Updated augustus 16, 2026
Summary: The proposed Cloud Act for Digital Autonomy (CADA) creates four binding assurance levels that cloud providers must demonstrate to qualify for EU public-sector contracts, with Articles 16–19 defining the conformity assessment routes, national authority recognition, and third-country provider conditions. CISOs and procurement officers must use CADA alongside the existing EUCS framework during the legislative transition to avoid compliance gaps.

CADA Article 16 sovereignty assurance levels are the structured conformity tiers that the proposed Cloud Act for Digital Autonomy introduces to establish a uniform, legally binding benchmark for cloud providers supplying EU public administrations and regulated sectors. Unlike voluntary best-practice labels, these levels attach specific legal consequences to procurement decisions, creating a hierarchy of demonstrated sovereignty that runs from basic transparency at level 1 to full operational and jurisdictional independence at level 4. Understanding how the four levels are defined, how recognition is obtained, and how they interact with the existing EUCS framework under the Cybersecurity Act is now a prerequisite for any CISO, data protection officer, or procurement officer evaluating cloud infrastructure for sensitive workloads.

What CADA Article 16 Actually Requires at Each Level

Article 16 defines four Union assurance levels through a cumulative logic: each level inherits the requirements of the one below it and adds new, independently verifiable criteria.

Level 1 requires providers to document data localisation commitments, identify the legal jurisdiction of the operating entity, and publish their data access policies in machine-readable form. This is essentially a transparency baseline, demanding disclosure rather than demonstrated control.

Level 2 adds requirements for access control audits, incident logging with mandated retention, and a binding contractual prohibition on transferring EU data to third countries without a transfer mechanism recognised under GDPR Chapter V. This is the minimum floor for general public-sector buyers under the proposed CADA procurement framework.

Level 3 introduces the sovereignty core: providers must demonstrate operational independence from entities incorporated or majority-controlled outside the EU or EEA, show that no applicable foreign law grants a third country’s authorities effective access to the data, and submit to an accredited third-party conformity assessment. CADA Annex II enumerates the specific technical and organisational controls that constitute this demonstration, including key management architecture, supply-chain vetting of hardware and software, and personnel security screening.

Level 4 is reserved for classified or strategically critical workloads. It adds requirements for physical security of data centres meeting EU government facility standards, cryptographic isolation provable under post-quantum assumptions, and continuous on-site auditing by a nationally designated authority. Very few commercial providers are expected to qualify at this level in the short term.

Let op: CADA Article 16 levels are cumulative and additive. A provider claiming level 3 must satisfy all level 1 and level 2 requirements in full, not merely the incremental level 3 criteria. Procurement officers should request the complete conformity documentation package, not a summary certificate.

Article 17: How National Competent Authority Recognition Works

Recognition under Article 17 is not self-executing: a provider must apply to a designated national competent authority (NCA) in a member state, which then issues a formal level recognition that is valid across the EU under a mutual recognition principle.

In practice, the audit documentation package that a sovereign hosting provider must submit includes the full technical specification of its infrastructure against CADA Annex II controls, legal opinions on the jurisdiction of all operating entities in its corporate structure, a third-party audit report from an accredited conformity assessment body for level 3 and above, a data flow map covering all subprocessors, and evidence of incident response capability meeting the NIS-2 Directive thresholds. The NCA has a defined review window, after which it either issues recognition or issues a reasoned rejection that the provider can contest.

The mutual recognition mechanism means that a provider recognised at level 3 by, for example, the French ANSSI or the German BSI does not need to repeat the full assessment in every member state where it bids. This is significant for cross-border procurement frameworks such as the EU Cloud III Dynamic Purchasing System, which already operates across multiple member states and will likely require CADA level recognition as a qualification criterion once the regulation enters into force.

See how Qsentinel solves this in practice.Start a 10-user pilot →

Article 18: The Third-Country Provider Problem

Article 18 creates a narrow pathway for third-country providers to qualify at level 3, but the conditions are structurally onerous for US-headquartered entities. The provider must demonstrate through legally binding and independently audited structural measures that no foreign law, including the US CLOUD Act, FISA 702, or any analogous instrument, grants a third country’s authorities effective access to EU-resident data.

“A cloud certification that does not address the legal jurisdiction of the provider’s parent company leaves a structural gap that technical controls alone cannot close.” (European Data Protection Supervisor, Opinion 22/2022)

The residual legal exposure for EU organisations that continue using recognised US-headquartered providers, even if those providers achieve level 3 recognition under Article 18, is that the recognition is conditional on the continued validity of the structural measures. If a US court issues a production order that a provider complies with, the recognition lapses and any public-sector contract relying on that recognition becomes non-compliant. Procurement officers should build contractual audit rights and lapse-notification obligations into any contract with an Article 18-recognised provider.

Provider type Maximum achievable CADA level Key limiting factor
EU/EEA incorporated, no non-EU parent Level 4 (subject to technical audit) None structural; depends on Annex II compliance
US-headquartered (CLOUD Act / FISA 702 exposure) Level 2 in practice; level 3 via Art. 18 only with structural separation Foreign jurisdiction access obligation
Swiss-hosted, no EU/EEA incorporation Not directly recognised; alignment via Annex II gap analysis Outside EU regulatory perimeter

Article 19 Self-Assessment: When Is It Legally Sufficient?

Self-assessment under Article 19 is permitted at level 1 for all providers and at level 2 for low-risk use cases where the data involved is not subject to sector-specific regulation under DORA, NIS-2, or the AI Act. For level 3 and level 4, the proposed regulation explicitly requires a conformity assessment conducted by an accredited third-party audit body, and self-assessment cannot substitute for this requirement.

The practical implication for procurement officers is that a provider offering only a self-assessment certificate for a level 3 procurement requirement must be disqualified, regardless of the technical quality of that self-assessment. The SEAL framework, which has been developed as a voluntary sovereignty label by several European cloud associations, uses a structured self-assessment methodology that maps to CADA Annex II criteria. This can be a useful pre-screening tool, but it does not replace the mandatory third-party audit for level 3 compliance purposes.

Let op: Self-assessment documentation produced for Article 19 purposes must be retained and made available to the NCA on request. A declaration that cannot be substantiated with underlying evidence exposes both the provider and the procuring organisation to regulatory liability.

CADA Assurance Levels and the EUCS Tier Framework: Using Both in Parallel

The European Union Cybersecurity Certification Scheme for Cloud Services (EUCS), developed by ENISA under the Cybersecurity Act, operates on three tiers: Basic, Substantial, and High. These tiers address technical security controls, vulnerability management, and incident handling. CADA assurance levels address those same technical dimensions at levels 1 through 3, but add explicit sovereignty criteria, including operational independence and third-country jurisdiction immunity, that the EUCS framework does not fully resolve even at the High tier.

“Cloud services used by public administrations must meet sovereignty requirements that go beyond traditional cybersecurity certification; data localisation, operational control and immunity from third-country law are distinct and cumulative conditions.” (ENISA, EUCS Scheme Documentation)

During the legislative transition period, before CADA formal recognition is operational in all member states, CISOs and procurement officers should treat EUCS High certification as a necessary but not sufficient condition for sensitive workloads. A provider holding EUCS High certification but not meeting CADA Annex II sovereignty criteria should be used only for non-sensitive data until full CADA recognition is in place. Where both frameworks operate simultaneously, the more restrictive requirement governs.

It is also worth noting that approximately 65 percent of European public cloud infrastructure revenue is controlled by AWS, Microsoft Azure, and Google Cloud combined (ENISA, 2023), which means that the transition to CADA-compliant alternatives requires active investment in European sovereign providers, not merely a relabelling exercise.

Swiss-Hosted Providers and CADA Level Compliance: The Positioning Challenge

Switzerland is not an EU or EEA member state, which means Swiss-incorporated providers fall outside the CADA regulatory perimeter and cannot obtain NCA recognition directly. This creates a structural challenge when bidding into EU public-sector contracts that mandate a minimum CADA level.

The most viable positioning strategy combines four elements. First, the provider should commission a documented gap analysis against CADA Annex II controls, conducted by an EU-accredited conformity assessment body, and make that analysis available to procuring authorities. Second, it should demonstrate alignment with the revised Swiss Federal Act on Data Protection (revFADP), which came into full effect in September 2023 and provides data protection guarantees broadly equivalent to GDPR, including restrictions on data transfers to third countries without adequate safeguards. Third, it should provide legal opinions confirming that no Swiss law, and no applicable foreign law through Swiss entities, grants third-country authorities access to EU-resident data hosted in Swiss facilities. Fourth, it should seek contractual incorporation into a recognised EU-established operator’s service delivery chain, where that operator holds formal CADA recognition, effectively converting the Swiss provider into a subprocessor covered by the EU operator’s recognition.

