EU-only TLS termination with ISO 27001-certified facilities
Cloudflare has announced the general availability of a new Regional Services region that restricts HTTPS traffic decryption to ISO 27001-certified data centers within the European Union. The setting is a one-click toggle on the Cloudflare dashboard, aimed at organizations that must guarantee only specific facilities can decrypt and service their traffic.
Regional Services was introduced in 2020 as a response to regulatory pressure that made it difficult for some enterprises to use global-scale vendors. It decouples DDoS mitigation from application-layer processing: the closest data center accepts the raw TCP connection, but that connection is forwarded to a pre-selected facility for decryption and Layer 7 handling. Only those in-region machines ever see the unencrypted HTTP request, so sensitive content such as financial or medical data is never exposed outside the chosen geography. Subsequent releases added regions for Japan, Australia, and India.
The newly available EU region goes beyond geography, though. The selection criterion here is not location alone but the possession of an ISO 27001 certification, a widely recognized standard for information security management systems. Under the new configuration, Cloudflare products including WAF, Bot Management, and Workers execute only inside facilities that maintain that certification.
The rationale for this kind of region is familiar to security and compliance teams. Many customers are restricted by contractual commitments or regulatory obligations. But an increasing number are asking not only where data may be processed, but whether the facilities meet specific security assurance standards. That distinction drives the need for certification-based, rather than purely geographic, traffic placement.
Per-hostname configuration from the DNS tab
Alongside the new region, Cloudflare has redesigned the Data Localization Suite interface. Previously, a region applied to an entire zone, preventing customers from mixing configurations across hostnames. The new UI supports per-hostname region selection directly from the DNS tab, with changes taking effect within seconds.
The updated interface also adds a self-serve option for configuring the Metadata Boundary, the feature that controls where log flows are directed.
Both the new EU region and the refreshed configuration flow are live in the dashboard. The announcements position Cloudflare to serve organizations that need to meet both strict data-residency policies and verifiable security standards without sacrificing the benefits of a distributed edge network.



