The European Cybersecurity Certification Scheme for Cloud Services (EUCS) is a certification framework being developed under the 2019 EU Cybersecurity Act (CSA), led by ENISA. It is not yet adopted — the scheme has been in drafting since 2020 and remains stalled as of mid-2026 due to unresolved political disagreements over digital sovereignty requirements. EUCS is designed as an EU-wide, voluntary certification that would harmonize the fragmented national cloud certifications (such as France’s SecNumCloud or Germany’s C5) into three assurance levels: basic, substantial, and high. It applies to cloud service providers offering IaaS, PaaS, or SaaS on the European market. While EUCS is technically voluntary, its practical impact will be significant because the NIS2 Directive allows Member States to require entities in essential and important sectors to use only EUCS-certified cloud services. The core political controversy centers on whether the “high” assurance level should include sovereignty requirements — mandating EU headquarters, EU-only data processing, and immunity from non-EU extraterritorial laws (e.g. the US CLOUD Act). A March 2024 draft removed these requirements to achieve technical consensus, but the proposed recast of the Cybersecurity Act (CSA2), tabled in January 2026, would reinstate a formal sovereignty tier, with France leading advocacy for its inclusion.
Red Hat is impacted by EUCS both as a cloud technology provider and as a platform underlying cloud deployments. Red Hat does not operate hyperscale public cloud infrastructure directly, but Red Hat OpenShift is the application platform running atop — and certified on — all three major EU and US cloud providers, and is also deployed on-premises and at sovereign cloud operators. If EUCS mandates sovereignty criteria at the “high” level, the immediate impact falls on the CSPs themselves (AWS, Azure, GCP, OVHcloud, etc.), but Red Hat’s positioning enables customers to meet sovereignty objectives by running OpenShift on EU-headquartered infrastructure without changing their application stack. Red Hat’s open source model and absence of proprietary lock-in align well with the sovereignty principle of immunity from non-EU legal interference — no single vendor’s jurisdiction decision forces a platform migration. For the technical cybersecurity requirements at all EUCS assurance levels (encryption, key management, access control, auditability), Red Hat provides foundational capabilities: FIPS 140-3 validated cryptographic modules in RHEL, SELinux mandatory access control, the Compliance Operator for automated CIS/STIG profile enforcement on OpenShift, and full audit-log infrastructure. Organizations preparing for eventual EUCS certification can leverage Red Hat’s portfolio to demonstrate technical compliance at the platform layer regardless of which cloud hosts the workload.
