CADA tracker · source extraction
ANNEX II
CRITERIA FOR UNION ASSURANCE LEVELS
This Annex sets out the criteria to be met by cloud computing service providers and their
cloud computing services in order to be recognised as offering services at Union assurance
levels 1, 2, 3 and 4. For the purpose of the criteria under Union assurance levels 1, 2, 3, and 4,
‘software’ within the meaning of Regulation (EU) 2024/2847, Article 3, point (4) falls within
the scope of this Annex and Annex III to this Regulation. ‘Hardware’ within the meaning of
Regulation (EU) 2024/2847, Article 3, point (5) is outside of the scope.
1. Union assurance level 1
1.1. For Union assurance level 1, cloud computing service providers must meet the
following cumulative criteria:
(a) the cloud computing service provider is established in the Union;
(b) the infrastructure and assets of the cloud computing service provider, including those
of its subcontractors which are involved in the provision of the service, are located in
the Union unless the public sector body explicitly requires otherwise;
(c) the customer data, including metadata and telemetry data, that is processed, stored
and transferred by the cloud computing service provider, and by the subcontractors,
which are involved in the provision of the service, remain exclusively within the
Union, unless the public sector body explicitly requires otherwise and at any time,
including before, during or after the configuration or use of the service;
(d) where the cloud computing service provider outsources the technical and operational
support or assistance, including any subsequent sub-outsourcing arrangements, to
third-party service providers outside of the Union, the necessary legal, technical and
organisational measures are implemented to ensure traceability, security and
governance of those operations and those operations do not, in any way, compromise
the operational autonomy of the cloud computing service provider;
(e) the cloud computing service provider demonstrates that the service complies with the
state-of-the-art cybersecurity standards;
(f) the cloud computing service provider provides full transparency around the use of
subcontractors. The cloud computing service provider subjects subcontractors to due
diligence, contractual obligations and ongoing oversight to meet Union legal
obligations;
(g) Where the cloud computing service provider is subject to the control of a third
country or a legal entity established in a third-country, the cloud computing service
provider guarantees that there are no existing laws and practices in that third country,
demonstrated by independent sources, that require the cloud computing service
provider to report information on software vulnerabilities to authorities of that third
country prior to those vulnerabilities being known to have been exploited.
1.2. For Union assurance level 1, the subcontractors referred to in the first paragraph
must be subcontractors that are third parties that have a direct contractual
relationship with the cloud computing service provider and that contribute to the
provision and the delivery of the cloud computing service.
2. Union assurance level 2
2.1. For Union assurance level 2, cloud computing service providers must meet the
following cumulative criteria:
(a) the audited provider and the subcontractors which are involved in the provision of
the audited service are established in the Union;
(b) the infrastructure, assets, and personnel of the audited provider, including those of its
subcontractors which are involved in the provision of the service are located in the
Union;
(c) the customer data, including metadata and telemetry data, that is processed, stored
and transferred by the audited provider and the subcontractors which are involved in
the provision of the service, remain exclusively within the Union, unless the public
sector body explicitly requires otherwise and at any time, including before, during or
after the configuration or use of the service;
(d) if the public sector body determines that imposing additional personnel screening and
Union citizenship requirements are necessary, the audited provider should ensure that
presonnel meeting those requirements are available;
(e) the audited service obtains a European cybersecurity certificate of at least assurance
level ‘substantial’ under a European cybersecurity certification scheme covering
cloud computing services to be established under Regulation (EU) 2019/881,
provided that such a scheme has been established under that Regulation and is
available to cloud computing service providers. Until the establishment of such a
scheme, national cybersecurity certification schemes shall apply, where they exist.
