Chapter 6 of 8
Inside the Four Union Assurance Levels
The decisive requirements are buried in Annexes II and III, where establishment, infrastructure, personnel, data, control, support operations, cybersecurity, AI training, and software supply chains are tested cumulatively. The progression from Level 1 to Level 4 is therefore more complex than a simple data-residency ladder. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))
1. Start with the legal status and the core rule
Current legal status
As of July 19, 2026, COM(2026) 502 final is a proposal, published on June 3, 2026. It is not yet an adopted EU Regulation.
The cumulative ladder
The four levels form a cumulative stack. Passing Level 3 means meeting relevant Level 1 and Level 2 criteria as well as Level 3 criteria.
Beyond data residency
The assessment asks more than where data sits: who owns, controls, supports, updates, accesses, and can disrupt the cloud service?
2. Read Annex II as a control map
Use an eight-question review
Review establishment, footprint, data, people, cybersecurity, AI use, ownership/control, and support plus software. Each reveals a different sovereignty risk.
Metadata is data
The proposed criteria expressly include metadata and telemetry. Backups, logs, monitoring data, and administrative traces matter, not only application records.
A weakest-link assessment
Picture eight gates around the service. EU hosting alone cannot compensate for a failed gate such as third-country remote administration or uncontrolled software updates.
3. Level 1: Establishment plus a baseline EU boundary
Level 1 baseline
Level 1 requires Union establishment plus EU location of infrastructure, assets, and customer data, including metadata and telemetry, subject to defined customer-requested exceptions.
External support is not automatically banned
At Level 1, support may be outsourced outside the Union only if legal, technical, and organisational measures preserve traceability, security, governance, and operational autonomy.
Apply the distinction
A France-based provider with a third-country help desk might meet Level 1. That same help desk blocks Level 2 because Level 2 requires support to be initiated and performed in the Union.
4. Level 2: Turn location into auditable operations
What changes at Level 2?
Level 2 converts the Level 1 baseline into an independently audited operating model: EU establishment, infrastructure, assets, personnel, data boundary, and EU-only support.
AI and support controls
Service-generated data cannot train or fine-tune third-country-operated AI and cannot leave the Union. Support and subsequent sub-outsourcing must be initiated and performed in the Union.
Software becomes auditable
Auditors expect an up-to-date SBOM, dependency list, remote-feature controls, source-code audit arrangements where relevant, and a tested vendor-failure migration plan.
5. Activity: Find the Level 2 blockers
Scenario: Municipal Permit Platform
A municipal authority uses a cloud platform for building-permit applications.
- The provider is established in Spain.
- Production, backups, and logs are hosted in Spain and Ireland.
- Customer telemetry is sent to an analytics service in a third country.
- The security operations centre is in Poland, but emergency database administration can be performed by a team in a third country.
- The provider has an SBOM, but no documented migration plan for a proprietary third-country database engine.
- The platform contract says usage data may improve an AI system operated by the provider's non-EU parent.
Your task
Identify at least four Level 2 blockers. Then propose one evidence item or remediation action for each.
Suggested answer
- Telemetry transfer outside the Union: Telemetry is customer data for this framework. Stop the transfer or obtain the narrow customer-authorised exception where applicable; produce data-flow diagrams and telemetry-routing logs.
- Non-EU emergency administration: Level 2 requires technical and operational support to be initiated and performed exclusively in the Union. Move privileged emergency support to the Union; provide privileged-access records and geo-restricted access controls.
- Third-country AI training: Data generated through the service cannot be used to train or fine-tune third-country-operated AI. Remove the clause; provide AI-use contractual clauses, model documentation, and MLOps records.
- No migration plan: A third-country software dependency needs documented controls and a migration plan if the vendor fails or restrictions arise. Create and test a switchover plan.
Nuance: Spain and Ireland hosting is compatible with an EU-wide location rule. The proposal is about the Union boundary, not a rule that everything must remain in one Member State.
6. Level 3: Personnel citizenship and control become decisive
Level 3 raises the autonomy threshold
Level 3 requires Union establishment plus EU-based infrastructure, assets, and personnel. It additionally requires relevant personnel to be Union citizens.
Clearance and control
Where classified information is handled, necessary Member State security clearance is also required. Providers and relevant subcontractors normally cannot be subject to third-country control.
Do not collapse two tests
EU residence and Union citizenship are different tests. At Level 3, support must be Union-based, performed by Union residents, and delivered by parties free from third-country control.
7. Level 4: Full autonomy and high assurance
The Level 4 data rule
At Level 4, customer data identified as sensitive, including metadata and telemetry, must remain exclusively in the Union throughout the full service lifecycle.
High assurance cybersecurity
Level 4 requires at least high assurance under the relevant European cloud cybersecurity scheme when available, rather than the substantial threshold proposed for Levels 2 and 3.
Software sovereignty matters
A third-country entity cannot effectively control a critical component's design, maintenance, security remediation, technical roadmap, or long-term continuity.
8. Build an Annex III evidence pack
Evidence-mapping exercise
You are preparing an audit pack for a Level 3 candidate service. Match each assurance question to the most persuasive evidence.
- Is the provider genuinely established in the Union?
- Do all production, backup, disaster-recovery, and log systems remain in the Union?
- Can only authorised Union-citizen staff administer the service?
- Does a third country or third-country entity exercise control?
- Can non-EU support staff remotely operate the service?
- Can the provider survive a critical software vendor failure?
Model mapping
- Company-register extracts, tax-residency documents, EU premises evidence, payroll records, and Union-based incident and contractual-operation records.
- Precise infrastructure-location inventory, architecture and network diagrams, backup and replication records, facility logs, and data-flow diagrams.
- Citizenship-verification process, organisational charts, role descriptions, privileged-access policies, and access audit trails.
- Cap table; ownership chain to ultimate owners; shareholder agreements; board composition; veto, appointment, and voting rights; long-term commercial and financial dependency documents.
- Subcontractor register, support contracts, geo-restricted access controls, privileged-access-management records, SOC/NOC operating evidence, and access-revocation records.
- SBOM, dependency inventory, source-code audit rights where applicable, alternative-solution analysis, tested switchover results, and a migration plan.
Audit mindset: A policy statement is weaker than operational proof. An auditor looks for evidence that can be traced to real systems, real people, real contracts, and real logs.
9. Quiz: Identify the correct level
One best answer
A provider has EU-based infrastructure, assets, and personnel; keeps customer data, metadata, and telemetry in the Union; uses EU-only support; maintains an SBOM and migration plans; and is independently audited. Its relevant operators are Union citizens, but a third-country corporation has a contractual veto over major strategic decisions.
What is the best conclusion under the proposed framework?
Which statement is most accurate?
- The provider can qualify for Level 3 because its infrastructure and personnel are in the Union.
- The provider may satisfy some Level 2 controls, but the third-country strategic veto is a Level 3 control problem unless the narrow Article 18 pathway applies.
- The provider automatically qualifies for Level 4 because its operators are Union citizens.
- Ownership and contractual veto rights are irrelevant if data remains in the Union.
Show Answer
Answer: B) The provider may satisfy some Level 2 controls, but the third-country strategic veto is a Level 3 control problem unless the narrow Article 18 pathway applies.
Level 3 normally requires the provider and relevant subcontractors not to be subject to third-country control. Annex III requires auditors to examine not only shareholding but also voting, veto, appointment, commercial, financial, and other control links. EU location and Union citizenship do not eliminate a third-country control concern.
10. Flashcards: Audit-ready vocabulary
Flip each card and test your recall
Use these terms when comparing providers or preparing an evidence pack.
- Cumulative criteria
- Requirements that must all be met. A higher Union assurance level includes applicable lower-level requirements; one failed criterion can prevent conformity.
- Metadata and telemetry
- Service-derived information such as logs of users, times, functions, identities, configurations, and usage. The proposed framework treats it as customer data.
- SBOM
- Software bill of materials: an up-to-date inventory of software components. Annex II also expects a documented list of relevant dependencies.
- Third-country control
- Control that may arise through ownership, voting rights, vetoes, board appointments, commercial dependency, financial links, or other durable influence over management and resources.
- Level 2 cybersecurity threshold
- At least substantial assurance under a relevant European cloud cybersecurity scheme when available; interim national or highest-applicable-Union-law evidence may apply under the proposal.
- Level 3 personnel rule
- Relevant personnel, including relevant subcontractor personnel, must be Union citizens. Necessary Member State security clearance is also required where classified information is handled.
- Level 4 software autonomy
- The provider must retain effective control: no third country or third-country entity may materially influence critical software design, maintenance, security remediation, evolution, or continuity.
- Audit evidence
- Verifiable information supporting audit findings, including documents, databases, IT-system records, interviews, testing, contracts, diagrams, access logs, and ownership records.
Key Terms
- SBOM
- Software bill of materials: a structured inventory of software components and dependencies used to provide a service.
- MLOps
- Machine learning operations: the processes and tooling used to build, test, deploy, monitor, and maintain AI or machine-learning systems.
- Annex II
- The proposed annex setting the cumulative criteria for Union assurance Levels 1 through 4.
- Annex III
- The proposed annex listing indicative audit evidence that auditing organisations should request for Levels 2 through 4.
- Telemetry
- Operational or usage data emitted by a service, such as log records, performance signals, configuration information, and user activity traces.
- Customer data
- Data under the customer's control that are input into or produced through use of a cloud service, including relevant service-derived data such as telemetry and metadata.
- Migration plan
- A documented and tested plan for switching to an alternative supplier or solution if a vendor fails, becomes unavailable, or is affected by third-country restrictions.
- Privileged access
- Elevated technical access that enables administration, configuration, maintenance, security operations, or control of systems and data.
- Union establishment
- A genuine and stable provider presence in the EU, assessed through incorporation, registered office, central administration, main establishment, premises, staffing, and operational records.
- Operational autonomy
- The provider's ability to deliver and maintain the service without external arrangements undermining its control, continuity, security, or governance.
- Third-country control
- Control exercised by a non-EU country or a legal entity established there, including through ownership, governance rights, contractual leverage, financial dependence, or other durable influence.
- Union assurance levels
- The four proposed levels in COM(2026) 502 final for assessing cloud computing services against progressively stricter sovereignty, autonomy, operational, and security criteria.