SkarpSkarp

Chapter 5 of 17

The Sovereignty Risk Model and Public-Sector Demand

Foreign control, extraterritorial law, concentration, and disruption become the basis for a four-level Union assurance system. The recitals then translate those risks into audits, supervision, public-sector assessments, procurement requirements, and a carefully qualified route for some third-country-controlled providers.

23 min readen

1. Reading the Text: Purpose, Scope, and Current Status

What kind of text is this?

Recitals (45)-(68) explain why the proposed Regulation takes its approach. They frame the intended system, while operative articles would set the binding legal rules.

Currency note

As of July 20, 2026, this is a Commission proposal, COM(2026) 502, published in June 2026. It has not yet become a final enacted Regulation.

Recital (45): who is covered?

The text says the Regulation should apply to Union entities when they procure cloud computing services and AI systems falling within its scope.

The actors

Track three roles: providers offer services; public bodies assess risks and buy services; authorities and auditors recognise, supervise, and examine compliance.

2. The Sovereignty Risk Model: Dependency, Law, and Disruption

The central diagnosis

"The Union still remains critically dependent on a limited number of cloud computing service providers subject to the control of third countries". This is the text's stated dependency risk.

Risk is multi-dimensional

The recitals combine legal reach, possible service disruption, weaker oversight of data and infrastructure, and possible economic or political influence.

Why existing rules are not enough

Cybersecurity, data protection, interoperability, and portability rules exist, but recital (47) says no cross-cutting Union framework defines trusted cloud services for these sovereignty risks.

Why national solutions are not enough

National sovereign-service approaches may not solve cross-border dependence and may fragment the internal market, undermining common autonomy and sovereignty goals.

3. Applying the Risk Model to a Public Service

Scenario

An emergency-coordination platform processes operational plans, location data, communications, and supplier information. Its cloud choice can affect continuity and control.

Do not reduce risk to location alone

The recitals focus on possible legal access, service disruption, control of data and infrastructure, and dependency. They do not state a blanket ban on every foreign-linked provider.

Recital (50) risk categories

Assess misuse, access to information, and dependency vulnerabilities. Examples include sabotage, exfiltration, espionage, lock-in, embargos, sanctions, and monopoly pricing.

A useful visual

Map the authority, its data, provider, subcontractors, governing law, and alternatives. The map reveals possible routes for external access, disruption, or coercive dependence.

4. The Four-Level Union Assurance Framework

The framework

"the framework should provide for four different levels of trusted offers (‘Union assurance levels’)." The text uses graded assurance rather than one universal category.

Proportionality

Most public services should not need the highest assurance. In specific cases, levels 3 or 4 may be necessary and proportionate to preserve public order.

How recognition works

Recognition is based on either a level 1 EU statement of conformity or a "positive" audit opinion and report. Positive recognition has effect across the Union.

Who supervises?

The recital supports supervision and enforcement by competent authorities in the Member State where the provider has its main establishment.

5. Evidence and Accountability: Self-Assessment, Audits, and Reporting

Level 1: provider-led evidence

For level 1, "cloud computing service providers should have sole responsibility for carrying out conformity self-assessments" using evidence, internal controls, and continuous monitoring.

Levels 2 to 4: external verification

For higher levels, "the applicable criteria for Union assurance levels 2, 3 or 4 are verified by third-party independent experts".

Provider cooperation

Providers should enable effective audits by giving access to relevant data and premises and answering questions. They should not undermine the audit process.

Audit opinions

A positive opinion means all evidence shows compliance. A negative opinion means non-compliance. Inconclusive aspects must be identified and explained.

Assurance is not permanent by default

Material changes should be reported promptly. This allows reports, opinions, and recognition to be reassessed, amended, or withdrawn; a repository supports information exchange.

6. Thought Exercise: Build an Assurance Path

Your task

Compare routine internal document storage with a public-order-relevant critical activity. Identify the likely assurance route, evidence route, and oversight actors.

Level 1 reasoning

Level 1 uses a provider's conformity self-assessment supported by documented evidence, internal controls, and continuous monitoring. That is not the same as Union-wide recognition.

Higher-level reasoning

Levels 2-4 depend on independent third-party verification, a substantiated audit report, and an audit opinion. The provider remains accountable for compliance.

Discipline in interpretation

These recitals do not give every detailed technical criterion for each level. A careful reader states that limit rather than inventing requirements.

7. Authorities, Cross-Border Cooperation, and Third-Country Level 3 Access

National competent authorities

Member States should designate one or more authorities for recognition and supervision. They need powers, resources, expertise, technical means, independence, and clear responsibilities.

Cross-border enforcement

Mutual assistance supports timely information exchange, coordinated investigative measures, and consistent enforcement when risks and providers operate across Member State borders.

Autonomy is not isolation

The text frames Union autonomy as capacity to act autonomously where needed while remaining open, cooperative, and consistent with international commitments and partnerships.

The level 3 exception route

"the Commission may decide, for Union assurance level 3, that a cloud computing service subject to the control of a third country or a legal entity established in a third-country can still be audited".

