The centrepiece of the Tech Sovereignty Package, read article by article. CADA pairs a capacity push (triple EU data-centre capacity by 2030) with a single, audited cloud sovereignty framework of four Union assurance levels, so Europe runs more of its own compute and can choose sovereign services for its most critical use cases. Adopted by the College on 3 June 2026.
Too little compute, too dependent on a few providers
EU computing capacity is limited and geographically concentrated, holding back competitiveness and the adoption of AI, especially low-latency workloads. At the same time, three non-EU hyperscalers control over 70% of the European cloud market, and EU providers' share fell from 29% in 2017 to 15% in 2022. Dependence on providers under third-country jurisdiction creates risks to control over data and operational continuity. National policies fragment deployment. The Draghi report called for regaining control over data and cloud, expanding domestic compute, and building a financial and talent flywheel.
CADA is the centrepiece of the European Technological Sovereignty Package adopted on 3 June 2026, alongside Chips Act 2.0, the EU Open Source Strategy and the Strategic Roadmap for Digitalisation and AI in Energy. It operationalises the AI Continent Action Plan and the Apply AI Strategy, including AI factories and AI gigafactories.
A deliberately split instrument
CADA rests on a dual legal basis, which gives it two distinct general objectives:
1 increase EU computing capacity through innovative and sustainable technologies.
2 ensure attractive conditions for that deployment.
3 reduce overall reliance on non-sovereign cloud and AI services.
4 protect public order by making cloud and AI supply resilient, in particular in the public sector.
48 articles across five titles, plus three annexes
| Title | What it covers |
|---|---|
| I. General (Arts 1-2) | Subject matter (5 measures); definitions (cloud service = NIS2; AI system = AI Act; software/SBOM = Cyber Resilience Act). |
| II. Cloud + AI Leadership Initiatives (Arts 3-9) | 8 operational objectives; Centres for AI (Art 5); implementation via grand challenges (Art 6); national strategies within 1 year (Art 7); frontier AI priority projects (Art 8); EuroHPC compute matching (Art 9). |
| III. Data-centre capacity (Arts 10-15) | Acceleration zones (Art 10); conditions (Art 11); single information points (Art 12); 12-month permitting (Art 13); strategic projects (Art 14); capacity-gap monitoring (Art 15). |
| IV. Autonomy (Arts 16-44) | Sovereignty framework + 4 assurance levels (16-28); demand-side procurement (29-33); EuroCloud Federation (34-36); Commission procurement (37-40); open source (41-44). |
| V. Final (Arts 45-48) | Delegated + implementing acts; review at 4 years then every 5 (Art 47); entry into force + application (Art 48). |
| Annexes | I grand challenges; II criteria for the four assurance levels; III audit evidence (11 criteria). |
The industrial-support engine (Article 173(3) TFEU)
The Cloud Leadership Initiative and the AI Leadership Initiative pursue eight operational objectives: energy-efficient data-centre tech, autonomous cloud stacks, frontier AI, physical AI, industrial AI, AI-agent platforms, public-sector AI, and regional/local adoption. Key instruments:
How the initiatives are delivered in practice
Acceleration zones, faster permits, strategic projects (Title III)
CADA aims to triple EU data-centre capacity by 2030 (an intermediate target; the explanatory memorandum frames it as five to seven years) and to meet the EU's needs by 2035, with balanced geographic deployment. Each Member State must designate at least one data-centre acceleration zone within six months (Art 10), set up single information points (Art 12), and issue an aggregated baseline permit so that permitting in a zone takes no more than 12 months (Art 13). A separate target sets all data-centre permits at under 18 months by 2030. Brownfield sites are preferred, waste-heat reuse and power purchase agreements are encouraged, and sustainability KPIs follow Delegated Regulation (EU) 2024/1364.
The Commission can designate a project as strategic if it meets at least two of five criteria: it supports essential public-sector functions; it is highly sustainable or innovative; it strengthens grid stability or co-locates clean energy; it integrates EU-designed or EU-made chips, processors or quantum computers; or it addresses a compute shortage. Strategic projects receive the competitiveness seal under the European Competitiveness Fund.
The core innovation: graded, auditable cloud sovereignty
| Level | Verified by | Key criteria (cumulative) |
|---|---|---|
| Level 1 | Provider self-assessment + public EU statement of conformity | EU establishment; EU data and infrastructure residency (unless the customer asks otherwise); state-of-the-art cybersecurity; full subcontractor transparency. SME statements are auto-recognised across the EU. |
| Level 2 | Independent third-party audit | + EU-located personnel; EU cybersecurity certificate "substantial" (EUCS); customer data never used to train third-country AI; software bill of materials and source-code audits; EU-only technical support; legal separation of the EU parent from any third-country subsidiary. |
| Level 3 | Independent third-party audit | + EU-citizen personnel (with national security clearance for classified information); provider not under third-country control (save the associated-third-country derogation); EU-resident support only; may host EU classified information. |
| Level 4 | Independent third-party audit (highest) | + cybersecurity certificate "high"; risk-assessed sensitive data kept in the EU; no third-country effective control over the design, maintenance or evolution of software components. |
A provider under third-country control can still reach Level 3, but only if the Commission designates that third country as "associated": it must have a GDPR adequacy decision, no laws compelling data access, service disruption or sanctions, an open market, and reciprocal access to its public procurement.
One audit, valid EU-wide, to end "sovereign-washing"
A provider applies to the national competent authority of establishment (Art 17), which has 60 days to assess and then notifies the other Member States for a 60-day review; disputes go to the Commission for a binding decision. Level 1 rests on a self-assessment (Art 19); Levels 2 to 4 require an independent third-party audit at the provider's expense (Art 20), with strict auditor-independence rules (no non-audit services 12 months before or after, no audit work in the prior 10 years, no contingent fees) and annual re-review. Recognised services are listed in a public central repository (Art 22). Annex III lists 11 audit-evidence criteria: Union establishment, location of infrastructure and personnel, data localisation, Union citizenship, EU cybersecurity certification, no third-country AI training, absence of third-country control (a 5% ownership and ultimate-owner test), EU-only support including the SOC and NOC, software-supply-chain transparency, open source, and third-country subsidiary separation.
Turning public demand into European supply
| Mechanism | What it does |
|---|---|
| Risk assessments (Art 29) | Member States and Union entities map public-order activities to required assurance levels, within one year then every two years. |
| Public procurement (Art 30) | Non-public-order bodies use at least Level 1; public-order activities (NIS2 sectors, national security, defence, justice, law enforcement, border management) use Levels 2 to 4. |
| Private essential entities (Art 31) | Entities in NIS2 Annex I sectors may run the same assessments. |
| Union added value (Art 32) | Non-price award criteria for EU supply chain and EU-made hardware (suggested maximum 15 of 120 points). |
| Innovation procurement (Art 33) | Member States aspire to award at least 25% of cloud and AI innovation procurement to innovative SMEs. |
| EuroCloud Federation (Arts 34-36) | A public-sector-only federation to pool and share idle compute, free of charge or at cost, outside procurement rules. |
| Commission procurement (Arts 37-40) | The Commission may act as a central purchasing body for Union entities and Member State authorities (framework contracts, dynamic purchasing systems). |
| Open source first (Arts 41-44) | Open-source-first for public bodies; an EU Open Source Solutions Catalogue on the Interoperable Europe portal; an OSPO network. |
CADA does not stand alone
The mandatory measures reach the public sector and private essential entities in the sectors of Annex I of NIS2 (Directive (EU) 2022/2555): energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space.
| Instrument | Relationship to CADA |
|---|---|
| Data Act | Cloud switching and interoperability reduce lock-in, making it easier to move to EU services; CADA builds the sovereign road the Data Act opens. |
| DMA | Three market investigations into cloud services and gatekeeper designation were opened on 18 November 2025. |
| EUCS / Cybersecurity Act revision (CSA2) | Provide the cybersecurity certification CADA's assurance levels rely on; CADA fills the sovereignty gap. |
| Cyber Resilience Act | Defines the software bill of materials (SBOM) CADA audits require. |
| AI Continent Action Plan / AI factories | CADA supplies the broad cloud and data-centre capacity AI factories and gigafactories need. |
| EU Open Source Strategy | A sibling instrument in the same package; CADA carries several of its open-source measures. |
Where CADA stands in the ordinary legislative procedure
Brubru tracks CADA across Chat, the Legislative Tracker and your My Files workspace. Ask "What are the four Union assurance levels in CADA?" or "Who is in scope of the Cloud and AI Development Act?" and Brubru answers from the verified record, then links you straight to the file.