Where no Union or national cybersecurity certification schemes exist, the audited
provider is to demonstrate that the service complies with the highest cybersecurity
standards under applicable Union law;
(f) the data generated by using the audited service are not used to train or fine-tune any
AI system operated by a third country or a legal entity established in a third-country ,
and are not transferred outside the Union in any case;
(g) if the audited provider and the subcontractors which are involved in the provision of
the audited service are subject to the control of a third country or a legal entity
established in a third-country, they demonstrate that the necessary legal, technical
and organisational measures have been implemented to ensure that the:
i. control of the third country or the legal entity established in a third-country
over the audited provider is not exercised in a manner that restrains or restricts
the provider’s ability to perform and deliver the service, imposes limitations on
the infrastructure, assets, and personnel required for the service provision, or
undermines the capabilities and standards necessary to perform the audited
service;
ii. access by a third country or by a legal entity established in a third-country to
customer data is prevented;
iii. possibility of disruption of the service continuity and/or the degradation of the
service quality by a third country or a legal entity established in a third country
is prevented;
iv. control of the third country or the legal entity established in a third-country
over the audited provider is not exercised in a manner that obliges the audited
provider to implement, enforce, give effect to, or comply with restrictive
measures such as sanction regimes, embargoes, or any equivalent legal or
administrative measures adopted by a third country, unless such measures are
legitimate under the national laws of Member States or Union law
(h) the technical and operational support or assistance related to the audited service,
including subsequent sub-outsourcing arrangements, are initiated and performed
exclusively within the Union;
(i) the audited provider demonstrates that the following software supply chain measures
are in place:
i. a complete and up-to-date software bill of materials (SBOM), as defined in
Article 3, point (39), of Regulation (EU) 2024/2847,and a list of identified
dependencies relevant to the provision of the service are documented and made
available to the auditing organisation;
ii. where software components as defined in Regulation (EU) 2024/2847 Article
3, point 6 or products are provided, owned, and licensed by a legal entity
established in a third country, controls are implemented and documented to
block any remote features that could materially tamper with or disrupt a device,
system, or software (including during updates) and to ensure that the security-
relevant components from third-country software manufacturers, as defined in
Regulation (EU) 2024/2847 Article 3, point 13, are subject to source code
audits, and have a documented migration plan in the event that the vendor fails
or a third country imposes restrictions;
iii. where the cloud computing service provider is subject to the control of a third
country or a legal entity established in a third-country, the cloud computing
service provider guarantees that there are no existing laws and practicesin that
third country, demonstrated by independent sources, that require the cloud
computing service provider to report information on software vulnerabilities to
authorities of that third country prior to those vulnerabilities being known to
have been exploited;
(j) where software released under an open-source licence is used for the provision of the
service, the audited provider demonstrates that it has implemented and documented
the appropriate controls to prevent the use of any remote features or mechanisms that
could be used to materially tamper with or disrupt a device, system, or software;
(k) to the extent that the audited provider provides its services globally and maintains a
subsidiary in a third country, the audited provider has implemented the necessary
measures to ensure and enforce the effective legal, technical and organisational
separation between the Union parent company and any such third-country subsidiary.
2.2. For Union assurance level 2, the subcontractors referred to in the first paragraph
must be subcontractors that are third parties that have a direct contractual
relationship to the cloud computing service provider and that contribute to the
provision and delivery of the cloud computing service.
3. Union assurance level 3
3.1. For Union assurance level 3, cloud computing service providers must meet the
following cumulative criteria:
(a) the audited provider and the subcontractors which are involved in the provision of
the audited service are established in the Union;
(b) the infrastructure, assets, and personnel of the audited provider, including those of
the subcontractors which are involved in the provision of the service, are located in
the Union;
(c) the customer data, including metadata and telemetry data, that is processed, stored
and transferred by the audited provider and the subcontractors which are involved in
the provision of the service, remain exclusively within the Union unless the public
sector body explicitly requires otherwise and at any time, including before, during or
after the configuration or use of the service;
(d) the personnel, including the personnel of the subcontractors which are involved in
the provision of the audited service are Union citizens and where appropriate, the
personnel must also have the necessary national security clearance issued by a
Member State when handling classified information, as defined in Article 2, point
(21), of Regulation (EU) 2021/697;
(e) the audited service obtains a European cybersecurity certificate of at least assurance
level ‘substantial’ under a European cybersecurity certification scheme covering
cloud computing services to be established under Regulation (EU) 2019/881,
provided that such a scheme has been established under that Regulation and is
available to cloud computing service providers. Until the establishment of such a
scheme, national cybersecurity certification schemes shall apply, where they exisit.
Where no Union or national cybersecurity certification schemes exist, the audited
provider is to demonstrate that the service complies with the highest cybersecurity
standards under applicable Union law;
(f) the data generated by using the audited service are not used to train or fine-tune any
AI system operated by a third country or a legal entity established in a third-country
and are not transferred outside the Union in any case;
(g) the audited provider and the subcontractors which are involved in the provision of
the audited service are not subject to the control of a third country or a legal entity
established in a third-country. By way of derogation to this criterion, a cloud
computing service provider and its subcontractors which are involved in the
provision of the audited service that are subject to the control of a third country or a
legal entity established in a third-country may be audited for Union assurance level
3 where the Commission has adopted an implementing act under Article 19. Where
the Commission has adopted an implementing act under Article 19, the audited
provider and the subcontractors which are involved in the provision of the audited
service must also demonstrate that the necessary legal, technical and organisational
measures have been implemented to ensure that the:
i. control of the third country or the legal entity established in a third-country
over the audited provider is not exercised in a manner that restrains or restricts
the provider’s ability to perform and deliver the service, imposes limitations on
the infrastructure, assets, and personnel required for the service provision, or
undermines the capabilities and standards necessary to perform the audited
