Chapter 5 of 8
Pillar Three: How Sovereignty Recognition Would Work
The proposal turns the contested idea of cloud sovereignty into a recognition system administered through national authorities and a Union-wide repository. Articles 16 to 28 establish self-assessment for Level 1, independent audits for Levels 2 to 4, cross-border recognition, transparency duties, supervision, and enforcement. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))
1. Start Here: A Proposal, Not Yet an Operational Scheme
Current legal status
As of 19 July 2026, COM(2026) 502 is a proposal adopted on 3 June 2026 and still undergoing the ordinary legislative procedure. The recognition scheme is therefore not operational law yet.
The core mechanism
The proposal would turn cloud sovereignty into four Union assurance levels. A provider supplies evidence for a specific cloud service; a national authority evaluates recognition; the result applies across the Union.
Proportional assurance
Level 1 is based on self-assessment. Levels 2-4 require an independent audit and positive opinion. Higher levels are cumulative, so a gap at a lower level blocks a higher-level claim.
2. Understand What Is Being Recognised
Service-level recognition
The applicant is a cloud provider, but recognition attaches to the cloud computing service. One company can therefore have services with different recognition outcomes because their technical and governance arrangements differ.
Four cumulative levels
Annex II would define four Union assurance levels. A higher-level applicant must satisfy all applicable lower-level criteria too; failure at a lower level prevents conformity at the higher level.
Do not collapse the concepts
Cybersecurity certification and sovereignty assurance may overlap, but they answer different questions. Sovereignty assurance also addresses autonomy, continuity, dependency, and external-control risks.
3. Level 1 Pathway: Self-Assessment to Recognition
Example service
Hypothetical provider NordCloud seeks Level 1 recognition for its specific managed-storage service, `ArchiveEU`. It must first define the actual scope of that service and assemble evidence against Annex II.
Self-assessment output
For Level 1, the provider conducts a conformity self-assessment, issues a public EU statement of conformity, and assumes responsibility for the service's compliance with the proposed criteria.
Authority and peer review
The authority of the provider's main establishment evaluates the application. A draft recognition is shared with other national authorities for a 60-day review period before Union-wide recognition.
Special SME rule
For an SME, the proposed Level 1 EU statement of conformity would be automatically recognised across Member States without prior recognition by the evaluating national authority.
4. Levels 2 to 4: Why Independent Audit Is Required
Required evidence
A Level 2, 3, or 4 applicant would need an independent third-party audit at its own expense, producing both an audit report and a positive audit opinion.
Independence safeguards
The proposal restricts conflicts of interest: no related non-audit services in the 12 months before or after the audit, no outcome-contingent fees, and demonstrated competence and ethics.
What auditors test
Auditors assess Annex II criteria using Annex III evidence. Evidence must be relevant, sufficient, and reliable; providers must provide access and must not obstruct or improperly influence the audit.
Ongoing assurance
A positive opinion is not a one-time credential. The provider would submit it for annual review, after which the auditing organisation may confirm, update, or revoke its initial conclusion.
5. Decision Exercise: Choose the Evidence Route
Apply the framework
For each scenario, decide which evidence pathway is appropriate under the proposal. Then explain your reasoning in one sentence.
Scenario A: Municipal events website
A city hosts public event calendars and non-sensitive visitor information in a cloud service. The activity has not been identified as contributing to the preservation of public order.
- Choose: Level 1 self-assessment or Level 2-4 independent audit?
Scenario B: Border-management case system
A public authority uses cloud services for an activity identified in its risk assessment as contributing to preservation of public order.
- Choose: Level 1 only or a recognised Level 2, 3, or 4 service?
Scenario C: Provider seeking Level 3
A provider has a robust internal compliance team and publishes a detailed self-assessment. It has not undergone an external audit.
- Can it be recognised at Level 3?
Suggested answers
- A: Level 1 is the proposed minimum route for public-sector activities not identified as public-order relevant.
- B: The authority would need a recognised Level 2, 3, or 4 service; the risk assessment determines which level is appropriate.
- C: No. Levels 2-4 require an independent third-party audit, a report, and a positive opinion. Internal evidence can support the audit but cannot replace it.
Reflect: The framework does not say every public service needs the strongest level. It links the burden of assurance to the consequences of failure, external control, or disruption.
6. Recognition Across Borders: One Evaluation, Union-Wide Effect
The lead authority
The proposed lead enforcer is the authority where the provider has its main establishment: the place of its head or registered office from which principal financial and operational control is exercised.
Recognition sequence
The lead authority evaluates the application, then circulates a draft recognition and evidence to other Member States for a 60-day review. No reasoned objection means Union-wide recognition.
Handling disagreement
Another authority may seek clarification or make a reasoned objection. If disagreement persists, it can be referred to the Commission, which may issue a binding decision.
