The European Cybersecurity Certification Scheme for Cloud Services (EUCS) is a proposed EU-wide certification for the security of cloud services, prepared by ENISA, the EU cybersecurity agency, under the EU Cybersecurity Act. It would let a cloud service be certified once at one of three assurance levels, basic, substantial or high, with the certificate recognized across EU member states. It remains a candidate scheme: it has not been adopted, largely because of a long dispute over whether the high level should include sovereignty requirements. This entry is an overview for buyers, not legal advice.
At a glance
- EUCS is a candidate certification scheme for cloud services, not an adopted one, as far as the Commission’s published information shows.
- It follows the Cybersecurity Act’s three assurance levels: basic, substantial and high.
- Earlier drafts proposed sovereignty requirements for the high level; a later draft dropped them, and the debate continues.
- The Commission proposed a revised Cybersecurity Act in 2026 and says EUCS work is expected to resume under it.
- Until it is adopted, buyers rely on ISO/IEC 27001, SOC 2 and national schemes such as France’s SecNumCloud.
What problem it solves
European buyers comparing cloud services face a patchwork of evidence: international certifications, audit reports and national schemes that differ by country. A provider selling across the EU may need several national certifications, and a buyer in one country may not recognize a scheme from another.
EUCS aims to give one EU-wide scheme with common requirements and assurance levels, so buyers, especially public bodies and regulated sectors, can specify a level and trust that a certified service meets it wherever it was assessed. A second question has shaped the scheme: whether certification should also show that a cloud service is shielded from non-EU laws, such as the US CLOUD Act, that can compel providers to disclose data.
How it works
Legal basis. The EU Cybersecurity Act sets up a framework for voluntary European certification schemes. The Commission asks ENISA to prepare a candidate scheme, which is then adopted by Commission implementing act. EUCS was requested under this process and has gone through several drafts.
Requirements. The drafts set security requirements across areas such as access control, cryptography, operations, incident management and supply chain, plus transparency about where data is located and which legal regimes apply to the provider. Requirements grow in number and depth with each assurance level.
Assessment. Under the Cybersecurity Act, self-assessment is allowed only at the basic level; higher levels need evaluation by an accredited conformity assessment body, with more testing at higher levels.
The sovereignty debate. Some member states and European providers pushed for the high level to require EU-only data processing, EU headquarters and protection from non-EU law; others opposed this as market exclusion. A 2024 draft removed the requirement. The Commission’s 2026 proposals, a revised Cybersecurity Act and the Cloud and AI Development Act (CADA) with its own cloud sovereignty assurance levels, say they will address sovereignty and non-technical risks. Both are proposals in the legislative process, so their final shape is open.
Assurance levels
These are the levels in the candidate scheme, which is not yet adopted; final content may change. The risk descriptions follow the Cybersecurity Act’s definitions of each level.
| Assurance level | Risk it is meant to address (Cybersecurity Act) | How it is validated | What a provider would typically show |
|---|---|---|---|
| Basic | Known basic risks of incidents and cyberattacks | Self-assessment allowed if the scheme permits it, or third-party assessment | Declaration or certificate naming the service and level |
| Substantial | Known cybersecurity risks, and incidents and attacks by actors with limited skills and resources | Third-party evaluation by an accredited conformity assessment body, including limited testing | Certificate from an accredited body, scoped to the service |
| High | State-of-the-art cyberattacks by actors with significant skills and resources | Third-party evaluation with deeper testing, including penetration testing; sovereignty conditions debated | Certificate from an accredited body; any sovereignty conditions depend on the adopted text |
As a non-binding buyer example, the candidate scheme’s own guidance pointed basic toward non-critical workloads, substantial toward business-critical ones and high toward mission-critical ones; the level a buyer needs depends on its own risk assessment and any customer or regulatory requirement.
When it matters for buyers
- When European customers or public bodies ask about cloud certifications. Be ready to explain that EUCS is pending and what evidence you offer instead.
- When choosing a cloud provider for sensitive EU workloads. Ask about national schemes and contractual protections, since EUCS cannot yet be relied on.
- When foreign government access is a concern. Certification alone may not answer it; see data sovereignty.
- When planning multi-year cloud commitments. Requirements may change once EUCS or related laws are adopted.
Our governance, risk and compliance overview covers how to collect and compare provider evidence.
Questions to ask vendors
- Which security certifications do you hold today for the specific service we would buy?
- Do you plan to certify under EUCS once adopted, and at which assurance level?
- Do you hold national schemes such as SecNumCloud or C5, and for which services and regions?
- Where is our data stored, and who can be compelled to disclose it, including under non-EU law?
- Which legal entity operates the service, and where is it headquartered?
- How will you tell us if certification scope or status changes?
How it differs from ISO/IEC 27001
ISO/IEC 27001 is an international standard for an organization’s information security management system, certified by accredited bodies worldwide; it describes how an organization manages security, not a fixed level for a particular cloud service. EUCS would be an EU legal-framework certification for specific cloud services at defined assurance levels, recognized across member states. Many providers hold ISO/IEC 27001 or SOC 2 reports, which remain the common baseline while EUCS is pending. Neither addresses which governments can reach data, the subject of the EU Data Act, GDPR and wider cloud security planning, nor where data sits, which is data residency.
