SkarpSkarp

Chapter 16 of 17

Assurance Levels 3 and 4 and the Evidence Behind Them

The highest assurance levels demand increasingly deep Union control over infrastructure, personnel, support, data, and software. Annex III then begins the auditor’s evidence trail, showing how genuine establishment, localization, assets, personnel, and Union-citizen support capacity may be tested.

20 min readen

1. Where Levels 3 and 4 Fit

A cumulative framework

Levels 3 and 4 contain cumulative criteria. A provider must satisfy every applicable requirement, rather than selecting a convenient subset.

Status as of July 20, 2026

The supplied wording appears in Commission proposal COM(2026) 502, published in June 2026. It is proposed text, not final enacted law.

From rules to proof

Annex II states the criteria. Annex III begins the evidence trail: what auditors should request when assessing compliance.

2. Level 3: Union Establishment, Location, Data, and People

Level 3 begins with establishment

The audited provider and subcontractors involved in the audited service must be established in the Union.

Location is operational

Infrastructure, assets, and personnel must be located in the Union, including those of subcontractors involved in providing the service.

Data scope is broad

Level 3 covers customer data, metadata, and telemetry data that are processed, stored, or transferred for the service.

The citizenship rule

Level 3 requires: the personnel, including the personnel of the subcontractors which are involved in the provision of the audited service are Union citizens.

3. Level 3: Cybersecurity, AI, Control, Support, and Software

Certification pathway

Level 3 specifies a European cybersecurity certificate of at least assurance level "substantial", subject to the scheme's establishment and availability.

AI-use restriction

Data generated by use of the service cannot train or fine-tune AI operated by a third country or third-country legal entity, and cannot leave the Union.

Control rule and exception

The default rule is that providers and relevant subcontractors are not subject to the control of a third country or a legal entity established in a third-country.

Supply-chain visibility

Level 3 requires a complete, current SBOM, identified dependencies, and stated controls for relevant software, remote features, audits, and migration.

4. Worked Example: Can "EuroCloud Public" Reach Level 3?

The initial facts

EU incorporation, Union-based systems, Union-located staff, and Union citizens may support several Level 3 criteria, but they do not end the assessment.

Third-country software

Third-country-owned software is not automatically disqualifying at Level 3, but the text requires remote-feature controls, source-code audits, and a migration plan.

Control cannot be ignored

If a third-country legal entity controls the provider, Level 3 needs the Article 19 implementing-act route plus every listed safeguard.

5. Level 4: The Higher Threshold

Level 4 retains the foundation

Level 4 keeps Union establishment, location, citizenship, support, data, AI, open-source, and subsidiary-separation requirements.

Sensitive data

After a risk assessment identifies data as sensitive, that data must remain exclusively within the Union and at any time.

Higher cybersecurity bar

Level 4 requires a European cybersecurity certificate of at least assurance level "high" when the relevant scheme is established and available.

Software control matters

Level 4 asks who can materially influence a component's evolution, maintenance priorities, security remediation, and long-term continuity.

6. Quiz: Identify the Level 4 Difference

Choose the answer that best reflects the supplied text.

Which statement correctly describes a difference expressly stated between Level 3 and Level 4?

  1. Level 4 requires a European cybersecurity certificate of at least assurance level "high", while Level 3 specifies at least "substantial".
  2. Level 4 permits a third-country-control derogation whenever a provider uses encryption.
  3. Only Level 3 requires Union establishment of the provider.
  4. Only Level 4 requires an SBOM and dependency list.
Show Answer

Answer: A) Level 4 requires a European cybersecurity certificate of at least assurance level "high", while Level 3 specifies at least "substantial".

Correct. Level 3 criterion (e) specifies at least "substantial" and Level 4 criterion (e) specifies at least "high", subject to the scheme and interim conditions stated in the text. Both levels address Union establishment and require an SBOM/dependency list. The Level 3 derogation depends on a Commission implementing act under Article 19; it is not an encryption exception.

7. Annex III: Evidence Is Indicative, Not Exhaustive

Indicative evidence

This Annex is indicative and does not limit the evidence that may be requested or considered by the auditing organisations.

Not a checkbox exercise

Even where requested evidence is the same, auditors analyse it differently according to the applicable assurance level and its strictness.

Establishment must be real

Auditors should verify whether their establishment is genuine and stable, rather than assuming an EU-facing provider is genuinely established in the Union.

Operational presence

Evidence can address premises, permanent staff, Union customer support, Union contractual operations, and exclusively Union banking and accounting.

