CADA tracker · source extraction

Annex II

printed pages 4–10 · source locator: Annex II; printed pages 4–10

Official source: COM(2026) 502 final — Annexes I–III

ANNEX II

CRITERIA FOR UNION ASSURANCE LEVELS
     This Annex sets out the criteria to be met by cloud computing service providers and their
     cloud computing services in order to be recognised as offering services at Union assurance
     levels 1, 2, 3 and 4. For the purpose of the criteria under Union assurance levels 1, 2, 3, and 4,
     ‘software’ within the meaning of Regulation (EU) 2024/2847, Article 3, point (4) falls within
     the scope of this Annex and Annex III to this Regulation. ‘Hardware’ within the meaning of
     Regulation (EU) 2024/2847, Article 3, point (5) is outside of the scope.
     1.       Union assurance level 1
     1.1.     For Union assurance level 1, cloud computing service providers must meet the
              following cumulative criteria:
     (a)      the cloud computing service provider is established in the Union;
     (b)      the infrastructure and assets of the cloud computing service provider, including those
              of its subcontractors which are involved in the provision of the service, are located in
              the Union unless the public sector body explicitly requires otherwise;
     (c)      the customer data, including metadata and telemetry data, that is processed, stored
              and transferred by the cloud computing service provider, and by the subcontractors,
              which are involved in the provision of the service, remain exclusively within the
              Union, unless the public sector body explicitly requires otherwise and at any time,
              including before, during or after the configuration or use of the service;
     (d)      where the cloud computing service provider outsources the technical and operational
              support or assistance, including any subsequent sub-outsourcing arrangements, to
              third-party service providers outside of the Union, the necessary legal, technical and
              organisational measures are implemented to ensure traceability, security and
              governance of those operations and those operations do not, in any way, compromise
              the operational autonomy of the cloud computing service provider;
     (e)      the cloud computing service provider demonstrates that the service complies with the
              state-of-the-art cybersecurity standards;
     (f)      the cloud computing service provider provides full transparency around the use of
              subcontractors. The cloud computing service provider subjects subcontractors to due
              diligence, contractual obligations and ongoing oversight to meet Union legal
              obligations;
     (g)      Where the cloud computing service provider is subject to the control of a third
              country or a legal entity established in a third-country, the cloud computing service
              provider guarantees that there are no existing laws and practices in that third country,
              demonstrated by independent sources, that require the cloud computing service
              provider to report information on software vulnerabilities to authorities of that third
              country prior to those vulnerabilities being known to have been exploited.
     1.2.     For Union assurance level 1, the subcontractors referred to in the first paragraph
              must be subcontractors that are third parties that have a direct contractual
              relationship with the cloud computing service provider and that contribute to the
              provision and the delivery of the cloud computing service.
     2.       Union assurance level 2

     2.1.   For Union assurance level 2, cloud computing service providers must meet the
            following cumulative criteria:
     (a)    the audited provider and the subcontractors which are involved in the provision of
            the audited service are established in the Union;
     (b)    the infrastructure, assets, and personnel of the audited provider, including those of its
            subcontractors which are involved in the provision of the service are located in the
            Union;
     (c)    the customer data, including metadata and telemetry data, that is processed, stored
            and transferred by the audited provider and the subcontractors which are involved in
            the provision of the service, remain exclusively within the Union, unless the public
            sector body explicitly requires otherwise and at any time, including before, during or
            after the configuration or use of the service;
     (d)    if the public sector body determines that imposing additional personnel screening and
            Union citizenship requirements are necessary, the audited provider should ensure that
            presonnel meeting those requirements are available;
     (e)    the audited service obtains a European cybersecurity certificate of at least assurance
            level ‘substantial’ under a European cybersecurity certification scheme covering
            cloud computing services to be established under Regulation (EU) 2019/881,
            provided that such a scheme has been established under that Regulation and is
            available to cloud computing service providers. Until the establishment of such a
            scheme, national cybersecurity certification schemes shall apply, where they exist.
            Where no Union or national cybersecurity certification schemes exist, the audited
            provider is to demonstrate that the service complies with the highest cybersecurity
            standards under applicable Union law;
     (f)    the data generated by using the audited service are not used to train or fine-tune any
            AI system operated by a third country or a legal entity established in a third-country ,
            and are not transferred outside the Union in any case;
     (g)    if the audited provider and the subcontractors which are involved in the provision of
            the audited service are subject to the control of a third country or a legal entity
            established in a third-country, they demonstrate that the necessary legal, technical
            and organisational measures have been implemented to ensure that the:
            i.     control of the third country or the legal entity established in a third-country
                   over the audited provider is not exercised in a manner that restrains or restricts
                   the provider’s ability to perform and deliver the service, imposes limitations on
                   the infrastructure, assets, and personnel required for the service provision, or
                   undermines the capabilities and standards necessary to perform the audited
                   service;
            ii.    access by a third country or by a legal entity established in a third-country to
                   customer data is prevented;
            iii.   possibility of disruption of the service continuity and/or the degradation of the
                   service quality by a third country or a legal entity established in a third country
                   is prevented;
            iv.    control of the third country or the legal entity established in a third-country
                   over the audited provider is not exercised in a manner that obliges the audited
                   provider to implement, enforce, give effect to, or comply with restrictive
                   measures such as sanction regimes, embargoes, or any equivalent legal or

