Product review
AWS European Sovereign Cloud: an honest review
AWS European Sovereign Cloud is a genuine engineering effort. Launched in Brandenburg (Germany) in January 2026, it is a structurally separate cloud operated by AWS Europe (sovereign) S.a.r.l., a Luxembourg entity whose employees are EU residents, whose data never leaves EU jurisdiction, and whose operations are isolated from the AWS global control plane. It is real engineering, and it deserves to be described as such. This review also names, precisely, what it does not change.
This review is based on AWS public documentation and announcements current to January 2026. AWS European Sovereign Cloud terms and capabilities may have been updated since. Verify claims against current AWS documentation before making procurement decisions.
What AWS European Sovereign Cloud actually is
AWS European Sovereign Cloud (ESC) launched in January 2026 in the AWS EU (Sovereign) Region in Brandenburg, Germany. It is not a marketing rebrand of an existing region. The operating entity is AWS Europe (sovereign) S.a.r.l., incorporated in Luxembourg, whose workforce is exclusively EU residents and citizens. The entity is separate from Amazon.com, Inc., and from Amazon Web Services EMEA SARL (the entity that operates standard AWS EU regions).
All customer data, metadata, and backups remain within the EU. Customer support is provided exclusively by EU-resident staff. Administrative access to the infrastructure is limited to EU persons. The AWS global control plane does not access or replicate ESC customer data. These are structural guarantees written into the service terms, not marketing claims.
What ESC changes vs standard AWS EU regions
| Dimension | AWS European Sovereign Cloud | Standard AWS EU regions | Change vs standard |
|---|---|---|---|
| Data location | All data, metadata and backups remain in EU | EU region data stays in-region by default; same guarantee | No change vs EU regions |
| Operating entity jurisdiction | Luxembourg entity (EU law) | Amazon Web Services EMEA SARL (Luxembourg entity); parent Amazon.com Inc (US) | Improvement: ESC entity does not have US parent in chain of control |
| Staff access | EU-resident staff only for operations and support | Global staff pool for support; EU staff for local operations | Improvement: access limited to EU residents |
| CLOUD Act exposure | Designed to limit practical exposure; EU entity with EU-only staff and isolated control plane | US parent; standard EU regions remain subject to US parent's legal exposure | Material improvement; not an absolute legal immunity guarantee (see limits section) |
| Service catalogue breadth | Subset of AWS services at launch (January 2026); growing over time | 200+ services in standard EU regions | Standard regions have a broader catalogue |
| Pricing | Not publicly listed at launch; premium expected for structural isolation | Published list prices | Standard regions are price-transparent |
What ESC genuinely delivers
The structural isolation is real. A standard AWS EU region uses a shared global control plane that is operated, in part, by non-EU staff and is subject to the legal exposure of Amazon.com, Inc. AWS European Sovereign Cloud breaks that link at the control-plane level: the ESC operating entity, its staff, and its infrastructure are structurally separate from the global AWS estate.
The EU-resident staff commitment is also real. A support or operations request in ESC cannot be handled by a non-EU-resident employee. This is the operational-sovereignty layer that standard cloud regions, whether US or EU owned, routinely lack: even when data stays in a region, administrative access is often globally pooled.
For regulated industries, this matters. DORA, NIS2, and sector-specific regulations increasingly ask about staff access, not just data location. ESC provides a contractual and structural answer to that question that standard AWS EU regions cannot.
What ESC does not change
The CLOUD Act question remains contested. The CLOUD Act (18 U.S.C. 2703) gives US law enforcement a mechanism to compel US persons and entities to produce data they possess, custody, or control, regardless of where it is stored. AWS Europe (sovereign) S.a.r.l. is a Luxembourg entity, not a US entity. Whether a US court can compel Amazon.com, Inc. to produce data held in ESC via its chain of control over the subsidiary is a legal question that has not been litigated and on which reputable lawyers disagree.
AWS has structured ESC to make that production order as difficult as possible: the subsidiary has EU-only staff, an isolated control plane, and data that never touches the global estate. But "designed to resist" is not the same as "legally immune." If your regulator or your DPO requires a guarantee that no US production order can ever reach your data, ESC does not provide that guarantee in writing, and it would be inaccurate to claim otherwise.
The service catalogue is a subset of full AWS at launch. ESC launches with a curated set of core services. If your architecture depends on services not available in ESC, you face a choice between using standard AWS regions for those services (which reintroduces the sovereignty question) or redesigning. The catalogue will grow, but the timeline is not publicly committed.
Who ESC is and is not designed for
ESC is designed for regulated European enterprises that need EU-operated infrastructure with contractual commitments on staff access and data isolation, but that also need the breadth and tooling of the AWS ecosystem. Defence, financial services, healthcare, and public sector organisations with DORA, NIS2, or sector-specific mandates are the primary addressable market.
ESC is not designed for, and does not solve the problem for, organisations whose requirement is legal immunity from US law. If your DPO or regulator requires an absolute guarantee that US authorities cannot reach your data under any legal theory, the only providers that can plausibly make that claim are those with no US-connected parent and no US-person operational access, such as OVHcloud, Scaleway, Hetzner, or Outscale. ESC reduces risk; it does not eliminate it.
Common questions
- Can I migrate my existing AWS workload to ESC?
- ESC is a separate region, not a toggle on an existing account. Migration is a region migration: you move data and infrastructure to the ESC region, reprovisioning services that are available there. Services not yet in the ESC catalogue must remain in a standard region or be redesigned. The AWS migration tooling (Database Migration Service, Application Migration Service) works, but you need to verify each service is available in ESC before planning.
- Is ESC SecNumCloud qualified?
- No. SecNumCloud is a French qualification granted by ANSSI. AWS European Sovereign Cloud is not SecNumCloud-qualified and is not designed around the SecNumCloud governance model. For French public sector workloads that require SecNumCloud, providers with existing qualification (OVHcloud for specific SKUs) are the relevant options.
- How does ESC pricing compare to standard AWS?
- AWS has not published a price list for ESC at launch. Structural isolation requires dedicated infrastructure and EU-only operational staff, which adds cost. Expect a premium over standard EU region pricing. If pricing is a primary decision factor, request a quote from AWS directly and compare against your current standard-region spend.