Cloud

Europe hasn't agreed on cloud certification. Your customers have.

EUCS is six years in and still not adopted. Meanwhile SecNumCloud, C5, DORA and NIS2 decide real procurements every week. We build the assurance position that wins tenders today and converts when Brussels finally lands.

CLOUD SERVICE CONTROLS ATTESTATIONS

The landscape

What applies to you

No single European cloud certificate exists yet — which makes the strategy question harder, not easier. The short version:

You are a cloud service provider selling in Europe

EUCS remains stuck in the sovereignty deadlock — six years of drafts, no adoption, and a Cybersecurity Act review that may reshuffle the deck entirely. What decides deals now: ISO 27001/27017/27018 as the floor, C5 attestation for Germany, SecNumCloud qualification for French sensitive workloads, ENS for Spain. Waiting for one European certificate is not a strategy.

C5 · SECNUMCLOUD

EUCS PENDING

You serve financial entities

DORA applies since January 2025: your financial customers must evidence ICT third-party risk, exit strategies and contract clauses — and the largest providers face direct EU oversight as critical ICT third parties. Every bank contract renewal now arrives with a DORA annex. Your compliance package either answers it or your customer’s lawyers write you into their risk register.

DORA

CTPP OVERSIGHT

You are yourselves a NIS2 essential entity

Cloud computing providers, data centres and managed service providers sit in NIS2’s essential category: Article 21 measures, incident reporting, management liability — under the jurisdiction of your main-establishment member state. Your customers’ auditors and your own regulator now ask overlapping questions; the answers had better match.

NIS2 ESSENTIAL

ART. 21/23

You host AI services or sensitive public-sector workloads

The AI Act’s high-risk obligations flow into infrastructure requirements — logging, robustness, access control — and member states increasingly gate public procurement on sovereignty-qualified clouds. The Commission’s Cloud Sovereignty Framework adds another vocabulary. Sovereignty is no longer one requirement; it is a spectrum you need a documented position on.

AI ACT

SOVEREIGNTY

You buy cloud at scale and must prove it's under control

NIS2, DORA and sector regulators all make outsourcing your problem: provider attestations must be mapped to your own risk framework, concentration risk documented, exit tested. A pile of vendor PDFs is not a third-party risk framework — assurance mapping is the work.

THIRD-PARTY RISK

MULTI-CLOUD

The clock is running

The certificate is stuck. The obligations are not.

Regulatory demand for cloud assurance grows every quarter — the harmonised European answer keeps slipping.

Jan 2025 IN FORCE

DORA applies

Financial entities enforce ICT third-party requirements downstream; oversight of critical ICT providers ramps up.

Rolling LIVE

NIS2 transpositions cover cloud and data centres

Essential-entity duties land country by country, with registration and reporting mechanics that differ per member state.

2026 Now

EUCS still unadopted; Cybersecurity Act under review

The sovereignty dispute (High/High+ requirements, ICPA attestations) keeps EUCS in limbo, while the CSA review and the Commission's Cloud Sovereignty Framework may redraw the map. Anyone promising you an EUCS certificate date is guessing.

11 Sep 2026

CRA reporting obligations begin

Cloud-connected products and the software you ship fall under CRA reporting; SaaS with on-prem components needs a position.

Horizon

EUCS or its successor arrives

Whatever form it takes, it will absorb existing control frameworks. Providers with clean C5/SecNumCloud/ISO mappings will convert first and cheapest.

How we work

One control framework, every attestation you need

1

Assurance strategy

Which markets, which schemes, which sequence — SecNumCloud vs. C5 vs. ISO-first, decided on deal flow, not fashion.

2

Unified control framework

One control set mapped to ISO 27001/17/18, C5, SecNumCloud and the EUCS draft — every audit draws from the same well.

3

Gap assessment & remediation

Against the target scheme’s real audit practice, not just its control list. Priced and sequenced.

4

Audit & qualification support

Evidence packages, auditor liaison, qualification-body process management — through to attestation.

5

Customer-facing compliance

DORA annexes, NIS2 supply-chain answers, sovereignty position papers — the documents your sales team keeps being asked for.

6

Regulatory watch & conversion

EUCS, CSA review, sovereignty frameworks tracked; your framework updated before the change, not after.

One control set, five outputs

Every framework below asks 70–90% the same questions. The margin is where audits are won — and where duplicated effort goes to die.

CONTROL FRAMEWORK ISO 27001/17/18 C5 attestation SecNumCloud DORA answers NIS2 evidence EUCS-ready

For the specialists

The detail behind the summary

If you already live in the CC world, start here.

EUCS: reading the deadlock honestly

The technical scheme has been essentially ready for years — three levels (Basic/Substantial/High), CAB-audited above Basic, built on the C5/SecNumCloud heritage. What blocks adoption is purely the sovereignty question: earlier drafts’ immunity requirements for High+ were removed in the March 2024 draft in favour of ICPA-style jurisdiction disclosure, which satisfied neither camp. The Cybersecurity Act review now on the table could change how schemes get adopted at all, and the Commission’s Cloud Sovereignty Framework adds a parallel sovereignty vocabulary for procurement.

Our position: plan on the control substance, not the politics. The Substantial/High control sets are stable enough to build against today — and they overlap C5 and SecNumCloud heavily. Sovereignty positioning is a business decision to make explicitly, not a certification feature to wait for.

These are different instruments, not translations of each other. SecNumCloud is a qualification — ANSSI-governed, sovereignty-inclusive (3.2 added immunity requirements), gate to French sensitive workloads and the “cloud de confiance” doctrine. C5 is an attestation — BSI-defined controls, audited under ISAE-style engagements, mandatory in German federal contexts and de-facto standard in regulated industries. ENS is Spanish public-sector certification with its own levels.

Sequencing matters: SecNumCloud is a multi-year architectural commitment; C5 is achievable on a mature ISO base in one audit cycle.

Our position: pick the anchor scheme by revenue geography, then map everything else onto it. Chasing all three in parallel without a unified framework triples audit cost for zero extra trust.

DORA regulates your customers, but its Article 30 contract requirements, register-of-information demands and threat-led penetration testing (TLPT) expectations arrive on your desk verbatim. Designated critical ICT third-party providers face direct ESA oversight — fees, inspections, recommendations. Below that threshold, the practical burden is contractual: audit rights, subcontracting transparency, exit support that is actually testable.

Our position: build a standard DORA response package once — contract clause positions, register data, TLPT cooperation terms — instead of negotiating each bank separately. Your legal team will not enjoy the alternative.

Cloud providers, data centres and MSPs are essential entities with main-establishment jurisdiction — one lead regulator, but incident reporting that can span every member state you serve. The interesting structural point: you are simultaneously a regulated entity, a supply-chain risk for your customers’ Article 21 files, and a consumer of your own subprocessors’ assurance. The same control evidence flows in three directions.

Our position: design the evidence once with all three consumers in mind. An ISO certificate plus a mapped C5 report answers most NIS2 supply-chain questionnaires before they are asked — put the mapping in the data room, not in each reply.

Talk to people who have watched EUCS since draft one

Thirty minutes with a cloud assurance expert. A straight answer on which schemes matter for your pipeline — and which can wait.

Contact us

Request this document

We’ll send you access by email.