Tool & Stack Analyses
    14 min read

    AWS EUSC vs. Scaleway: Which is Actually Sovereign?

    Last reviewed: 10 February 2026

    Sovereignty Comparison Scorecard

    Provider A

    AWS EUSC

    52
    Moderate Risk

    Focus: EU

    Provider B

    Scaleway

    83
    Low Risk

    Focus: EU

    Last reviewed: 10 February 2026Scores reflect European sovereignty risk exposure

    Comparison Overview

    Primary Subject

    AWS EUSC

    US-headquartered · CLOUD Act applies

    European Alternative

    Scaleway

    EU-headquartered · EU jurisdiction

    Detailed capability comparison and trade-offs are covered in the analysis below.

    "Sovereign" has become the most overloaded word in European cloud marketing. Every major cloud provider now claims some form of sovereignty, from AWS's European Sovereign Cloud (EUSC) to Scaleway's EU-native infrastructure. The problem is that "sovereign" means something specific in a legal and operational context, and marketing pages are not the right place to evaluate it.

    This comparison strips sovereignty back to its structural components: who owns the infrastructure, which courts have jurisdiction, who can access customer data under compulsion, and what sub-processors sit in the chain. These are the dimensions that matter in procurement, in NIS2 compliance documentation, and in boardroom risk discussions.

    AWS EUSC represents a genuine investment by Amazon in addressing European sovereignty concerns. Whether that investment is sufficient — whether an operational entity separated from a US parent company actually insulates European data from US legal process — is the question this analysis examines. Scaleway, as an EU-born and EU-owned provider, offers a structurally different sovereignty profile. The question there is whether a smaller provider can deliver enterprise-grade reliability for the workloads that need sovereign infrastructure.

    Neither answer is simple. That is precisely why an independent evaluation framework matters.

    Why 'Sovereign' Needs a Stricter Definition

    The European Commission's proposed certification scheme for cloud services (EUCS) has gone through multiple drafts, each with different sovereignty requirements. The term has no single, enforceable legal definition across EU member states. This ambiguity allows providers to claim sovereignty based on different — and sometimes superficial — criteria.

    For procurement and compliance purposes, sovereignty should be evaluated across five structural dimensions:

    1. **Jurisdiction & ownership** — Where is the provider incorporated? Who are the ultimate beneficial owners? Which courts and governments have legal authority over the entity? 2. **Data residency guarantees** — Where is data stored and processed? Are these guarantees contractual or architectural? 3. **Operator access & support model** — Who can access customer data in operations? Are support and administration staff within EU jurisdiction? 4. **Sub-processors and dependencies** — Does the provider depend on non-EU sub-processors for core functionality? 5. **Legal exposure to non-EU authorities** — Can any non-EU government compel data access through legal process?

    A provider can satisfy some of these dimensions while failing others. The marketing label "sovereign" does not distinguish between partial and comprehensive sovereignty.

    AWS European Sovereign Cloud: Sovereignty Profile

    AWS announced its European Sovereign Cloud (EUSC) as a physically and logically separate AWS partition, operated by EU-resident staff and subject to EU jurisdiction. The first EUSC region launched in Brandenburg, Germany.

    **Jurisdiction & ownership**: AWS EUSC is operated by an EU-incorporated entity. However, Amazon.com, Inc. (US) is the ultimate parent company. The legal question is whether US authorities can compel Amazon to direct its EU subsidiary to produce data. Under the CLOUD Act, US authorities can issue orders to US companies for data they control or possess — and whether a subsidiary relationship constitutes sufficient control is legally contested but not resolved in Amazon's favour.

    **Data residency**: EUSC data remains in EU data centres. AWS has committed to processing and storing all customer data within the EU for EUSC workloads. This is an architectural guarantee, not just a configuration option.

    **Operator access**: AWS states that EUSC will be operated by EU-resident staff with EU-based support. Administrative access is restricted to personnel within EU jurisdiction. This is a significant operational separation from standard AWS regions.

    **Sub-processors**: This is where complexity emerges. AWS EUSC may still depend on global AWS systems for certain functions — DNS, certificate management, identity services, billing, and software updates. The extent to which these dependencies create non-EU data exposure is not fully transparent.

