The EU’s Proposed CADA: Why Cloud Sovereignty Matters for Business Strategy

Table of Contents

Here’s a number that explains a lot about where European tech policy is headed right now: in 2017, European cloud providers held about 29% of their own home market. By 2022, that figure had fallen to roughly 15%, and it has barely moved since. Three American companies, Amazon, Microsoft, and Google, now account for around 70% of cloud computing across the continent. That erosion, playing out over just five years, is the backdrop for the European Commission’s newest and most ambitious attempt to change course: the proposed Cloud and AI Development Act, or CADA. Published on June 3, 2026, as the centerpiece of the Commission’s wider Tech Sovereignty Package, CADA is the EU’s attempt to make its cloud and AI ecosystem, in the Commission’s own words, more competitive and resilient. Natallia Karniyevich, a cybersecurity partner at McDermott Will & Schulte, and Müge Fazlioglu, principal researcher for privacy law and policy at the IAPP, recently walked through what the proposal actually contains and why it deserves attention well beyond the usual circle of EU regulatory watchers. Their analysis is worth unpacking, because CADA isn’t really a data protection law or a cybersecurity law in the traditional sense. It’s an attempt to use the EU’s own purchasing power to reshape who gets to build the infrastructure Europe’s economy increasingly runs on.

What CADA is actually trying to fix

The Commission’s diagnosis of the problem has two parts. First, Europe doesn’t have enough of its own data center capacity to keep pace with demand, especially as AI workloads scale up. Second, and more politically charged, the continent has become dependent on a small handful of non-EU cloud providers for infrastructure that increasingly underpins everything from hospital records to defense systems. CADA tries to address both problems at once. On the supply side, it includes measures meant to expand European compute capacity. On the demand side, and this is the part getting most of the attention, it uses public procurement rules to steer government spending toward providers that meet certain sovereignty criteria. That second piece is where things get interesting for any business that sells cloud or AI services into the European public sector, or that supplies components to companies that do.

The four assurance levels, explained plainly

At the heart of CADA sits a graduated system called the Union Assurance Levels, four tiers that link a cloud provider’s security, resilience, and sovereignty posture to how much of the EU public sector market it can actually serve. Here’s roughly how they break down:
  1. Level 1 is the baseline. With only narrow exceptions, every cloud provider that wants to sell to the EU public sector will need to meet this floor, regardless of what it’s selling or to whom.
  2. Level 2 and Level 3 apply where a Member State or EU body determines, through a formal risk assessment, that a particular use case has what the proposal calls “public order relevance.” Level 3 goes further than most people expect. It sets EU citizenship as a baseline requirement for the staff who operate the service, not just a preference, and adds security clearance requirements where classified information is involved.
  3. Level 4 is reserved for the most sensitive categories, think defense and national security processing, and it’s a different kind of test entirely. At this tier, having servers physically located in the EU is no longer enough. The provider itself, along with its software supply chain, cannot be subject to the effective control of a non-EU country. That’s a much harder bar to clear than a data residency requirement, and it’s the one detail in CADA that has drawn the most pushback from global providers with EU subsidiaries.
It’s worth being precise about what CADA does and doesn’t do here. This isn’t a ban on non-EU providers. The framework is explicitly designed to be risk based and procurement driven rather than exclusionary, meaning global hyperscalers can still participate, just under a heavier compliance load the higher up the assurance ladder their customers’ use cases sit. According to the proposal’s own recitals, most public services won’t need anything close to the top tier. Levels 3 and 4 are meant for specific, sensitive cases, with the risk assessment process designed to keep the requirements proportionate rather than sweeping. Whether that proportionality holds up in practice is a separate question. Because the risk assessments are conducted at the Member State level using a Commission template, there’s real potential for individual countries to apply the assurance levels differently depending on local political appetite, which could leave providers facing a patchwork of expectations across the EU rather than one uniform standard.

This isn’t coming from nowhere

If the assurance level concept sounds familiar, that’s because it is. CADA borrows heavily from France’s SecNumCloud regime, a national sovereignty certification scheme that has already been running for several years. It also revives an idea that nearly made it into EU law once before: sovereignty requirements were debated extensively during work on the EU cloud cybersecurity certification scheme, known as EUCS, before ultimately being stripped out of that framework. CADA effectively brings that idea back, except this time as directly applicable law tied to procurement rather than as an optional certification criterion. France’s experience with SecNumCloud also offers a useful, slightly uncomfortable lesson for how CADA might play out. Even fully qualified French entities under that scheme haven’t been able to escape technological dependence on American hyperscalers entirely. Two notable examples, S3NS and Bleu, are French sovereign cloud offerings built respectively on Google and Microsoft infrastructure. France’s own cybersecurity agency has acknowledged the limits of what a national qualification can guarantee when the underlying technology stack still traces back to a non-EU parent company. That tension, between wanting sovereign infrastructure and needing the technical capability that mostly still lives with a few large American firms, is likely to follow CADA through its own implementation.

How CADA fits alongside everything else

One of the more practically important points in Karniyevich and Fazlioglu’s analysis is that CADA doesn’t operate in isolation. It layers directly onto an already dense stack of EU digital regulation. The proposal creates explicit connections to existing cybersecurity certification requirements, incident reporting obligations, and AI risk classification rules that many affected companies are already working through. Notably, the framework also extends beyond government buyers. Private companies that qualify as “essential entities” under the NIS2 Directive, which covers a wide range of critical infrastructure operators, may end up conducting similar sovereignty risk assessments on their own cloud vendors, effectively pulling CADA’s logic into private sector procurement even though the law’s formal scope is public sector focused. For a compliance or procurement team, that’s the detail worth sitting with. A company that never sells directly to an EU government body could still feel CADA’s effects indirectly, either because a public sector customer down the supply chain starts asking sovereignty questions, or because an essential entity under NIS2 begins treating assurance levels as part of its own vendor risk process.

Where this stands and what to watch

CADA is still just a proposal. It needs to move through negotiations between the European Parliament and the Council before anything becomes binding, and the cloud sovereignty framework in particular is expected to be one of the central battlegrounds in that process. Final adoption isn’t expected until the end of 2027 at the earliest. That said, treating this as a distant, theoretical concern would be a mistake. The Commission has already adopted its own internal Cloud Sovereignty Framework for procurement within its own departments, setting concrete sovereignty objectives ahead of the broader law taking effect. Provider qualification decisions with multi-year timelines are already being shaped by where a company expects to land on these assurance tiers, regardless of exactly when the final text is signed. For any business with exposure to the European public sector, whether as a direct cloud provider, a software vendor building on top of one, or a supplier somewhere in that chain, the practical move right now isn’t to wait for the final regulation. It’s to start mapping where your own infrastructure and ownership structure would actually land under these four levels, particularly if any part of your business touches defense, government services, or other areas likely to draw a public order relevance finding. The criteria are specific enough to begin that internal exercise today, well before formal implementing guidance arrives. Given how much weight the Commission is placing on procurement as a lever for reshaping the market, the companies that understand their own assurance level early are the ones that will be positioned to compete for that business once the rules actually bite.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.