Skip to main content
  1. Index/

EU Cloud Services Scheme (EUCS)

Table of Contents

The European Cybersecurity Certification Scheme for Cloud Services (EUCS) is a certification framework being developed under the 2019 EU Cybersecurity Act (CSA), led by ENISA. It is not yet adopted — the scheme has been in drafting since 2020 and remains stalled as of mid-2026 due to unresolved political disagreements over digital sovereignty requirements. EUCS is designed as an EU-wide, voluntary certification that would harmonize the fragmented national cloud certifications (such as France’s SecNumCloud or Germany’s C5) into three assurance levels: basic, substantial, and high. It applies to cloud service providers offering IaaS, PaaS, or SaaS on the European market. While EUCS is technically voluntary, its practical impact will be significant because the NIS2 Directive allows Member States to require entities in essential and important sectors to use only EUCS-certified cloud services. The core political controversy centers on whether the “high” assurance level should include sovereignty requirements — mandating EU headquarters, EU-only data processing, and immunity from non-EU extraterritorial laws (e.g. the US CLOUD Act). A March 2024 draft removed these requirements to achieve technical consensus, but the proposed recast of the Cybersecurity Act (CSA2), tabled in January 2026, would reinstate a formal sovereignty tier, with France leading advocacy for its inclusion.

Red Hat is impacted by EUCS both as a cloud technology provider and as a platform underlying cloud deployments. Red Hat does not operate hyperscale public cloud infrastructure directly, but Red Hat OpenShift is the application platform running atop — and certified on — all three major EU and US cloud providers, and is also deployed on-premises and at sovereign cloud operators. If EUCS mandates sovereignty criteria at the “high” level, the immediate impact falls on the CSPs themselves (AWS, Azure, GCP, OVHcloud, etc.), but Red Hat’s positioning enables customers to meet sovereignty objectives by running OpenShift on EU-headquartered infrastructure without changing their application stack. Red Hat’s open source model and absence of proprietary lock-in align well with the sovereignty principle of immunity from non-EU legal interference — no single vendor’s jurisdiction decision forces a platform migration. For the technical cybersecurity requirements at all EUCS assurance levels (encryption, key management, access control, auditability), Red Hat provides foundational capabilities: FIPS 140-3 validated cryptographic modules in RHEL, SELinux mandatory access control, the Compliance Operator for automated CIS/STIG profile enforcement on OpenShift, and full audit-log infrastructure. Organizations preparing for eventual EUCS certification can leverage Red Hat’s portfolio to demonstrate technical compliance at the platform layer regardless of which cloud hosts the workload.

Additional Information
#

Related

ANSSI SecNumCloud

SecNumCloud is a security qualification (“Visa de sécurité”) issued by ANSSI (Agence Nationale de la Sécurité des Systèmes d’Information), France’s national cybersecurity agency. Created in 2016 and currently in version 3.2 (published March 2022), it is the most demanding cloud security standard in France. SecNumCloud applies to cloud service providers offering IaaS, PaaS, SaaS, or CaaS (Container as a Service) and evaluates them against 354 requirements organized across 15 chapters (chapters 5–19) structured on ISO/IEC 27002:2013 Annex A (chapters 5–18: security policies, organization, HR security, asset management, access control, cryptography, physical security, operational security, communications security, system acquisition/development/maintenance, supplier relationships, incident management, business continuity, conformity) plus an additional chapter 19 with sovereignty-specific requirements (data localization, reversibility, and protection from extraterritorial law). The qualification is voluntary in principle — no law forces all cloud providers to obtain it — but it is effectively mandatory for providers serving French public administration, Opérateurs d’Importance Vitale (OIV), and entities handling sensitive government data, as French procurement policy (the “doctrine cloud de confiance”) requires the use of SecNumCloud-qualified providers. Version 3.2’s most significant addition is chapter 19.6, which mandates that qualified providers be headquartered in the EU, owned by European entities (individual non-EU shareholding ≤24 %, collective ≤39 %), and be immune from non-European extraterritorial legislation such as the US CLOUD Act or FISA. SecNumCloud is the model upon which France advocates for the “high+sovereignty” tier in the EU-wide EUCS scheme. Qualification is valid for 3 years with annual audits conducted by PASSI-accredited assessors.

EU Cybersecurity Act (CSA)

The EU Cybersecurity Act (CSA) — Regulation (EU) 2019/881 — was adopted by the European Council in April 2019 and fully entered into force on 28 June 2021. It is a European regulation (directly applicable in all Member States without transposition) that serves two primary functions: it strengthened and made permanent the mandate of ENISA (the EU Agency for Cybersecurity), and it established a voluntary EU-wide cybersecurity certification framework for ICT products, services, and processes. The CSA is not itself a certification scheme but rather the legal foundation upon which specific schemes are built — currently EUCC (adopted January 2024), EUCS (cloud, under development), EU5G (5G networks, under development), EUDI Wallets, and EUMSS (managed security services). Each scheme defines assurance levels (basic, substantial, high), evaluation methodologies, and mutual recognition rules so that a certificate issued in one Member State is valid across the entire EU. The CSA applies to any entity — manufacturer, service provider, or operator — that voluntarily seeks EU cybersecurity certification for its offerings, though sector-specific regulations (NIS2, CRA, DORA) may make certification effectively mandatory for certain use cases. A recast of the CSA (CSA2) was proposed by the European Commission on 20 January 2026, aiming to strengthen certification mandates, reinstate sovereignty requirements in cloud certification, and reinforce ENISA’s supervisory role.

EU5G Certification Scheme

The EU5G cybersecurity certification scheme is a certification framework being developed under the EU Cybersecurity Act (Regulation 2019/881), intended to provide harmonized security assurance for 5G network products and components across the European Union. ENISA established an Ad Hoc Working Group (AHWG) on EU5G in Q4 2021 following a European Commission request. As of mid-2026, the scheme has not been formally adopted and no complete public draft is available — making it the least mature of the three schemes requested under the CSA (after EUCC, adopted in January 2024, and EUCS, still stalled). Current work has focused on specific components: in June 2024, ENISA launched a public consultation on technical specifications for eUICC (embedded Universal Integrated Circuit Card) certification, which will be handled under the existing EUCC framework rather than a new standalone scheme. A broader EU NESAS scheme for 5G network products is under development, leveraging the existing GSMA NESAS/3GPP SCAS methodology. The scheme is expected to be voluntary once adopted, with assurance levels aligned to the CSA’s basic/substantial/high structure. Its practical significance will be shaped by the revised Cybersecurity Act (CSA2), proposed in January 2026, which strengthens ENISA’s mandate and may provide additional impetus for adoption.