CADA is not simply another cloud regulation. Published in June 2026 as the centrepiece of the EU Tech Sovereignty Package, it converts sovereignty from a marketing claim into a procurement condition: four Union assurance levels, a mandatory floor for all public-sector supply, and higher tiers reserved for workloads judged relevant to public order.
The decisive question is whether eligibility is settled by ownership or by verifiable safeguards. That single design choice determines whether hyperscalers can qualify through architectural separation, or whether European operators hold protected demand outright. Because each Member State runs its own risk assessment, the same service may qualify differently across markets. CADA is still a proposal in trilogue, but its qualification logic is already the planning basis for portfolio, partnership and European capacity decisions.
From sovereignty claim to procurement condition
The shift is from voluntary positioning to audited recognition. The stated objective is to strengthen Europe's strategic autonomy by scaling sovereign cloud and AI infrastructure, reducing critical dependencies and improving the EU's ability to compete in the global digital economy.
What changes in practice is the burden of proof. A sovereignty claim used to be a positioning statement. Under CADA it becomes a status that has to be demonstrated, audited and recognised before a service can be offered to parts of the public sector.
The four pillars of the proposal

- Common assurance levels. Four Union assurance levels create a shared language for sovereign cloud requirements.
- Audit and recognition. Providers must show evidence. Higher levels rely on independent audits and national authority recognition.
- Public-sector pull. Risk assessments can force sensitive workloads toward recognised sovereign cloud services.
- EU added value. Open source, European supply-chain contribution and common procurement become differentiators.
What CADA asks of hyperscalers
Three obligations follow from the proposal, and each one touches the operating model rather than the marketing layer.
- Repackage. Higher assurance levels may require dedicated EU entities, clearer operating boundaries and stronger continuity arrangements.
- Prove. Claims must withstand audit evidence on software supply chain, operational continuity and jurisdictional exposure.
- Partner. Local telecom, defence and cloud operators help bridge sovereignty gaps without replacing hyperscaler technology.
A fourth response runs alongside them. Global providers are lobbying for risk-based eligibility and against ownership-driven exclusion, localisation requirements and closed procurement.
Where the industry pushes back
Google Cloud supports Europe's sovereignty agenda but argues that CADA should recognise verifiable technical, operational and encryption controls rather than exclude trusted global providers by ownership.
We believe certain elements of the Cloud and AI Development Act should be changed to avoid unintended market isolation.
Giorgia Abeltino, Head of Government Affairs and Public Policy, Google Cloud EMEA, 18 June 2026
The endorsement is explicit on the objectives: Europe's aim to strengthen digital sovereignty, security and infrastructure capacity, harmonised EU sovereignty criteria with tiered compliance across Member States, open and interoperable cloud ecosystems that improve portability, faster permitting and grid access for sustainable data centres, and European partnerships that combine global technology with local operational and jurisdictional controls.
The demands are equally explicit:
- CADA should not exclude trusted global providers solely because of corporate ownership.
- Assurance levels should recognise verifiable technical, operational and encryption-based sovereignty controls.
- Rigid geographic criteria could disrupt supply chains and constrain European customer choice.
- Trusted non-EU partners should remain eligible where safeguards mitigate extraterritorial access risks.
- Openness must extend across infrastructure, AI models and applications to prevent lock-in.

The other initial reactions follow the same line. AWS and CCIA warn that ownership-based assurance levels could fragment the EU cloud market. Microsoft and BSA support stronger resilience but oppose ownership restrictions and localisation mandates. The objection is narrow and shared: not the goal, but origin as the test.
What the market is saying
We reviewed 106 public commentaries on the proposal. The debate has moved past the sovereignty question itself. What is contested now is whether CADA can create competitive European capacity without weak assurance, insufficient demand or discriminatory access.
- 51 percent read CADA as a mechanism for translating sovereignty ambitions into market demand and European capacity.
- 42 percent support the objective but expect implementation choices to decide whether CADA delivers genuine sovereignty.
- 7 percent warn that origin-based eligibility could restrict technology choice, investment and consistent EU-wide implementation.

Six themes carry the discussion, ranked by how often they came up:
- Procurement becomes the sovereignty gatekeeper (80 mentions). Procurement is CADA's primary enforcement lever. Assurance levels and non-price criteria decide who may serve public bodies.
- Ownership replaces simple data residency (70). EU data hosting alone is rejected as sovereignty. The focus turns to ownership, jurisdiction, encryption control and foreign dependence.
- Assurance levels reshape cloud competition (54). A four-level framework segments the market by sensitivity and adds EU-control, third-country independence and supply-chain demands.
- Open source becomes strategic infrastructure (41). Open source is treated as industrial policy, a lever to cut vendor lock-in and build interoperable, EU-rooted ecosystems.
- Europe must build, not regulate (38). CADA is read as a shift from regulating foreign platforms to building EU capacity in cloud, data centres and AI compute.
- AI access becomes geopolitical risk (32). Sovereignty expands beyond data to GPUs, foundation models and training frameworks, where reliance on non-EU suppliers is treated as a vulnerability.

Achieving a Union assurance level becomes effectively mandatory for any cloud provider that wants to sell to the public sector.
Senior Director, Global Public Policy, global enterprise software provider
Most of the market will now default to one question: which level can this stack pass?
Chief Strategy Officer, technology strategy consultancy
How do you build sovereign infrastructure when GPU chips, foundation models and training frameworks are dominated by non-European firms?
Chief Product Officer and Board Member, European cloud provider
Portfolio economics: a two-speed cloud market
CADA and the Cloud Sovereignty Framework could turn sovereignty into a portfolio profit-and-loss decision.
- The real impact is felt at service level. Hyperscalers may retain broad market access while losing eligibility for specific workloads where operational control, software dependencies or supply-chain exposure remain unresolved.
- This forces harder portfolio segmentation. Providers will need to decide which services justify sovereign redesign, which can be delivered through controlled European environments, and which regulated opportunities are no longer commercially attractive.
- The result could be a two-speed cloud market. Standard services continue to optimise for global scale, while sovereign variants carry higher delivery costs, slower release cycles and stricter limits on technology reuse.
For hyperscalers, the strategic response shifts from localisation to architectural separation. Local regions, European data residency and contractual safeguards may no longer provide sufficient differentiation once CADA and the CSF begin testing where authority actually sits. Deeper separation of administration, software updates, privileged access and service continuity is more disruptive than adding a sovereign label, because it challenges the operating model behind globally standardised cloud platforms.
Demand depends on 27 national judgements
- Level 1 is the universal entry ticket and therefore creates no competitive advantage. Commercial upside exists only where a national risk assessment pushes a workload to level 2 or above.
- Because that classification sits with Member States and Union entities under a Commission template, the addressable sovereign market is defined by 27 separate judgements rather than by the regulation itself.
- Divergent national classification of comparable workloads could force providers to adapt and certify the same sovereign service in each Member State. Recognition portability, not certification count, decides EU-wide scale.
- The first tenders that assign assurance levels to concrete workload categories will set the reference points later procurements reuse, and will determine where providers invest in separate European operations and supply-chain controls.
Sovereignty moves deeper into software and AI
The public debate is shifting from data residency towards control over software supply chains, operational continuity and dependence on non-European technology layers.
Open source strengthens auditability and substitutability, and CADA counts it as EU added value. It only becomes a credible public-sector option once maintenance and long-term operational responsibility are clearly assigned.
Sovereign environments still depend on non-European GPUs and development frameworks, and that gap will not close within this legislative cycle. Credibility will come from a disclosed dependency map with a dated reduction path, not from a claim of full independence.
What providers should do now
- Plan for two segments. Standardised services will continue to serve most public-sector demand, while higher-assurance services will require a separate operating model and slower release cycles.
- Engage while the criteria are open. The proposal is still in trilogue. Decisions on the assurance-level criteria, and on whether a recognition obtained in one Member State is accepted in another, will determine eligibility for several years.
- Decide at service level. Establish which services justify investment in a sovereign variant, and which regulated opportunities are no longer commercially viable. Partnerships with hyperscalers will be assessed on the operational authority actually transferred to the European partner.
- Prepare auditable evidence before bidding. Documented control over privileged access and over the integrity of software updates will determine eligibility in procurement, and should be ready before award rather than after it.
- Watch the national layer. CADA establishes minimum requirements across the EU, but Member States retain discretion over architecture and over which workloads require higher assurance. Demand will also extend beyond public authorities.
In our workshops with ICT providers, the recurring question is no longer whether sovereignty matters. It is which of today's services already clear the emerging thresholds, and which need a different operating model or a different partner before procurement requirements harden.
The providers that win the first tenders will not be the ones with the loudest sovereignty claim. They will be the ones who can show, service by service, where the sovereign boundary sits and who holds authority inside it.
About Frenus
We are a market intelligence firm based in Stuttgart. We work with ICT providers and investors on the questions that decide market access: where a portfolio stands against emerging requirements, which submarkets are genuinely addressable, and what a competitor can actually prove. Every two weeks we track this debate with our community in the Cloud Insights and Sovereignty edition.
Talk it through
Marcel Blume leads our market advisory work with ICT providers. He is happy to walk through what the assurance-level logic means for a specific portfolio.
Marcel Blume, Director Market Advisory
Frenus GmbH, Zettachring 8, 70567 Stuttgart
[email protected]
+49 711 99529 610
Book a call

.png)
.png)
.png)
.png)
.png)
.png)
