EUCS is six years in and still not adopted. Meanwhile SecNumCloud, C5, DORA and NIS2 decide real procurements every week. We build the assurance position that wins tenders today and converts when Brussels finally lands.
The landscape
No single European cloud certificate exists yet — which makes the strategy question harder, not easier. The short version:
EUCS remains stuck in the sovereignty deadlock — six years of drafts, no adoption, and a Cybersecurity Act review that may reshuffle the deck entirely. What decides deals now: ISO 27001/27017/27018 as the floor, C5 attestation for Germany, SecNumCloud qualification for French sensitive workloads, ENS for Spain. Waiting for one European certificate is not a strategy.
C5 · SECNUMCLOUD
EUCS PENDING
DORA applies since January 2025: your financial customers must evidence ICT third-party risk, exit strategies and contract clauses — and the largest providers face direct EU oversight as critical ICT third parties. Every bank contract renewal now arrives with a DORA annex. Your compliance package either answers it or your customer’s lawyers write you into their risk register.
DORA
CTPP OVERSIGHT
Cloud computing providers, data centres and managed service providers sit in NIS2’s essential category: Article 21 measures, incident reporting, management liability — under the jurisdiction of your main-establishment member state. Your customers’ auditors and your own regulator now ask overlapping questions; the answers had better match.
NIS2 ESSENTIAL
ART. 21/23
The AI Act’s high-risk obligations flow into infrastructure requirements — logging, robustness, access control — and member states increasingly gate public procurement on sovereignty-qualified clouds. The Commission’s Cloud Sovereignty Framework adds another vocabulary. Sovereignty is no longer one requirement; it is a spectrum you need a documented position on.
AI ACT
SOVEREIGNTY
NIS2, DORA and sector regulators all make outsourcing your problem: provider attestations must be mapped to your own risk framework, concentration risk documented, exit tested. A pile of vendor PDFs is not a third-party risk framework — assurance mapping is the work.
THIRD-PARTY RISK
MULTI-CLOUD
The clock is running
Regulatory demand for cloud assurance grows every quarter — the harmonised European answer keeps slipping.
Financial entities enforce ICT third-party requirements downstream; oversight of critical ICT providers ramps up.
Essential-entity duties land country by country, with registration and reporting mechanics that differ per member state.
The sovereignty dispute (High/High+ requirements, ICPA attestations) keeps EUCS in limbo, while the CSA review and the Commission's Cloud Sovereignty Framework may redraw the map. Anyone promising you an EUCS certificate date is guessing.
Cloud-connected products and the software you ship fall under CRA reporting; SaaS with on-prem components needs a position.
Whatever form it takes, it will absorb existing control frameworks. Providers with clean C5/SecNumCloud/ISO mappings will convert first and cheapest.
How we work
Which markets, which schemes, which sequence — SecNumCloud vs. C5 vs. ISO-first, decided on deal flow, not fashion.
One control set mapped to ISO 27001/17/18, C5, SecNumCloud and the EUCS draft — every audit draws from the same well.
Against the target scheme’s real audit practice, not just its control list. Priced and sequenced.
Evidence packages, auditor liaison, qualification-body process management — through to attestation.
DORA annexes, NIS2 supply-chain answers, sovereignty position papers — the documents your sales team keeps being asked for.
EUCS, CSA review, sovereignty frameworks tracked; your framework updated before the change, not after.
Every framework below asks 70–90% the same questions. The margin is where audits are won — and where duplicated effort goes to die.
For the specialists
If you already live in the CC world, start here.
The technical scheme has been essentially ready for years — three levels (Basic/Substantial/High), CAB-audited above Basic, built on the C5/SecNumCloud heritage. What blocks adoption is purely the sovereignty question: earlier drafts’ immunity requirements for High+ were removed in the March 2024 draft in favour of ICPA-style jurisdiction disclosure, which satisfied neither camp. The Cybersecurity Act review now on the table could change how schemes get adopted at all, and the Commission’s Cloud Sovereignty Framework adds a parallel sovereignty vocabulary for procurement.
Our position: plan on the control substance, not the politics. The Substantial/High control sets are stable enough to build against today — and they overlap C5 and SecNumCloud heavily. Sovereignty positioning is a business decision to make explicitly, not a certification feature to wait for.
These are different instruments, not translations of each other. SecNumCloud is a qualification — ANSSI-governed, sovereignty-inclusive (3.2 added immunity requirements), gate to French sensitive workloads and the “cloud de confiance” doctrine. C5 is an attestation — BSI-defined controls, audited under ISAE-style engagements, mandatory in German federal contexts and de-facto standard in regulated industries. ENS is Spanish public-sector certification with its own levels.
Sequencing matters: SecNumCloud is a multi-year architectural commitment; C5 is achievable on a mature ISO base in one audit cycle.
Our position: pick the anchor scheme by revenue geography, then map everything else onto it. Chasing all three in parallel without a unified framework triples audit cost for zero extra trust.
DORA regulates your customers, but its Article 30 contract requirements, register-of-information demands and threat-led penetration testing (TLPT) expectations arrive on your desk verbatim. Designated critical ICT third-party providers face direct ESA oversight — fees, inspections, recommendations. Below that threshold, the practical burden is contractual: audit rights, subcontracting transparency, exit support that is actually testable.
Our position: build a standard DORA response package once — contract clause positions, register data, TLPT cooperation terms — instead of negotiating each bank separately. Your legal team will not enjoy the alternative.
Cloud providers, data centres and MSPs are essential entities with main-establishment jurisdiction — one lead regulator, but incident reporting that can span every member state you serve. The interesting structural point: you are simultaneously a regulated entity, a supply-chain risk for your customers’ Article 21 files, and a consumer of your own subprocessors’ assurance. The same control evidence flows in three directions.
Our position: design the evidence once with all three consumers in mind. An ISO certificate plus a mapped C5 report answers most NIS2 supply-chain questionnaires before they are asked — put the mapping in the data room, not in each reply.
Thirty minutes with a cloud assurance expert. A straight answer on which schemes matter for your pipeline — and which can wait.
We’ll send you access by email.