The EUCS candidate scheme is the European Union’s proposed cybersecurity certification framework for cloud services, developed by ENISA under the Cybersecurity Act. After years of political deadlock over whether sovereignty requirements should be embedded in the scheme itself, the European Commission’s COM(2026) 502, the Cloud and AI Development Act (CADA), has broken the impasse by placing sovereignty assurance in a separate but parallel legislative instrument. For compliance officers, CISOs and procurement leads in regulated sectors, understanding how these two tracks interact is no longer optional: it is a prerequisite for defensible cloud sourcing.
Why EUCS Work Stalled, and How COM(2026) 502 Restarts It
The core political dispute that froze EUCS was whether the scheme’s “High” assurance level should require providers to be immune from non-European legal jurisdiction, specifically from instruments such as the US CLOUD Act, FISA Section 702 and the Clarifying Lawful Overseas Use of Data Act. US-headquartered hyperscalers and several member states argued this would amount to a trade barrier; France, Germany and others insisted that a certification scheme for sensitive public sector data must include a legal immunity test. The result was years of circulating draft text with no agreed conclusion.
COM(2026) 502 resolves this deadlock structurally rather than politically. By introducing sovereignty assurance as a four-tier framework within CADA itself, the Commission removes the need to embed it directly in EUCS. EUCS is free to focus on cybersecurity controls, and CADA governs the jurisdiction and ownership questions separately. The revised Cybersecurity Act (CSA2), which provides the legal basis for the updated EUCS, mandates that ENISA resume and finalise the scheme as a complement to this sovereignty framework, not as a replacement for it.
EUCS and CADA: Two Frameworks, One Procurement Decision
The relationship between EUCS and CADA is complementary but not equivalent. EUCS evaluates the technical and organisational cybersecurity posture of a cloud service: encryption standards, key management, access controls, incident response, vulnerability management and audit logging. CADA evaluates who has legal access to the data that sits on top of those controls.
The CADA framework uses four sovereignty assurance tiers. The lowest tier covers basic transparency about data location and subcontractors. The highest tier requires that the provider and all material subcontractors are incorporated and operationally controlled within the EU, with no exposure to third-country laws that could compel data disclosure. A provider can demonstrate textbook cybersecurity hygiene at EUCS High level while simultaneously being a subsidiary of a US parent company, meaning that a National Security Letter or FISA 702 order could legally require disclosure of customer data without notifying the customer. EUCS certification would not detect or prevent this.
| Assessment Dimension | EUCS (cybersecurity) | CADA (sovereignty) |
|---|---|---|
| Encryption and key management | Evaluated | Not evaluated |
| Incident response and logging | Evaluated | Not evaluated |
| Legal jurisdiction of provider entity | Not evaluated | Core requirement |
| Exposure to CLOUD Act / FISA 702 | Not evaluated | Core requirement |
| Subcontractor nationality and legal exposure | Partially (supply chain security) | Explicitly assessed |
| NIS-2 / DORA control alignment | Facilitates compliance | Not in scope |
CAB Accreditation: What the EUCC Precedent Tells Us
The accreditation pathway for Conformity Assessment Bodies (CABs) under EUCS will follow the model established by the EUCC. The EUCC Implementing Regulation (EU) 2024/482 established the first EU-wide cybersecurity certification scheme for ICT products based on Common Criteria. The first CABs were formally accredited under this regulation in 2025, representing the first operational proof that EU member states can coordinate national accreditation bodies to recognise each other’s CAB decisions across borders.
As of early 2025, the first Conformity Assessment Bodies were formally accredited under Implementing Regulation (EU) 2024/482, marking the first operational milestone for the EU cybersecurity certification ecosystem.
This precedent matters for EUCS readiness in two ways. First, the procedural machinery, national accreditation bodies, peer review processes and ENISA oversight, has been shown to work. Second, the competency requirements for EUCS CABs will be substantially more complex than for EUCC, because cloud audits must cover multi-tenant architectures, shared responsibility models, dynamic scaling and geographically distributed data processing. ENISA will need to publish cloud-specific competency criteria, and national accreditation bodies will need to develop auditor training programmes before a functioning CAB market can emerge. Regulated buyers should not expect EUCS-certified providers to be widely available in the near term and should plan procurement timelines accordingly.
National Schemes as Interim Evidence: BSI C5 and SecNumCloud
Two national cloud certification schemes have established enough depth and market recognition to serve as credible interim evidence during the EUCS transition period: Germany’s BSI C5 and France’s SecNumCloud.
BSI C5, published by the Bundesamt für Sicherheit in der Informationstechnik, is a criteria catalogue covering 17 control domains including organisation, physical security, identity management, encryption, incident management and business continuity. It operates on a Type 1 (design) and Type 2 (operating effectiveness over a defined period) audit model familiar from SOC 2. A C5 Type 2 attestation provides regulated buyers with structured, independently verified evidence of cybersecurity controls that maps closely to what EUCS High is expected to require.
SecNumCloud, managed by ANSSI, France’s national cybersecurity authority, goes further. As ANSSI states explicitly in its referential documentation: “SecNumCloud qualification requires that the cloud provider and its subcontractors are not subject to non-European law that could compromise the confidentiality of hosted data.” This makes SecNumCloud the closest existing approximation to a combined EUCS-plus-CADA assessment. Buyers procuring for workloads that contain health records, legal privilege material or classified public sector data should treat current SecNumCloud qualification as strong interim evidence of both cybersecurity and sovereignty posture.
