Cloud compliance in the European Union.
Understand data protection and cloud placement across 12 European national frameworks, alongside EU requirements. The calculator applies specifically to a Slovak ISVS.
Data ClassificationWork through the Slovak ISVS model. See compatible levels, incident impact and the controls that follow.C · I · AIncident impactModelled service level Start classifyingClose section
Classify your system
Choose one answer for each property below. Your answers then unlock the incident assessment and hosting requirements.
- Classify the dataChoose C, I and A
- Describe the impactAssess a credible incident
- Review the requirementsConfirm criteria and read the result
Answer the questions below to determine the cloud service level.
-
Property 1 of 3 · Confidentiality
How damaging would it be if this data leaked?
Pick the description that best matches who is allowed to see the data. If two look close, take the higher one. Dôvernosť · Workbook
Choose one levelNo answer selected -
Property 2 of 3 · Integrity
How damaging would it be if this data were wrong?
Think about silent corruption rather than an outage: the system runs, but the numbers are incorrect. Integrita · Workbook
Choose one levelNo answer selected -
Property 3 of 3 · Availability
How damaging would it be if this system went down?
Consider whether there is a fallback. If people can still get the service another way, availability is lower. Dostupnosť · Workbook
Choose one levelNo answer selected -
Incident impact · Stage 2
What would a bad day actually look like?
The workbook asks whether compromise could cause a category I, II or III incident. Rather than assume you know those thresholds, these questions ask the underlying facts and derive the category for you. Decree 165/2018 §24(2)
-
Hosting requirements · Stage 3
A few things only you can confirm
Criteria already settled by your answers
Know what you are protectingWho can see the cargo, whether the chart is right, and whether the lighthouse is available when needed.ConfidentialityIntegrityAvailabilityService level ExploreClose section
Before you choose a cloud, know what you are protecting.
A leak, a wrong record, an outage: CIA classifies their impact. For Slovak ISVS, the assessment then determines U, the required cloud service level.
Keep the manifest in the right hands.
Confidentiality keeps information from unauthorized readers. The captain may read the cargo manifest; a passing stranger may not.
The manifest is readable only by authorized crew.
If this data leaked to someone without permission, who would be harmed—and how seriously?
Details & limits of the example
The captain needs the cargo manifest. A passing stranger does not. The document stays the same; what matters is who can read it.
Classify the impact of a leak, rather than how secure the system feels today.
A safe passage starts with a true chart.
Integrity protects data from improper changes or destruction. Altering a chart from 3 m to 12 m leaves it readable—but unsafe to trust.
Chart: 3 m. Actual depth: 3 m. The ship avoids the shallows.
What harm would wrong, altered or missing information cause, even if the system stayed online?
Details & limits of the example
Someone changes a recorded depth from 3 m to 12 m. The chart is still readable, but now it sends the ship into shallow water. Checking the real depth and correcting the chart makes it safe to trust again.
A high integrity requirement means bad data could have serious consequences. It is not a score of current data quality.
Keep the light on when it matters.
Availability means being able to use information or a service when needed. A ship loses its guidance when the lighthouse fails without a backup.
The light marks the channel; the ship rounds the island safely.
How long could people manage without this service, what would stop, and what backup would they have?
Details & limits of the example
A ship rounds the lighthouse, using its signal to follow the channel. Take away that guidance without a backup, and the approach becomes dangerous.
The classification reflects the impact of an outage. Backup routes and recovery time matter to the assessment.
Match the harbor to what it must protect.
For this Slovak ISVS assessment, U1–U4 describe the required cloud service level. Like choosing a harbour for its cargo, the host must meet the resulting baseline.
Illustrative assessment result: U3 is required.
Does the proposed host meet the assessed U level and all other placement requirements? U is not an uptime percentage or approval by itself.
Details & limits of the example
Think of the data as the cargo and the hosting service as its harbor. C, I and A, together with the applicable risk and category criteria, establish the minimum level that host must meet.
U is an assessment result, not a fourth CIA property or an uptime percentage. Meeting it does not by itself approve a placement.
Read the applicable frameworks29 sourced notes, grouped by the layer of assurance you need to check.EU regulationNational frameworksAssurance Browse frameworksClose section
EU regulation
Binding instruments that reach cloud providers and their customers directly, regardless of member state.
- DORA for Cloud — Overview of the EU Financial-Sector Operational Resilience Regime The Digital Operational Resilience Act has been in force since January 2025 and applies to every financial entity in the EU. This article is the overview — what DORA is, its five pillars, and how it fits with national frameworks. For the CTPP regime and contractual content, see the dedicated deep-dive articles.
- DORA Article 30 — Cloud Contracts, Audit Rights, and Exit Strategies DORA Article 30 specifies the contractual content every financial entity must obtain from its cloud providers. The list is long, the substance is operational, and most pre-DORA cloud contracts do not meet it. This article walks through each clause, what it means in practice, and what financial entities and cloud providers actually negotiate.
- DORA CTPP Regime — Direct ESA Supervision of Critical Cloud Providers The Critical Third-Party Provider regime is the most consequential innovation in DORA. For the first time in EU law, the European Supervisory Authorities can directly supervise cloud providers — not via their financial-services customers, but as named regulated entities. This article walks through how CTPP designation actually works, what direct supervision means operationally, and what hyperscalers do to prepare.
- NIS2 Supply Chain — What Essential Entities Actually Need From Cloud Providers NIS2 doesn't just regulate operators directly — it regulates their supply chains, including cloud providers. This article unpacks what NIS2 supply-chain obligations actually look like for cloud customers and what evidence cloud providers must produce, with the per-country variation that matters in practice.
- EU AI Act × Cloud — How AI Regulation Reaches Cloud Providers and Their Customers The EU AI Act applies progressively from 2025 through 2028, after the Digital Omnibus deferred the high-risk deadlines in July 2026. For cloud providers, two roles matter: provider of general-purpose AI models, and infrastructure for customer-deployed AI systems. For customers, deployer obligations apply at scale. This article walks through what AI Act actually requires of cloud providers, where it intersects with GDPR and NIS2, and what to plan for.
- GDPR Article 28 and the EU Cloud Code of Conduct — What They Actually Demonstrate GDPR Article 28 is the operative article for every controller-processor cloud relationship. The EU Cloud Code of Conduct is the most pragmatic instrument for demonstrating Article 28 compliance at scale. This article walks through what Article 28 actually requires and what the CoC actually demonstrates.
- EUCS Watch — Political Tracking of the European Cybersecurity Certification Scheme for Cloud Services EUCS has been the most-anticipated and least-delivered EU cloud regulation for half a decade. This article tracks what state EUCS is in as of mid-2026, who's blocking what, what the ANSSI/BSI November 2025 joint statement means, and what realistic adoption scenarios look like. A dated reference article — designed to be re-read against current events.
National frameworks
What each authority will actually accept. The frameworks diverge more than the EU layer suggests.
- France — ANSSI SecNumCloud: The Strictest Sovereignty Framework in the EU Single qualification level, 350+ requirements, hard caps on non-EU ownership, immunity from extraterritorial law. SecNumCloud is the framework that defined the modern EU sovereignty debate.
- Germany — BSI C5: The Attestation That Quietly Became Europe's Reference C5 is not a certification, it is an attestation — and that distinction matters. The framework most adopted by hyperscalers, the de facto reference for EUCS Substantial, and the one that pairs cleanly with SOC 2. C5:2026 was published in March 2026, with C5:2020 remaining operative until audit periods beginning on or after 1 June 2027.
- Italy — ACN Qualificazione: The Most Procedural Cloud Framework in the EU Italy's qualification framework is the most formally structured in the EU — statutory timelines, four levels, mandatory public catalogue, and a state-controlled Polo Strategico Nazionale for the strictest workloads.
- Spain — ENS: The National Security Framework Spans Every Public-Sector System ENS is not a cloud-specific framework — it covers every public-sector information system. But its cloud profile (PCE) and three-tier model make it one of the more workable EU regimes for hyperscalers.
- Netherlands — BIO2: Government Baseline Becoming a Statutory Obligation BIO2 v1.3 is the Dutch government's security baseline since 5 March 2026, superseding BIO v1.04zv. The Cyberbeveiligingswet — the Dutch NIS2 transposition — has been in force since 15 August 2026 and makes BIO2 a statutory obligation. The cloud profile is operated by hyperscalers via independent attestation.
- Poland — KSC and the Pending National Cybersecurity Certification System Poland regulates cloud through the National Cybersecurity System (KSC). The NIS2-aligned amendment (informally 'KSC2') entered into force on 3 April 2026 with a pending Constitutional Tribunal review. The parallel National Cybersecurity Certification System (KSCC) was adopted in June 2025 and is operationalising.
- Czechia — NÚKIB and the New Cybersecurity Act: NIS2 Without a Dedicated Cloud Scheme Czechia has no dedicated cloud qualification framework. Cloud security is regulated horizontally through the new Cybersecurity Act (264/2025 Sb.), effective 1 November 2025, with a full implementing-decree stack already in force (408, 409, 410/2025 Sb. and others). NÚKIB supervises; CSPs are assessed as supply-chain participants.
- Slovakia — KsVC: How MIRRI Decides Which Cloud Services the Government Can Use The Slovak government cloud catalogue is mandatory for the public sector and tied to the national cybersecurity audit framework. As of mid-2026, it is also operationally out of step with the NIS2-era risk-based regime — the methodology still classifies by U1–U4 while the underlying law has moved to risk analysis.
- Finland — PiTuKri: Guidance That Doubles as the Gate for Classified Information PiTuKri is officially guidance, not statutory. In practice, it is the gate for handling Finnish classified information in the cloud. The Finnish NIS2 transposition (Act 124/2025) has been in force since April 2025; the replacement criteria library is in public consultation and scheduled for finalisation in autumn 2026 — until then, a real gap between the new risk-based law and the 2020 cloud framework exists.