7. Recognition Is a Lifecycle, Not a Badge
Trigger: material change
A provider that learns of a material change capable of affecting its audit result or recognition must notify the auditing organisation and the authority of establishment as soon as possible.
Reassessment chain
The auditor may amend or revoke its report or opinion. The national authority then assesses whether recognition must be amended or revoked, and informs other authorities and the Commission.
Public traceability
The Commission would maintain a public central repository of recognised services. A revoked audit opinion or recognition would remain visible in the repository for five years.
Enforcement tools
Authorities would be able to seek information, inspect where legally appropriate, order infringements to cease, and impose fines or periodic penalties. National rules must be effective, proportionate, and dissuasive.
8. Who Does What? Roles and Accountability
Provider and auditor
Providers assemble evidence and report changes. For Levels 2-4, independent auditors test the evidence, issue an opinion, and may revoke it if incorrect or misleading evidence was supplied.
National authority
The authority of establishment evaluates recognition, supervises the provider, and enforces the framework. Member States would designate one or more authorities and notify the Commission.
Commission and other authorities
The Commission would maintain central public registers and resolve certain disputes. A destination authority can trigger review when it suspects a recognised service no longer meets the applicable requirements.
9. Flashcards: Essential Vocabulary
Flip each card, then use the term in a sentence about the proposed recognition process.
- Union assurance level
- One of four proposed levels in the Union cloud computing sovereignty framework. The criteria would be set out in Annex II.
- Conformity self-assessment
- The Level 1 pathway in which a provider assesses compliance and issues a public EU statement of conformity.
- EU statement of conformity
- A provider declaration that Level 1 compliance has been demonstrated; issuing it makes the provider responsible for that claim.
- Independent third-party audit
- The required pathway for Levels 2, 3, and 4, producing an audit report and a positive or negative audit opinion.
- National competent authority of establishment
- The authority in the Member State of the provider's main establishment that evaluates recognition and has exclusive competence for enforcement under the proposed chapter.
- Central repository
- The proposed public Commission-maintained repository of recognised cloud services, including published revocations.
- Material change
- New information or changed circumstances that may affect an audit result or recognition and must be reported promptly.
- Cross-border cooperation
- A process allowing a destination authority or the Commission to ask the authority of establishment to investigate suspected non-compliance.
10. Knowledge Check: Select the Best Answer
Scenario
A large provider applies for Level 3 recognition for one of its cloud services. It submits a public Level 1 EU statement of conformity but has not commissioned an independent audit.
Which is the best assessment under the proposal?
Can the service be recognised at Level 3 on the basis of the Level 1 statement alone?
- Yes. A public Level 1 statement automatically establishes compliance at all higher levels.
- Yes, if the provider's national authority trusts its internal compliance team.
- No. Levels 2, 3, and 4 require an independent third-party audit, an audit report, and a positive audit opinion.
- No. Only SMEs can apply for recognition above Level 1.
Show Answer
Answer: C) No. Levels 2, 3, and 4 require an independent third-party audit, an audit report, and a positive audit opinion.
Levels 2-4 require an independent audit at the provider's expense. A higher-level applicant must also meet the applicable lower-level criteria, but Level 1 self-assessment cannot replace the required external audit. The SME exception concerns automatic recognition of an SME's Level 1 statement, not access to higher levels.
Key Terms
- Material change
- Information or a changed circumstance that may affect an audit opinion or recognition and therefore triggers notification duties.
- Central repository
- The proposed public repository maintained by the Commission for cloud services recognised under Article 17, including revocations.
- Union assurance level
- A proposed Level 1, 2, 3, or 4 assurance outcome under the cloud sovereignty framework.
- Positive audit opinion
- The favorable audit conclusion required, together with the audit report, for a provider seeking recognition at Level 2, 3, or 4.
- Cloud computing service
- The specific service that is the object of the recognition outcome; recognition should not be treated as a blanket label for every service offered by a company.
- Cross-border cooperation
- The proposed mechanism through which destination authorities and the Commission can request investigation of suspected non-compliance by the authority of establishment.
- Conformity self-assessment
- The proposed Level 1 process in which the provider assesses its own compliance with Annex II criteria.
- EU statement of conformity
- The public statement issued after a Level 1 self-assessment, through which the provider assumes responsibility for compliance.
- Independent third-party audit
- The required assessment route for proposed Levels 2-4, performed by an independent auditing organisation.
- Cloud computing service provider
- The entity that applies for recognition when it seeks to offer a cloud computing service at a proposed Union assurance level.
- Union cloud computing sovereignty framework
- The proposed four-level EU framework in Article 16, with detailed criteria in Annex II and evidence expectations in Annex III.
- National competent authority of establishment
- The authority in the Member State of the provider's main establishment that evaluates recognition and leads enforcement under the proposed framework.