Chapter 15 of 17
Assurance Levels 1 and 2: The Baseline Sovereignty Tests
Annex II makes the abstract assurance framework operational through cumulative legal, technical, and organizational criteria. Levels 1 and 2 establish the baseline tests for Union establishment, data location, cybersecurity, operational autonomy, foreign influence, and software integrity.
Annex II: Scope, Structure, and Status
Four assurance levels
Annex II establishes criteria for cloud services seeking recognition at Union assurance levels 1, 2, 3, and 4. This lesson focuses on the first two levels.
Cumulative means all
Each listed criterion is cumulative. A provider cannot compensate for a missing location, data, governance, or cybersecurity condition by performing well on another condition.
Software, not hardware
The Annex includes software within scope but expressly excludes hardware by reference to Regulation (EU) 2024/2847, Article 3, point (5).
Current status
On 20 July 2026, this text is part of a Commission proposal dated 3 June 2026, rather than a final Regulation in force.
Level 1: Union Establishment, Assets, and Data
1.1(a): Establishment
Level 1 requires the cloud computing service provider to be established in the Union. This is a requirement about the provider itself.
1.1(b): Infrastructure and assets
Infrastructure and assets of both the provider and involved subcontractors must be in the Union, unless the public sector body explicitly requires otherwise.
1.1(c): Broad data coverage
Customer data includes metadata and telemetry data. The rule covers processing, storage, and transfer by the provider and relevant subcontractors.
Timing matters
The Union-only data condition applies before, during, and after configuration or use. It is not limited to the period when a customer is actively using the service.
Level 1: Support, Subcontractors, Cybersecurity, and Foreign Control
Outsourced support
Level 1 does not categorically forbid support outside the Union. Instead, it requires traceability, security, governance, and protection of the provider's operational autonomy.
Cybersecurity and oversight
The provider must demonstrate state-of-the-art cybersecurity and must make subcontractor use transparent through due diligence, contracts, and ongoing oversight.
Foreign-control safeguard
A provider under third-country control must use independent sources to demonstrate that vulnerability-reporting laws or practices do not create the specified pre-exploitation reporting duty.
Which subcontractors count?
Section 1.2 covers third-party subcontractors with a direct contract with the provider that contribute to provision and delivery of the cloud computing service.
Level 1 Decision Check
Apply the Level 1 test
A provider is established in the Union. Its customer files are stored in the Union, but its telemetry data is sent to a non-Union analytics environment during service configuration. The public sector body has not explicitly required this transfer.
Your task
Decide whether the arrangement satisfies 1.1(c). Then identify the two details that control your answer.
- Does the Annex treat telemetry as customer data?
- Does the data-location rule apply during configuration?
Suggested answer
It does not satisfy 1.1(c). Telemetry data is expressly included, and the requirement applies before, during, and after configuration or use. The stated exception requires the public sector body to explicitly require otherwise.
Level 2: A More Constrained Union Operating Model
Level 2 terminology
Level 2 speaks of an audited provider and an audited service. It requires Union establishment for both the provider and subcontractors involved in the audited service.
Personnel are added
Level 2 expressly places infrastructure, assets, and personnel in the Union. It also addresses additional screening and Union-citizenship requirements when the public sector body determines they are necessary.
Certification sequence
Use an available European cloud certificate at least at substantial assurance. Until such a scheme exists, use national schemes where available; otherwise demonstrate the highest applicable Union-law standards.
Generated data
Data generated by the audited service cannot train or fine-tune a third-country-operated AI system or one operated by a legal entity established in a third country. It also cannot leave the Union.
Level 2: Foreign Control and Support Operations
Control is not automatically decisive
Level 2 addresses third-country control through required safeguards. The provider must demonstrate measures that prevent control from restricting service delivery or necessary resources.
Protect data and continuity
The measures must prevent third-country access to customer data and prevent disruption of service continuity or degradation of service quality.
Restrictive measures
Third-country control must not force compliance with foreign sanctions, embargoes, or equivalent measures, unless those measures are legitimate under Member State national law or Union law.
Support must stay in the Union
Unlike Level 1's conditional approach to outsourced support, Level 2 requires technical and operational support for the audited service to be initiated and performed exclusively within the Union.