                   administrative measures adopted by a third country, unless such measures are
                   legitimate under the national laws of Member States or Union law
     (h)    the technical and operational support or assistance related to the audited service,
            including subsequent sub-outsourcing arrangements, are initiated and performed
            exclusively within the Union;
     (i)    the audited provider demonstrates that the following software supply chain measures
            are in place:
            i.     a complete and up-to-date software bill of materials (SBOM), as defined in
                   Article 3, point (39), of Regulation (EU) 2024/2847,and a list of identified
                   dependencies relevant to the provision of the service are documented and made
                   available to the auditing organisation;
            ii.    where software components as defined in Regulation (EU) 2024/2847 Article
                   3, point 6 or products are provided, owned, and licensed by a legal entity
                   established in a third country, controls are implemented and documented to
                   block any remote features that could materially tamper with or disrupt a device,
                   system, or software (including during updates) and to ensure that the security-
                   relevant components from third-country software manufacturers, as defined in
                   Regulation (EU) 2024/2847 Article 3, point 13, are subject to source code
                   audits, and have a documented migration plan in the event that the vendor fails
                   or a third country imposes restrictions;
            iii.   where the cloud computing service provider is subject to the control of a third
                   country or a legal entity established in a third-country, the cloud computing
                   service provider guarantees that there are no existing laws and practicesin that
                   third country, demonstrated by independent sources, that require the cloud
                   computing service provider to report information on software vulnerabilities to
                   authorities of that third country prior to those vulnerabilities being known to
                   have been exploited;
     (j)    where software released under an open-source licence is used for the provision of the
            service, the audited provider demonstrates that it has implemented and documented
            the appropriate controls to prevent the use of any remote features or mechanisms that
            could be used to materially tamper with or disrupt a device, system, or software;
     (k)    to the extent that the audited provider provides its services globally and maintains a
            subsidiary in a third country, the audited provider has implemented the necessary
            measures to ensure and enforce the effective legal, technical and organisational
            separation between the Union parent company and any such third-country subsidiary.
     2.2.   For Union assurance level 2, the subcontractors referred to in the first paragraph
            must be subcontractors that are third parties that have a direct contractual
            relationship to the cloud computing service provider and that contribute to the
            provision and delivery of the cloud computing service.
     3.     Union assurance level 3
     3.1.   For Union assurance level 3, cloud computing service providers must meet the
            following cumulative criteria:
     (a)    the audited provider and the subcontractors which are involved in the provision of
            the audited service are established in the Union;

     (b)   the infrastructure, assets, and personnel of the audited provider, including those of
           the subcontractors which are involved in the provision of the service, are located in
           the Union;
     (c)   the customer data, including metadata and telemetry data, that is processed, stored
           and transferred by the audited provider and the subcontractors which are involved in
           the provision of the service, remain exclusively within the Union unless the public
           sector body explicitly requires otherwise and at any time, including before, during or
           after the configuration or use of the service;
     (d)   the personnel, including the personnel of the subcontractors which are involved in
           the provision of the audited service are Union citizens and where appropriate, the
           personnel must also have the necessary national security clearance issued by a
           Member State when handling classified information, as defined in Article 2, point
           (21), of Regulation (EU) 2021/697;
     (e)   the audited service obtains a European cybersecurity certificate of at least assurance
           level ‘substantial’ under a European cybersecurity certification scheme covering
           cloud computing services to be established under Regulation (EU) 2019/881,
           provided that such a scheme has been established under that Regulation and is
           available to cloud computing service providers. Until the establishment of such a
           scheme, national cybersecurity certification schemes shall apply, where they exisit.
           Where no Union or national cybersecurity certification schemes exist, the audited
           provider is to demonstrate that the service complies with the highest cybersecurity
           standards under applicable Union law;
     (f)   the data generated by using the audited service are not used to train or fine-tune any
           AI system operated by a third country or a legal entity established in a third-country
           and are not transferred outside the Union in any case;
     (g)   the audited provider and the subcontractors which are involved in the provision of
           the audited service are not subject to the control of a third country or a legal entity
           established in a third-country. By way of derogation to this criterion, a cloud
           computing service provider and its subcontractors which are involved in the
           provision of the audited service that are subject to the control of a third country or a
           legal entity established in a third-country may be audited for Union assurance level
           3 where the Commission has adopted an implementing act under Article 19. Where
           the Commission has adopted an implementing act under Article 19, the audited
           provider and the subcontractors which are involved in the provision of the audited
           service must also demonstrate that the necessary legal, technical and organisational
           measures have been implemented to ensure that the:
           i.     control of the third country or the legal entity established in a third-country
                  over the audited provider is not exercised in a manner that restrains or restricts
                  the provider’s ability to perform and deliver the service, imposes limitations on
                  the infrastructure, assets, and personnel required for the service provision, or
                  undermines the capabilities and standards necessary to perform the audited
                  service. The audited provider should allow for reasonable access to the code;
           ii.    access by a third country or by a legal entity established in a third-country to
                  customer data is prevented;
           iii.   possibility of disruption of the service continuity and/or the degradation of the
                  service quality by a third country or a legal entity established in a third country
                  is prevented;

            iv.    control of the third country or the legal entity established in a third-country
                   over the audited provider is not exercised in a manner that obliges the audited
                   provider to implement, enforce, give effect to, or comply with restrictive
                   measures such as sanction regimes, embargoes, or any equivalent legal or
                   administrative measures adopted by a third country, unless such measures are
                   legitimate under the national laws of Member States or Union law;
     (h)     the technical and operational support or assistance related to the audited service,
            including subsequent sub-outsourcing arrangements, are initiated and performed
            exclusively within the Union, by personnel that are Union residents, and by third
            parties that are not subject to the control of a third country or a legal entity
            established in a third country;
     (i)    the audited provider demonstrates that the following software supply chain measures
            are in place:
            i.     a complete and up-to-date SBOM and a list of identified dependencies relevant
                   to the provision of the service are documented and made available to the
                   auditing organisation;
            ii.    where software components or products are provided, owned, and licensed by a
                   legal entity established in a third country, controls are implemented and
                   documented to block any remote features that could materially tamper with or
                   disrupt a device, system, or software (including during updates) and to ensure
                   that the security-relevant components from third-country manufacturers are
                   subject to source code audits, and have a documented migration plan in the
                   event that the vendor fails or a third country imposes restrictions;
            iii.   where the cloud computing service provider is subject to the control of a third
                   country or a legal entity established in a third-country, the cloud computing
                   service provider guarantees that there are no existing laws and practices in that
                   third country, demonstrated by independent sources, that require the cloud
                   computing service provider to report information on software vulnerabilities to
                   authorities of that third country prior to those vulnerabilities being known to
                   have been exploited;
     (j)    where software released under an open-source licence is used for the provision of the
            service, the audited provider demonstrates that it has implemented and documented
            the appropriate controls to prevent the use of any remote features or mechanisms that
            could be used to materially tamper with or disrupt a device, system, or software;
     (k)    to the extent that the audited provider provides its services outside of the Union and
            maintains a subsidiary in a third country, the audited provider demonstrates that it
            has implemented the necessary measures to ensure and enforce the effective legal,
            technical and organisational separation between the Union parent company and any
            such third-country subsidiary.
     3.2.   For Union assurance level 3, the subcontractors referred to in the first paragraph
            must be subcontractors that are third parties that have a direct contractual
            relationship to the cloud computing service provider and that contribute to the
            provision and the delivery of the cloud computing service, and that may require
            access to classified or sensitive information, as defined in Article 2, point (22), of
            Regulation (EU) 2021/697.
     4.     Union assurance level 4

