SkarpSkarp

Chapter 7 of 8

Public Procurement as the Adoption Engine

CADA would make public purchasing the principal demand-side lever for sovereign cloud services. Articles 29 to 40 link recurring risk assessments to minimum assurance levels, migration decisions, EU-added-value criteria, SME participation, the EuroCloud Federation, and Commission-led joint procurement. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))

15 min readen

1. Why Procurement Is the Adoption Engine

Proposal, Not Current Law

As of July 19, 2026, the Cloud and AI Development Act remains a Commission proposal. Treat Articles 29 to 40 as proposed obligations, not rules already binding on contracting authorities.

Procurement Changes Demand

The proposal would make public purchasing a demand-side lever: assess a public activity, select the required Union assurance level, then procure cloud services that meet it.

The Full Pathway

`Public activity -> Risk assessment -> Assurance level -> Tender -> Migration or monitoring`. This links sovereignty recognition to day-to-day purchasing decisions.

2. Start with the Procurement Decision Tree

Step 1: Establish Scope

First ask whether the authority is procuring cloud computing services for its exclusive use. That is the proposed Article 30 starting point.

Step 2: Read the Assessment

If the activity is not identified as contributing to public order, the proposed baseline is a service recognised at Union assurance level 1.

Step 3: Escalate or Justify

For identified public-order activities in covered sectors or listed sensitive areas, use level 2, 3, or 4. Any departure would be exceptional and duly justified.

3. Perform the Public-Order Risk Assessment

Assess the Public Activity

Article 29 focuses on the public activity using cloud services. The assessment identifies activities connected to public order and selects level 2, 3, or 4 where appropriate.

Three Risk Lenses

Evaluate data sensitivity and scale, unlawful third-country access, and service disruption. For each, ask both likelihood and consequences for public order.

Architecture Matters

The proposed assessment also considers whether a multi-vendor or multi-cloud strategy is appropriate. Resilience can depend on avoiding a single operational dependency.

4. Worked Example: Selecting Level 1 or Higher

Low-Risk Public Website

A public events website has limited operational sensitivity and no material public-order function. If it is not identified in the assessment, the proposed procurement minimum is level 1.

Emergency Coordination Platform

Sensitive operational data, possible third-country access, and disruption during a crisis point toward a public-order assessment and a required level of 2, 3, or 4.

Migration Has a Ceiling

Where the assessment requires migration, the transition must be reasonable but cannot exceed 12 months. Plan for portability and uninterrupted essential service.

5. Apply the Risk Factors

Your turn: build a defensible recommendation

A city wants to procure a cloud platform for its smart-traffic control centre. The platform receives live traffic-camera metadata, manages traffic-light priorities for ambulances, and supports evacuation routes during emergencies. The provider's corporate group is subject to a third-country legal regime that may compel data access. A four-hour outage would disable automated traffic coordination.

Complete this mini-assessment

  1. Data: Which information is sensitive or critical, even if some data are not personal data?
  2. Third-country access: What public-order harm could result from unlawful access?
  3. Disruption: What happens during a four-hour outage?
  4. Assurance conclusion: Would you retain level 1, or recommend that the Article 29 assessment determine a higher level?
  5. Resilience: Would multi-cloud or multi-vendor design reduce the most serious risk?

Suggested answer

The case strongly supports identifying the activity as public-order relevant. The combination of emergency functions, operational sensitivity, potential unlawful third-country access, and high disruption impact means level 1 would be difficult to justify. The assessment should select the appropriate level from 2 to 4 and test whether a multi-cloud or multi-vendor design improves continuity.

6. Use Derogations Narrowly and Plan Migration

A Derogation Is Not a Preference

The proposed exception is available only on an exceptional and duly justified basis. It is not permission to bypass recognised assurance levels because an incumbent is convenient.

Three Proposed Grounds

The listed grounds are: no suitable recognised service or alternative, no suitable response to a similar tender in the prior year, or disproportionate cost.

Evidence and Exit Plan

Document market evidence and procurement records. If migration is required, plan immediately: the proposed transition period may not exceed 12 months.

7. Award for Union Added Value and SME Access

Union Added Value

For innovative cloud and AI procurement, evaluate quality as well as price. Proposed criteria examine a supplier's contribution to the European cloud and AI ecosystem.

Use Criteria Lawfully

Criteria must be connected to the contract, published in advance, structured rather than discretionary, and ancillary rather than decisive in the award decision.

The SME Objective

Member States would pursue an objective of at least 25% of cloud and AI procurement awarded to innovative SMEs, supported by monitoring, lots, consultations, and SME-friendly terms.

8. EuroCloud Federation and Common Procurement

EuroCloud Federation

EuroCloud would be a voluntary public-sector federation. Its Commission platform would catalogue public services and support exchange and orchestration of shared computing resources.

