European sovereign cloud providers compare on Kubernetes, certification and jurisdiction?

Scaleway and OVHcloud win on breadth and price, Exoscale on Kubernetes ergonomics, Cloud Temple and 3DS Outscale on regulated assurance, Clever Cloud on developer experience, T-Systems and IONOS Cloud on enterprise procurement and German jurisdiction, and Aruba Cloud on Italian jurisdiction. There is no single winner; the right answer is whichever one clears the constraint that would fail your audit or blow your budget.

ProviderHQ / jurisdictionOwnershipModelManaged KubernetesKey verified certificationsEU footprintBest fit
ScalewayFranceiliad GroupIaaS + K8sKapsule + KosmosISO 27001, HDS (SecNumCloud in process)Paris, Amsterdam, Warsaw, MilanBreadth and pricing
OVHcloudFranceOVH Groupe SA (Euronext Paris)IaaS, bare metal, K8sMKSSecNumCloud 3.2 (qualified offers), HDS, ISO 27001FR, DE, PL, UK (+ non-EU)Scale and bare metal
ExoscaleSwitzerland / EUAkenes SA (A1 Telekom Austria Group)IaaS + K8sSKSISO 27001CH, DE, AT, BG, HRKubernetes-first, Swiss jurisdiction
Clever CloudFranceIndependentPaaS (+ K8s beta)CKE (public beta)ISO 27001, HDS (SecNumCloud in progress)FranceDeveloper-first shipping
Cloud TempleFranceNeurones groupIaaS, PaaS, K8sManaged KubernetesSecNumCloud 3.2 (Secure Temple), HDS, ISO 27001FranceSecNumCloud-regulated workloads
3DS OutscaleFranceDassault SystèmesIaaS + K8sOKSSecNumCloud 3.2, HDSFranceRegulated / industrial
StackItGermanySchwarz GroupIaaS + K8sSKEBSI C5 Type 2, ISO 27001, TISAXGermany, AustriaGerman sovereign backing
IONOS CloudGermanyIONOS Group SE (listed)IaaS + K8sManaged KubernetesBSI C5 Type 1, ISO 27001Germany (+ EU)German jurisdiction on a budget
Aruba CloudItalyAruba S.p.A.IaaS + K8sManaged KubernetesISO 27001, ACN QC3Italy (Ponte San Pietro)Italian jurisdiction
T-Systems (T Cloud Public)GermanyDeutsche TelekomIaaS + K8sCCEBSI C5 Type 2, ISO 27001EU-DE, EU-NLEnterprise procurement + C5
CivoUnited KingdomCivo LtdManaged K8s (k3s)Civo KubernetesCNCF conformant (non-EU jurisdiction)FrankfurtLow-cost K8s, UK jurisdiction
HetznerGermanyHetzner Online GmbHIaaS (self-managed K8s)None (self-managed)ISO 27001 (not marketed on sovereignty)Germany, FinlandCheapest raw compute

A few weaknesses that apply across the EU-owned field, stated plainly: thinner managed-service catalogs, fewer managed AI and GPU options, smaller marketplaces, less third-party and Terraform provider coverage than AWS, GCP or Azure, and smaller footprints outside Europe. None of that shows up in a feature checklist; all of it shows up in month two.

Who should pick what:

  • French regulated workload under DORA or HDS: Cloud Temple or 3DS Outscale for the SecNumCloud-qualified core, OVHcloud where its qualified offer fits, and keep the rest on a cheaper EU provider behind one delivery layer.
  • German enterprise procurement requiring C5: T-Systems Open Telekom Cloud or IONOS Cloud, with StackIt as the newer German-owned alternative.
  • EU startup optimizing cost and developer velocity: Scaleway or Exoscale for managed Kubernetes, Hetzner where raw compute price dominates and you can run the cluster yourself, Clever Cloud if you would rather not touch Kubernetes at all.

Every certification claim above should be re-checked against the provider's own trust page or the ANSSI, BSI or CNCF list on the day you sign, because qualification is per-offer and it changes.

