On 3 June 2026, the European Commission adopted its proposal for the Cloud and AI Development Act (CADA) — a Regulation built to close a gap the numbers make hard to ignore: three non-EU hyperscalers currently control over 70% of the EU cloud market, while EU providers’ own share has fallen from 29% (2017) to 15% (2022) and has stagnated since.

CADA is still moving through the ordinary legislative procedure — Parliament and Council negotiations are expected to run for roughly 15 months, with the Regulation becoming directly applicable across all Member States one year after entry into force. But for cloud providers, data-centre operators and public-sector buyers, waiting for the final text is not really an option: the framework’s core mechanic — a four-level Union assurance system — is already clear enough to start preparing against.

Four assurance levels — and a two-step test that decides which one applies

CADA doesn’t classify products the way some other EU digital regulations do. It classifies activities and the cloud services that support them, on a scale from Level 1 to Level 4, through a two-step test under Article 29:

● Step 1 — Public order screening: does the activity touch public order?

● Step 2 — Risk-based level selection: for flagged activities, the exact level depends on data sensitivity, the risk of unlawful third-country access, and the risk of service disruption — with Level 4 reserved for the most critical cases, such as defence.

What makes this genuinely tricky in practice is a distinction that’s easy to miss: the Article 29 criteria determine which level a given public-sector activity requires, while a separate set of Annex II criteria determines whether a provider’s service actually qualifies to be recognized at that level. Getting only one half of that equation right is a common gap — and the Commission can override an inadequate level choice, with migration to a compliant service required within 12 months.

Why the level you land on changes your entire compliance burden

The assurance level isn’t just a label — it determines the evidentiary route. Level 1 allows cloud providers to self-certify against the Annex II criteria and publish an EU statement of conformity, with no third-party involvement. Levels 2 to 4 require a mandatory independent audit, with strict independence rules for the auditor: no non-audit services to the same provider in the prior 12 months, no audit engagement with that provider in the prior 10 years, and fees that cannot depend on the outcome. Each higher level is cumulative — it must still satisfy every requirement of the levels below it.

For data-center operators and cloud providers, this means the assurance-level question isn’t just a compliance checkbox — it shapes procurement eligibility from day one, since public bodies will be required to source Level 2+ services for public-order-sensitive workloads.

The real starting point: knowing where your cloud footprint actually sits

At Axon Advisory & Consulting, we help organizations map exactly this: which of your cloud-dependent activities are likely to be screened as public-order-sensitive, what assurance level that implies, and what a defensible self-assessment or audit file looks like at that level. Where self-assessment applies (Level 1), we can carry the exercise through with you end to end. For Levels 2 to 4, we offer both sides of the engagement — audit-readiness advisory to close your evidence gaps against the Annex II criteria, and, as an independent auditing organisation meeting the Article 20(4) requirements ourselves, the mandatory third-party audit itself, issuing the audit report and opinion your recognition file needs. In line with the same independence rules we’d be assessing you against, we take on only one role per client: if we’ve advised you, we won’t audit you, and vice versa — so which one we can offer depends on where you are in the process.

If your organization operates data centers, provides cloud or AI infrastructure, or procures cloud services for public-sector use, the practical question to start answering now isn’t whether CADA will apply — it’s which assurance level your activities are heading toward, and whether your current setup would actually meet it.

Let’s talk. The Axon Advisory & Consulting team can help you map your cloud footprint against CADA’s assurance framework, ahead of the final text landing.

#CADA #CloudSovereignty #DigitalSovereignty #EURegulation #AI #RiskManagement #AxonAdvisory