Updated juli 24, 2026
Summary: COM(2026) 502 creates the EU's first binding sovereign cloud framework, linking CADA assurance levels, EUCS certification and CSA2 into a single compliance stack. Regulated buyers should begin aligning procurement criteria now, and Swiss FADP hosting satisfies several but not all of the proposal's operational sovereignty requirements.

COM(2026) 502, the Commission’s June 2026 Proposal for a Sovereign Cloud Regulation, is the EU’s first attempt to codify sovereign cloud computing as a binding legal concept rather than a procurement preference. It defines operational sovereignty as the condition under which a cloud provider processes and stores data exclusively under EU legal governance, such that no foreign authority can compel disclosure without going through EU or member-state judicial channels. For government bodies and regulated sectors comparing sovereign alternatives to US-controlled cloud platforms, the proposal fundamentally changes what due diligence must look like.

What COM(2026) 502 Actually Introduces

The proposal creates a tiered framework that distinguishes between providers offering cloud services to third parties and organisations running dedicated infrastructure for their own use. On-premises deployments that serve only the deploying organisation’s own workloads fall outside the provider-side obligations entirely. The binding provisions apply to cloud service providers, not to self-hosted infrastructure.

For providers that do offer services to others, COM(2026) 502 introduces a formal “Sovereign Cloud Service” designation. To carry that designation, a provider must demonstrate that all processing occurs in jurisdictions whose legal systems do not expose stored data to unilateral foreign-government access, that its ownership and control structure is free from non-EU governing-law obligations, and that it holds or is pursuing certification under the EUCS scheme at the High or Sovereign assurance level.

Key point: The designation is voluntary for providers but becomes effectively mandatory for regulated buyers in sensitive-workload tenders, because COM(2026) 502 introduces complementary procurement criteria that direct contracting authorities to favour certified sovereign providers. Organisations that do not plan ahead risk being unable to demonstrate compliance when those criteria become standard in public tenders.

The EU-US Data Privacy Framework Does Not Close the Sovereignty Gap

COM(2026) 502 explicitly addresses the EU-US Data Privacy Framework and reaches a conclusion that compliance officers should treat as settled. The DPF resolves the question of lawful commercial data transfers under GDPR Article 46 by providing an adequacy basis for US-based recipients listed on the DPF register. What it does not do is restrict or condition US intelligence collection under FISA 702 or Executive Order 12333.

As the European Data Protection Supervisor has stated: “Sovereignty is not just about where data sits. It is about who can compel access to it, under which legal order, and whether the operator can resist that compulsion.” FISA 702 authorises the collection of communications of non-US persons transiting US-controlled infrastructure without an individualised warrant directed at a specific suspect. A provider can be DPF-listed, can sign standard contractual clauses under GDPR Article 46(2)(c), and can still be legally compelled to provide bulk communications data to US signals intelligence agencies. COM(2026) 502 treats the DPF as a necessary but insufficient condition: lawful transfer does not equal operational sovereignty.

Max Schrems, chairman of noyb, put the structural problem clearly in his 2023 analysis: “The Data Privacy Framework reduces but does not eliminate the risk of US intelligence access. FISA 702 collection does not require individualised court orders and remains a structural exposure for any data touching US-controlled infrastructure.” The proposal’s recitals cite this distinction as a core justification for the new framework.

See how Qsentinel solves this in practice.Start a 10-user pilot →

The Integrated Compliance Stack: CADA, EUCS and CSA2

COM(2026) 502 does not operate in isolation. It is designed to interlock with three parallel instruments to form what the Commission’s explanatory memorandum describes as an “integrated sovereign cloud compliance stack.”

Instrument Role in the stack Interaction with COM(2026) 502
CADA (Cloud and AI Development Act) Defines sovereignty assurance levels for cloud and AI services COM(2026) 502 adopts CADA assurance levels as the baseline for the Sovereign Cloud Service designation
EUCS (EU Cybersecurity Certification Scheme for Cloud Services) Provides technical certification at Basic, Substantial and High levels; draft High level includes sovereignty criteria EUCS High or Sovereign certification is a prerequisite for the COM(2026) 502 designation
CSA2 (revised Cybersecurity Act) Strengthens ENISA’s mandate and introduces mandatory certification for critical infrastructure sectors COM(2026) 502 relies on CSA2’s mandatory certification powers to make EUCS requirements binding for providers serving regulated sectors

For a CISO evaluating a cloud contract today, this stack means that a provider’s claim to be “sovereignty-aligned” should be assessed against all three instruments simultaneously. A provider holding only a Basic EUCS certificate and no CADA assurance mapping does not satisfy the COM(2026) 502 framework, regardless of what its marketing materials say.

Swiss Hosting Under the Revised FADP: Where It Fits and Where It Falls Short

Switzerland holds an adequacy decision from the European Commission for GDPR purposes, which means that data transfers to Swiss-hosted infrastructure satisfy the GDPR Article 46 requirement without needing standard contractual clauses. The revised Swiss Federal Act on Data Protection (nDSG, in force since September 2023) aligns Swiss data protection obligations closely with GDPR on data subject rights, privacy by design, and breach notification timelines.

