Chapter 16 of 17
Assurance Levels 3 and 4 and the Evidence Behind Them
The highest assurance levels demand increasingly deep Union control over infrastructure, personnel, support, data, and software. Annex III then begins the auditor’s evidence trail, showing how genuine establishment, localization, assets, personnel, and Union-citizen support capacity may be tested.
1. Where Levels 3 and 4 Fit
A cumulative framework
Levels 3 and 4 contain cumulative criteria. A provider must satisfy every applicable requirement, rather than selecting a convenient subset.
Status as of July 20, 2026
The supplied wording appears in Commission proposal COM(2026) 502, published in June 2026. It is proposed text, not final enacted law.
From rules to proof
Annex II states the criteria. Annex III begins the evidence trail: what auditors should request when assessing compliance.
2. Level 3: Union Establishment, Location, Data, and People
Level 3 begins with establishment
The audited provider and subcontractors involved in the audited service must be established in the Union.
Location is operational
Infrastructure, assets, and personnel must be located in the Union, including those of subcontractors involved in providing the service.
Data scope is broad
Level 3 covers customer data, metadata, and telemetry data that are processed, stored, or transferred for the service.
The citizenship rule
Level 3 requires: the personnel, including the personnel of the subcontractors which are involved in the provision of the audited service are Union citizens.
3. Level 3: Cybersecurity, AI, Control, Support, and Software
Certification pathway
Level 3 specifies a European cybersecurity certificate of at least assurance level "substantial", subject to the scheme's establishment and availability.
AI-use restriction
Data generated by use of the service cannot train or fine-tune AI operated by a third country or third-country legal entity, and cannot leave the Union.
Control rule and exception
The default rule is that providers and relevant subcontractors are not subject to the control of a third country or a legal entity established in a third-country.
Supply-chain visibility
Level 3 requires a complete, current SBOM, identified dependencies, and stated controls for relevant software, remote features, audits, and migration.
4. Worked Example: Can "EuroCloud Public" Reach Level 3?
The initial facts
EU incorporation, Union-based systems, Union-located staff, and Union citizens may support several Level 3 criteria, but they do not end the assessment.
Third-country software
Third-country-owned software is not automatically disqualifying at Level 3, but the text requires remote-feature controls, source-code audits, and a migration plan.
Control cannot be ignored
If a third-country legal entity controls the provider, Level 3 needs the Article 19 implementing-act route plus every listed safeguard.
5. Level 4: The Higher Threshold
Level 4 retains the foundation
Level 4 keeps Union establishment, location, citizenship, support, data, AI, open-source, and subsidiary-separation requirements.
Sensitive data
After a risk assessment identifies data as sensitive, that data must remain exclusively within the Union and at any time.
Higher cybersecurity bar
Level 4 requires a European cybersecurity certificate of at least assurance level "high" when the relevant scheme is established and available.
Software control matters
Level 4 asks who can materially influence a component's evolution, maintenance priorities, security remediation, and long-term continuity.
6. Quiz: Identify the Level 4 Difference
Choose the answer that best reflects the supplied text.
Which statement correctly describes a difference expressly stated between Level 3 and Level 4?
- Level 4 requires a European cybersecurity certificate of at least assurance level "high", while Level 3 specifies at least "substantial".
- Level 4 permits a third-country-control derogation whenever a provider uses encryption.
- Only Level 3 requires Union establishment of the provider.
- Only Level 4 requires an SBOM and dependency list.
Show Answer
Answer: A) Level 4 requires a European cybersecurity certificate of at least assurance level "high", while Level 3 specifies at least "substantial".
Correct. Level 3 criterion (e) specifies at least "substantial" and Level 4 criterion (e) specifies at least "high", subject to the scheme and interim conditions stated in the text. Both levels address Union establishment and require an SBOM/dependency list. The Level 3 derogation depends on a Commission implementing act under Article 19; it is not an encryption exception.
7. Annex III: Evidence Is Indicative, Not Exhaustive
Indicative evidence
This Annex is indicative and does not limit the evidence that may be requested or considered by the auditing organisations.
Not a checkbox exercise
Even where requested evidence is the same, auditors analyse it differently according to the applicable assurance level and its strictness.
Establishment must be real
Auditors should verify whether their establishment is genuine and stable, rather than assuming an EU-facing provider is genuinely established in the Union.
Operational presence
Evidence can address premises, permanent staff, Union customer support, Union contractual operations, and exclusively Union banking and accounting.
