Government Cloud: Sovereign Providers & Frameworks
Government workloads are where sovereignty stops being optional. Classification systems, assessment programmes and procurement frameworks (G-Cloud, MeitY, GI Cloud) turn residency and control into contractual requirements.
Assessment frameworks by country
| Country | Framework | What it means for cloud |
|---|---|---|
| 🇦🇺 Australia | IRAP (DTA) + ISM/PSPF | Assessments to PROTECTED; residency decisions per classification |
| 🇩🇪 Germany | BSI C5 (high) | Cloud security attestation; classified-capable sovereign clouds |
| 🇫🇷 France | SecNumCloud (ANSSI) | Sovereignty qualification incl. non-EU law immunity |
| 🇺🇸 United States | FedRAMP | Standardised security assessment for federal cloud |
| 🇬🇧 United Kingdom | G-Cloud / NCSC principles | Procurement framework and cloud-security principles |
| 🇮🇳 India | MeitY empanelment / GI Cloud | Government cloud empanelment and national cloud strategy |
Providers for government workloads
| Provider | Government product | Assessments | Classified-capable |
|---|---|---|---|
| AUCloud | Sovereign government cloud | IRAP, ISO 27001 | Yes (enclaves) |
| Open Telekom Cloud | Sovereign OTC | BSI C5 (high) | Yes (German-administered) |
| S3NS | French sovereign cloud | SecNumCloud (targeted) | Planned |
| AWS | GovCloud / Dedicated Regions | IRAP, FedRAMP, C5 | Yes (air gap) |
| Microsoft Azure | Azure Government / Sovereign Landscapes | IRAP, FedRAMP, C5 | Yes |
| Oracle Cloud | Government Cloud / Dedicated Region | IRAP, FedRAMP, C5 | Yes (Alloy air-gap) |
Key procurement questions
- What is the data classification, and which assessment level does it require?
- Must administration be restricted to national personnel?
- Is air-gapped or disconnected operation required?
- Which foreign jurisdictions can compel the provider or parent?
- Are sovereign AI services available for government AI workloads?