Conditions for Sharing

A sharing entity must own the hardware directly or through a controlled intermediary, provide the service, and show the Commission that its arrangements are secure and resilient.

Buy Together

The Commission could act as a central purchasing body using framework contracts or dynamic purchasing systems. A practical agreement with at least two Member States comes first.

9. Procurement Design Challenge

Design a procurement plan

A national health agency needs an innovative AI-assisted capacity-planning tool for public hospitals. The tool uses hospital occupancy data and predicts staffing and bed needs. The activity is important, but the agency's assessment has not identified it as contributing to preservation of public order.

Choose a design for the proposed framework:

  1. Minimum assurance: What recognised assurance level is the starting requirement?
  2. Innovation award criteria: Name two relevant Union-added-value criteria that are linked to this contract.
  3. SME access: Choose one tender design feature that could improve participation without lowering quality.
  4. Scale option: Would EuroCloud sharing or Commission-led common procurement be useful? Explain your choice.

Model response

  • Start with level 1, unless a later Article 29 assessment identifies the activity as public-order relevant.
  • Evaluate, for example, integration of EU-developed technologies and contribution to security of supply.
  • Use preliminary market consultation and divide the procurement into suitable lots where appropriate.
  • Common procurement may help multiple health agencies aggregate demand; EuroCloud may help if another public body can lawfully share an existing public-sector service.

10. Key Terms Review

Flip each card, then explain how the term changes a procurement decision.

Public-order risk assessment
A proposed Article 29 assessment that identifies relevant public activities and determines whether Union assurance level 2, 3, or 4 is appropriate.
Union assurance level 1
The proposed minimum for in-scope public-sector activities that have not been identified as contributing to preservation of public order.
Exceptional derogation
A narrowly available, duly justified departure where specified conditions such as lack of a suitable recognised service, failed prior procurement, or disproportionate cost apply.
Union added value
Non-price quality evaluation of a tenderer's contribution to the European cloud and AI ecosystem in innovative cloud and AI procurement.
EuroCloud Federation
A proposed voluntary federation through which Union entities and public-sector bodies could share eligible public-sector cloud and data-centre services.
Common procurement
Commission-led purchasing that could use framework contracts, dynamic purchasing systems, a common platform, and central purchasing support.

11. Check Your Understanding

Select the best answer. Focus on the proposed framework, not current binding law.

A public authority's Article 29 assessment finds that a cloud-supported emergency-response activity contributes to preservation of public order. What is the best proposed procurement approach?

  1. Procure any cloud service, provided that it is the lowest-priced tender.
  2. Use a recognised level 1 service because level 1 is always sufficient for public authorities.
  3. Procure only a cloud service recognised at level 2, 3, or 4, with the precise level determined by the risk assessment.
  4. Use an unrecognised service automatically if the authority has used it before.
Show Answer

Answer: C) Procure only a cloud service recognised at level 2, 3, or 4, with the precise level determined by the risk assessment.

For an identified public-order activity in the covered sectors or listed areas, Article 30 would require procurement of a recognised level 2, 3, or 4 service. The Article 29 assessment determines which of those higher levels is appropriate. Level 1 is the baseline only for activities not identified as contributing to preservation of public order.

Key Terms

Innovative SME
An innovative small or medium-sized enterprise. The proposal would set a Member State objective for at least 25% of relevant cloud and AI procurement to be awarded to innovative SMEs.
Union added value
Proposed non-price, ancillary quality criteria for innovative cloud and AI procurement that evaluate contribution to the European cloud and AI ecosystem.
EuroCloud Federation
A proposed voluntary federation for Union entities and public-sector bodies to share eligible public-sector data-centre and cloud services.
Contracting authority
A public buyer subject to EU public-procurement rules; the proposal would place specified cloud-purchasing obligations on such authorities.
Union assurance level
A proposed recognised level of cloud sovereignty assurance. Level 1 is the baseline for non-identified activities, while levels 2 to 4 would apply where the assessment identifies relevant public-order activities.
Dynamic purchasing system
An electronic purchasing process that can remain open to new suppliers during its period of validity and could be operated by the Commission under the proposed common-procurement framework.
Third-country access risk
The risk that a third country or entity established there could obtain unlawful access under Union law to data processed through a cloud service.
Migration transition period
Where an Article 29 assessment requires migration to another cloud service, the proposal limits the reasonable transition period to no more than 12 months.
Cloud and AI Development Act
The Commission proposal adopted on June 3, 2026, to establish measures for strengthening Europe's cloud and AI ecosystem. As of July 19, 2026, it remains an ongoing legislative proposal.
Public-order risk assessment
The proposed recurring assessment under Article 29 that links public activities, data and access risks, service-disruption risks, and an appropriate assurance level.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself