Quick summary
- The AWS European Sovereign Cloud is a separate AWS partition, operated inside the EU by EU citizens, with its own root account structure, IAM and billing. Your commercial AWS credentials do not work there.
- That separation is the point, and it is also the catch: backup tools do not follow you into the partition automatically. Each one has to be available inside it.
- AWS Backup and AWS Elastic Disaster Recovery are available natively in the partition.
- As of publication, third-party vendors with announced ESC support include N2W, Cohesity, Commvault and MSP360.
- Tools that run inside your account (rather than shipping your data to a vendor-operated vault) carry the sovereignty guarantee through to the backup layer without a second assessment.
The AWS European Sovereign Cloud (ESC) is a physically and logically separate AWS partition, operated entirely within the EU by EU citizens, with independent root account structure, IAM and billing. It launched in January 2026 with its first region in Brandenburg, Germany. For anyone running regulated workloads in Europe, it answers the question of where the data sits and who can reach it, at the infrastructure layer.
It also breaks assumptions. A partition is not a region. Tooling that works across eu-central-1 and eu-west-1 does not automatically work in ESC, and that includes your backup software.
Which backup and DR tools work in the AWS European Sovereign Cloud?
| Tool | Type | ESC support | What it protects | Where the backup data sits |
|---|---|---|---|---|
| AWS Backup | AWS native | Yes, available in ESC | AWS services covered by AWS Backup in the partition | Your ESC account, in an AWS Backup vault |
| AWS Elastic Disaster Recovery | AWS native | Yes, available in ESC | Server replication for DR | Your ESC account |
| N2W | Third-party, in-account | Yes, from v5.0 | EC2, EBS, RDS, Aurora, EFS, DynamoDB, EKS | Your ESC account. N2W never takes custody |
| Commvault | Third-party | Yes, named an ESC launch partner | Broad, check the partition-specific matrix | Depends on deployment model |
| Cohesity | Third-party | Yes, named an ESC launch partner | Broad, check the partition-specific matrix | Depends on deployment model |
| MSP360 | Third-party | Yes, announced February 2026 | File, image, and workload backup | Depends on deployment model |
First, “supports ESC” is not one capability. A vendor can be present in the partition and still cover a narrower set of services there than it does in the commercial partition. Ask for the partition-specific support matrix, not the general one.
Second, the last column is the one auditors ask about, and it splits the market cleanly. Some tools back up into storage you own inside your own ESC account. Others send data into infrastructure the vendor operates. Both can be legitimate. They are different conversations with your data protection officer.
What the European Sovereign Cloud actually is
AWS operates several partitions. The commercial partition is the one most people mean when they say “AWS”. GovCloud is another, for US government workloads. ESC is the newest, and the separation is structural rather than a configuration setting.
It’s important to remember that vendor-operated storage means a second chain of custody, and a second attack surface. Your Data Protection Officer (DPO) now has to evaluate not just your controls, but theirs: who has access, where their staff sit, what their sub-processor list looks like. Every credential, API, and employee in that vendor’s environment is a path to your backups that didn’t exist when the data stayed in your account — and it’s a path you don’t control and can’t fully audit.
What that means in practice:
- Separate root account structure. You create a new organization in ESC. You do not extend your existing one into it.
- Separate IAM. Your existing users, roles and policies do not exist there. Neither do your existing access keys.
- Separate billing. ESC billing runs through an EU entity, independent of your commercial AWS bill.
- EU-resident operations. The infrastructure is operated by EU citizens residing in the EU, which is the part that addresses third-country access concerns rather than only data location.
- Independent service availability. Services arrive in ESC on their own schedule. Check availability rather than assuming parity with eu-central-1.
The partition carries ISO/IEC 27001, SOC 1/2/3 and BSI C5 attestations. Those belong to AWS and to the partition. They do not transfer to any software you run inside it, yours or a vendor’s, and no backup vendor can hand you compliance on the strength of them.
Data residency and data sovereignty are not the same requirement
Residency is about where bytes are stored. You can satisfy it today by picking an EU region in the commercial partition.
Sovereignty is about who can compel access, who operates the infrastructure, and under whose law. That is what a separate partition with EU-resident operators and EU billing addresses, and it is why organisations that already run in Frankfurt are still looking at ESC.
If your requirement is residency, you probably do not need ESC. If your requirement came from a legal team asking about third-country access, you probably do.
What changes about backup when you move into the partition
Your backup tool needs its own home in ESC
An in-account tool like N2W runs as an EC2 instance inside your account. Move to ESC and you deploy a fresh instance inside your ESC account, with an IAM role created in ESC. It is a new deployment, not a migration, because the identity layer does not cross the boundary.
The same logic applies to any tool that authenticates with AWS credentials. Plan for a parallel deployment rather than an extension.
Cross-partition copies are not a DR strategy you can assume
You cannot casually copy a snapshot from eu-central-1 into ESC. The partitions are isolated, and that isolation is the product. If your DR design currently relies on cross-region copies, redraw it inside the partition: cross-region and cross-account within ESC, using the regions ESC actually offers.
This is worth catching early, because it changes the RPO and RTO numbers you promise the business.
Your compliance evidence changes shape
Auditors reviewing an ESC environment ask where every copy of the data goes, including backups. A backup that leaves the partition is the exception that undoes the architecture. Whatever tool you pick, be able to draw the line on a whiteboard from production to the last retained copy without crossing the boundary.
