COM(2026) 502, the Commission’s June 2026 Proposal for a Sovereign Cloud Regulation, is the EU’s first attempt to codify sovereign cloud computing as a binding legal concept rather than a procurement preference. It defines operational sovereignty as the condition under which a cloud provider processes and stores data exclusively under EU legal governance, such that no foreign authority can compel disclosure without going through EU or member-state judicial channels. For government bodies and regulated sectors comparing sovereign alternatives to US-controlled cloud platforms, the proposal fundamentally changes what due diligence must look like.
What COM(2026) 502 Actually Introduces
The proposal creates a tiered framework that distinguishes between providers offering cloud services to third parties and organisations running dedicated infrastructure for their own use. On-premises deployments that serve only the deploying organisation’s own workloads fall outside the provider-side obligations entirely. The binding provisions apply to cloud service providers, not to self-hosted infrastructure.
For providers that do offer services to others, COM(2026) 502 introduces a formal “Sovereign Cloud Service” designation. To carry that designation, a provider must demonstrate that all processing occurs in jurisdictions whose legal systems do not expose stored data to unilateral foreign-government access, that its ownership and control structure is free from non-EU governing-law obligations, and that it holds or is pursuing certification under the EUCS scheme at the High or Sovereign assurance level.
The EU-US Data Privacy Framework Does Not Close the Sovereignty Gap
COM(2026) 502 explicitly addresses the EU-US Data Privacy Framework and reaches a conclusion that compliance officers should treat as settled. The DPF resolves the question of lawful commercial data transfers under GDPR Article 46 by providing an adequacy basis for US-based recipients listed on the DPF register. What it does not do is restrict or condition US intelligence collection under FISA 702 or Executive Order 12333.
As the European Data Protection Supervisor has stated: “Sovereignty is not just about where data sits. It is about who can compel access to it, under which legal order, and whether the operator can resist that compulsion.” FISA 702 authorises the collection of communications of non-US persons transiting US-controlled infrastructure without an individualised warrant directed at a specific suspect. A provider can be DPF-listed, can sign standard contractual clauses under GDPR Article 46(2)(c), and can still be legally compelled to provide bulk communications data to US signals intelligence agencies. COM(2026) 502 treats the DPF as a necessary but insufficient condition: lawful transfer does not equal operational sovereignty.
Max Schrems, chairman of noyb, put the structural problem clearly in his 2023 analysis: “The Data Privacy Framework reduces but does not eliminate the risk of US intelligence access. FISA 702 collection does not require individualised court orders and remains a structural exposure for any data touching US-controlled infrastructure.” The proposal’s recitals cite this distinction as a core justification for the new framework.
The Integrated Compliance Stack: CADA, EUCS and CSA2
COM(2026) 502 does not operate in isolation. It is designed to interlock with three parallel instruments to form what the Commission’s explanatory memorandum describes as an “integrated sovereign cloud compliance stack.”
| Instrument | Role in the stack | Interaction with COM(2026) 502 |
|---|---|---|
| CADA (Cloud and AI Development Act) | Defines sovereignty assurance levels for cloud and AI services | COM(2026) 502 adopts CADA assurance levels as the baseline for the Sovereign Cloud Service designation |
| EUCS (EU Cybersecurity Certification Scheme for Cloud Services) | Provides technical certification at Basic, Substantial and High levels; draft High level includes sovereignty criteria | EUCS High or Sovereign certification is a prerequisite for the COM(2026) 502 designation |
| CSA2 (revised Cybersecurity Act) | Strengthens ENISA’s mandate and introduces mandatory certification for critical infrastructure sectors | COM(2026) 502 relies on CSA2’s mandatory certification powers to make EUCS requirements binding for providers serving regulated sectors |
For a CISO evaluating a cloud contract today, this stack means that a provider’s claim to be “sovereignty-aligned” should be assessed against all three instruments simultaneously. A provider holding only a Basic EUCS certificate and no CADA assurance mapping does not satisfy the COM(2026) 502 framework, regardless of what its marketing materials say.
Swiss Hosting Under the Revised FADP: Where It Fits and Where It Falls Short
Switzerland holds an adequacy decision from the European Commission for GDPR purposes, which means that data transfers to Swiss-hosted infrastructure satisfy the GDPR Article 46 requirement without needing standard contractual clauses. The revised Swiss Federal Act on Data Protection (nDSG, in force since September 2023) aligns Swiss data protection obligations closely with GDPR on data subject rights, privacy by design, and breach notification timelines.
This places Swiss-hosted infrastructure in a strong position on several COM(2026) 502 criteria: the hosting jurisdiction is adequacy-recognised, the legal framework governing data subject rights is materially equivalent to GDPR, and Swiss law does not contain provisions comparable to the US CLOUD Act or FISA 702 that would compel Swiss-domiciled operators to hand data to foreign intelligence services outside Swiss legal process.
For self-hosted on-premises infrastructure, neither the provider-side designation requirements nor the EUCS obligation applies directly. An organisation running its own servers in a Swiss data centre, governed by the revised FADP and Swiss contract law, sits outside the proposal’s provider perimeter. Its obligation is on the buyer side: when it procures cloud services from third parties, it must apply the new procurement criteria.
Provider Audit Obligations and Self-Assessment Under COM(2026) 502
Providers seeking the Sovereign Cloud Service designation face a two-stage compliance process under the proposal. In the first stage, they submit a structured self-assessment covering ownership and control structure, data residency guarantees, access-request procedures, and a mapping to the applicable CADA assurance level. In the second stage, an accredited conformity assessment body reviews the self-assessment and conducts an independent audit before the designation is granted.
The self-assessment template mirrors the technical specifications already developed under EUCS, which means providers that have already gone through EUCS certification at the High level can present that certificate as partial evidence. However, COM(2026) 502 adds sovereign-specific questions that EUCS High does not currently cover, in particular: documentation of all sub-processors and their governing jurisdictions, a legal opinion confirming that no extraterritorial statute grants a foreign government unilateral access rights, and an incident-response plan describing how the provider would respond to a foreign-government access demand. These requirements are substantive rather than administrative and will require legal review in addition to technical audit.
Procurement Criteria and How Regulated Buyers Should Use Them Now
COM(2026) 502 introduces sovereignty-weighted award criteria that complement but do not replace the most-economically-advantageous-tender framework under Directives 2014/24/EU and 2014/25/EU. Contracting authorities in regulated sectors can assign additional score weighting to providers that hold EUCS High or Sovereign certification, process data exclusively in adequacy-recognised jurisdictions, and submit a legal opinion confirming absence of extraterritorial access obligations.
Regulated buyers should not wait for formal adoption to begin using this logic. IBM’s 2024 Cost of a Data Breach Report recorded the average breach cost at USD 4.88 million per incident, and ENISA’s Threat Landscape 2023 found that 19 percent of all recorded ransomware incidents targeted EU public-sector organisations. Meanwhile, cumulative GDPR fines across the EU and EEA exceeded EUR 4.5 billion by end of 2023, according to the GDPR Enforcement Tracker maintained by CMS Law. These figures give compliance officers and procurement teams a concrete cost basis for justifying sovereignty criteria as proportionate requirements rather than optional preferences.
Practically, regulated buyers should take four interim actions before COM(2026) 502 is adopted. First, audit existing cloud contracts for CLOUD Act and FISA 702 exposure clauses and document the findings as part of the organisation’s DORA and NIS-2 risk register. Second, include EUCS-alignment and data-residency requirements in all new tender specifications as non-mandatory but scored criteria. Third, request that existing cloud providers supply a legal opinion on extraterritorial access exposure as part of the next contract renewal. Fourth, document the sovereignty risk assessment process so that it is available as evidence when NIS-2 supervisory audits or DORA ICT third-party risk reviews occur, even before COM(2026) 502 is formally in force.
Legislative Timeline and What Comes Next
As a Commission proposal published in June 2026, COM(2026) 502 enters the ordinary legislative procedure requiring co-decision by the European Parliament and the Council of the EU. Given the political salience of digital sovereignty, the proposal is likely to receive expedited treatment, but realistic adoption is not expected before 2028, with an 18- to 24-month transition period thereafter. National competent authorities designated under NIS-2 and sectoral supervisors under DORA are expected to begin referencing the proposal’s criteria in their guidance before formal adoption, as has occurred with other major digital-regulation proposals during their legislative passage.
For CISOs and data protection officers in public administration, finance and healthcare, the practical horizon is therefore 2030 for full formal compliance, but the reputational and procurement risk of non-alignment begins now. Organisations that have mapped their cloud supply chain against CADA assurance levels and begun EUCS certification conversations with their providers will be in a demonstrably better position during supervisory reviews in the interim period.
FAQ
Does COM(2026) 502 apply to an organisation that hosts its own servers on-premises and does not sell cloud services to others?
No. The proposed regulation targets providers that offer cloud computing services to third parties. An organisation running dedicated on-premises infrastructure solely for its own workloads falls outside the provider-side obligations. When that organisation procures cloud services from third parties, however, the buyer-side procurement criteria in the proposal do apply to its purchasing decisions.
Does Swiss hosting under the revised FADP satisfy the sovereignty requirements in COM(2026) 502?
Partially. Switzerland’s adequacy status satisfies data-transfer legality under GDPR Article 46, and the revised FADP (nDSG) aligns closely with GDPR on data subject rights and security obligations. Swiss law does not contain provisions comparable to FISA 702 or the CLOUD Act. However, COM(2026) 502 also requires EUCS certification at the High or Sovereign level, which is an EU scheme administered by ENISA. A Swiss provider can obtain that certification, but it must do so separately: adequacy status alone does not substitute for EUCS.
Why does COM(2026) 502 conclude that the EU-US Data Privacy Framework does not resolve operational sovereignty concerns?
The DPF addresses commercial data transfers and provides a redress mechanism for EU individuals whose data is processed by listed US companies. It does not restrict or condition US intelligence collection under FISA 702, which permits bulk acquisition of communications transiting US-controlled infrastructure without an individualised warrant. COM(2026) 502 distinguishes between lawful transfer adequacy and operational sovereignty, which requires that no foreign authority can compel the provider to disclose data without going through EU or member-state legal channels.
What procurement criteria does COM(2026) 502 add on top of the existing Public Procurement Directives?
The proposal introduces sovereignty-weighted award criteria allowing contracting authorities to assign additional score to providers holding EUCS High or Sovereign certification, processing and storing data exclusively in adequacy-recognised jurisdictions, and demonstrating through a legal opinion that no extraterritorial law grants a foreign government unilateral access to contract data. These criteria work alongside the existing most-economically-advantageous-tender framework, not as a replacement for it.
What should regulated buyers do before COM(2026) 502 is formally adopted?
Four practical steps apply now: audit existing cloud contracts for CLOUD Act and FISA 702 exposure; include EUCS-alignment and data-residency requirements as scored criteria in new tenders; request legal opinions on extraterritorial access from providers at the next contract renewal; and document sovereignty risk assessments for use as evidence in NIS-2 and DORA supervisory reviews. These actions demonstrate good-faith alignment with the regulation’s direction and reduce exposure in the period before formal adoption.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
