Chapter 8 of 8
Preparing Before the Text Becomes Law
The proposal may change during negotiations, but waiting for the final regulation could leave organisations without the evidence, contracts, architecture maps, or procurement data needed to respond. A role-based readiness plan separates prudent no-regret actions from investments that should await the final text and secondary legislation.
1. Start With the Legal Boundary
Proposal, Not Law
On July 19, 2026, CADA is an ongoing legislative proposal, introduced on June 3, 2026. Do not treat its draft requirements as binding obligations.
Two Workstreams
Separate current-law compliance from CADA readiness. Continue applicable obligations now, while preparing reusable evidence for possible future requirements.
Decision Rule
Collect facts and preserve options now. Delay irreversible certification, migration, or construction commitments until the final legal text and follow-on rules are known.
2. Triage Actions: No-Regret or Wait?
Quick sorting exercise
For each action, label it No-regret now, Pilot now, or Wait for final rules.
- Create a register of every cloud service, region, tenant, and account.
- Terminate a multi-year provider contract solely because its future assurance level is uncertain.
- Ask suppliers to disclose their direct subcontractors and remote-support locations.
- Build a production facility designed only for a specific draft assurance level.
- Add a contractual right to receive updated evidence when ownership, support access, or hosting locations change.
Suggested answers
- No-regret now: 1, 3, and 5. These improve governance regardless of CADA's final wording.
- Wait for final rules: 2 and 4. They are costly, difficult to reverse, and depend on the adopted text, application timetable, and detailed rules.
- Pilot now: use this category for reversible technical tests, such as validating whether telemetry can be retained within the EU or whether administrator access can be geographically restricted.
Checkpoint: A no-regret action creates reliable information, contractual optionality, or reversible capability without assuming that a draft requirement will survive negotiation.
3. Create Four Role-Based Readiness Workstreams
Why Role Matters
A provider must demonstrate service evidence; a buyer must make defensible procurement decisions; a critical private entity manages operational exposure; a developer plans physical capacity.
Cloud Provider Stream
Map each service's legal entity, infrastructure, support, subcontractors, ownership, telemetry, and software dependencies. Treat evidence collection as an operational product.
Buyer and Critical-Entity Streams
Public bodies prepare risk and procurement records. Critical private entities build a repeatable impact-assessment capability without assuming that a future CADA duty already applies.
Data-Centre Stream
Developers should preserve capacity, grid, environmental, permitting, cooling, and supply-chain data while monitoring national strategies and proposed acceleration-zone mechanisms.
4. Build the Service and Data-Flow Inventory
Inventory the Actual Service
A vendor list is insufficient. Record the service in use, its legal and technical dependencies, and every relevant data or administrator-access path.
Map More Than Customer Data
Include backups, metadata, logs, telemetry, diagnostics, billing, prompts, outputs, secrets, and configuration data. These can travel differently from production records.
Map Human Access
Identify where support engineers, administrators, managed-service staff, and emergency responders can access systems or data, including subcontracted support.
Make Evidence Refreshable
For every inventory field, name an evidence owner, source, collection date, and refresh trigger such as a new region, acquisition, subcontractor, or support-model change.
5. Worked Example: A University Research Platform
The False Finish Line
An EU production region alone does not answer questions about backups, telemetry, remote support, subcontractors, or AI-service prompts. Data residency is only one part of the picture.
Classify Confidence
Label each fact confirmed, supplier-asserted, or unknown. This exposes where an assertion lacks a diagram, contract schedule, technical control, or audit-ready record.
Create Options, Not Claims
Consider restricted support, EU telemetry routing, key-management changes, or substitute services. Do not market the platform as CADA-assured while CADA remains a proposal.
6. Turn Contracts and Controls Into Evidence
Prepare for Evidence, Not Certification
The proposal envisages self-assessment for Level 1 and independent audits for Levels 2 to 4. Build evidence now, but do not claim recognition before a lawful process exists.
Contractual Optionality
Review clauses on subcontractors, data locations, privileged support access, material-change notifications, audit rights, AI training use, portability, and exit assistance.
Technical Proof
Preserve diagrams, access logs, key-management records, baselines, software dependency data, vulnerability records, and recovery-test results with clear scope and dates.
7. Plan Procurement and Infrastructure Without Premature Commitments
Procurement Portfolio
List contract end dates, renewal windows, criticality, switching constraints, budget cycles, and evidence gaps. Procurement readiness starts before a tender is published.
Proposed Public-Sector Path
The draft links public-sector risk assessments and assurance levels, but these are not current CADA duties while the proposal remains under negotiation.
Developer Decision Gates
Use base, readiness, and final-decision scenarios. Preserve site and capacity evidence now; defer design features that depend on adopted criteria or national implementation choices.
8. Build a Legislative Monitoring Dashboard
Follow the Full Rule Chain
Monitor the legislative procedure, changing articles and annexes, delegated acts, implementing acts, national strategies, competent authorities, procurement guidance, and supplier changes.
Why Annexes Matter
The proposal places detailed assurance criteria in Annex II and audit-evidence expectations in Annex III, both of which may be updated through the proposed legal mechanisms.
Make Monitoring Actionable
For every update, log what changed, which services or contracts are affected, the decision needed, the accountable owner, and the deadline for response.
9. Knowledge Check
Choose the best next action
A public body has a cloud contract ending in 18 months. Its provider says that all production data is in the EU, but cannot yet document telemetry destinations, remote-support locations, or subcontractor access.
What is the best readiness action?
What should the public body do first?
- Immediately terminate the contract because the provider cannot prove a future CADA assurance level.
- Request a scoped evidence pack, map the missing flows, record renewal and migration options, and monitor the final CADA rules.
- Treat EU production data residency as sufficient evidence and take no further action.
- Claim that the service meets Level 4 because it has EU hosting.
Show Answer
Answer: B) Request a scoped evidence pack, map the missing flows, record renewal and migration options, and monitor the final CADA rules.
The prudent response is to close factual evidence gaps and preserve procurement options. CADA was still a proposal on July 19, 2026, so immediate termination or an assurance-level claim would be premature.
10. Key Terms Review
Flip each card, then use the terms when designing your readiness plan.
- No-regret action
- A reversible or broadly useful action, such as building inventories, preserving evidence, or improving change notifications, that does not depend on one draft rule surviving.
- Evidence register
- A controlled list linking each claim to a document or system record, scope, owner, version, date, retention period, and refresh trigger.
- Data-flow inventory
- A map of where data, metadata, logs, telemetry, backups, prompts, outputs, and administrator access travel across services and organisations.
- Delegated act
- A non-legislative act that the Commission may adopt only if the final Regulation grants that power, subject to the controls specified by EU law.
- Implementing act
- An act used to establish uniform conditions for implementing EU law where the final Regulation gives the Commission that authority.
- Decision gate
- A defined point at which an organisation decides whether to make a costly or irreversible investment after new legal, technical, or procurement information becomes available.
Key Terms
- CADA
- The proposed EU Cloud and AI Development Act, formally COM(2026) 502 final. As of July 19, 2026, it is an ongoing legislative proposal rather than an enacted Regulation.
- Telemetry
- Operational data generated by systems, such as performance metrics, diagnostic data, logs, traces, and security events.
- Delegated act
- An act the European Commission may adopt only when an EU legislative act delegates power to supplement or amend specified non-essential elements.
- Subcontractor
- A third party engaged by a provider or supplier to perform part of the service, including hosting, support, maintenance, security, or processing activities.
- Implementing act
- An act used to set uniform conditions for implementation where EU legislation gives the Commission implementing powers.
- Sovereignty evidence
- Documented facts that may help demonstrate where a service is established, controlled, operated, supported, and supplied, including data, personnel, infrastructure, and software evidence.
- Procurement readiness
- Preparation of service, contract, risk, budget, migration, and market information so future purchasing decisions can respond promptly to legal or policy changes.
- Union assurance level
- A proposed CADA classification within the Union cloud computing sovereignty framework. The proposal describes four levels and cumulative criteria, but the final framework may change before adoption.
- Ultimate beneficial owner
- The natural person or persons who ultimately own or control an organisation, directly or indirectly.
- Cloud service and data-flow inventory
- A structured record of services, locations, data categories, transfers, access paths, suppliers, and technical controls.