Government Cloud: Sovereign Providers & Frameworks

Government workloads are where sovereignty stops being optional. Classification systems, assessment programmes and procurement frameworks (G-Cloud, MeitY, GI Cloud) turn residency and control into contractual requirements.

Assessment frameworks by country

CountryFrameworkWhat it means for cloud
🇦🇺 AustraliaIRAP (DTA) + ISM/PSPFAssessments to PROTECTED; residency decisions per classification
🇩🇪 GermanyBSI C5 (high)Cloud security attestation; classified-capable sovereign clouds
🇫🇷 FranceSecNumCloud (ANSSI)Sovereignty qualification incl. non-EU law immunity
🇺🇸 United StatesFedRAMPStandardised security assessment for federal cloud
🇬🇧 United KingdomG-Cloud / NCSC principlesProcurement framework and cloud-security principles
🇮🇳 IndiaMeitY empanelment / GI CloudGovernment cloud empanelment and national cloud strategy

Providers for government workloads

ProviderGovernment productAssessmentsClassified-capable
AUCloudSovereign government cloudIRAP, ISO 27001Yes (enclaves)
Open Telekom CloudSovereign OTCBSI C5 (high)Yes (German-administered)
S3NSFrench sovereign cloudSecNumCloud (targeted)Planned
AWSGovCloud / Dedicated RegionsIRAP, FedRAMP, C5Yes (air gap)
Microsoft AzureAzure Government / Sovereign LandscapesIRAP, FedRAMP, C5Yes
Oracle CloudGovernment Cloud / Dedicated RegionIRAP, FedRAMP, C5Yes (Alloy air-gap)

Key procurement questions

  • What is the data classification, and which assessment level does it require?
  • Must administration be restricted to national personnel?
  • Is air-gapped or disconnected operation required?
  • Which foreign jurisdictions can compel the provider or parent?
  • Are sovereign AI services available for government AI workloads?