8. Annex III Criteria B and C: Proving Location and Data Localisation
Address-level location evidence
Infrastructure evidence must state the precise location (number, street, city, postal code and country) of the infrastructure.
All resilience locations count
The location list includes primary, backup, disaster-recovery, and log-storage locations, not only the main production environment.
Functional scope
Auditors consider resources that handle data, could enable administrative access or visibility, or could disrupt the service if compromised or unavailable.
No unauthorised capability
Evidence must show that non-qualifying third parties cannot technically or operationally access, obtain, disrupt, destroy, or otherwise process customer data without prior authorisation.
Map the flows
A data-flow diagram must identify data sources and destinations and demonstrate that data do not leave the Union.
9. Annex III Criterion D: Testing Union Citizenship
Identity evidence
The text identifies valid official government issued documents (e.g. valid passport and national identity card) as citizenship evidence.
Who is in scope?
Relevant personnel may include people with physical or logical access, customer-support personnel, and all personnel with management control.
Test actual access
Organisational charts, job descriptions, access-control policies, and audit trails help test whether only authorised Union citizens accessed systems and data.
Citizenship is ongoing
The provider should show how citizenship is verified before assignment and how compliance is maintained throughout employment.
10. Flashcards: Exact Phrases and Evidence
Flip each card and recall both the rule and its audit significance.
- Level 3 personnel rule
- the personnel, including the personnel of the subcontractors which are involved in the provision of the audited service are Union citizens
- Level 3 baseline control rule
- are not subject to the control of a third country or a legal entity established in a third-country.
- Level 4 cybersecurity threshold
- a European cybersecurity certificate of at least assurance level 'high'
- Level 4 sensitive-data residency
- remain exclusively within the Union and at any time
- Effective software control
- Effective control includes the ability to materially influence the technical evolution, maintenance priorities, security remediation, and long-term continuity of the component;
- Annex III evidence status
- This Annex is indicative and does not limit the evidence that may be requested or considered by the auditing organisations.
- Union-establishment test
- whether their establishment is genuine and stable
- Citizenship-document example
- valid official government issued documents (e.g. valid passport and national identity card)
11. Final Quiz: Select the Best Evidence Set
Apply the Annex III evidence logic rather than relying on a single document.
An auditor needs to test whether a Level 3 service keeps customer data in the Union and prevents non-qualifying third parties from processing it without prior authorisation. Which evidence set best matches Annex III criterion C?
- Only the provider's EU incorporation certificate and VAT registration
- Access logs, support-access policies, privileged-access records, backup-retention policy, and a data-flow diagram showing storage, processing, replication, and backups
- Only employee passports and a Union-based office lease
- Only a cybersecurity certificate at assurance level "substantial"
Show Answer
Answer: B) Access logs, support-access policies, privileged-access records, backup-retention policy, and a data-flow diagram showing storage, processing, replication, and backups
Correct. Criterion C expressly gives examples including access logs, support access policies, privileged access records, backup retention policy, and a data-flow diagram. Incorporation evidence belongs principally to criterion A; passports and office leases relate to citizenship or establishment/location; certification addresses a different Annex II criterion.
Key Terms
- BRIS
- Business Registers Interconnected System, listed as possible evidence when auditors verify legal incorporation in a Member State.
- SBOM
- Software bill of materials: the documented, complete, and up-to-date inventory of software components required by the supplied Level 3 and Level 4 criteria.
- VIES
- VAT Information Exchange System, listed as possible evidence when auditors verify legal incorporation in a Member State.
- metadata
- Data about data or service activity that the supplied text includes within customer data for the relevant localisation criteria.
- customer data
- Data under the customer's control, including data input by or for the customer and data produced through use of the cloud service; the Annex also describes relevant derived data, including telemetry and metadata.
- telemetry data
- Data generated through monitoring or use of the service; the supplied text includes it in the relevant customer-data scope.
- audited service
- The cloud computing service that is assessed in the audit procedure.
- audited provider
- The cloud computing service provider whose audited service is being assessed against the applicable assurance-level criteria.
- effective control
- For Level 4 software components or products, control that includes the ability to materially influence technical evolution, maintenance priorities, security remediation, and long-term continuity.
- public sector body
- For Annex III's customer-data purpose, a customer that has entered a contractual or other legally binding arrangement with the cloud provider to access or use the cloud service.
- cumulative criteria
- Requirements that must all be met for the applicable assurance level; they are not alternative options.
- third-country control
- Control by a third country or by a legal entity established in a third country. Level 3 states a conditional Article 19 derogation; Level 4 states no such derogation in the supplied criterion.