Chapter 8 of 17
Proving and Enforcing Cloud Sovereignty
A sovereignty label has value only if evidence is credible and enforcement works across borders. These articles specify self-assessment, independent audits, repository disclosures, penalties, competent-authority powers, cooperation, and the procurement consequences of assigned assurance levels.
1. The Assurance System: Evidence Before a Sovereignty Label
Status as of July 20, 2026
This text is from the Commission proposal for the Cloud and AI Development Act, COM(2026) 502 final, published June 3, 2026. It is not yet in force.
A chain of proof
The proposal links Annex II criteria, evidence, assessment or audit, Article 17 recognition, repository disclosure, continuing oversight, and enforcement.
Two routes
Level 1 uses self-assessment. Levels 2, 3, and 4 use independent third-party audits. Higher-level assessments are cumulative.
Read the limits carefully
This extract refers to Annex II and Annex III but does not reproduce their detailed criteria or evidence. Do not invent them from general cloud-security knowledge.
2. Article 19: Level 1 Self-Assessment and Provider Accountability
Who uses Article 19?
A provider seeking Article 17 recognition at Union assurance level 1 must self-assess compliance with the corresponding Annex II criteria.
Required output
After self-assessment, the provider issues an EU statement of conformity stating that level 1 compliance has been demonstrated.
Responsibility stays with the provider
The source states: "the cloud computing service provider shall assume responsibility for the compliance of the cloud computing service".
Public disclosure
The EU statement of conformity must be publicly available. Article 19 does not specify its format, language, or a separate retention period.
Checkpoint: Recognising a Level 1 Service
Choose the answer that most closely follows Article 19. Focus on the distinction between a provider's self-assessment route and the audit route used at higher assurance levels.
A provider seeks recognition for Union assurance level 1. Which sequence does Article 19 require?
- Carry out a conformity self-assessment against Annex II level 1 criteria, issue an EU statement of conformity, and make that statement publicly available.
- Obtain a positive third-party audit opinion every year before issuing any statement.
- Submit a confidential marketing declaration to the Commission without assessing Annex II criteria.
- Obtain recognition first, then decide whether to assess the service.
Show Answer
Answer: A) Carry out a conformity self-assessment against Annex II level 1 criteria, issue an EU statement of conformity, and make that statement publicly available.
Article 19 requires a conformity self-assessment for level 1, followed by an EU statement of conformity that is publicly available. Independent third-party audits are the route specified in Article 20 for levels 2, 3, and 4.
3. Article 20: Independent Audits for Levels 2, 3, and 4
The higher-level route
For levels 2, 3, and 4, providers "shall undergo at their own expense, independent third-party audits" to obtain an audit report and opinion.
Cumulative means cumulative
A service pursuing a higher level must meet all applicable lower-level criteria. Failure on any lower-level requirement prevents higher-level conformity.
Audit access and conduct
Providers must provide relevant data, premises access, and answers. They must not hamper, unduly influence, or undermine the audit.
Independence safeguards
No relevant non-audit services in the 12 months before or after; no contingent fees; and no Article 20 auditing relationship in the preceding 10 years.
Report, review, and revocation
Reports need specified findings and a positive or negative opinion. Positive opinions face annual review; misleading evidence can lead to revocation.
4. Articles 21-23: Evidence, Repository Visibility, and Change Notifications
Evidence quality
Article 21 requires Annex III evidence to be relevant and sufficient for a report and opinion, and reliable under professional judgment and scepticism.
The central repository
The Commission establishes and maintains the repository. The competent authority of establishment registers each service it recognised under Article 17.
Five-year revocation record
A revoked audit report and opinion, or revoked recognition, is published in the repository and "shall remain available there for five years."
Notify, reassess, escalate
Material changes trigger prompt provider notification, auditor reassessment, authority reassessment, and cross-Member-State plus Commission notification when recognition changes.
5. Articles 24-28: Penalties, Authorities, and Cross-Border Enforcement
Penalties and remedies
Member States set effective, proportionate, and dissuasive penalties. They consider gravity, duration, mitigation, repeat conduct, gains, other factors, and Union turnover.
Compensation
Service recipients may seek compensation under Union and national law for damage or loss caused by a provider's Chapter infringement.
Competent authorities
Within one year after entry into force, Member States must designate one or more authorities. The Commission keeps a public register of them.
Exclusive jurisdiction
The Member State of the provider's main establishment "shall have exclusive competence for enforcing this Chapter."
Powers and deadlines
Authorities can demand information, inspect, seek explanations, order cessation, fine, and impose periodic payments. Mutual assistance generally has a two-month response deadline.
6. Flashcards: Assurance, Audit, and Enforcement Vocabulary
Flip each card, answer from memory, then check the precise rule. These cards focus on the distinctions most likely to cause errors in applying the text.
- What evidence route applies to Union assurance level 1?
- Article 19 requires provider conformity self-assessment against Annex II level 1 criteria, followed by an EU statement of conformity made publicly available.
- What assurance levels require independent third-party audits?
- Levels 2, 3, and 4. The provider undergoes the audit at its own expense to obtain an audit report and audit opinion.
- What does cumulative compliance mean in Article 20?
- A provider audited at a higher level must meet all applicable lower-level criteria. Failure on any lower-level requirement precludes higher-level conformity.
