AWS Unveils New Sovereign Controls and Governance Structure for the AWS European Sovereign Cloud

Author photo: Chantal Polsonetti
ByChantal Polsonetti
Category:
Company and Product News

AWS has unveiled the independent European governance structure for the AWS European Sovereign Cloud, including the creation of a dedicated Security Operations Center and the establishment of a new parent company for the AWS European Sovereign Cloud. This new company will be locally controlled within the European Union (EU), led by EU citizens, and subject to local laws. Launching by the end of 2025, the AWS European Sovereign Cloud will combine operational autonomy with a broad service portfolio to meet Europe's digital sovereignty requirements.

European-Based Control, Governance, and Operational Autonomy

AWS intends to establish a new European organization and operating model for the AWS European Sovereign Cloud, with a parent company and three subsidiaries incorporated in Germany. These dedicated European subsidiaries will implement controls to retain customer content and customer-created metadata within the EU, employ EU-resident personnel to operate the AWS European Sovereign Cloud, own and operate the underlying infrastructure, and hold EU-based root certificates and trust services necessary for authenticating the security and identity of cloud services.

AWS also plans to establish an independent advisory board for the AWS European Sovereign Cloud, legally obligated to act in its best interest. The board will consist of four EU citizens residing in EU member states, including at least one independent member not affiliated with Amazon. This board will provide expertise and accountability on sovereignty-related aspects of operations, including strong security and access controls and the ability to operate independently in the event of disruption. The cloud is designed to continue operations indefinitely, even if connectivity with the rest of the world is interrupted.

The AWS European Sovereign Cloud infrastructure will be located entirely within the EU, both physically and logically separate from other AWS Regions, and will operate as an independent cloud for Europe. It will have no critical dependencies on non-EU infrastructure. Additionally, there will be zero operational control from outside EU borders.

The cloud will feature dedicated networking infrastructure and connectivity from European providers, along with sovereign Points of Presence for direct network connections to the AWS European Sovereign Cloud via AWS Direct Connect. Customers will have an autonomous connection to the cloud. It will include a dedicated instance of Amazon Route 53, offering highly available and scalable Domain Name System (DNS) services, domain name registration, and health-checking. The Route 53 name servers will use only European Top Level Domains (TLDs). AWS will also launch a dedicated European “root” Certificate Authority, ensuring key materials, certificates, and identity verification for Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates operate entirely within the sovereign cloud. AWS Direct Connect, Amazon Route 53, and the European Certificate Authority will be available at launch.

Security will be managed by a dedicated European Security Operations Center (SOC) that mirrors global AWS security practices. AWS works closely with European regulators, including the German Federal Office for Information Security (BSI), which sets leading security standards for cloud providers in Germany and beyond. Earlier this year, AWS and BSI signed a cooperation agreement prioritizing governance and technical standards for operational separation and data flow management, aligning with BSI’s digital sovereignty requirements. The AWS European Sovereign Cloud will maintain key certifications such as ISO/IEC 27001:2013, SOC 1/2/3 reports, and BSI C5 attestation, all validated regularly by independent auditors.

The Sovereign Requirements Framework (SRF) is a comprehensive set of technical, legal, and operational controls derived from customer sovereignty expectations, EU regulatory requirements, industry frameworks, and partner feedback. With the SRF, AWS will demonstrate adherence to sovereignty standards and enable verifiable trust in a consistent, repeatable manner by implementing controls across services and operations, creating auditable evidence.

The AWS European Sovereign Cloud will offer a comprehensive suite of services, including artificial intelligence, compute, containers, database, networking, and security. AI services will include Amazon Bedrock, Amazon Q, and Amazon SageMaker.

Learn more about Digital Transformation in Industry, Energy, and Critical Infrastructure.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients