CADA: Europe Just Wrote a Tier List for Clouds

What a four-level sovereignty framework means if you sell to the EU public sector

CADA: Europe Just Wrote a Tier List for Clouds
James

On June 3, 2026, the European Commission proposed the Cloud and AI Development Act, and buried in its autonomy pillar is the most consequential ranking system Europe has produced since it started grading olive oil. CADA sorts cloud providers into four sovereignty assurance levels for sensitive public-sector and critical workloads. A tier list, in other words, with procurement money attached.

The claim of this post: tier lists change markets faster and more thoroughly than mandates do, because they don't need to be enforced to work; they only need to appear in checklists. If you sell infrastructure, or anything running on infrastructure, into the EU public sector, the sorting has effectively already begun.

The four shelves

The proposal's levels climb from location to control, summarized from the analyses published so far; the fine print will move in negotiation, the shape is clear.

LevelWhat it roughly requires
1Infrastructure located in the EU
2Demonstrated independence from third-country control
3EU ownership, control, and personnel criteria
4Full supply-chain transparency and control, no third-country interference

The framework doesn't arrive alone. CADA's other two pillars fund research and aim to expand European datacenter capacity dramatically, on the theory that a tier list without shelves to buy from is a wish. You can question whether subsidies build competitive clouds; you can't accuse the proposal of ranking vendors while ignoring supply.

Two more pieces travel with the table. Procurement: public authorities would weigh "Union added value" as a non-price criterion when buying cloud and AI services, which is a polite phrase for a thumb on the scale. And the timeline is the usual Brussels long game: this is a proposal, negotiation comes next, adoption is targeted for late 2027, and the tier requirements would phase in over years after that. Every date will move. The direction won't.

Read the table against the last two posts and you can see who it was written about. Level 1 is the region dropdown, formally demoted to the bottom shelf. Levels 2 and 3 are where the structural engineering of sovereign-branded hyperscaler offerings will be tested against ownership criteria a GmbH may or may not satisfy. Level 4 is a shelf almost nobody can reach today, which is partly the point of writing it down.

Why checklists beat mandates

A mandate needs enforcement, budgets, and court cases. A tier framework needs only existence: the day a procurement template gains a field that says "sovereignty level", every bid response, risk assessment, and vendor comparison in the public sector inherits the vocabulary, years before the law binds anyone. Sales cycles adapt to the paperwork, and the paperwork adapts first. We watched the same mechanism run with DORA's exit plans: the artifact became standard before most audits ever asked for it.

France ran the pilot for this mechanism, too. Its SecNumCloud qualification has for years sorted providers by immunity from non-EU law, and the label reshaped French public procurement long before any EU-wide rule required it: vendors restructured to earn it, buyers wrote it into templates, and the market learned to speak in its terms. CADA generalizes that playbook from one member state's doctrine to a single ladder for twenty-seven.

For startups, this cuts both ways, and honestly. The gift: a small EU vendor with clean ownership and an EU supply chain starts near the top of a ladder the giants must climb with lawyers, and "Union added value" is a non-price criterion that a two-person company can actually score on. The tax: tier frameworks come with conformity paperwork, and paperwork is regressive; a hyperscaler absorbs a compliance team, a startup feels every page. Whether CADA becomes a door or a moat for small European clouds depends on how light the assessment machinery turns out to be, and that fight is happening in the negotiation nobody reads.

The steelman: we've seen this movie

The obvious objection has a filmography. GAIA-X was going to federate European cloud and mostly federated meetings; sovereignty requirements have been watered down before under lobbying pressure, and a cynic expects levels 3 and 4 to gain carve-outs wide enough to drive a Frankfurt datacenter through. Protectionism dressed as security is also a real pattern, and some of CADA's critics are right to check its pockets. If adoption slips past late 2027, none of this touches a budget for years.

All plausible. Here's what the cynicism misses: the tier vocabulary survives even if the thresholds soften, because procurement language, once printed, outlives the politics that printed it. Weakened levels still sort vendors; delayed adoption still reshapes bids written this year by teams hedging against it. The question for anyone selling into this market isn't whether CADA arrives intact. It's whether you'd rather spend the interim becoming easy to classify favorably or arguing the classification shouldn't exist.

Our own position is easy to state and obviously self-interested: we're EU-owned, EU-run, and small enough that our supply chain fits on one page, so a ladder measured in ownership and transparency flatters us, and you should discount our enthusiasm accordingly. The non-negotiable we'd defend even if the ladder inverted is portability, because a tier list you can't move between is just lock-in with a flag on it. Whichever shelf your infrastructure sits on today: when a procurement form asks for its level next year, do you know the answer, and could you change it?


Related: The Most Honest Thing a Hyperscaler Ever Said, the testimony this framework grew out of. More about what we're building at light-cloud.com.