Ship faster on infrastructure you control.
Qovery gives your team self-service deployments on your own AWS, GCP, Azure or Scaleway account - or your existing Kubernetes cluster, wherever it runs in Europe. Start deploying in under 10 minutes.

Is a sovereign cloud cheaper or more expensive than AWS, GCP or Azure?

On raw compute and bandwidth, European sovereign providers are usually cheaper than AWS, GCP and Azure, and several bundle egress that the hyperscalers bill per GB. You pay the difference in missing managed services, which shows up as platform engineering time and on-call load, not as a line on the invoice.

Egress is where the gap is widest. AWS bills internet data transfer out at about 0.09 USD per GB after the first 100 GB free (AWS), and Azure at about 0.087 USD per GB from Europe after 100 GB free (Microsoft); Google Cloud is tiered and typically higher on its premium network (Google Cloud). Against that, OVHcloud includes public instance traffic at no charge (OVHcloud), Exoscale gives a free outbound allowance per instance (Exoscale), and Scaleway Object Storage includes 75 GB of egress a month and then charges 0.01 EUR per GB (Scaleway). For an egress-heavy workload, that single difference can dwarf the control-plane line.

The hyperscalers softened this in 2024. Google (January), AWS (March) and Azure (March) each announced free egress for customers leaving the platform (AWS, Google Cloud). Read the conditions: these waivers apply only on a complete exit, and Azure requires you to cancel all subscriptions to qualify. They help you leave once; they do not help ordinary day-to-day egress.

The regulation that actually changes exit economics is the EU Data Act (Regulation (EU) 2023/2854). Its switching provisions sit in Chapter VI, Articles 23 to 31; it became applicable on 12 September 2025, and under Article 29 providers may not impose any switching charges from 12 January 2027, with only cost-based charges permitted in the transition (EUR-Lex, European Commission). That directly attacks the egress lock-in that made leaving expensive.

The real cost shift is headcount. Fewer managed databases, queues, streaming and AI services means more self-hosting, more on-call and more people. A DevOps or SRE engineer runs a median around 78,000 to 84,000 euros in Germany (levels.fyi) and, depending on the source, roughly 50,000 to 68,000 euros in France (Glassdoor). If moving clouds saves you 2,000 euros a month on infrastructure but costs half an engineer to operate what you used to buy managed, you have not saved anything.

Where sovereign providers win predictably: flat or included bandwidth, no cross-AZ transfer tax, free or cheap Kubernetes control planes, and simpler, more forecastable billing. Price a realistic workload, never a lone vCPU. The table below prices one representative estate a month: a managed Kubernetes control plane, three worker nodes at roughly 4 vCPU and 16 GB, a small managed Postgres, 1 TB of object storage, and 5 TB of egress.

ProviderK8s control plane3 worker nodes (~4 vCPU / 16 GB)Managed Postgres (small)Object storage (1 TB)Egress (5 TB)Estimated monthly total
ScalewayFree (Kapsule)~€246 (PRO2-XS)~€32 (2 vCPU / 4 GB)~€16 (Multi-AZ)~€49 (75 GB free, then €0.01/GB)~€340
OVHcloudFree (MKS)~$264 (B3-16)~$64 (DB1-4)~$8 (Standard)Included on instances~$340
ExoscaleFree (Starter); €40 Pro~€409 (Standard XL)~€100 (Startup-4)~€20 (Tier 1)~€40 (free per instance, then €0.02/GiB)~€610
IONOS CloudFree~$191 (4 vCPU / 16 GB)~$130 (2 vCPU / 4 GB)~$5~$108 (first 2 TB free, tiered)~$435
StackIt~€73 (not free)~€431 (g1a.4d)~€92 (2 vCPU / 4 GB)~€27Included~€620
AWS (Frankfurt)~$73 (EKS)~$420 (t3.xlarge)~$54 (db.t4g.medium)~$25 (S3)~$441 ($0.09/GB after 100 GB)~$1,010

List prices checked on 26 September 2026, shown in the currency each provider publishes (roughly 1 EUR is 1.08 USD, so the EUR and USD totals are close in real terms). Managed-Postgres storage is billed separately on most providers and is not included above. The headline is not the compute line, it is egress: 5 TB out costs about 441 USD on AWS and between nothing and about 108 USD on the European providers, which is the single biggest driver of the gap. StackIt is the priciest sovereign option here, and its Kubernetes control plane is the only European one in this table that is not free.

One honest caveat: hyperscaler committed-use discounts and Savings Plans can close a large part of this gap for steady workloads, and GPU availability is still far better on AWS, GCP and Azure. Run the numbers on your own committed spend and your own accelerator needs before you conclude anything.

Which European sovereign cloud providers offer managed Kubernetes, and does standard tooling work?

Yes. Scaleway Kapsule, OVHcloud Managed Kubernetes Service, Exoscale SKS, 3DS Outscale OKS, StackIt Kubernetes Engine, IONOS Managed Kubernetes and T-Systems Open Telekom Cloud CCE all offer managed Kubernetes, and because they run CNCF-conformant distributions, standard tooling runs unchanged. The friction sits in the platform layer above Kubernetes, not in Kubernetes itself.

What ports cleanly: container images, Helm charts, GitOps with Argo CD or Flux, ingress controllers, cert-manager, external-dns, Prometheus and Grafana, and Terraform or OpenTofu providers. What does not port: provider-specific IAM models, serverless runtimes, proprietary managed services, and any CI/CD glue written against one cloud's APIs. That split is the whole portability story.

Verify conformance rather than trust a logo. Scaleway Kapsule, Exoscale SKS and Civo Kubernetes appear on the CNCF Certified Kubernetes list through recent versions, with StackIt SKE, OVHcloud MKS and IONOS Managed Kubernetes filed against slightly older versions, all in the kubernetes/k8s-conformance repository (CNCF software conformance). Conformance is what guarantees your manifests move between them.

The control-plane price is a real differentiator against the hourly EKS and AKS charge. AWS EKS bills 0.10 USD per cluster per hour, about 73 USD a month (AWS); Azure AKS is free on the base tier and 0.10 USD per hour on Standard (Microsoft); GKE charges the same 0.10 USD per hour with a monthly credit that makes one cluster effectively free (Google Cloud). On the European side, Scaleway Kapsule (mutualized), OVHcloud MKS and IONOS give you a free control plane, while StackIt charges roughly 0.10 EUR per cluster per hour.

Compare the operational details that actually bite during a pilot: autoscaling behaviour, node-pool lifecycle, CSI and CNI options, load-balancer provisioning and GPU node availability. That is where the EU field is less mature than the hyperscalers, and where a two-week test tells you more than any table.

Kubernetes is the practical sovereignty hedge because it makes the provider a substitutable layer, which is exactly what the Data Act exit rights assume. But be honest about what stays yours on every provider, sovereign or hyperscaler: cluster upgrades, per-environment RBAC, secrets management and developer self-service remain your problem. Managed Kubernetes manages the control plane, not your platform.

ProviderProductCNCF conformantControl plane priceAutoscalingNotable limitation
ScalewayKapsule / KosmosYes (v1.37)Free (mutualized)YesFew regions
OVHcloudMKSYes (v1.35)Free tierYesVersion detail varies by region
ExoscaleSKSYes (v1.37)Free (Starter)Yes (Karpenter on Pro)Smaller service catalog
3DS OutscaleOKSNot filed in CNCF repoPaidYesNewer service; verify conformance
StackItSKEYes (v1.36)~0.10 EUR/cluster/hrYesPaid plane, fewer regions
IONOSManaged KubernetesYes (v1.35)FreeYesThinner tooling and docs
T-SystemsCCENot filed as own entrySee providerYesBuilt on Huawei-derived OpenStack

How does an internal developer platform like Qovery fit into a sovereign cloud strategy?

Qovery is not a sovereign cloud provider and grants no certification. It is the internal developer platform layer that runs inside your own cloud account or your own Kubernetes cluster, which keeps the sovereignty decision (where workloads run) separate from the delivery decision (how your team ships). That separation is the whole reason it belongs in this article.

Qovery runs a bring-your-own-cloud model: the infrastructure runs in your own account, and the cloud bill plus any committed-use discounts stay in your name and your jurisdiction, which is exactly what a sovereignty review asks for. It runs natively on AWS, GCP, Azure and Scaleway, and on any existing Kubernetes cluster, including clusters on OVHcloud, Exoscale, StackIt, IONOS, Aruba Cloud or on-prem. A team on Scaleway Kapsule, Exoscale SKS or a StackIt cluster points Qovery at that cluster and keeps its workflow.

The capabilities I will stand behind are the ones we actually ship: git-push deployments, preview environments per pull request, environment auto-stop for non-production, managed cluster upgrades, per-environment RBAC, and databases backed by managed cloud services. Decoupling that delivery layer from the data plane means moving or mixing providers is a configuration change, not a rebuild of every pipeline. That is what makes the Data Act exit rights usable in practice instead of theoretical.

Two limits, stated plainly. Qovery does not make a provider sovereign, holds no SecNumCloud qualification, and does not replace a compliance review with your DPO or CISO. And it is not the only option. Clever Cloud is provider and platform in one, which suits teams who want a single French vendor; Qovery suits teams who want to own the infrastructure and keep the provider replaceable; Porter, Northflank BYOC and a self-built Backstage plus Argo CD stack are the other realistic routes. If you want the longer version of this argument, I wrote it up in how to keep the same Kubernetes workflow across EU sovereign clouds and AWS.

ApproachWhere workloads runSetup effortPortability between providersWho it fits
Self-built Backstage + Argo CDYour clusterHighHigh (you build it)Large platform teams
Clever Cloud PaaSClever Cloud infraLowLow (single vendor)Teams wanting one French vendor
Qovery BYOCYour account or clusterLowHighTeams keeping the provider replaceable
Porter / Northflank BYOCYour accountLow-mediumMediumTeams wanting a managed PaaS feel
Provider console onlyThat providerLowLowSmall single-cloud teams

How do you choose a sovereign cloud provider without locking yourself in? A 6-step checklist

Choose by constraint order, not by feature list: name the regulation first, verify the certification scope second, check the operating entity's jurisdiction third, then run a real proof of concept, write the exit plan before signing, and standardize delivery on Kubernetes.

  1. Name the regulation driving the decision. NIS2, DORA, GDPR transfer risk, HDS for French health data, or a public-sector or defense requirement. The regulation, not the vendor, sets the bar.
  2. Confirm the certification covers the exact offer and region you will use, not the company brand. Ask for the qualification reference number and its expiry date, because SecNumCloud and the rest are granted per offer.
  3. Check the jurisdiction of both the contracting and the operating entity, plus the support and on-call footprint and any third-country subprocessors listed in the data processing agreement.
  4. Run a real proof of concept on the services you actually need: managed Postgres, S3-compatible object storage, load balancers, GPUs and the IAM model. Test the CSI driver and the load balancer on your own workload.
  5. Write the exit plan before signing. Data Act switching rights only help if your architecture can move, so measure the time to redeploy a full environment elsewhere. If you cannot do it in an afternoon, you are locked in regardless of the contract.
  6. Standardize the delivery layer on Kubernetes and keep the developer platform provider-agnostic, so a future migration is a config change instead of a re-platforming project.

A worked example. A French fintech under DORA needs SecNumCloud for its regulated core but cannot afford SecNumCloud pricing for everything else. So it runs the regulated workload on a SecNumCloud-qualified offer from Cloud Temple or 3DS Outscale, runs the rest on Scaleway or Exoscale for cost, and puts one Kubernetes-native delivery layer across both. When the auditor asks about exit, the answer is a redeploy test, not a promise. That mixed estate is the pattern I see working, and it only works because Kubernetes made the provider the swappable part.

Frequently asked questions
What is the best sovereign cloud provider in Europe in 2026?

There is no single best one; the best provider is the one that clears your binding constraint. For broad IaaS with managed Kubernetes, Scaleway and OVHcloud lead among EU-owned providers. For SecNumCloud-regulated workloads in France, Cloud Temple and 3DS Outscale hold the qualification. For Swiss jurisdiction and a clean Kubernetes experience, Exoscale is the pick, and for German enterprise procurement, T-Systems and IONOS Cloud fit best. Decide by jurisdiction and certification scope first, then by price and managed-service breadth.

What does ANSSI SecNumCloud qualification mean, and which providers hold it?

SecNumCloud is the French state's cloud qualification, currently at version 3.2, and it is stricter than most schemes because it adds jurisdictional immunity from non-EU law on top of security controls. It is granted per offer and per region, never company-wide, so a vendor holding it for one service does not hold it for all. As of 2026, 3DS Outscale (qualified first under 3.2 in December 2023), Cloud Temple, OVHcloud on its SNC Cloud Platform, and the Thales-Google joint venture S3NS on PREMI3NS all hold SecNumCloud 3.2 for specific offers; Scaleway is in the qualification process but not yet qualified. Always check the current ANSSI list and ask for the reference number.

Are the AWS, Microsoft and Google "sovereign cloud" offerings in the EU actually sovereign?

Partly. AWS European Sovereign Cloud (launched January 2026 in Germany), Microsoft Sovereign Cloud and the Google-Thales S3NS all address data residency and operational access seriously, with EU-based operations and controls over who can access systems. The property they differ on is legal jurisdiction: AWS and Microsoft keep a US-headquartered ultimate parent, which the EDPB flagged as CLOUD Act exposure, whereas S3NS is a French entity majority-owned by Thales precisely to close that gap. If your requirement is immunity from non-EU law, the ownership structure is the thing to examine, not the datacenter location.

Which European sovereign cloud providers offer managed Kubernetes?

Scaleway (Kapsule and Kosmos), OVHcloud (Managed Kubernetes Service), Exoscale (SKS), 3DS Outscale (OKS), StackIt (Kubernetes Engine), IONOS Cloud (Managed Kubernetes) and T-Systems Open Telekom Cloud (CCE) all ship a managed control plane. Aruba Cloud offers Kubernetes in Italy as well. Hetzner is the notable exception with no first-party managed service, only self-managed Kubernetes on its VMs. Because these run CNCF-conformant distributions, your manifests, Helm charts and CI pipelines move between them.

Is a European sovereign cloud cheaper than AWS, GCP or Azure?

Usually cheaper on compute, bandwidth and the Kubernetes control plane, but not automatically cheaper overall. Several EU providers include or heavily discount egress that AWS bills at about 0.09 USD per GB and Azure at about 0.087 USD per GB, and offer free Kubernetes control planes against the 73 USD a month that EKS charges. The saving disappears if you have to hire platform engineers to self-host the managed databases, queues and streaming services you used to buy, so price the whole estate and the headcount, not just the invoice.

Does the EU Data Act make it easier to switch cloud providers?

Yes. The EU Data Act (Regulation (EU) 2023/2854) became applicable on 12 September 2025, and its switching provisions in Articles 23 to 31 require providers to remove technical and contractual obstacles to moving between clouds. Under Article 29, providers may not charge any switching costs from 12 January 2027, with only cost-based charges allowed during the transition. It makes the contract easier, but the practical constraint is still your architecture: the law only helps if your workloads can actually move.

Can I run an internal developer platform like Qovery on a European sovereign cloud?

Yes. Qovery is not a cloud provider and holds no sovereignty certification; it is a delivery layer that runs in your own account or your own Kubernetes cluster. It runs natively on Scaleway and on any existing Kubernetes cluster, including clusters on OVHcloud, Exoscale, StackIt, IONOS, Aruba Cloud or on-prem, so the cloud account, the bill and the data stay in your name and your jurisdiction. It gives your developers git-push deployments, per-pull-request preview environments, auto-stop and per-environment RBAC without changing where the workloads run, which is what keeps the sovereignty choice separate from the delivery choice.

Romaric Philogene
About the author
Romaric Philogene

Romaric founded Qovery to make Kubernetes accessible to every engineering team. He writes about platform strategy, developer experience, and the future of cloud infrastructure.

Next step

Ship faster on infrastructure you control.

Qovery gives your team self-service deployments on your own AWS, GCP, Azure or Scaleway account - or your existing Kubernetes cluster, wherever it runs in Europe. Start deploying in under 10 minutes.