     4.1.   For Union assurance level 4, cloud computing service providers must meet the
            following cumulative criteria:
     (a)    the audited provider and the subcontractors which are involved in the provision of
            the audited service are established in the Union;
     (b)    the infrastructure, assets, and personnel of the audited provider, including the
            subcontractors , which are involved in the provision of the service, are located in the
            Union;
     (c)    the customer data, including metadata and telemetry data, which, following a risk
            assessment, is identified as sensitive, that is processed, stored and transferred by the
            audited provider and the subcontractors which are involved in the provision of the
            service, remain exclusively within the Union and at any time, including before,
            during or after the configuration or use of the service;
     (d)    the personnel, including the personnel of the subcontractors , which are involved in
            the provision of the audited service are Union citizens and, where appropriate, the
            personnel must also have the necessary national security clearance issued by a
            Member State when handling classified information;
     (e)    the audited service obtains a European cybersecurity certificate of at least assurance
            level ‘high’ under a European cybersecurity certification scheme covering cloud
            computing services to be established under Regulation (EU) 2019/881, provided that
            such a scheme has been established under that Regulation and is available to cloud
            computing service providers. Until the establishment of such a scheme, national
            cybersecurity certification schemes shall apply, where they exist. Where no Union or
            national cybersecurity certification schemes exist, the audited provider is to
            demonstrate that the service complies with the highest cybersecurity standards under
            applicable Union law;
     (f)    the data generated by using the audited service are not used to train or fine-tune any
            AI system operated by a third country or a legal entity established in a third-country,
            and are not transferred outside the Union in any case;
     (g)    the audited provider and the subcontractors which are involved in the provision of
            the audited service are not subject to the control of a third country or a legal entity
            established in a third-country;
     (h)    the technical and operational support or assistance related to the audited service,
            including subsequent sub-outsourcing arrangements, are initiated and performed
            exclusively within the Union, by personnel that are Union residents, and by third
            parties that are not subject to the control of a third country or a legal entity
            established in a third country;
     (i)    the audited provider demonstrates that the following software supply chain measures
            are in place:
            i.    a complete and up-to-date SBOM and a list of identified dependencies relevant
                  to the provision of the service are documented and made available to the
                  auditing organisation;
            ii.   measures in place to retain effective control over the software components or
                  products by demonstrating that a third country or a legal entity established in a
                  third country does not hold or exercise effective control over the design,
                  development, maintenance, and evolution of those components or products.
                  Effective control includes the ability to materially influence the technical

                 evolution, maintenance priorities, security remediation, and long-term
                 continuity of the component;
     (j)    where software released under an open-source licence is used, the audited provider
            demonstrates that it has implemented and documented the appropriate controls to
            prevent the use of any remote features or mechanisms that could be used to
            materially tamper with or disrupt a device, system, or software;
     (k)    to the extent that the audited provider provides its services outside of the Union and
            maintains a subsidiary in a third country, the audited provider demonstrates that it
            has implemented the necessary measures to ensure and enforce the effective legal,
            technical and organisational separation between the Union parent company and any
            such third-country subsidiary.
     4.2.   For Union assurance level 4, the subcontractors referred to in the first paragraph
            must be subcontractors that are third parties that have a direct contractual
            relationship to the cloud computing service provider, that contribute to the provision
            and delivery of the cloud computing service, and that may require access to classified
            or sensitive information in order to carry out the service provision.

Qualifications