Home icon

Architecting a secure landing zone in the AWS European Sovereign Cloud

Security Blog



This article provides a comprehensive guide to architecting a secure landing zone in the AWS European Sovereign Cloud (aws-eusc), an independent cloud partition physically and logically separate from commercial AWS regions.

  • AWS European Sovereign Cloud operates as a distinct partition (aws-eusc) with independent IAM, billing, console, and service endpoints
  • Cross-partition features like AssumeRole, VPC peering, Transit Gateway, and S3 replication are not available across aws and aws-eusc boundaries
  • Use partition-aware infrastructure-as-code with Terraform and CloudFormation to ensure code works unchanged across partitions
  • Implement AWS Control Tower with Account Factory for Terraform (AFT) for account vending and governance within the partition
  • Manage IAM Identity Center as independent instance with permission sets and assignments defined as code, federated to corporate identity providers
  • Centralize logging in a Log Archive account with GuardDuty and Security Hub in a Security Tooling account for detective controls
  • Design network perimeter with centralized egress inspection, VPC endpoints for AWS services, and dedicated AWS Direct Connect connections
  • Use customer-managed AWS KMS keys for data protection; consider AWS KMS External Key Store for regulatory requirements
  • Deploy container images and artifacts natively in EUSC using separate credentials; cross-partition replication is not supported
  • Maintain separate billing systems per partition in EUR currency; consolidate billing within EUSC organization only

The AWS European Sovereign Cloud enables secure, scalable multi-account environments with centralized governance, identity, and logging entirely within the EU partition boundary.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Sep 28
2026
AWS European Sovereign Cloud: Demonstrating an independent operation
Sep 9
2026
Architecting SASE solutions using AWS Local Zones
Jan 30
2026
Sovereign failover – Design for digital sovereignty using the AWS European Sovereign Cloud
Dec 20
2024
Improving Overall Security Posture with Wiz Secured AWS landing zone

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.