8. Annex III Criteria B and C: Proving Location and Data Localisation

Address-level location evidence

Infrastructure evidence must state the precise location (number, street, city, postal code and country) of the infrastructure.

All resilience locations count

The location list includes primary, backup, disaster-recovery, and log-storage locations, not only the main production environment.

Functional scope

Auditors consider resources that handle data, could enable administrative access or visibility, or could disrupt the service if compromised or unavailable.

No unauthorised capability

Evidence must show that non-qualifying third parties cannot technically or operationally access, obtain, disrupt, destroy, or otherwise process customer data without prior authorisation.

Map the flows

A data-flow diagram must identify data sources and destinations and demonstrate that data do not leave the Union.

9. Annex III Criterion D: Testing Union Citizenship

Identity evidence

The text identifies valid official government issued documents (e.g. valid passport and national identity card) as citizenship evidence.

Who is in scope?

Relevant personnel may include people with physical or logical access, customer-support personnel, and all personnel with management control.

Test actual access

Organisational charts, job descriptions, access-control policies, and audit trails help test whether only authorised Union citizens accessed systems and data.

Citizenship is ongoing

The provider should show how citizenship is verified before assignment and how compliance is maintained throughout employment.

10. Flashcards: Exact Phrases and Evidence

Flip each card and recall both the rule and its audit significance.

Level 3 personnel rule
the personnel, including the personnel of the subcontractors which are involved in the provision of the audited service are Union citizens
Level 3 baseline control rule
are not subject to the control of a third country or a legal entity established in a third-country.
Level 4 cybersecurity threshold
a European cybersecurity certificate of at least assurance level 'high'
Level 4 sensitive-data residency
remain exclusively within the Union and at any time
Effective software control
Effective control includes the ability to materially influence the technical evolution, maintenance priorities, security remediation, and long-term continuity of the component;
Annex III evidence status
This Annex is indicative and does not limit the evidence that may be requested or considered by the auditing organisations.
Union-establishment test
whether their establishment is genuine and stable
Citizenship-document example
valid official government issued documents (e.g. valid passport and national identity card)

11. Final Quiz: Select the Best Evidence Set

Apply the Annex III evidence logic rather than relying on a single document.

An auditor needs to test whether a Level 3 service keeps customer data in the Union and prevents non-qualifying third parties from processing it without prior authorisation. Which evidence set best matches Annex III criterion C?

  1. Only the provider's EU incorporation certificate and VAT registration
  2. Access logs, support-access policies, privileged-access records, backup-retention policy, and a data-flow diagram showing storage, processing, replication, and backups
  3. Only employee passports and a Union-based office lease
  4. Only a cybersecurity certificate at assurance level "substantial"
Show Answer

Answer: B) Access logs, support-access policies, privileged-access records, backup-retention policy, and a data-flow diagram showing storage, processing, replication, and backups

Correct. Criterion C expressly gives examples including access logs, support access policies, privileged access records, backup retention policy, and a data-flow diagram. Incorporation evidence belongs principally to criterion A; passports and office leases relate to citizenship or establishment/location; certification addresses a different Annex II criterion.

Key Terms

BRIS
Business Registers Interconnected System, listed as possible evidence when auditors verify legal incorporation in a Member State.
SBOM
Software bill of materials: the documented, complete, and up-to-date inventory of software components required by the supplied Level 3 and Level 4 criteria.
VIES
VAT Information Exchange System, listed as possible evidence when auditors verify legal incorporation in a Member State.
metadata
Data about data or service activity that the supplied text includes within customer data for the relevant localisation criteria.
customer data
Data under the customer's control, including data input by or for the customer and data produced through use of the cloud service; the Annex also describes relevant derived data, including telemetry and metadata.
telemetry data
Data generated through monitoring or use of the service; the supplied text includes it in the relevant customer-data scope.
audited service
The cloud computing service that is assessed in the audit procedure.
audited provider
The cloud computing service provider whose audited service is being assessed against the applicable assurance-level criteria.
effective control
For Level 4 software components or products, control that includes the ability to materially influence technical evolution, maintenance priorities, security remediation, and long-term continuity.
public sector body
For Annex III's customer-data purpose, a customer that has entered a contractual or other legally binding arrangement with the cloud provider to access or use the cloud service.
cumulative criteria
Requirements that must all be met for the applicable assurance level; they are not alternative options.
third-country control
Control by a third country or by a legal entity established in a third country. Level 3 states a conditional Article 19 derogation; Level 4 states no such derogation in the supplied criterion.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself