Regulation (EU) 2022/2560, known as the Foreign Subsidies Regulation (FSR), is an EU competition instrument that gives the European Commission authority to investigate and, where necessary, exclude from public procurement procedures any economic operator that has received foreign state subsidies capable of distorting competition in the EU internal market. For compliance officers, CISOs and procurement teams in the public sector, finance, healthcare and legal industries, the FSR introduces a new and consequential layer of risk assessment when selecting cloud infrastructure and software-as-a-service providers.
What the Foreign Subsidies Regulation actually does in cloud procurement
The FSR closes a long-standing gap in EU trade and competition law: non-EU state subsidies were previously invisible to EU procurement oversight. Under the new regime, tenderers above defined thresholds must declare foreign financial contributions, and the Commission can block contract awards where those contributions distort fair competition.
Cloud and software contracts are squarely within scope. A hyperscaler that benefits from below-market financing, tax relief, preferential data-centre land rights or sovereign-backed research grants in its home country, and then bids at artificially low prices on an EU public tender, falls precisely within the regulation’s target. The Commission’s first formal FSR investigation into a public procurement procedure was opened in 2023, confirming that the mechanism is operational and not merely theoretical.
Notification thresholds and investigation triggers under FSR Articles 28-30
The mandatory notification regime under FSR Articles 28 to 30 sets a specific financial threshold above which the obligation to declare foreign financial contributions becomes binding before a contract is awarded.
According to Article 28 of Regulation (EU) 2022/2560, a tenderer must notify the contracting authority, who then forwards the notification to the European Commission, when the estimated contract value equals or exceeds EUR 250 million. Below that threshold, the Commission retains the right to open ex officio investigations whenever it has sufficient indications of distortive foreign subsidies, meaning that no public procurement procedure for cloud infrastructure is entirely outside the Commission’s reach.
| Scenario | Contract value | FSR obligation | Commission power |
|---|---|---|---|
| Large government cloud framework | Above EUR 250 million | Mandatory pre-award notification | Preliminary review, full investigation, suspension, exclusion |
| Mid-size regulated-sector SaaS contract | Below EUR 250 million | No mandatory notification | Ex officio investigation if indications of distortion exist |
| Consortium bidding across member states | Aggregated above threshold | Each consortium member must declare contributions | Investigation can cover all consortium partners |
During a preliminary review (Article 29), the Commission has 20 working days to assess the notification. If concerns remain, it opens an in-depth investigation (Article 30), which can last up to 110 working days. The contracting authority may not award the contract during this period, creating direct procurement delay for any buyer who has not factored FSR timelines into project planning.
How FSR compounds CADA sovereignty criteria for non-EU hyperscalers
The FSR does not operate in isolation. It interacts with the Cloud and AI Development Act (CADA), the EU’s emerging framework that is expected to introduce sovereignty criteria, interoperability requirements and restrictions on data flows for critical public-sector cloud procurement. Where CADA establishes baseline sovereignty conditions, the FSR adds a competition-law filter: a provider can be technically compliant with CADA’s data-localisation requirements and still face exclusion from a tender because it received distortive state aid from a third-country government.
For non-EU hyperscalers, this creates a compounding barrier. They must simultaneously demonstrate that their foreign financial contributions are below material thresholds, that they meet CADA’s sovereignty criteria, and that they can satisfy the jurisdiction independence requirements arising from GDPR, the US CLOUD Act and FISA 702. Each of these frameworks can independently disqualify a provider; together, they substantially narrow the field of compliant options for regulated public-sector buyers.
According to the European Parliamentary Research Service, more than 65 percent of European enterprise cloud spending currently flows to three US-headquartered hyperscalers. The combined effect of FSR, CADA and data-sovereignty law is to create structural incentives for that spending to shift toward European providers not subject to foreign-jurisdiction legal exposure or third-country subsidy scrutiny.
As former European Commission Executive Vice-President Margrethe Vestager stated at the FSR’s entry into force: “Foreign subsidies can allow companies to make offers on terms that European companies simply cannot match. The Foreign Subsidies Regulation gives us the tools to ensure a level playing field in public procurement.”
Due-diligence obligations when a provider faces an open FSR investigation
When an organisation has selected or is evaluating a cloud provider that is subject to an open FSR investigation, the procurement team faces specific risk-management obligations, even though the FSR’s direct legal effect is at the pre-award stage rather than in existing contracts.
Practically, an open investigation signals that the Commission has identified sufficient indications of distortive subsidies to warrant formal scrutiny. For a compliance officer, this constitutes material supplier risk that must be documented. The organisation should record the investigation reference, the scope of the Commission’s concerns, and the potential outcome scenarios (undertakings accepted by the provider, commitments imposed by the Commission, or outright exclusion from future tenders).
Procurement teams should also prepare a written fallback assessment. This means identifying at least one alternative sovereign provider capable of delivering equivalent functionality, estimating migration timelines and costs, and confirming that current contracts contain data-portability and exit rights. Failure to maintain this documentation creates audit exposure under GDPR accountability principles and, for financial entities, under DORA’s ICT third-party risk management requirements.
FSR redress mechanisms as sovereignty risk signals under NIS-2
The FSR provides three types of redress when an investigation finds distortive foreign subsidies: the provider can offer undertakings (behavioural commitments to remedy the distortion), the Commission can impose structural or financial commitments, or the Commission can prohibit the contract award entirely. Each of these outcomes carries different implications for a regulated organisation assessing its supply-chain exposure.
A provider that has accepted undertakings in a prior FSR proceeding should be treated as a higher-risk supplier for the purposes of NIS-2 Article 21(2)(d), which requires essential and important entities to address security in the supply chain, including the security-related aspects of the relationships between each entity and its direct suppliers or service providers. An undertaking accepted under the FSR does not remove the underlying subsidy relationship; it only constrains certain behaviours. The jurisdiction risk, including the provider’s exposure to CLOUD Act compelled-disclosure orders, remains unaffected by any FSR commitment.
ENISA’s NIS-2 implementation guidance states directly: “Supply-chain security is not optional under NIS-2. Entities must assess the security practices of their providers, and that assessment must include legal jurisdiction and the risk of foreign government access.” An FSR undertaking or investigation outcome should therefore be recorded in the organisation’s supplier risk register as evidence of a sovereignty concern that NIS-2 Article 21 requires to be addressed.
The Digital Markets Act (DMA) gatekeeper investigation framework adds further context. Several hyperscalers designated as gatekeepers under the DMA are also the most likely subjects of FSR scrutiny. A provider simultaneously subject to DMA gatekeeper obligations and an FSR investigation presents a concentration of regulatory risk that procurement governance frameworks in regulated sectors should treat as a compounding red flag, not two separate issues to be assessed in isolation.
Practical steps for CISOs and procurement teams to pre-empt FSR disruption
The most effective risk management against FSR-related contract disruption is structural: build sovereign exit rights and migration obligations into cloud contracts before signature, rather than trying to negotiate them after an investigation opens.
Concrete contractual provisions that reduce FSR disruption risk include: a data-portability clause specifying the format and timeline in which the provider must return all data, permissions, metadata and configuration on request; a termination-for-regulatory-cause right that allows the organisation to exit without penalty if the provider becomes subject to a binding FSR exclusion or commitment order; and a migration-assistance obligation requiring the provider to cooperate technically and operationally with a replacement supplier for a defined period after notice of termination.
At the procurement-design stage, including FSR-related due diligence as a scored criterion, not merely a compliance checkbox, strengthens defensibility in audit. Specifically, procurement teams can require tenderers to disclose all foreign financial contributions above the FSR notification threshold received in the preceding three fiscal years, regardless of whether the individual contract value reaches EUR 250 million. This voluntary disclosure requirement, which is permissible under EU Public Procurement Directives 2014/24/EU and 2014/25/EU as a technical or financial selection criterion, surfaces subsidy exposure before contract award and before a Commission investigation creates procurement delay.
For organisations evaluating sovereign European cloud providers, the FSR analysis is significantly simpler. A provider incorporated and operating under an EU member state jurisdiction, with no material financial contributions from third-country governments, presents no FSR notification burden and no investigation risk. Combined with the absence of CLOUD Act exposure and the ability to satisfy CADA sovereignty criteria natively, this risk differential is becoming a quantifiable procurement advantage that goes beyond the traditionally subjective concept of “digital sovereignty.”
Aligning FSR procurement strategy with the broader sovereign stack
The FSR is best understood not as a standalone compliance requirement but as one instrument within a converging regulatory framework that is systematically increasing the cost and risk of dependency on non-EU hyperscalers for regulated-sector procurement. GDPR accountability, NIS-2 supply-chain security, DORA ICT third-party risk, CADA sovereignty criteria and now FSR foreign-subsidy scrutiny each apply independently and each can disqualify or complicate a non-EU provider relationship.
For CISOs and data protection officers designing long-term cloud strategy, this regulatory convergence has a practical implication: the question is no longer whether to maintain sovereign alternatives, but how to document and evidence that sovereign alternatives exist, are tested, and can absorb workloads within a defined recovery time objective if a primary non-EU provider relationship is interrupted by regulatory action, whether that is an FSR exclusion, a CLOUD Act disclosure order or a DORA-triggered ICT service disruption.
FAQ
At what contract value does the Foreign Subsidies Regulation require mandatory notification for a cloud procurement?
Under FSR Article 28, a tenderer must notify the European Commission of foreign financial contributions when the estimated contract value reaches or exceeds EUR 250 million. Below that threshold the Commission can still open ex officio investigations if it suspects a distortion of competition.
Can the European Commission exclude a cloud provider from a public tender solely based on an FSR investigation, before a final ruling?
Yes. During a preliminary review or in-depth investigation under FSR Articles 29 and 30, the Commission can impose interim measures and ultimately prohibit the award of the contract to the investigated tenderer if it concludes that a foreign subsidy distorts the procurement.
How does the FSR interact with GDPR and NIS-2 when evaluating a cloud provider?
The FSR adds a competition-law layer on top of existing data-sovereignty obligations. A provider that clears GDPR Standard Contractual Clauses and claims NIS-2 compliance can still be blocked from a tender on FSR grounds if it receives distortive foreign subsidies. Procurement teams therefore need to evaluate providers across all three frameworks simultaneously.
What should a public-sector organisation do if it has already signed a cloud contract with a provider that later becomes subject to an FSR investigation?
The FSR applies primarily at the procurement stage, not to existing contracts. However, organisations should treat an open investigation as a material supplier risk, document a contingency plan including alternative providers and migration timelines, and review their contract for exit clauses and data-portability rights.
Does the Foreign Subsidies Regulation apply to private-sector regulated entities such as banks and hospitals, or only to government buyers?
The procurement instrument in FSR Articles 28 to 30 applies to contracting authorities and contracting entities under EU Public Procurement Directives 2014/24/EU and 2014/25/EU. This covers not only central government but also entities operating under the utilities directive, which can include certain publicly owned or regulated healthcare and energy bodies.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