What must be assessed?

The recital points to safeguards against unauthorised access and disruption, plus the scope of any GDPR Article 45 adequacy decision and relevant transfer safeguards.

8. Public-Sector Risk Assessments and Procurement Baselines

Risk assessment first

"Member States and the Union entities should carry out one or more risk assessments to determine public-sector activities that concerns public order."

What is assessed?

Assess the sensitivity, criticality and magnitude of personal and non-personal data, alongside the activity's public-order importance and applicable legal obligations.

Relevant activities

The recital names NIS2 sectors and national security, internal security, borders, defence, justice, and law enforcement, including criminal-offence prevention and prosecution.

Procurement consequence

Activities identified as contributing to public order should procure the appropriate level from 2 to 4. The broad baseline is described as "by mandating Union assurance level 1 across the Union".

Resilience architecture

A multi-vendor or multi-cloud strategy should be considered when a context-specific assessment identifies operational, regulatory, or resilience reasons supporting it.

9. Quiz: Evidence, Recognition, and Proportionality

Select the best answer

A provider wants to demonstrate a higher assurance level, and a public buyer assumes that the provider can simply complete the same self-assessment used for level 1. Which answer best reflects recitals (52) to (56)?

Which statement is most accurate?

  1. All four assurance levels use only provider self-assessment because this is the fastest route to recognition.
  2. Level 1 is based on provider-led conformity self-assessment, while levels 2, 3, and 4 require verification by third-party independent experts; the framework is designed to be proportionate.
  3. Levels 3 and 4 are automatically required for every public service because public procurement always concerns public order.
  4. An audit opinion is unnecessary once a provider gives confidential information to an auditor.
Show Answer

Answer: B) Level 1 is based on provider-led conformity self-assessment, while levels 2, 3, and 4 require verification by third-party independent experts; the framework is designed to be proportionate.

Recital (54) assigns sole responsibility for level 1 conformity self-assessments to providers. Recital (55) requires third-party independent verification for levels 2, 3, and 4. Recital (52) says most public services would not require the highest levels, so the system is proportionate rather than automatic.

10. Flashcards: Recall the Sovereignty Framework

Flip each card, then explain the term in your own words.

Focus on the relationship between risk, evidence, recognition, and procurement.

Dependency risk
The recital's core diagnosis is: "The Union still remains critically dependent on a limited number of cloud computing service providers subject to the control of third countries".
Union assurance levels
A four-level framework of trusted offers. It is intended to support proportionate protection of public order and public-sector control and agency.
Level 1 evidence route
The provider has sole responsibility for conformity self-assessment, using documented evidence, internal control procedures, and continuous monitoring.
Levels 2-4 evidence route
Applicable criteria are verified by third-party independent experts through an independent audit, report, and opinion.
Positive audit opinion
It should be given where all evidence shows that the provider complies with the applicable audit criteria and obligations.
Public-order risk assessment
Member States and Union entities should determine which public-sector activities concern public order and what assurance level is appropriate.
Procurement baseline
The recitals describe a minimum public-sector safeguard as "by mandating Union assurance level 1 across the Union".
Third-country level 3 route
The Commission may decide that a third-country-controlled service can still be audited for level 3 when specified safeguards prevent unauthorised access to Union data and service disruption.

11. Public Procurement as Market Policy: European Added Value and SMEs

Procurement sends a signal

The text says public assurance requirements can be mirrored by regulated private-sector entities, creating spillover effects and broader market realignment.

European added value

Quality evaluation may consider Union supply chains, Union technologies, innovation delivered in the Union, and hardware designed or manufactured in the Union.

Its limit and numerical guide

European added value should not be decisive; technical and financial performance criteria remain primary. Authorities could consider a maximum of 15 out of 120 points.

SME innovation objective

"Member States should therefore aspire to award at least 25% of relevant cloud and AI procurement innovation procedures to SMEs." They should actively report uptake to the Commission.

Key Terms

Union entities
Union institutions, bodies, offices and agencies.
positive opinion
An audit opinion given where all evidence shows that a provider complies with the audit criteria and obligations stated in the Regulation.
European added value
A non-decisive procurement quality consideration linked to reinforcing the Union digital supply chain, Union technologies, Union-based innovation, and specified hardware components.
auditing organisation
An independent organisation that audits cloud services for assurance levels 2, 3, and 4 and produces an audit report and opinion.
Union assurance levels
Four levels of trusted cloud service offers intended to provide proportionate safeguards for public order.
conformity self-assessment
For level 1, a provider-led assessment supported by documented evidence, internal controls, and continuous monitoring.
extraterritorial application
Application of a third country's laws in ways that may affect providers, data, or services beyond that country's territory.
competent authority of establishment
The competent authority in the Member State where a cloud provider's main establishment is located; the recitals assign it a central supervision and enforcement role.
multi-vendor or multi-cloud strategy
Use of more than one provider or cloud environment, considered where a context-specific risk assessment supports it.
cloud computing sovereignty framework
The proposed Union framework for determining criteria for trusted cloud computing services through four Union assurance levels.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself