What Is EUCS (European Cybersecurity Certification Scheme for Cloud Services)?

Also called: EU Cybersecurity Certification Scheme for Cloud Services, EU Cloud Services Scheme

Related problems: A European customer asked whether our cloud provider is EUCS certified; Need a common way to compare cloud security across EU countries; Want assurance a cloud service is protected from non-EU legal access; Too many national cloud certifications to track

The European Cybersecurity Certification Scheme for Cloud Services (EUCS) is a proposed EU-wide certification for the security of cloud services, prepared by ENISA, the EU cybersecurity agency, under the EU Cybersecurity Act. It would let a cloud service be certified once at one of three assurance levels, basic, substantial or high, with the certificate recognized across EU member states. It remains a candidate scheme: it has not been adopted, largely because of a long dispute over whether the high level should include sovereignty requirements. This entry is an overview for buyers, not legal advice.

At a glance

  • EUCS is a candidate certification scheme for cloud services, not an adopted one, as far as the Commission’s published information shows.
  • It follows the Cybersecurity Act’s three assurance levels: basic, substantial and high.
  • Earlier drafts proposed sovereignty requirements for the high level; a later draft dropped them, and the debate continues.
  • The Commission proposed a revised Cybersecurity Act in 2026 and says EUCS work is expected to resume under it.
  • Until it is adopted, buyers rely on ISO/IEC 27001, SOC 2 and national schemes such as France’s SecNumCloud.

What problem it solves

European buyers comparing cloud services face a patchwork of evidence: international certifications, audit reports and national schemes that differ by country. A provider selling across the EU may need several national certifications, and a buyer in one country may not recognize a scheme from another.

EUCS aims to give one EU-wide scheme with common requirements and assurance levels, so buyers, especially public bodies and regulated sectors, can specify a level and trust that a certified service meets it wherever it was assessed. A second question has shaped the scheme: whether certification should also show that a cloud service is shielded from non-EU laws, such as the US CLOUD Act, that can compel providers to disclose data.

How it works

Legal basis. The EU Cybersecurity Act sets up a framework for voluntary European certification schemes. The Commission asks ENISA to prepare a candidate scheme, which is then adopted by Commission implementing act. EUCS was requested under this process and has gone through several drafts.

Requirements. The drafts set security requirements across areas such as access control, cryptography, operations, incident management and supply chain, plus transparency about where data is located and which legal regimes apply to the provider. Requirements grow in number and depth with each assurance level.

Assessment. Under the Cybersecurity Act, self-assessment is allowed only at the basic level; higher levels need evaluation by an accredited conformity assessment body, with more testing at higher levels.

The sovereignty debate. Some member states and European providers pushed for the high level to require EU-only data processing, EU headquarters and protection from non-EU law; others opposed this as market exclusion. A 2024 draft removed the requirement. The Commission’s 2026 proposals, a revised Cybersecurity Act and the Cloud and AI Development Act (CADA) with its own cloud sovereignty assurance levels, say they will address sovereignty and non-technical risks. Both are proposals in the legislative process, so their final shape is open.

Assurance levels

These are the levels in the candidate scheme, which is not yet adopted; final content may change. The risk descriptions follow the Cybersecurity Act’s definitions of each level.

Assurance level Risk it is meant to address (Cybersecurity Act) How it is validated What a provider would typically show
Basic Known basic risks of incidents and cyberattacks Self-assessment allowed if the scheme permits it, or third-party assessment Declaration or certificate naming the service and level
Substantial Known cybersecurity risks, and incidents and attacks by actors with limited skills and resources Third-party evaluation by an accredited conformity assessment body, including limited testing Certificate from an accredited body, scoped to the service
High State-of-the-art cyberattacks by actors with significant skills and resources Third-party evaluation with deeper testing, including penetration testing; sovereignty conditions debated Certificate from an accredited body; any sovereignty conditions depend on the adopted text

As a non-binding buyer example, the candidate scheme’s own guidance pointed basic toward non-critical workloads, substantial toward business-critical ones and high toward mission-critical ones; the level a buyer needs depends on its own risk assessment and any customer or regulatory requirement.

When it matters for buyers

  • When European customers or public bodies ask about cloud certifications. Be ready to explain that EUCS is pending and what evidence you offer instead.
  • When choosing a cloud provider for sensitive EU workloads. Ask about national schemes and contractual protections, since EUCS cannot yet be relied on.
  • When foreign government access is a concern. Certification alone may not answer it; see data sovereignty.
  • When planning multi-year cloud commitments. Requirements may change once EUCS or related laws are adopted.

Our governance, risk and compliance overview covers how to collect and compare provider evidence.

Questions to ask vendors

  • Which security certifications do you hold today for the specific service we would buy?
  • Do you plan to certify under EUCS once adopted, and at which assurance level?
  • Do you hold national schemes such as SecNumCloud or C5, and for which services and regions?
  • Where is our data stored, and who can be compelled to disclose it, including under non-EU law?
  • Which legal entity operates the service, and where is it headquartered?
  • How will you tell us if certification scope or status changes?

How it differs from ISO/IEC 27001

ISO/IEC 27001 is an international standard for an organization’s information security management system, certified by accredited bodies worldwide; it describes how an organization manages security, not a fixed level for a particular cloud service. EUCS would be an EU legal-framework certification for specific cloud services at defined assurance levels, recognized across member states. Many providers hold ISO/IEC 27001 or SOC 2 reports, which remain the common baseline while EUCS is pending. Neither addresses which governments can reach data, the subject of the EU Data Act, GDPR and wider cloud security planning, nor where data sits, which is data residency.

Frequently Asked Questions

Can a cloud provider be EUCS certified today?
Not under EUCS itself, as far as the European Commission's published information shows. EUCS is a candidate scheme that has not been adopted, and the Commission has said work on it is expected to resume under a proposed revision of the Cybersecurity Act. Treat claims of EUCS certification with caution and ask what was actually assessed.
What are the EUCS assurance levels?
The candidate scheme uses the three levels set by the EU Cybersecurity Act: basic, substantial and high. Each level adds more security requirements and deeper evaluation, and under the Act self-assessment is allowed only at basic. Final requirements depend on the adopted scheme.
Does EUCS protect data from the US CLOUD Act?
Not as currently drafted, as far as published accounts show. Earlier drafts proposed sovereignty requirements for the high level, such as EU headquarters and protection from non-EU law, but a later draft removed them. The Commission has said sovereignty concerns will be addressed through other proposals that are still being negotiated.
What is SecNumCloud and how does it relate to EUCS?
SecNumCloud is France's national cloud security qualification, run by its cybersecurity agency ANSSI. It includes requirements intended to protect qualified services from non-EU laws, and it inspired the sovereignty requirements once proposed for EUCS. It is a national scheme, not an EU-wide one.
What should we ask for instead while EUCS is pending?
Common evidence includes ISO/IEC 27001 certification and SOC 2 reports scoped to the service you would buy, national schemes such as Germany's C5 or France's SecNumCloud where relevant, and contract terms on data location and government access requests.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.