The average total cost of a data breach reached USD 4.45 million in 2023, the highest in the 18-year history of the IBM/Ponemon study (IBM Cost of a Data Breach Report 2023), which contextualises why procurement officers cannot treat sovereignty assurance as an administrative formality. And with more than half of NIS-2 obligated EU organisations having not completed a formal gap assessment by the October 2024 transposition deadline (ENISA NIS Investments 2023), the combination of CADA level requirements and NIS-2 obligations is arriving faster than many compliance teams have prepared for.

FAQ

Which CADA assurance level is the minimum for regulated public-sector procurement?

Under the proposed CADA public-administration procurement framework, Union assurance level 2 is the minimum floor for general public-sector buyers. Entities handling classified or highly sensitive data, including those subject to DORA or sector-specific security obligations, are expected to require level 3 as a baseline, with level 4 reserved for classified government systems.

Can a US-headquartered cloud provider ever reach CADA level 3?

Article 18 allows a third-country provider to qualify at level 3 only if it can demonstrate through legally binding and independently audited structural measures that no foreign law grants that country’s authorities effective access to EU-hosted data. Given the CLOUD Act’s mandatory production order mechanism and FISA 702’s extraterritorial reach, achieving this in practice is structurally very difficult for any provider whose parent company is incorporated in the United States without a legally robust and operationally separate EU entity that has severed all meaningful control links to the US parent.

Is Article 19 self-assessment sufficient for a public procurement decision?

Self-assessment under Article 19 is legally sufficient only at level 1 and, for demonstrably low-risk use cases, at level 2. For level 3 and level 4, the proposed regulation requires a conformity assessment by an accredited third-party audit body, and procurement officers must obtain and retain that audit documentation as part of the contract file. A self-assessment declaration at those levels does not satisfy the legal requirement.

How do CADA assurance levels relate to EUCS tiers?

EUCS tiers (Basic, Substantial, High) map roughly onto CADA levels 1 through 3 for technical security controls, but CADA adds explicit sovereignty criteria that EUCS does not fully address at any tier. During the legislative transition, organisations should require both an EUCS High certificate and CADA level 3 recognition (or an equivalent Annex II-aligned demonstration) for sensitive workloads, treating the more restrictive requirement as the effective compliance benchmark.

How should a Swiss-hosted provider position itself for EU contracts requiring minimum CADA level compliance?

A Swiss provider should commission a gap analysis against CADA Annex II conducted by an EU-accredited body, demonstrate revFADP compliance as an equivalent data protection baseline, provide legal opinions confirming no third-country law grants access to EU-resident data, and consider structuring delivery through a CADA-recognised EU operator where the Swiss entity acts as a vetted subprocessor. This combination will not produce formal CADA recognition, but it provides the documented sovereignty assurance that a procurement officer can evaluate against the level 2 or level 3 criteria.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Which CADA assurance level is the minimum for regulated public-sector procurement?
Under the proposed CADA public-administration procurement framework, Union assurance level 2 is the minimum floor for general public-sector buyers, while entities handling classified or highly sensitive data are expected to require level 3 or level 4.
Can a US-headquartered cloud provider ever reach CADA level 3?
Article 18 allows a third-country provider to qualify at level 3 only if it can demonstrate, through legally binding and independently audited structural measures, that no foreign law grants that third country's authorities effective access to EU-hosted data. Given the CLOUD Act and FISA 702, this is structurally very difficult for any provider whose parent company is incorporated in the United States.
Is Article 19 self-assessment sufficient for a public procurement decision?
Self-assessment under Article 19 is legally sufficient only at level 1 and, for low-risk use cases, level 2. For level 3 and level 4, the proposed regulation requires a conformity assessment by an accredited third-party audit body, and procurement officers must obtain and retain that audit documentation.
How do CADA assurance levels relate to the EUCS tiers?
EUCS tiers (Basic, Substantial, High) map roughly onto CADA levels 1 through 3 for technical security controls, but CADA adds explicit sovereignty criteria, including data localisation, operational independence, and third-country jurisdiction immunity, that EUCS does not fully address at any tier. During the legislative transition, organisations should require both an EUCS High certificate and CADA level 3 recognition for sensitive workloads.
How should a Swiss-hosted provider position itself for EU public-sector contracts requiring minimum CADA level compliance?
A Swiss provider falls outside the EU regulatory perimeter and cannot obtain CADA recognition directly through an EU national competent authority. It can, however, contract with an EU-recognised conformity assessment body, demonstrate alignment with CADA Annex II technical and legal criteria, and operate under the revised Swiss Federal Act on Data Protection (revFADP), which provides equivalent data protection guarantees. Procurement officers should request a gap analysis against CADA Annex II and confirm that no Swiss or foreign law grants third-country authorities access to the hosted data.