The average cost of a data breach globally reached USD 4.45 million in 2023, the highest figure in the 18-year history of the IBM Cost of a Data Breach Report. For regulated organisations operating under GDPR, NIS-2 or DORA, this figure does not capture the additional regulatory fine exposure, reputational damage or mandatory notification costs that compound the direct breach cost. Procuring from providers that hold credible certification, whether C5, SecNumCloud or, in due course, EUCS, reduces this exposure by demonstrating documented due diligence.
Procurement Due Diligence: Separating the Two Assessments
For compliance officers and IT decision-makers in government, finance, healthcare or legal sectors, the practical challenge is structuring procurement evaluation so that EUCS cybersecurity assurance and CADA sovereignty assurance are assessed as distinct but equally mandatory criteria. Conflating them, or treating one as a proxy for the other, creates compliance gaps that will not survive regulatory scrutiny under GDPR, NIS-2 or DORA.
A workable due-diligence checklist separates into two independent gates. The first gate covers cybersecurity assurance: what assurance level does the provider claim or hold under EUCS, BSI C5 or SecNumCloud; which accredited CAB issued the certificate or attestation; what is the scope, including which service components and geographic regions are covered; and how do the certified controls map to the NIS-2 and DORA requirements applicable to the buyer’s sector. A provider that cannot answer these questions with documented evidence should not advance.
The second gate covers sovereignty assurance: in which jurisdiction is the legal operating entity incorporated; which third-country laws, specifically the CLOUD Act, FISA 702 and national security instruments, could compel disclosure of customer data without customer notification; are all material subcontractors and infrastructure providers similarly free of non-EU legal exposure; and at which of the four CADA tiers does the provider position itself, with what independent evidence. For the highest-sensitivity workloads, on-premises or private cloud deployment under Swiss or EU-exclusive jurisdiction may remain the only defensible option, because no public cloud provider subject to US ownership can currently satisfy CADA’s highest tier regardless of its EUCS cybersecurity score.
ENISA registered more than 360 cybersecurity certification-related activities across EU member states in its 2023 certification tracking work. This fragmentation is precisely the problem EUCS is designed to solve: a single European scheme will allow buyers to compare providers on a common evidentiary basis rather than translating between incompatible national frameworks. Until EUCS is finalised and CABs are accredited, buyers must do that translation themselves, using the guidance above.
As Margrethe Vestager noted in European Commission digital strategy communications: “Cloud services are the backbone of Europe’s digital economy and public services. Ensuring that they meet high cybersecurity standards through a common European certification framework is a strategic priority, not a technical detail.” The CADA and CSA2 package represents the legislative moment where that strategic priority becomes a legal obligation with enforceable procurement consequences.
FAQ
What is the EUCS candidate scheme, and who manages it?
The European Union Cloud Services cybersecurity certification scheme (EUCS) is managed by ENISA under the Cybersecurity Act. It defines assurance levels (Basic, Substantial, High) for cloud services and is intended to harmonise the patchwork of national schemes across member states. Work on the scheme was paused during political negotiations over sovereignty requirements but is being resumed under COM(2026) 502 and the revised Cybersecurity Act (CSA2).
Can a cloud provider pass EUCS High certification while still failing CADA sovereignty requirements?
Yes. EUCS certifies cybersecurity controls: encryption, access management, incident response and similar technical measures. CADA adds a separate four-tier sovereignty assurance layer that examines legal jurisdiction, ownership, subcontractor nationality and exposure to non-EU laws such as the US CLOUD Act. A provider can demonstrate strong EUCS cybersecurity hygiene while remaining legally exposed to foreign government access requests, meaning EUCS alone is not sufficient for data that must remain sovereign.
Are BSI C5 and SecNumCloud still valid while EUCS is not yet finalised?
Both schemes remain valid and actively used. BSI C5, published by Germany’s Bundesamt für Sicherheit in der Informationstechnik, provides a structured Type 2 audit attestation covering 17 control domains. SecNumCloud, operated by France’s ANSSI, is stricter and includes an explicit sovereignty test on legal exposure. Regulated buyers should treat current attestations under these national schemes as interim evidence of compliance maturity, with the expectation that EUCS will eventually align or supersede them.
What is the EUCC accreditation precedent, and why does it matter for EUCS readiness?
The EUCC was established by Implementing Regulation (EU) 2024/482. The first Conformity Assessment Bodies were formally accredited under this regulation in 2025, proving that the EU can operationalise a cross-border CAB accreditation infrastructure. This gives confidence that a similar ecosystem will be buildable for EUCS, though cloud-specific audit competencies will require additional training and ENISA guidance before a functioning CAB market can serve regulated buyers at scale.
How should a compliance officer structure a procurement checklist to cover both EUCS and CADA?
The checklist should have two clearly separated gates. The first covers EUCS cybersecurity assurance: which assurance level is claimed or certified, which CAB issued the certificate, what the certificate’s scope and validity period are, and whether controls cover NIS-2 and DORA-relevant domains. The second covers CADA sovereignty assurance: in which jurisdiction the legal entity is incorporated, which laws could compel disclosure (CLOUD Act, FISA 702, national security orders), whether subcontractors are subject to non-EU jurisdiction, and at which CADA tier the provider can demonstrate independent evidence of compliance. Only providers satisfying both gates should progress to contract negotiation for sensitive or regulated workloads.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