- Norway — NSM Grunnprinsipper, Sikkerhetsloven, and the EEA Cloud Position Norway is in the EEA. Most EU cloud regulation reaches Norway via EEA incorporation, including GDPR (directly applicable) and DORA (in force since July 2025), with NIS2 still pending. On top, NSM's Grunnprinsipper guide ICT security, Sikkerhetsloven governs classified information, and Finanstilsynet supervises financial-sector cloud. This article maps how the Norwegian regime relates to the EU base.
- Switzerland — FINMA, nFADP, and the Cloud Framework Outside the EU Switzerland is not in the EU and not in the EEA, but is deeply bilateral with both. The cloud framework is composed: FINMA Circular 2018/3 for financial services, the revised nFADP for data protection (GDPR-aligned with lower penalties), and sector-specific regulation for healthcare, defence, and classified information. For Slovak organisations with Swiss customers — and Swiss organisations consuming EU cloud — the regime is adjacent but procedurally distinct.
- United Kingdom — NCSC Cloud Security Principles and the Post-Brexit Position The UK left the EU but kept GDPR (as UK GDPR), kept ISO standards, and did not adopt EUCS. NCSC's 14 Cloud Security Principles are the operative UK government cloud guidance, with Cyber Essentials and Cyber Essentials Plus as the certification scheme. For EU CSPs serving UK customers (and UK CSPs serving EU customers), the regime is adjacent but distinct.
Assurance underlay
The certifications and attestations every national framework builds on — and how to read them.
- ISO 27001 / 27017 / 27018 / 27701 — The Universal Underlay Every National Framework Builds On Every national cloud security framework in Europe — KsVC, BSI C5, ENS, ACN, SecNumCloud, PiTuKri, BIO2 — references some combination of ISO 27001, 27017, 27018, and 27701. Knowing what each standard actually covers (and where each stops) is the prerequisite for working effectively with any of them.
- SOC 2 Reports — How to Actually Read Them SOC 2 is the most commonly referenced cloud security attestation in procurement. It is also the one most often misread — Type 1 confused with Type 2, scope confused with depth, exception language misunderstood. This article walks through what a SOC 2 report actually contains and how to read it for real signal.
- CSA STAR Registry — The Cross-Cutting Trust Layer Across Frameworks The Cloud Security Alliance STAR Registry is the closest thing the cloud industry has to a global trust register. Three assurance levels, the CCM as the underlying control matrix, and integration with most major national frameworks. Useful as a navigation layer when comparing CSPs across heterogeneous compliance regimes.
- Reading Cloud Attestation Reports — A Practitioner's Guide A SOC 2 report, a C5 attestation, an ENS audit certificate, an ACN qualification dossier — what to look for, what to ignore, what to ask follow-up questions about. The practitioner skill that turns compliance documents into actual signal.
- Cloud Encryption Key Custody — BYOK, HYOK, and the Practical Sovereignty Answer Provider-managed keys, BYOK, HYOK, External Key Stores. Every cloud sovereignty conversation eventually arrives at key custody. This article walks through the patterns, the hyperscaler implementations (AWS XKS, Azure CMK, Google EKM), the operational trade-offs, and why customer-held keys are the most practical sovereignty answer short of full sovereign cloud.
Market and posture
Choosing where to land, and who can actually host you under each posture.
- Choosing Your Cloud Compliance Posture — A Decision Framework The national frameworks, cross-cutting baselines, and regulatory overlays add up to dozens of acronyms. This article is the decision tree that maps 'I am [type of organisation] doing [type of workload] in [geography]' to 'these are the frameworks that actually apply to you'.
- Data Security in the Cloud — How EU Member States Actually Decide What's Safe Every EU member state grades cloud security differently, and the 'European' scheme that was supposed to harmonise them has been stuck for two years. Here is the actual map — who leads, who drifts, and what a multicloud operator has to navigate.
- Sovereign Cloud Products in 2026 — The European Landscape Hyperscaler joint ventures, EU-native operators, partner sovereign clouds, and dedicated sovereign regions. The European sovereign cloud market in 2026 has more options than three years ago, but the variety hides real differences in what each product actually delivers. This article maps the landscape.
- EU-Native Cloud Providers — The Landscape Beyond Hyperscalers and Sovereign JVs OVHcloud, Scaleway, Hetzner, IONOS, STACKIT, T Cloud Public, 3DS Outscale, Cegedim.cloud, Aruba. EU-native pure-play providers mapped by compliance tier, service breadth, and procurement fit.
- Hyperscaler EU Data Boundary Commitments — What They Actually Mean Microsoft EU Data Boundary, AWS European Sovereign Cloud, Google Workspace EU Data Boundary. Three different commitments, three different scopes, three different things being promised. This article unpacks what each actually covers, what each excludes, and how to read the technical small print.
Every note is sourced and carries a review date. Regulatory positions move — browse the full set or get in touch if you need a position assessed against a specific framework.