Sovereign cloud in the EU: what the term means, where EUCS stands and what to ask a provider
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- As of October 2026 no EU legal act in force defines “sovereign cloud”; the term covers data location, the operator’s jurisdiction and ownership, administrative access, encryption keys, the supply chain and exit, and each EU text weighs these differently
- ENISA’s EUCS, a cybersecurity certification scheme for cloud services with the assurance levels Basic, Substantial and High, was still a candidate scheme on the Commission’s page of 9 September 2026, and the CADA proposal would require a European cybersecurity certificate for its levels 2 to 4 once such a scheme exists
- The Commission’s Cloud Sovereignty Framework, first presented in an October 2025 tender for the EU institutions, rates eight objectives from SEAL-0 to SEAL-4; the weakest objective sets the overall level, and SEAL-2 was the minimum in that tender
- The Cloud and AI Development Act proposed on 3 June 2026, COM(2026) 502, would make public buyers procure at least level 1, which would require an EU-established provider with infrastructure and customer data in the Union, and level 2, 3 or 4 where a risk assessment finds public order relevance; it awaits a committee decision in Parliament
- Data Act Article 28, applicable since 12 September 2025, makes cloud providers publish the jurisdiction of their ICT infrastructure and a general description of their measures against conflicting foreign governmental access, and Article 32 requires such measures for non-personal data held in the Union
Eurokommerz × Vixen.UNO: EU Cloud Talk to an expert →
What sovereign cloud means in the EU
Sovereign cloud has no single legal definition in EU law as of October 2026. The term is used for cloud services that keep data and operations under EU control and limit their exposure to non-EU law, and EU texts differ on which points count and how far each has to go. The Commission treats the topic as part of digital sovereignty, an aim of its proposed Cloud and AI Development Act (CADA). When a provider or a tender calls a service sovereign, ask which published criteria the claim refers to and which evidence stands behind it.
Four EU texts serve as reference points; only the Data Act is binding law today.
| TEXT | PUBLISHED BY | STATUS, OCT 2026 | WHAT IT SETS OUT |
|---|---|---|---|
| EUCS | ENISA | draft of 22 December 2020, still a candidate scheme | cybersecurity requirements at three assurance levels; transparency on data location |
| Cloud Sovereignty Framework | European Commission | used in a tender from October 2025; guidance of 1 June 2026 | eight objectives, a rating from SEAL-0 to SEAL-4, a score from 48 criteria |
| CADA | European Commission | proposal of 3 June 2026, awaiting committee decision | four Union assurance levels, minimum levels for public buyers |
| Data Act Art. 28 and 32 | European Parliament and Council | applies since 12 September 2025 | jurisdiction disclosure, safeguards against conflicting foreign access |
ENISA (December 2020); Commission certification page (9 September 2026), guidance and news item (1 June 2026); COM(2026) 502 and the Legislative Observatory (6 October 2026); Regulation (EU) 2023/2854.
EUCS certification: what ENISA published and where it stands
ENISA prepares EUCS, the European Cybersecurity Certification Scheme for Cloud Services, under the Cybersecurity Act, Regulation (EU) 2019/881, and published the draft candidate scheme for consultation on 22 December 2020. The Commission’s summary of June 2021 describes the draft as a voluntary scheme for IaaS, PaaS, SaaS and other cloud services with three assurance levels, Basic, Substantial and High. On location, the draft asks for “transparency about the location of the processing and storage of data” and about the applicable laws.
ENISA’s certification library lists only that draft, so later versions are known from secondary accounts. A brief by the EU Institute for Security Studies of 3 November 2025 says that after the consultation the Commission asked ENISA for a clause at the highest level keeping data out of non-European jurisdictions, meaning hosting and processing only in the EU, a European headquarters and majority European ownership. According to the brief, a May 2023 draft included data localisation, and a March 2024 version removed this “sovereignty requirement” and proposed leaving the matter to national regulators.
As of 6 October 2026 neither ENISA nor the Commission lists the cloud scheme as adopted; the Commission’s certification framework page, updated on 9 September 2026, still names it among the candidate schemes it has asked ENISA to prepare. The CADA proposal states that work on EUCS “will resume”. Its Annex II would require, for levels 2 and 3, a European cybersecurity certificate of at least assurance level “substantial” and, for level 4, “high”, under a cloud scheme still “to be established” under the Cybersecurity Act; until then, national schemes would apply where they exist. No provider can hold an EUCS certificate today, and an offer that cites EUCS refers to a draft.