How N2W fits
N2W deploys inside the AWS European Sovereign Cloud the way it deploys in any other AWS partition: as an EC2 instance in your own account, calling standard AWS APIs through an IAM role you create.
The practical consequence is the sentence worth taking to a compliance review: N2W never takes custody of your data or your keys, so it introduces no additional attack surface, nor a compliance gap at the backup and DR layer. Snapshots stay in your ESC account. Archived copies go to storage you own. There is no N2W-operated vault anywhere in the picture, which means there is no second boundary for an auditor to assess.
What that gets you inside the partition:
- Backups as often as every 60 seconds for snapshot-based workloads, in your own account.
- Immutability through AWS’s own native locks, S3 Object Lock and EBS Snapshot Lock, rather than a vendor layer wrapped around them. The lock is enforced by AWS inside your partition.
- Cross-region and cross-account recovery within ESC, including network cloning, so a recovered instance has a VPC, subnets, security groups and routing to land in.
- Dry-run DR tests that cost nothing, using read-only AWS APIs. Nothing launches, and the test validates down to IP address availability. Useful when your DR evidence has to be produced on a schedule.
Two honest limits. N2W is agentless for crash-consistent EC2, EBS and RDS backups; application-consistent Windows backups use VSS through the N2W Thin Backup Agent or AWS Systems Manager. And N2W’s cross-cloud recovery path runs AWS to Azure, one way, which is a commercial-partition capability and not part of an ESC sovereignty story. Inside ESC, the relevant isolation is cross-account and cross-region within the partition.
What EU-regulated customers have done with it
Randstad Spain, running GDPR-regulated HR data, cut backup maintenance effort by 80% and made DR testing 8x faster, taking a full test from most of a day to under an hour. David Encinar, their Cloud Infrastructure Manager, put the ROI in days rather than months.
iFeu, a Spanish managed service provider, runs about 115 instances across more than 100 AWS accounts in 3 regions, and reports up to 60% lower compliance costs. The detail that matters for a sovereignty conversation: customer data never leaves the customer’s own accounts.
DB Systel, the IT arm of Deutsche Bahn, holds 7+ years of retention for compliance across 700 servers, 1,500+ volumes and more than half a petabyte.
None of those ran in ESC, which did not exist when the stories were published. They are here because the operational shape is the same one an ESC buyer is in: regulated data, evidence obligations, and an estate too large to protect by hand.
Choosing between the options
AWS Backup is the better fit when your workloads are all AWS services it covers, you want nothing else in the account, and your retention and restore requirements are simple. It is native, it is in the partition, and it costs you no extra vendor relationship. Note, AWS Backup has limitations. For example, it is designed for organization-wide management within a single AWS Organization rather than environments where multiple AWS Organizations need to be managed centrally.
A broad enterprise platform like Commvault or Cohesity is the better fit when ESC is one estate among many, including on-premises, and you need one console and one set of policies across all of them.
N2W is the better fit when the estate is AWS-native, the backup layer has to stay inside your own account for the sovereignty argument to hold, and you want recovery of the environment rather than only the data.
It adds what the other two don’t: full control with IaaS deployment, automated DR drills that prove recoverability instead of assuming it, metadata restore via VPC capture and clone so you can rebuild the environment itself rather than just the data inside it, and policy-driven multi-retention that collapses what’s usually a sprawl of manual rules into a handful of tiers (retention reality for most businesses, not the single-policy case AWS Backup assumes). Per-instance pricing that does not move with data volume also helps when retention is set by a regulator rather than by you.
For DORA and NIS2 obligations specifically, the partition answers the residency and operator questions, and your backup design still has to answer the testing and recoverability ones. Those are covered in the DORA and NIS2 guides.
Frequently asked questions
Does AWS Backup work in the AWS European Sovereign Cloud?
Yes. AWS Backup is available in the partition, documented in the ESC user guide. AWS Elastic Disaster Recovery is available there too. Check the ESC-specific service list rather than the commercial one, because service availability in the partition is on its own schedule.
Can I copy backups from a commercial AWS region into the European Sovereign Cloud?
No, and that is deliberate. The partitions are isolated from each other, with separate IAM and separate account structures. Design your backup and DR topology inside ESC, using cross-account and cross-region copies within the partition.
Is the AWS European Sovereign Cloud the same as AWS regions in Europe?
No. Frankfurt, Ireland and Stockholm are regions inside the standard commercial partition. ESC is a separate partition with its own operations, run inside the EU by EU citizens, with independent root accounts and billing. Choosing an EU region answers data residency. The partition addresses sovereignty, which is a question about operator control and legal jurisdiction.
Does using the European Sovereign Cloud make my backups GDPR compliant?
No single technology choice does that. The partition carries ISO/IEC 27001, SOC 1/2/3 and BSI C5 attestations and gives you EU-resident operations, which addresses part of a GDPR assessment. Your compliance still depends on how you configure retention, access control, encryption and deletion, and on where every copy of the data ends up, backups included.
Which backup vendors support the AWS European Sovereign Cloud?
AWS Backup and AWS Elastic Disaster Recovery are available natively. Among third parties, Commvault and Cohesity were named ESC launch partners, MSP360 announced support in February 2026, and N2W supports it from v5.0. Ask any vendor for the partition-specific support matrix, since presence in ESC does not always mean the same service coverage as the commercial partition.