Updated augustus 12, 2026
Summary: The EU Preparedness Union Strategy (COM(2025) final) identifies foreign-controlled cloud platforms as potential single points of failure in crisis scenarios, directly raising the compliance stakes for organisations subject to NIS-2, DORA and GDPR. Sovereign on-premises or Swiss-hosted infrastructure is no longer a niche preference but a documentable resilience posture.

The EU Preparedness Union Strategy (COM(2025) final) is the European Commission’s most explicit statement to date that digital infrastructure dependencies are not merely an IT governance concern but a matter of collective security and societal continuity. For compliance officers, CISOs and data protection officers in regulated sectors, the Strategy does something consequential: it elevates the risk of relying on foreign-controlled cloud platforms from a data-protection question to a systemic-resilience question, one that intersects with NIS-2, DORA, the Critical Entities Resilience (CER) Directive 2022/2557 and national continuity planning frameworks simultaneously.

The Strategy’s systemic-risk framing and what it means for cloud procurement

The EU Preparedness Union Strategy explicitly identifies concentration in a small number of foreign-controlled digital infrastructure providers as a systemic risk, meaning a failure or disruption in one node can cascade across sectors, borders and interdependent public services.

This framing is not new in academic or technical circles, but its elevation into a Commission strategy document changes its regulatory weight. Supervisory authorities across the EU are now expected to read their existing mandates, including those under NIS-2 and DORA, through this lens. An organisation that processes mission-critical workloads exclusively on a platform subject to the US CLOUD Act, FISA Section 702 or the USA PATRIOT Act is not merely accepting a data-protection risk. Under the Strategy’s framing, it is accepting a single point of systemic failure: the provider may become legally compelled to disclose data, technically unavailable due to geopolitical sanctions, or operationally disrupted by a foreign government’s administrative action.

Key implication: The Preparedness Union Strategy means that a cloud vendor’s legal jurisdiction is now a continuity variable, not just a compliance checkbox. Regulators in NIS-2 and DORA supervisory roles are expected to assess it as such.

Ransomware accounted for 34% of all cyber incidents targeting EU essential-service operators in the 2022-2023 reporting period, according to ENISA’s Threat Landscape 2023. Over 42% of operators of essential services in the EU reported at least one significant incident to national authorities in 2023 (ENISA Threat Landscape 2023). These figures confirm that the disruption scenarios the Strategy describes are not hypothetical: they are the current baseline threat environment into which any resilience architecture must be designed.

CADA Article 29 and whole-of-government continuity planning

CADA Article 29 introduces a mandatory pre-procurement risk assessment obligation for public administrations, requiring them to evaluate legal-access exposure, continuity risk and vendor-lock-in before contracting with or renewing agreements with providers operating under a foreign jurisdiction.

The interaction with the Preparedness Union Strategy is direct. The Strategy calls for whole-of-government continuity planning, meaning public administrations cannot treat their digital dependencies as isolated departmental choices. CADA Article 29’s risk assessment mechanism operationalises this at the procurement level: it forces the question of whether a given provider’s legal exposure under foreign law is compatible with the administration’s continuity obligations before a contract is signed, not years later when an incident or a regulator’s inspection reveals the gap.

In practice, this means that a ministry or municipal authority that is mid-contract with a US hyperscaler for its document collaboration, email or citizen-data processing must now assess, document and report on whether that dependency is consistent with its continuity plan. Where it is not, CADA Article 29 creates an obligation to remediate, either through contractual restructuring, data localisation or migration to a jurisdiction-clean alternative.

See how Qsentinel solves this in practice.Start a 10-user pilot →

NIS-2 Annex I continuity obligations and the single-point-of-failure problem

For private-sector entities in NIS-2 Annex I’s highly critical sectors (energy, transport, banking, financial market infrastructures, health, digital infrastructure and public administration, among others), the Strategy’s single-point-of-failure framing has concrete compliance implications.

NIS-2 requires Annex I entities to implement measures that ensure the continuity of their services in the event of a significant incident. Using a US-controlled cloud platform that may be subject to a foreign government’s access order, a sanctions regime change or a geopolitical disruption is, under the Strategy’s logic, a documented continuity risk that must appear in the entity’s risk register. EU-CyCLONe (the European Cyber Crisis Liaison Organisation Network) coordinates cross-border incident response precisely for this category of systemic disruption: a provider-level incident affecting multiple critical entities simultaneously.