This places Swiss-hosted infrastructure in a strong position on several COM(2026) 502 criteria: the hosting jurisdiction is adequacy-recognised, the legal framework governing data subject rights is materially equivalent to GDPR, and Swiss law does not contain provisions comparable to the US CLOUD Act or FISA 702 that would compel Swiss-domiciled operators to hand data to foreign intelligence services outside Swiss legal process.

Important distinction: Swiss hosting satisfies the jurisdiction and legal-framework criteria of COM(2026) 502, but it does not automatically satisfy the EUCS certification requirement. A Swiss provider wishing to carry the Sovereign Cloud Service designation must separately obtain EUCS certification, which is an EU scheme administered by ENISA. Swiss providers can pursue EUCS certification, but it is a distinct compliance step that on-premises or Swiss-hosted deployments cannot shortcut.

For self-hosted on-premises infrastructure, neither the provider-side designation requirements nor the EUCS obligation applies directly. An organisation running its own servers in a Swiss data centre, governed by the revised FADP and Swiss contract law, sits outside the proposal’s provider perimeter. Its obligation is on the buyer side: when it procures cloud services from third parties, it must apply the new procurement criteria.

Provider Audit Obligations and Self-Assessment Under COM(2026) 502

Providers seeking the Sovereign Cloud Service designation face a two-stage compliance process under the proposal. In the first stage, they submit a structured self-assessment covering ownership and control structure, data residency guarantees, access-request procedures, and a mapping to the applicable CADA assurance level. In the second stage, an accredited conformity assessment body reviews the self-assessment and conducts an independent audit before the designation is granted.

The self-assessment template mirrors the technical specifications already developed under EUCS, which means providers that have already gone through EUCS certification at the High level can present that certificate as partial evidence. However, COM(2026) 502 adds sovereign-specific questions that EUCS High does not currently cover, in particular: documentation of all sub-processors and their governing jurisdictions, a legal opinion confirming that no extraterritorial statute grants a foreign government unilateral access rights, and an incident-response plan describing how the provider would respond to a foreign-government access demand. These requirements are substantive rather than administrative and will require legal review in addition to technical audit.

Procurement Criteria and How Regulated Buyers Should Use Them Now

COM(2026) 502 introduces sovereignty-weighted award criteria that complement but do not replace the most-economically-advantageous-tender framework under Directives 2014/24/EU and 2014/25/EU. Contracting authorities in regulated sectors can assign additional score weighting to providers that hold EUCS High or Sovereign certification, process data exclusively in adequacy-recognised jurisdictions, and submit a legal opinion confirming absence of extraterritorial access obligations.

Regulated buyers should not wait for formal adoption to begin using this logic. IBM’s 2024 Cost of a Data Breach Report recorded the average breach cost at USD 4.88 million per incident, and ENISA’s Threat Landscape 2023 found that 19 percent of all recorded ransomware incidents targeted EU public-sector organisations. Meanwhile, cumulative GDPR fines across the EU and EEA exceeded EUR 4.5 billion by end of 2023, according to the GDPR Enforcement Tracker maintained by CMS Law. These figures give compliance officers and procurement teams a concrete cost basis for justifying sovereignty criteria as proportionate requirements rather than optional preferences.

Practically, regulated buyers should take four interim actions before COM(2026) 502 is adopted. First, audit existing cloud contracts for CLOUD Act and FISA 702 exposure clauses and document the findings as part of the organisation’s DORA and NIS-2 risk register. Second, include EUCS-alignment and data-residency requirements in all new tender specifications as non-mandatory but scored criteria. Third, request that existing cloud providers supply a legal opinion on extraterritorial access exposure as part of the next contract renewal. Fourth, document the sovereignty risk assessment process so that it is available as evidence when NIS-2 supervisory audits or DORA ICT third-party risk reviews occur, even before COM(2026) 502 is formally in force.

Legislative Timeline and What Comes Next

As a Commission proposal published in June 2026, COM(2026) 502 enters the ordinary legislative procedure requiring co-decision by the European Parliament and the Council of the EU. Given the political salience of digital sovereignty, the proposal is likely to receive expedited treatment, but realistic adoption is not expected before 2028, with an 18- to 24-month transition period thereafter. National competent authorities designated under NIS-2 and sectoral supervisors under DORA are expected to begin referencing the proposal’s criteria in their guidance before formal adoption, as has occurred with other major digital-regulation proposals during their legislative passage.

For CISOs and data protection officers in public administration, finance and healthcare, the practical horizon is therefore 2030 for full formal compliance, but the reputational and procurement risk of non-alignment begins now. Organisations that have mapped their cloud supply chain against CADA assurance levels and begun EUCS certification conversations with their providers will be in a demonstrably better position during supervisory reviews in the interim period.

FAQ

Does COM(2026) 502 apply to an organisation that hosts its own servers on-premises and does not sell cloud services to others?

No. The proposed regulation targets providers that offer cloud computing services to third parties. An organisation running dedicated on-premises infrastructure solely for its own workloads falls outside the provider-side obligations. When that organisation procures cloud services from third parties, however, the buyer-side procurement criteria in the proposal do apply to its purchasing decisions.

Does Swiss hosting under the revised FADP satisfy the sovereignty requirements in COM(2026) 502?

Partially. Switzerland’s adequacy status satisfies data-transfer legality under GDPR Article 46, and the revised FADP (nDSG) aligns closely with GDPR on data subject rights and security obligations. Swiss law does not contain provisions comparable to FISA 702 or the CLOUD Act. However, COM(2026) 502 also requires EUCS certification at the High or Sovereign level, which is an EU scheme administered by ENISA. A Swiss provider can obtain that certification, but it must do so separately: adequacy status alone does not substitute for EUCS.

Why does COM(2026) 502 conclude that the EU-US Data Privacy Framework does not resolve operational sovereignty concerns?

The DPF addresses commercial data transfers and provides a redress mechanism for EU individuals whose data is processed by listed US companies. It does not restrict or condition US intelligence collection under FISA 702, which permits bulk acquisition of communications transiting US-controlled infrastructure without an individualised warrant. COM(2026) 502 distinguishes between lawful transfer adequacy and operational sovereignty, which requires that no foreign authority can compel the provider to disclose data without going through EU or member-state legal channels.

What procurement criteria does COM(2026) 502 add on top of the existing Public Procurement Directives?

The proposal introduces sovereignty-weighted award criteria allowing contracting authorities to assign additional score to providers holding EUCS High or Sovereign certification, processing and storing data exclusively in adequacy-recognised jurisdictions, and demonstrating through a legal opinion that no extraterritorial law grants a foreign government unilateral access to contract data. These criteria work alongside the existing most-economically-advantageous-tender framework, not as a replacement for it.

What should regulated buyers do before COM(2026) 502 is formally adopted?

Four practical steps apply now: audit existing cloud contracts for CLOUD Act and FISA 702 exposure; include EUCS-alignment and data-residency requirements as scored criteria in new tenders; request legal opinions on extraterritorial access from providers at the next contract renewal; and document sovereignty risk assessments for use as evidence in NIS-2 and DORA supervisory reviews. These actions demonstrate good-faith alignment with the regulation’s direction and reduce exposure in the period before formal adoption.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Does COM(2026) 502 apply to an organisation that hosts its own servers on-premises and does not sell cloud services to others?
No. The proposed regulation targets providers that offer cloud computing services to third parties. An organisation running dedicated on-premises infrastructure solely for its own workloads falls outside the provider-side obligations. However, if that organisation procures cloud services from a provider, the buyer-side provisions, including the new procurement criteria, apply to its purchasing decisions.
Does Swiss hosting under the revised FADP satisfy the sovereignty requirements in COM(2026) 502?
Partially. Switzerland is recognised under GDPR as an adequate jurisdiction, which satisfies data-transfer legality. The revised FADP (nDSG) aligns closely with GDPR on data subject rights and security obligations. However, COM(2026) 502 introduces specific operational sovereignty criteria, including EU-law-governed access procedures and EUCS certification at the High or Sovereign level, which Swiss-based providers must separately demonstrate. A Swiss provider can meet these requirements but must obtain relevant EUCS certification and contractually exclude foreign-jurisdiction access.
Why does COM(2026) 502 conclude that the EU-US Data Privacy Framework does not resolve operational sovereignty concerns?
The DPF addresses commercial data transfers and provides a redress mechanism for EU individuals. It does not limit or condition US intelligence collection under FISA 702, which permits bulk acquisition of communications transiting US-controlled infrastructure without an individualised warrant. COM(2026) 502 distinguishes between lawful transfer adequacy under GDPR Article 46 and operational sovereignty, which requires that no foreign authority can compel the provider to disclose data without going through EU or member-state legal channels.
What procurement criteria does COM(2026) 502 add on top of the existing Public Procurement Directives 2014/24/EU and 2014/25/EU?
The proposal introduces sovereignty-weighted award criteria that allow contracting authorities to assign additional score to providers that hold EUCS certification at the High or Sovereign level, process and store data exclusively in EU or adequacy-recognised jurisdictions, and can demonstrate that no extraterritorial law grants a foreign government unilateral access to contract data. These criteria operate alongside, not instead of, the existing most-economically-advantageous-tender (MEAT) framework.
What is the expected legislative timeline for COM(2026) 502 and what should regulated buyers do before it is adopted?
As a Commission proposal published in June 2026, COM(2026) 502 must pass through the ordinary legislative procedure involving the European Parliament and the Council. Adoption is realistically expected no earlier than 2028, with a transition period thereafter. In the interim, regulated buyers should include EUCS-alignment and sovereignty clauses in tender specifications now, map existing cloud contracts for CLOUD Act and FISA 702 exposure, and document their sovereignty risk assessments to demonstrate good-faith alignment with the proposal's direction when NIS-2 and DORA audits occur.