service. The audited provider should allow for reasonable access to the code;
ii. access by a third country or by a legal entity established in a third-country to
customer data is prevented;
iii. possibility of disruption of the service continuity and/or the degradation of the
service quality by a third country or a legal entity established in a third country
is prevented;
iv. control of the third country or the legal entity established in a third-country
over the audited provider is not exercised in a manner that obliges the audited
provider to implement, enforce, give effect to, or comply with restrictive
measures such as sanction regimes, embargoes, or any equivalent legal or
administrative measures adopted by a third country, unless such measures are
legitimate under the national laws of Member States or Union law;
(h) the technical and operational support or assistance related to the audited service,
including subsequent sub-outsourcing arrangements, are initiated and performed
exclusively within the Union, by personnel that are Union residents, and by third
parties that are not subject to the control of a third country or a legal entity
established in a third country;
(i) the audited provider demonstrates that the following software supply chain measures
are in place:
i. a complete and up-to-date SBOM and a list of identified dependencies relevant
to the provision of the service are documented and made available to the
auditing organisation;
ii. where software components or products are provided, owned, and licensed by a
legal entity established in a third country, controls are implemented and
documented to block any remote features that could materially tamper with or
disrupt a device, system, or software (including during updates) and to ensure
that the security-relevant components from third-country manufacturers are
subject to source code audits, and have a documented migration plan in the
event that the vendor fails or a third country imposes restrictions;
iii. where the cloud computing service provider is subject to the control of a third
country or a legal entity established in a third-country, the cloud computing
service provider guarantees that there are no existing laws and practices in that
third country, demonstrated by independent sources, that require the cloud
computing service provider to report information on software vulnerabilities to
authorities of that third country prior to those vulnerabilities being known to
have been exploited;
(j) where software released under an open-source licence is used for the provision of the
service, the audited provider demonstrates that it has implemented and documented
the appropriate controls to prevent the use of any remote features or mechanisms that
could be used to materially tamper with or disrupt a device, system, or software;
(k) to the extent that the audited provider provides its services outside of the Union and
maintains a subsidiary in a third country, the audited provider demonstrates that it
has implemented the necessary measures to ensure and enforce the effective legal,
technical and organisational separation between the Union parent company and any
such third-country subsidiary.
3.2. For Union assurance level 3, the subcontractors referred to in the first paragraph
must be subcontractors that are third parties that have a direct contractual
relationship to the cloud computing service provider and that contribute to the
provision and the delivery of the cloud computing service, and that may require
access to classified or sensitive information, as defined in Article 2, point (22), of
Regulation (EU) 2021/697.
4. Union assurance level 4
4.1. For Union assurance level 4, cloud computing service providers must meet the
following cumulative criteria:
(a) the audited provider and the subcontractors which are involved in the provision of
the audited service are established in the Union;
(b) the infrastructure, assets, and personnel of the audited provider, including the
subcontractors , which are involved in the provision of the service, are located in the
Union;
(c) the customer data, including metadata and telemetry data, which, following a risk
assessment, is identified as sensitive, that is processed, stored and transferred by the
audited provider and the subcontractors which are involved in the provision of the
service, remain exclusively within the Union and at any time, including before,
during or after the configuration or use of the service;
(d) the personnel, including the personnel of the subcontractors , which are involved in
the provision of the audited service are Union citizens and, where appropriate, the
personnel must also have the necessary national security clearance issued by a
Member State when handling classified information;
(e) the audited service obtains a European cybersecurity certificate of at least assurance
level ‘high’ under a European cybersecurity certification scheme covering cloud
computing services to be established under Regulation (EU) 2019/881, provided that
such a scheme has been established under that Regulation and is available to cloud
computing service providers. Until the establishment of such a scheme, national
cybersecurity certification schemes shall apply, where they exist. Where no Union or
national cybersecurity certification schemes exist, the audited provider is to
demonstrate that the service complies with the highest cybersecurity standards under
applicable Union law;
(f) the data generated by using the audited service are not used to train or fine-tune any
AI system operated by a third country or a legal entity established in a third-country,
and are not transferred outside the Union in any case;
(g) the audited provider and the subcontractors which are involved in the provision of
the audited service are not subject to the control of a third country or a legal entity
established in a third-country;
(h) the technical and operational support or assistance related to the audited service,
including subsequent sub-outsourcing arrangements, are initiated and performed
exclusively within the Union, by personnel that are Union residents, and by third
parties that are not subject to the control of a third country or a legal entity
established in a third country;
(i) the audited provider demonstrates that the following software supply chain measures
are in place:
i. a complete and up-to-date SBOM and a list of identified dependencies relevant
to the provision of the service are documented and made available to the
auditing organisation;
ii. measures in place to retain effective control over the software components or
products by demonstrating that a third country or a legal entity established in a
third country does not hold or exercise effective control over the design,
development, maintenance, and evolution of those components or products.
Effective control includes the ability to materially influence the technical
evolution, maintenance priorities, security remediation, and long-term
continuity of the component;
(j) where software released under an open-source licence is used, the audited provider
demonstrates that it has implemented and documented the appropriate controls to
prevent the use of any remote features or mechanisms that could be used to
materially tamper with or disrupt a device, system, or software;
(k) to the extent that the audited provider provides its services outside of the Union and
maintains a subsidiary in a third country, the audited provider demonstrates that it
has implemented the necessary measures to ensure and enforce the effective legal,
technical and organisational separation between the Union parent company and any
such third-country subsidiary.
4.2. For Union assurance level 4, the subcontractors referred to in the first paragraph
must be subcontractors that are third parties that have a direct contractual
relationship to the cloud computing service provider, that contribute to the provision
and delivery of the cloud computing service, and that may require access to classified
or sensitive information in order to carry out the service provision.