Level 2: Software Supply-Chain Controls
Inventory the software
The audited provider must supply an up-to-date SBOM and relevant dependency list to the auditing organisation. The requirement is both documentation and availability for audit.
Control remote capabilities
For specified third-country software, documented controls must block remote features that could materially tamper with or disrupt systems, including through updates.
Audit and migrate
Security-relevant components from third-country manufacturers require source-code audits. A documented migration plan is also required if the vendor fails or restrictions are imposed.
Open source is addressed too
Use of open-source software does not remove the obligation. Appropriate documented controls must prevent remote mechanisms from materially tampering with or disrupting relevant technology.
Level 2: Separation and Subcontractor Boundary
Third-country subsidiaries
A global provider with a third-country subsidiary must ensure and enforce effective legal, technical, and organisational separation between its Union parent company and that subsidiary.
The subcontractor boundary remains narrow
At Level 2, relevant subcontractors are direct-contract third parties that contribute to provision and delivery of the service. This mirrors the Level 1 definition.
Read the lists carefully
Level 2 contains a more detailed set of requirements, but this excerpt presents separate cumulative criteria lists and does not expressly require a separate Level 1 recognition process.
Knowledge Check: Certification Logic
Choose the best answer
Under Level 2, what does Section 2.1(e) require if no European cloud cybersecurity certification scheme is available, but a relevant national cybersecurity certification scheme exists?
What is the correct next step under 2.1(e)?
- Use the national cybersecurity certification scheme where it exists.
- Skip certification because the European scheme is unavailable.
- Use any private-sector cloud certificate.
- Demonstrate only state-of-the-art cybersecurity standards.
Show Answer
Answer: A) Use the national cybersecurity certification scheme where it exists.
Section 2.1(e) creates a sequence: use the European scheme if established and available; until then, national schemes apply where they exist. Demonstrating the highest standards under applicable Union law is the fallback only where no Union or national scheme exists.
Rapid Review: Baseline Sovereignty Terms
Flip each card
Use these terms to distinguish the Level 1 baseline from the additional Level 2 controls.
- Cumulative criteria
- Every listed criterion for the relevant assurance level must be met; satisfying only some criteria is insufficient.
- Level 1 data residency
- Customer data, including metadata and telemetry data, must remain exclusively within the Union unless the public sector body explicitly requires otherwise, including before, during, and after configuration or use.
- Level 1 outsourced support
- Support outside the Union may occur only with legal, technical, and organisational measures for traceability, security, and governance that do not compromise operational autonomy.
- Level 2 cybersecurity
- The specified European certificate must be at least assurance level substantial when the relevant Union scheme has been established and is available.
- SBOM
- A complete and up-to-date software bill of materials, plus relevant identified dependencies, must be documented and made available to the auditing organisation at Level 2.
- Level 2 support
- Technical and operational support for the audited service, including subsequent sub-outsourcing, must be initiated and performed exclusively within the Union.
Key Terms
- SBOM
- A software bill of materials: the Level 2 text requires a complete and up-to-date SBOM and relevant dependency list to be documented and made available to the auditing organisation.
- metadata
- Data describing or contextualising other data; Annex II expressly includes it within customer data for the location rules.
- customer data
- For these criteria, data includes metadata and telemetry data as well as other customer data.
- subcontractor
- For Levels 1 and 2, a third party with a direct contractual relationship with the cloud computing service provider that contributes to provision and delivery of the service.
- third country
- A country outside the Union, as used in the Annex's control, access, disruption, software, and subsidiary safeguards.
- telemetry data
- Operational or measurement data generated through systems or services; Annex II expressly includes it within customer data for the location rules.
- audited provider
- The term used in Level 2 for the provider whose audited service is assessed against the Level 2 criteria.
- operational autonomy
- The provider's ability to operate and deliver the service without outsourced operations compromising that ability.
- software supply chain
- The software components, dependencies, vendors, remote features, update paths, auditing controls, and migration planning addressed in Level 2 criteria 2.1(i) and 2.1(j).
- European cybersecurity certificate
- The Level 2 certification route under a European cybersecurity certification scheme for cloud computing services established under Regulation (EU) 2019/881, if established and available.