- What is the auditor's long rotation restriction?
- The auditor must not have provided Article 20 auditing services to the provider or a connected legal person during the 10-year period before the audit begins.
- How long must revocations remain in the central repository?
- Five years. This applies to the specified revocation of an audit report and opinion or revocation of recognition.
- Which authority normally enforces a provider's compliance?
- The competent authority in the Member State of the provider's main establishment, which has exclusive competence for enforcing this Chapter.
- What is the usual mutual-assistance response deadline?
- As soon as possible and no later than two months after receipt of the request, unless duly justified.
7. Article 29: Risk Assessments Drive Public-Sector Cloud Choices
Assessment frequency
Risk assessments occur within one year after entry into force, then every two years, or whenever necessary. This is an ongoing procurement-control process.
What is selected?
For identified public-order-related activities, the assessment determines the appropriate assurance level: 2, 3, or 4.
Three minimum risk dimensions
Assess data sensitivity and processing impacts, unlawful third-country access risks, and possible service-disruption risks and their public-order consequences.
Commission review and migration
Member States report results within three months. If migration is required, the reasonable transition period "shall not exceed 12 months."
8. Articles 30-33: Procurement Rules, Union Added Value, and SME Monitoring
Default procurement outcome
Activities not identified as contributing to public-order preservation must use Article 17-recognised services at Union assurance level 1.
Public-order procurement
Identified activities in the listed critical and security areas may procure only Article 17-recognised services at level 2, 3, or 4.
Exceptional derogation
A derogation requires exceptional, duly justified circumstances: no suitable recognised service, a failed similar tender, or disproportionate cost.
Union added value
Innovative cloud and AI tenders assess "the tenderer’s contribution to the development of a European cloud and AI ecosystem."
A boundary on award criteria
The non-price criterion must be contract-linked, transparent, constrained, and "ancillary and not decisive in the award of the contract."
SME objective and reporting
Member States report yearly on procurement innovation and pursue an objective of at least 25% of cloud and AI procurement awarded to innovative SMEs.
9. Final Application Quiz: Risk, Procurement, and Enforcement
Apply the articles as a connected system. The question tests whether you can distinguish a risk-assessment conclusion from the later procurement rule and from the exceptional derogation.
A Member State's Article 29 assessment identifies a justice-sector activity as contributing to preservation of public order and determines that level 3 is appropriate. Which procurement approach best matches the text?
- The contracting authority may buy any cloud service if it prefers a lower price.
- The contracting authority shall only procure a service recognised at Union assurance level 2, 3, or 4; the risk assessment indicates level 3 as the appropriate level for this activity.
- The authority must always use a level 1 service because level 1 is the general public-sector default.
- The authority can ignore recognised services whenever it wants to favour a European supplier.
Show Answer
Answer: B) The contracting authority shall only procure a service recognised at Union assurance level 2, 3, or 4; the risk assessment indicates level 3 as the appropriate level for this activity.
Article 30(3) confines identified public-order activities to recognised level 2, 3, or 4 services, while Article 29 determines which of those levels is appropriate. Departure from recognised levels is only exceptional and duly justified under Article 30(4); it is not a general price or supplier-preference option.
10. Integrated Takeaway: How to Explain the Proposal Accurately
Proof route
Level 1 is self-assessment plus a public conformity statement. Levels 2-4 require independent audit, and higher levels include applicable lower-level requirements.
Continuing accountability
Reliable evidence, annual review of positive audit opinions, prompt notification of material change, and repository disclosure keep recognition from becoming static.
Enforcement across borders
Main-establishment authorities lead enforcement, but mutual assistance and destination-authority or Commission requests support consistent cross-border application.
Buying according to risk
Risk assessments steer public procurement to the relevant recognised assurance level, while procurement policy also supports ecosystem and SME objectives.
Key Terms
- audit opinion
- The positive or negative opinion included in an audit report concerning compliance with applicable Annex II criteria.
- innovative SME
- An innovative small or medium-sized enterprise relevant to the Article 33 objective that at least 25% of cloud and AI procurement be awarded to innovative SMEs.
- risk assessment
- The Article 29 assessment by Member States and Union entities that identifies relevant public-sector activities and determines an appropriate assurance level 2, 3, or 4.
- audited provider
- A cloud computing service provider undergoing the Article 20 audit procedure for recognition at Union assurance level 2, 3, or 4.
- Union added value
- The Article 32 procurement evaluation of a tenderer's contribution to development of a European cloud and AI ecosystem.
- central repository
- The Commission-maintained public repository of cloud computing services recognised under Article 17.
- Union assurance level
- A recognition level under Article 17. This extract addresses level 1 through self-assessment and levels 2, 3, and 4 through independent third-party audit.
- auditing organisation
- The independent organisation that conducts Article 20 audits, prepares an audit report, and provides an audit opinion.
- EU statement of conformity
- The statement a level 1 provider issues after self-assessment, stating that compliance with the relevant Annex II criteria has been demonstrated.
- competent authority of destination
- A competent authority that may suspect a provider no longer fulfils Annex II requirements and request action from the competent authority of establishment.
- competent authority of establishment
- The national competent authority in the Member State of a provider's main establishment, which has exclusive competence for enforcing this Chapter.