    **Legal exposure**: The fundamental unresolved question. Amazon is a US company. Even with an EU subsidiary operating EUSC, the corporate relationship creates potential exposure to US legal process. AWS argues that EUSC's operational separation provides meaningful protection. Critics note that no corporate restructuring can override a US company's obligations under the CLOUD Act.

    **Certifications**: AWS EUSC targets C5 (Germany), SecNumCloud (France), and other national certification schemes. Some certifications are pending. Standard AWS regions already hold ISO 27001, SOC 2, and C5 certification.

    Scaleway: Sovereignty Profile

    Scaleway is a French cloud provider, a subsidiary of the Iliad Group — one of France's largest telecoms and technology conglomerates. Founded in 1999, Scaleway has operated EU-only infrastructure since inception.

    **Jurisdiction & ownership**: Scaleway is incorporated in France. Iliad Group, the parent company, is publicly traded on Euronext Paris with French beneficial ownership. There is no US parent company, US subsidiary, or US ownership stake that would create CLOUD Act exposure.

    **Data residency**: All Scaleway data centres are in France (Paris DC2–DC5) and the Netherlands (Amsterdam AMS1). Data never leaves EU infrastructure. This is structural — not a configuration option or premium tier.

    **Operator access**: All Scaleway operations, support, and engineering staff are EU-based. There is no offshore or non-EU support tier. Administrative access is limited to EU-resident personnel under French and EU employment law.

    **Sub-processors**: Scaleway operates its own data centres on its own hardware. The sub-processor chain is substantially shorter than hyperscaler alternatives. Some third-party tools are used for specific functions (monitoring, ticketing), but the core infrastructure stack is self-operated.

    **Legal exposure**: No exposure to US CLOUD Act, FISA 702, or other non-EU extraterritorial data access legislation. French law (including the Loi de Programmation Militaire) allows government access under judicial oversight, but this is EU-internal legal process, not extraterritorial.

    **Certifications**: ISO 27001, SOC 2, HDS (health data hosting). SecNumCloud certification is in progress. PCI DSS available for payment workloads.

    Side-by-Side Comparison

    | Dimension | AWS EUSC | Scaleway | |---|---|---| | **Sovereignty Score** | 52/100 | 83/100 | | **Incorporation** | EU entity (US parent) | France (EU parent) | | **Ultimate ownership** | Amazon.com, Inc. (US) | Iliad Group (France) | | **CLOUD Act exposure** | Contested — structural risk remains | Not exposed | | **Data residency** | EU-only (EUSC partition) | EU-only (all regions) | | **Operator access** | EU-resident staff (EUSC) | EU-resident staff (all) | | **Sub-processor transparency** | Partial — global dependencies unclear | High — self-operated core | | **SecNumCloud** | Targeted, pending | In progress | | **NIS2 relevance** | High (critical ICT provider) | Lower concentration risk | | **Managed service breadth** | Extensive (inherits AWS catalogue) | Focused IaaS/PaaS | | **Migration complexity from AWS** | Low (same ecosystem) | Medium (IaaS portable, PaaS requires adaptation) |

    Grey Areas & Gotchas

    **AWS EUSC: The subsidiary question** The most significant grey area is whether AWS EUSC's corporate separation actually protects against US legal process. The CLOUD Act applies to data that a US company "possesses, has custody of, or has control over." If a US court determines that Amazon has control over its EU subsidiary's data — even through an indirect corporate relationship — the separation provides no legal protection. This question has not been definitively tested in court.

    **AWS EUSC: Sub-processor opacity** AWS has not published a complete, public list of sub-processors specifically for EUSC. Standard AWS sub-processor lists include US-based entities. Whether EUSC uses entirely separate sub-processors or shares some with global AWS is not fully documented.

    **Scaleway: Scale and enterprise maturity** Scaleway's infrastructure is smaller than AWS's. For organisations requiring global edge presence, advanced AI/ML managed services, or dozens of specialised managed services, Scaleway cannot match AWS's breadth. The trade-off is sovereignty for service depth.

    **Scaleway: French government access** While Scaleway is not exposed to US legal process, French intelligence law does permit government access to data under judicial oversight. For organisations operating entirely within the EU, this is acceptable — it is the expected legal framework. For organisations concerned about any government access, additional encryption measures apply regardless of provider.

    **Both: Certification timing** Neither provider has completed SecNumCloud certification for all relevant services as of February 2026. Organisations requiring certified sovereign cloud should verify current certification status at the time of procurement, not rely on announced intentions.

    **Both: Sovereignty is not security** A fully sovereign provider with poor security practices offers no meaningful advantage. Sovereignty assessment must be combined with security assessment. Neither replaces the other.

    How SovereigntyScore Evaluates Sovereignty Beyond Marketing Pages

    SovereigntyScore's assessment methodology is designed to cut through exactly the kind of ambiguity this comparison highlights. Rather than accepting provider claims at face value, the platform evaluates sovereignty across structural dimensions:

    • **Ownership chain analysis** — traces corporate ownership to identify non-EU parent companies, investors, or board control that could create jurisdictional exposure. • **Legal jurisdiction mapping** — identifies which governments have legal authority to compel data access, distinguishing between data residency and legal jurisdiction. • **Sub-processor depth** — evaluates not just the primary provider but the chain of sub-processors, identifying where non-EU entities sit in the processing chain. • **Operational separation scoring** — assesses whether sovereign claims are backed by genuine operational isolation (separate staff, separate infrastructure) or merely marketing commitments. • **Regulatory alignment** — maps provider profiles against NIS2, DORA, GDPR, and CLOUD Act requirements relevant to the customer's sector and use case.

    This framework produces a 0–100 sovereignty score that enables direct comparison between providers — including between providers who both claim to be "sovereign." A score of 52 (AWS EUSC) versus 83 (Scaleway) reflects the structural difference between sovereignty-by-restructuring and sovereignty-by-design.

    The score is not a recommendation. It is an evidence-based input for procurement decisions where sovereignty is a stated requirement.

    Frequently Asked Questions

    **Is AWS EUSC actually sovereign?** AWS EUSC addresses data residency and operational access — two important sovereignty dimensions. However, the ultimate US ownership of Amazon means structural legal exposure under the CLOUD Act remains. Whether this constitutes "sovereign" depends on your organisation's risk tolerance and regulatory requirements.

    **Does Scaleway have the same services as AWS?** No. Scaleway offers comprehensive IaaS and core PaaS (managed Kubernetes, databases, object storage, serverless), but does not match AWS's breadth of managed services. Organisations using advanced AWS-specific services (SageMaker, DynamoDB, Step Functions) would need to find alternatives or redesign.

    **Which should I choose for NIS2 compliance?** Both can support NIS2 compliance. Scaleway's EU-native ownership simplifies the jurisdictional dimension of NIS2's supply chain requirements. AWS EUSC requires additional documentation justifying the US parent company relationship.

    **Can I migrate from AWS to Scaleway easily?** IaaS workloads (VMs, block storage, S3-compatible object storage) migrate with moderate effort. Kubernetes workloads port directly. AWS-specific PaaS services require redesign. Terraform providers are available for both platforms.

    **Is AWS EUSC subject to the CLOUD Act?** This is legally contested. Amazon is a US company, and the CLOUD Act applies to data US companies possess or control. AWS argues that EUSC's operational separation provides protection. The question has not been definitively resolved in court.

    Key Takeaways for Technical Leaders

    • AWS EUSC scores 52/100 on sovereignty; Scaleway scores 83/100 — the gap reflects structural ownership and jurisdictional differences, not marketing claims
    • AWS EUSC addresses data residency and operator access but cannot resolve the fundamental CLOUD Act exposure created by US parent company ownership
    • Scaleway's EU-native ownership under Iliad Group eliminates non-EU jurisdictional risk entirely, with no corporate restructuring required
    • Sub-processor transparency is a critical gap — AWS EUSC's dependency on global AWS systems for ancillary functions is not fully documented
    • Sovereignty claims require independent verification; provider marketing pages are insufficient for procurement and compliance documentation

    Audit your technology stack

    Comparing one pair is useful. Your Technology Stack Audit scores every tool in your technology stack as one system, with a cross-tool migration plan. One-off €99.

    Audit my technology stack — €99