The compliance obligation is therefore not merely to have a business continuity plan, but to have one that does not itself depend on the infrastructure identified as a potential failure source. An Annex I entity that lists “Microsoft 365 unavailability” or “AWS region outage” in its risk register but has no documented alternative processing capability has an incomplete continuity posture under both NIS-2 and the Strategy’s requirements.

Documenting ICT dependencies under DORA Articles 6-14

DORA Articles 6-14 establish the ICT risk management framework for financial entities, requiring asset identification, classification, scenario-based impact analysis and documented exit strategies for critical third-party providers. The Preparedness Union Strategy’s systemic-risk framing strengthens the case for treating provider jurisdiction as a first-class risk variable within that framework.

Practical guidance: Under DORA Articles 6-14, the ICT asset register must include the legal jurisdiction of every critical third-party provider. The Preparedness Union Strategy provides the policy rationale for escalating jurisdiction-related concentration risk to board level, not leaving it at operational IT level.

The European Systemic Risk Board (ESRB) stated in its 2022 report on systemic cyber risk: “Dependence on a small number of foreign cloud providers creates concentration risk that has systemic implications for the functioning of public services and financial markets alike.” This observation predates COM(2025) final but is now reinforced by it. Financial entities that have not yet mapped their critical workloads against provider jurisdiction, and modelled the impact of forced data-access or provider unavailability, have a gap that DORA supervisory authorities are increasingly likely to probe.

The IBM Cost of a Data Breach Report 2024 recorded an average total breach cost of USD 4.88 million, the highest in the report’s history. For financial entities subject to DORA, that figure is the floor: regulatory fines, supervisory remediation orders and reputational damage compound the direct cost, particularly where a breach involves data held under foreign jurisdiction without adequate legal-access controls.

Sovereign infrastructure as a documented resilience posture

Sovereign on-premises infrastructure or Swiss-hosted infrastructure addresses the disruption scenarios the Strategy identifies in a way that contractual commitments from a US hyperscaler cannot.

Disruption scenario US-controlled hyperscaler Sovereign or Swiss-hosted infrastructure
Foreign government access order (CLOUD Act, FISA 702) Provider legally compelled to comply; customer notification not guaranteed No US legal nexus; Swiss revFADP prohibits disclosure without Swiss legal process
Geopolitical sanctions affecting US entities Service may be restricted or suspended for affected customers Operationally independent; no US parent or controlling entity
Provider-level ransomware or outage Recovery timeline controlled by provider; customer has limited leverage Recovery under customer’s direct control; air-gapped backups feasible
Regulatory order to suspend service (e.g. Schrems II successor ruling) Data transfers may be suspended by DPA order pending legal resolution No cross-Atlantic transfer; no exposure to transfer-mechanism invalidation

The CER Directive 2022/2557 requires member states to identify critical entities across eleven sectors and ensure those entities adopt resilience measures against a defined range of disruption scenarios, explicitly including geopolitical ones. For critical entities in these sectors, sovereign infrastructure is not gold-plating: it is the architecture that makes the resilience measures credible under regulatory scrutiny.

Using the Strategy and CADA Article 29 as a procurement argument

Total-cost-of-ownership comparisons between a sovereign alternative and a hyperscaler frequently show a premium for the sovereign option, at least in the short term. The CADA sovereignty assurance framework and the Preparedness Union Strategy together provide a structured basis for justifying that premium in procurement processes, board papers and supervisory submissions.

The argument has three components. First, the Strategy creates a documented policy expectation, backed by the Commission, that regulated organisations should reduce systemic digital dependencies. This shifts the burden of justification: the question is no longer “why pay more for sovereignty?” but “why accept documented systemic risk for a cost saving?” Second, CADA Article 29’s mandatory risk assessment makes non-sovereign choices formally documented and attributable, meaning a decision-maker who approves continued US-controlled cloud use after a CADA Article 29 assessment has named and owned that risk. Third, the true cost differential narrows substantially when breach costs, regulatory remediation, supervisory scrutiny and the operational cost of managing cross-jurisdictional legal exposure are factored into the model rather than excluded from it.

The European Commission itself stated in COM(2025) final: “Resilience is not a technical afterthought. It is a political choice that must be built into procurement, into law, and into the daily operations of every organisation that society depends upon.” For a CISO or procurement officer presenting a sovereign infrastructure business case to a board or a ministerial committee, that sentence is a direct policy endorsement, sourced from the institution whose regulatory instruments govern the organisation’s compliance obligations.

FAQ

Does the EU Preparedness Union Strategy create direct legal obligations for private-sector organisations?

Not directly. COM(2025) final is a strategic policy document from the European Commission. However, it informs how existing binding instruments, including NIS-2, DORA and the CER Directive, are interpreted and enforced, and it signals the legislative direction regulators and supervisory authorities will follow. Organisations that document alignment with its framing are better positioned in audits and supervisory dialogues.

What is CADA Article 29 and why does it matter for public-sector cloud procurement?

CADA Article 29 establishes a mandatory risk assessment obligation for public administrations before they adopt or renew contracts with providers that process data under a foreign jurisdiction. It requires documentation of legal-access risks, continuity risks and exit options, making a structured sovereignty analysis a precondition for contract approval rather than an optional exercise.

Which NIS-2 Annex I sectors face the highest exposure from US-controlled cloud dependency?

NIS-2 Annex I lists energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space as highly critical sectors. Organisations in these sectors that process operational or patient data through platforms subject to the US CLOUD Act or FISA Section 702 face the compound risk of foreign-government access and single-point-of-failure disruption in geopolitical crisis scenarios.

How does DORA require financial entities to address concentration risk in cloud dependencies?

DORA Articles 6-14 require financial entities to maintain a comprehensive ICT risk management framework that includes identification and classification of all ICT assets and dependencies, scenario-based business impact analysis, documented exit strategies for critical third-party providers, and ongoing monitoring of concentration risk. The European Supervisory Authorities have signalled that reliance on a single hyperscaler for critical functions constitutes a concentration risk that must be quantified, mitigated or escalated to the board.

Is Swiss hosting genuinely outside the reach of US legal-access orders such as the CLOUD Act?

Swiss-domiciled providers that have no US parent, no US subsidiaries and no US persons in a controlling position are not subject to the CLOUD Act, which applies to providers established under US law or controlled by US persons. Switzerland’s revised Federal Act on Data Protection (revFADP) additionally prohibits disclosure of personal data to foreign authorities without Swiss legal process. This combination removes the primary legal vectors through which US agencies compel access, though organisations should always verify the corporate and ownership structure of their specific provider.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Does the EU Preparedness Union Strategy create direct legal obligations for private-sector organisations?
Not directly. COM(2025) final is a strategic policy document from the European Commission. However, it informs how existing binding instruments, including NIS-2, DORA and the CER Directive, are interpreted and enforced, and it signals the legislative direction regulators and supervisory authorities will follow. Organisations that document alignment with its framing are better positioned in audits and supervisory dialogues.
What is CADA Article 29 and why does it matter for public-sector cloud procurement?
CADA (the proposed EU Common Administrative Data Act, or the relevant national transposition framework depending on jurisdiction) Article 29 establishes a mandatory risk assessment obligation for public administrations before they adopt or renew contracts with providers that process data under a foreign jurisdiction. It requires documentation of legal-access risks, continuity risks and exit options, making a structured sovereignty analysis a precondition for contract approval rather than an optional exercise.
Which NIS-2 Annex I sectors face the highest exposure from US-controlled cloud dependency?
NIS-2 Annex I lists energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space as highly critical sectors. Organisations in these sectors that process operational or patient data through platforms subject to the US CLOUD Act or FISA Section 702 face the compound risk of foreign-government access and single-point-of-failure disruption in geopolitical crisis scenarios.
How does DORA require financial entities to address concentration risk in cloud dependencies?
DORA Articles 6-14 require financial entities to maintain a comprehensive ICT risk management framework that includes identification and classification of all ICT assets and dependencies, scenario-based business impact analysis, documented exit strategies for critical third-party providers, and ongoing monitoring of concentration risk. The European Supervisory Authorities have signalled in supervisory guidance that reliance on a single hyperscaler for critical functions constitutes a concentration risk that must be quantified, mitigated or escalated to the board.
Is Swiss hosting genuinely outside the reach of US legal-access orders such as the CLOUD Act?
Swiss-domiciled providers that have no US parent, no US subsidiaries and no US persons in a controlling position are not subject to the CLOUD Act, which applies to providers established under US law or controlled by US persons. Switzerland's revised Federal Act on Data Protection (revFADP) additionally prohibits disclosure of personal data to foreign authorities without Swiss legal process. This combination removes the primary legal vectors through which US agencies compel access, though organisations should always verify the corporate and ownership structure of their specific provider.