CADA tracker · source extraction
Article 2
Definitions
For the purposes of this Regulation, the following definitions apply:
(1) ‘cloud computing service’ means cloud computing service as defined in Article 6,
point (30), of Directive (EU) 2022/2555;
(2) ‘cloud computing service provider’ means a legal entity which provides a cloud
computing service;
(3) ‘AI system’ means an AI system as defined in Article 3, point (1), of Regulation
(EU) 2024/1689;
(4) ‘frontier AI’ means AI models or AI systems built upon such models that can
perform a wide variety of tasks and that approach, reach or exceed the current state
of the art;
(5) ‘AI agent’ means an AI system or a coordinated set of AI systems, that can perceive
and act upon their environment, with a degree of autonomy, using tools as needed to
achieve specific goals and adapt to changing inputs and contexts;
(6) ‘public sector body’ means public sector body as defined in Article 2, point (1), of
Directive (EU) 2019/1024;
(7) ‘Union entities’ means the Union institutions, bodies, offices and agencies set up by
or pursuant to the Treaty on European Union, the Treaty on the Functioning of the
European Union (TFEU) or the Treaty establishing the European Atomic Energy
Community;
(8) ‘small and medium-sized enterprise’ or ‘SME’ means a small or medium-sized
enterprise as defined in Article 2 of Annex I to Commission Recommendation
2003/361/EC;
(9) ‘small mid-cap’ or ‘SMC’ means a small mid-cap enterprise as defined in point 2 of
the Annex to Commission Recommendation (EU) 2025/1099;
(10) ‘data centre’ means data centre as defined in point 2.6.3.1.16 of Annex A to
Regulation (EC) No 1099/2008 of the European Parliament and of the Council;
(11) ‘data centre operator’ means data centre operator as defined in Article 2, point (7), of
Delegated Regulation (EU) 2024/1364;
(12) ‘data centre service’ means data centre service as defined in Article 6, point (31), of
Directive (EU) 2022/2555;
(13) ‘software’ means software as defined in Article 3, point (4), of Regulation (EU)
2024/2847;
(14) ‘hardware’ means hardware as defined in Article 3, point 5, of Regulation (EU)
2024/2847;
(15) ‘component’ means component as defined in Article 3, point (6), of Regulation (EU)
2024/2847;
(16) ‘manufacturer’ means manufacturer as defined in Article 3, point (13), of Regulation
(EU) 2024/2847;
(17) ‘auditing organisation’ means an individual organisation, a consortium or other
combination of organisations, including any subcontractors, that the audited cloud
computing service provider has contracted to perform an independent audit;
(18) ‘audited service’ means a cloud computing service being audited for the purpose of
receiving an audit report and an audit opinion;
(19) ‘audit criteria’ means the criteria, pursuant to Annex II to this Regulation, against
which the auditing organisation assesses whether the audited provider and its audited
service comply with each cumulative criterion to be met for it to be recognised as
offering Union assurance levels 2, 3, or 4;
(20) ‘audit evidence’ means any information used by an auditing organisation to support
the audit findings and conclusions and to issue an audit opinion, including data
collected from documents, databases or IT systems, interviews or testing performed;
(21) ‘control’ means control as defined in Article 2, point (6), of Regulation (EU)
2021/697;
(22) ‘contracting authorities’ means contracting authorities as defined in Article 2(1),
point (1), of Directive 2014/24/EU;
(25) ‘open source licence’ means open source licence as defined in Article 2, point (12),
of Regulation (EU) 2024/903.