The Commission’s Cloud Sovereignty Framework and SEAL levels
The Commission first presented its Cloud Sovereignty Framework in October 2025, in a call for tenders under the Cloud III Dynamic Purchasing System to buy sovereign cloud for the EU institutions, bodies, offices and agencies. It awarded the contract in April 2026, and on 1 June 2026 its Directorate-General for Digital Services published implementation guidance with a spreadsheet calculator. The Commission encourages “all organisations, both public and private” to use the framework.
The framework rates eight sovereignty objectives: strategic, legal and jurisdictional, data and AI, operational, supply chain, technology, security and compliance, and environmental sustainability. Each receives a Sovereignty Effectiveness Assurance Level (SEAL), from SEAL-0, where non-EU parties have exclusive control under non-EU jurisdictions, to SEAL-4, where technology and operations are under complete EU control, subject only to EU jurisdiction and with “no critical non-EU dependencies”. Bidders answer questions under each objective, and each answer carries a score and a SEAL level. The overall SEAL is the lowest level reached in any objective. The contracting authority sets the minimum, SEAL-2 in the Commission’s tender, and a sovereignty score from 48 criteria, weighted by objective, then compares the offers that reach it.
Several criteria work as questions for any provider, among them its exposure to non-EU laws with cross-border reach, such as the US CLOUD Act, and whether only the customer has effective control over cryptographic access to its data.
Sovereignty levels in the proposed Cloud and AI Development Act
The Commission proposed the Cloud and AI Development Act on 3 June 2026 (COM(2026) 502, procedure 2026/0138(COD)). On 6 October 2026 the European Parliament’s Legislative Observatory listed it as “Awaiting committee decision”, so the text can still change. Article 16 sets up a Union cloud computing sovereignty framework with four assurance levels; Annex II lists the criteria. Level 1 already requires a provider “established in the Union”, infrastructure and assets, subcontractors’ included, located in the Union, and customer data, including metadata and telemetry, kept “exclusively within the Union” unless the public body requires otherwise. On the Commission’s page, level 2 adds independence from third countries and transparency over the software supply chain, level 3 requires providers “owned and controlled from the EU” that meet criteria such as personnel citizenship, and level 4 adds full transparency and control over the software supply chain and no interference from a third country. Under Article 18, services controlled from a recognised third country could qualify for level 3.
According to the explanatory memorandum, providers apply for recognition in their Member State of establishment (Article 17), level 1 is documented by a conformity self-assessment, auditing organisations assess levels 2 to 4, and the Commission keeps a central repository of recognised services. Contracting authorities would procure at least level 1 and, where a risk assessment finds that their activities have public order relevance, only services recognised at level 2, 3 or 4 (Articles 29 and 30). Recital 62 ties public order to the NIS2 sectors, national and internal security, external border management, defence, justice and law enforcement.
Recital 66 observes that such requirements on public buyers tend to be mirrored by private companies in regulated industries, and stresses the importance of private entities in the sectors of Annex I to the NIS2 Directive being able to carry out the same assessments.
Data Act Articles 28 and 32: rules for every cloud provider today
The Data Act, Regulation (EU) 2023/2854, has applied to providers of data processing services since 12 September 2025. Article 28(1) requires each provider to publish on its website, and keep up to date, the jurisdiction to which the ICT infrastructure of each service is subject, and “a general description of the technical, organisational and contractual measures” adopted to prevent international governmental access to, or transfer of, non-personal data held in the Union in conflict with Union or national law. Under Article 28(2), those websites have to be listed in the provider’s contracts.
Article 32 requires adequate technical, organisational and legal measures against such access, and a third-country order for such data is recognised or enforceable “only if based on an international agreement”. Without one, access is allowed only under the conditions of Article 32(3). In either case the provider hands over the minimum data permissible and informs the customer before complying, except where the request serves law enforcement and for as long as that is needed to keep it effective. Our article on the CLOUD Act and EU data residency explains how these rules meet US law.
Article 28 asks for a statement of jurisdiction, not for EU jurisdiction, so whether the answer is acceptable is your decision. The safeguards in both articles concern non-personal data; for personal data the GDPR applies, from Article 48 on third-country orders to the processor contract, which our guide to GDPR in cloud hosting, the DPA and subprocessors covers. The Digital Omnibus proposal of 19 November 2025 would amend the Data Act, but on 6 October 2026 it still awaited a committee decision in Parliament.
Questions to ask a sovereign cloud provider and the evidence to expect
A sovereignty claim becomes comparable once each dimension is a question with a document behind the answer, such as a contract clause, a log or the scope of an audit. The questions follow the Commission’s framework and the CADA levels. In the Commission’s guidance, the assessment rests on answers, supporting documents and public information, and covers all subcontractors and suppliers.
| DIMENSION | QUESTION | VERIFIABLE ANSWER |
|---|---|---|
| Data location | Where are data, metadata, telemetry, backups, logs and replicas stored and processed, support and failover copies included? | sites named in the contract or service description, no fallback outside the EU |
| Jurisdiction and ownership | Which legal entity signs, under which law, and who owns or controls it? | register extract, ownership structure, governing-law clause, the Data Act Article 28 page |
| Foreign access requests | What does the provider do when a third-country authority asks for data? | the Article 28(1)(b) description, a contract clause on notice and challenge |
| Administrative access | Who can reach systems and data, from which countries, with which approvals? | access policy, support locations, privileged sessions logged and open to your review |
| Encryption keys | Who generates and holds the keys for storage and backups, and which components see data in clear? | key management design, the option of keys held by you and its limits |
| Supply chain and support | Which vendors supply hardware, virtualisation and management software, and what if one ends support? | supplier and subprocessor list, licence dependencies, a plan for a vendor exit |
| Certificates and audits | Which certificates cover which entity, site and service, until when? | certificate with scope and validity; no EUCS certificate exists yet |
| Exit and portability | How do data and virtual machines come back, in which formats, within which periods? | Data Act Article 25 terms in the contract, export formats, a test export |
Commission, Cloud Sovereignty Framework implementation guidance (1 June 2026); COM(2026) 502, Annex II, and the Commission’s page on it (3 June 2026); Regulation (EU) 2023/2854, Articles 25, 28 and 32.
For the exit row, our guide to Data Act cloud switching sets out the contract periods.
Our EU Cloud runs in Baltneta’s Tier-3 data centres in Lithuania, keeps data and backups in the EU and names subprocessors in the contract. Send us the questions your procurement asks through the form below; we fill in supplier questionnaires.
Setting sovereign cloud requirements for your own company
The CADA levels would bind only public buyers and the Commission’s framework is voluntary, so a private company derives its requirements from its own risk assessment, its customer contracts and, for personal data, the GDPR. Each step up narrows the choice of providers and services, so set the level per data class rather than for the whole company.
- List systems and data classes; mark personal data, data whose location or access customer contracts restrict, and data under sector rules.
- Per class, decide which dimensions are mandatory: EU location only, or also an EU operator, restricted administrative access, keys held by you or supply chain criteria.
- Write each requirement as a question with the evidence you will accept, as in the table above, and send it to providers before asking for offers.
- Rate each answer and take the weakest dimension as the result for the data class, as the SEAL rule does.
- Record the decision and the remaining risk, and repeat the check at renewal and when a provider changes owners, subprocessors or support locations.
How these rules apply to your data and contracts is a legal assessment for your legal department. The choice between IaaS, a private cloud and hybrid is a separate one, covered in our comparison of IaaS, private cloud and hybrid.
Data in the EU, a European operator and subprocessors named in the contract are part of our EU Cloud offer. Tell us which systems and data classes you would move first, and where they run today.
General information on EU law as of October 2026, not legal advice for an individual case.
What we do
Our EU Cloud service provides IaaS on the VMware vSphere platform or a dedicated private cloud in Baltneta’s Tier-3 data centres in Lithuania, certified to ISO 27001 and PCI DSS Level 1, and data and backups stay in the EU. Baltneta, a European operator, runs the platform, the contract is with Eurokommerz under Austrian law, and our engineering partner Vixen.UNO handles migration and support within an access scope the contract defines and that can be limited by agreement. Our security and compliance page lists what we sign, including an NDA before technical detail and a data processing agreement under Article 28 GDPR on request. The first call is free of charge, and the price of the technical assessment is fixed before work begins.
FAQ
What is a sovereign cloud?
What is EUCS certification?
Does EUCS require data to stay in the EU?
What are the requirements for an EU sovereign cloud?
What does the Data Act say about foreign government access to cloud data?
How can I check a provider’s sovereign cloud claim?
Send us the systems and data classes you plan to host and the requirements your procurement or legal department has set on location, operator, administrative access, keys and exit. We reply within one business day to arrange a first call, from which you leave with two or three configuration options and an indicative monthly invoice. The first call is free of charge.
Talk to an expertWe reply within one business day