SkarpSkarp

Chapter 15 of 17

Assurance Levels 1 and 2: The Baseline Sovereignty Tests

Annex II makes the abstract assurance framework operational through cumulative legal, technical, and organizational criteria. Levels 1 and 2 establish the baseline tests for Union establishment, data location, cybersecurity, operational autonomy, foreign influence, and software integrity.

15 min readen

Annex II: Scope, Structure, and Status

Four assurance levels

Annex II establishes criteria for cloud services seeking recognition at Union assurance levels 1, 2, 3, and 4. This lesson focuses on the first two levels.

Cumulative means all

Each listed criterion is cumulative. A provider cannot compensate for a missing location, data, governance, or cybersecurity condition by performing well on another condition.

Software, not hardware

The Annex includes software within scope but expressly excludes hardware by reference to Regulation (EU) 2024/2847, Article 3, point (5).

Current status

On 20 July 2026, this text is part of a Commission proposal dated 3 June 2026, rather than a final Regulation in force.

Level 1: Union Establishment, Assets, and Data

1.1(a): Establishment

Level 1 requires the cloud computing service provider to be established in the Union. This is a requirement about the provider itself.

1.1(b): Infrastructure and assets

Infrastructure and assets of both the provider and involved subcontractors must be in the Union, unless the public sector body explicitly requires otherwise.

1.1(c): Broad data coverage

Customer data includes metadata and telemetry data. The rule covers processing, storage, and transfer by the provider and relevant subcontractors.

Timing matters

The Union-only data condition applies before, during, and after configuration or use. It is not limited to the period when a customer is actively using the service.

Level 1: Support, Subcontractors, Cybersecurity, and Foreign Control

Outsourced support

Level 1 does not categorically forbid support outside the Union. Instead, it requires traceability, security, governance, and protection of the provider's operational autonomy.

Cybersecurity and oversight

The provider must demonstrate state-of-the-art cybersecurity and must make subcontractor use transparent through due diligence, contracts, and ongoing oversight.

Foreign-control safeguard

A provider under third-country control must use independent sources to demonstrate that vulnerability-reporting laws or practices do not create the specified pre-exploitation reporting duty.

Which subcontractors count?

Section 1.2 covers third-party subcontractors with a direct contract with the provider that contribute to provision and delivery of the cloud computing service.

Level 1 Decision Check

Apply the Level 1 test

A provider is established in the Union. Its customer files are stored in the Union, but its telemetry data is sent to a non-Union analytics environment during service configuration. The public sector body has not explicitly required this transfer.

Your task

Decide whether the arrangement satisfies 1.1(c). Then identify the two details that control your answer.

  • Does the Annex treat telemetry as customer data?
  • Does the data-location rule apply during configuration?

Suggested answer

It does not satisfy 1.1(c). Telemetry data is expressly included, and the requirement applies before, during, and after configuration or use. The stated exception requires the public sector body to explicitly require otherwise.

Level 2: A More Constrained Union Operating Model

Level 2 terminology

Level 2 speaks of an audited provider and an audited service. It requires Union establishment for both the provider and subcontractors involved in the audited service.

Personnel are added

Level 2 expressly places infrastructure, assets, and personnel in the Union. It also addresses additional screening and Union-citizenship requirements when the public sector body determines they are necessary.

Certification sequence

Use an available European cloud certificate at least at substantial assurance. Until such a scheme exists, use national schemes where available; otherwise demonstrate the highest applicable Union-law standards.

Generated data

Data generated by the audited service cannot train or fine-tune a third-country-operated AI system or one operated by a legal entity established in a third country. It also cannot leave the Union.

Level 2: Foreign Control and Support Operations

Control is not automatically decisive

Level 2 addresses third-country control through required safeguards. The provider must demonstrate measures that prevent control from restricting service delivery or necessary resources.

Protect data and continuity

The measures must prevent third-country access to customer data and prevent disruption of service continuity or degradation of service quality.

Restrictive measures

Third-country control must not force compliance with foreign sanctions, embargoes, or equivalent measures, unless those measures are legitimate under Member State national law or Union law.

Support must stay in the Union

Unlike Level 1's conditional approach to outsourced support, Level 2 requires technical and operational support for the audited service to be initiated and performed exclusively within the Union.

Level 2: Software Supply-Chain Controls

Inventory the software

The audited provider must supply an up-to-date SBOM and relevant dependency list to the auditing organisation. The requirement is both documentation and availability for audit.

Control remote capabilities

For specified third-country software, documented controls must block remote features that could materially tamper with or disrupt systems, including through updates.

Audit and migrate

Security-relevant components from third-country manufacturers require source-code audits. A documented migration plan is also required if the vendor fails or restrictions are imposed.

Open source is addressed too

Use of open-source software does not remove the obligation. Appropriate documented controls must prevent remote mechanisms from materially tampering with or disrupting relevant technology.

Level 2: Separation and Subcontractor Boundary

Third-country subsidiaries

A global provider with a third-country subsidiary must ensure and enforce effective legal, technical, and organisational separation between its Union parent company and that subsidiary.

The subcontractor boundary remains narrow

At Level 2, relevant subcontractors are direct-contract third parties that contribute to provision and delivery of the service. This mirrors the Level 1 definition.

Read the lists carefully

Level 2 contains a more detailed set of requirements, but this excerpt presents separate cumulative criteria lists and does not expressly require a separate Level 1 recognition process.

Knowledge Check: Certification Logic

Choose the best answer

Under Level 2, what does Section 2.1(e) require if no European cloud cybersecurity certification scheme is available, but a relevant national cybersecurity certification scheme exists?

What is the correct next step under 2.1(e)?

  1. Use the national cybersecurity certification scheme where it exists.
  2. Skip certification because the European scheme is unavailable.
  3. Use any private-sector cloud certificate.
  4. Demonstrate only state-of-the-art cybersecurity standards.
Show Answer

Answer: A) Use the national cybersecurity certification scheme where it exists.

Section 2.1(e) creates a sequence: use the European scheme if established and available; until then, national schemes apply where they exist. Demonstrating the highest standards under applicable Union law is the fallback only where no Union or national scheme exists.

Rapid Review: Baseline Sovereignty Terms

Flip each card

Use these terms to distinguish the Level 1 baseline from the additional Level 2 controls.

Cumulative criteria
Every listed criterion for the relevant assurance level must be met; satisfying only some criteria is insufficient.
Level 1 data residency
Customer data, including metadata and telemetry data, must remain exclusively within the Union unless the public sector body explicitly requires otherwise, including before, during, and after configuration or use.
Level 1 outsourced support
Support outside the Union may occur only with legal, technical, and organisational measures for traceability, security, and governance that do not compromise operational autonomy.
Level 2 cybersecurity
The specified European certificate must be at least assurance level substantial when the relevant Union scheme has been established and is available.
SBOM
A complete and up-to-date software bill of materials, plus relevant identified dependencies, must be documented and made available to the auditing organisation at Level 2.
Level 2 support
Technical and operational support for the audited service, including subsequent sub-outsourcing, must be initiated and performed exclusively within the Union.

Key Terms

SBOM
A software bill of materials: the Level 2 text requires a complete and up-to-date SBOM and relevant dependency list to be documented and made available to the auditing organisation.
metadata
Data describing or contextualising other data; Annex II expressly includes it within customer data for the location rules.
customer data
For these criteria, data includes metadata and telemetry data as well as other customer data.
subcontractor
For Levels 1 and 2, a third party with a direct contractual relationship with the cloud computing service provider that contributes to provision and delivery of the service.
third country
A country outside the Union, as used in the Annex's control, access, disruption, software, and subsidiary safeguards.
telemetry data
Operational or measurement data generated through systems or services; Annex II expressly includes it within customer data for the location rules.
audited provider
The term used in Level 2 for the provider whose audited service is assessed against the Level 2 criteria.
operational autonomy
The provider's ability to operate and deliver the service without outsourced operations compromising that ability.
software supply chain
The software components, dependencies, vendors, remote features, update paths, auditing controls, and migration planning addressed in Level 2 criteria 2.1(i) and 2.1(j).
European cybersecurity certificate
The Level 2 certification route under a European cybersecurity certification scheme for cloud computing services established under Regulation (EU) 2019/881, if established and available.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself