CADA and the EU Tech Sovereignty Package – Why Tier 3 Forces a Microsoft 365 Decision on German Public Authorities in 2026
CADA and the EU Tech Sovereignty Package – Why Tier 3 Forces a Microsoft 365 Decision on German Public Authorities in 2026
On 3 June 2026 the European Commission tabled the European Technological Sovereignty Package. It bundles four building blocks – the Chips Act 2.0, the Cloud and AI Development Act (CADA), an EU Open Source Strategy and the strategic roadmap for digitalisation and AI in the energy sector. For German administrations and for SMEs serving the public sector, CADA is the most consequential piece of the package because it anchors a four-tier sovereignty framework for public cloud procurement for the first time. Tier 3 demands European ownership of the provider. Tier 3 is the minimum tier for critical public infrastructure.
We break down what the package changes structurally, how it interacts with the CLOUD Act, DORA and NIS2, and what concrete steps a municipal IT shop, a state authority or a school-trust operator must take now in order not to walk into a CADA trap at the next procurement round.
What was actually tabled on 3 June 2026
The Sovereignty Package consists of several acts that run in parallel and cross-reference each other. The split that matters to cloud and IT leads in public bodies and SMEs is this:
- CADA – Cloud and AI Development Act: defines the sovereignty tiers, a legal basis for tripling European data-centre capacity by 2030, and procurement rules for the public sector.
- CSA2 – Cyber Solidarity Act 2 (proposal of 20 January 2026): extends supply-chain risk assessment, strengthens ENISA, and introduces fines of up to seven percent of worldwide group turnover.
- EUCS – European Cybersecurity Certification Scheme for Cloud Services: remains the technical certification scheme. It supplies the technical audit that a CADA Tier 3 evaluation additionally references.
- EU Open Source Strategy: for the first time officially endorses open source as a structural lever for sovereignty. Tightly linked to the openDesk partner program 2026.
CADA is a proposal, not law in force. Trilogue is expected to open in Q3 2026, with a final text not before late 2027. Application typically follows twelve to twenty-four months later – realistically 2029. But: framework contracts with five- or seven-year terms signed today already run into the CADA application window.
The four sovereignty tiers in detail
The CADA draft defines four cumulative assurance levels. Each tier contains the requirements of the tier below.
Tier 1 – EU location
Data is stored and processed in EU data centres. Microsoft Azure with EU Data Boundary already covers this tier – with the known weaknesses around diagnostic telemetry and third-country support access.
Tier 2 – Independence from third countries
Additionally technical and organisational independence from third countries and full transparency over the software supply chain. Microsoft Copilot Flex Routing, which can route between EU Boundary and US data centres, fails here – see Microsoft Copilot Flex Routing.
Tier 3 – European ownership
Additionally European ownership and control of the provider. Exceptions for third-country providers are possible but tied to strict conditions. This is the minimum tier for critical public infrastructure – electronic files, OZG online-services workloads, social and tax data, health workloads, law-enforcement systems.
Tier 4 – Full sovereignty
Additionally full control of the software supply chain and verifiable absence of foreign interference. This tier is reserved for the most sensitive workloads – classified material, defence-relevant infrastructure, highly sensitive judicial data.
Why Microsoft Azure and Microsoft 365 structurally cannot reach Tier 3
Microsoft Ireland Operations Limited is a subsidiary of the US parent Microsoft Corporation. US law applies – the CLOUD Act 2018, FISA 702 and Executive Order 12333 compel the parent to surrender data on order, regardless of where the data is stored. We have spelled out the legal assessment in our analysis after the latest CJEU ruling in Schrems III.
Concretely, for the Microsoft constructions widely deployed in Germany:
- Microsoft 365 EU Data Boundary: at best satisfies Tier 1. Residual telemetry and support access make Tier 2 contested.
- Microsoft Cloud for Sovereignty: an overlay on top of Azure with additional controls. Reaches parts of Tier 2. Tier 3 is structurally out of reach because the provider, by ownership, is not European.
- Microsoft Sovereign Cloud Partner: licensed resellers, where parts of the operation are in European hands. Whether such a setup clears Tier 3 will depend in each case on whether legal control truly passes to the European partner – or whether it is, in effect, a Microsoft tenant under a different name.
In other words: anyone running a Tier 3 workload on Microsoft 365 today has a documentable replacement date in the procurement plan – at the latest when the current framework contracts run out.
What a German public authority must do in the second half of 2026
The HowTo block above structures this in six steps; here is the summary with a focus on the German public-sector and SME context.
Step 1: Inventory by processing purpose {#step-1}
Each cloud contract is mapped to a processing purpose. Office is not a business application, and a business application is not classified material.
Step 2: Name the sovereignty gap per workload {#step-2}
For each workload determine the likely CADA tier. OZG online services, social data, tax data, health data, law enforcement tend to fall into Tier 3 or above.
Step 3: Validate the replacement stack {#step-3}
A European open-source stack per Tier 3 workload – openDesk, Nextcloud, Element/Matrix, Keycloak, Open-Xchange or Mailcow. Component overview at /en/alternativen.
Step 4: Re-cut tender documents along CADA tiers {#step-4}
Extend the evaluation criteria with sovereignty tier and EUCS certificate. The procurement chamber checks that the wording is admissible – it is, because it rests on an objective EU-law-backed schema.
Step 5: Plan a transition phase {#step-5}
At least 18 months of transition. Identity first, then mail, then collaboration. A big-bang migration is unrealistic for Tier 3 workloads.
Step 6: Four-regime documentation {#step-6}
GDPR Art. 30, NIS2 Art. 21, BSI IT-Grundschutz and the CADA tier per workload in one database. Duplicate paperwork is the single biggest drag on public-sector IT efficiency.
Terms – briefly defined
- CADA: Cloud and AI Development Act, draft regulation of the European Commission of 3 June 2026. Defines a four-tier sovereignty framework and procurement rules for the public sector, plus the legal basis for tripling EU data-centre capacity by 2030.
- Sovereignty Tier 3: minimum tier for critical public infrastructure under CADA. Demands European ownership and control of the provider, with narrowly drawn third-country exceptions.
- CSA2: Cyber Solidarity Act 2. Proposal of 20 January 2026. Extends supply-chain risk assessment, strengthens ENISA, fines up to seven percent of worldwide annual turnover.
- EUCS: European Cybersecurity Certification Scheme for Cloud Services. Technical certification scheme that feeds into a CADA Tier 3 evaluation.
- EU Data Boundary: Microsoft's construct for storing and processing EU customer data inside the EU. Addresses Tier 1, with residual concerns around telemetry and support access.
- OZG: Onlinezugangsgesetz, the German framework law on digitising public-administration services. Many OZG workloads tend to fall into CADA Tier 3.
Where europioneer fits in
europioneer runs a European-sovereign stack based on Nextcloud, Open-Xchange, Element/Matrix, Keycloak and Collabora Online – as a managed hosted service in German and EU data centres, without hyperscaler sub-processors. For public authorities and SMEs we take on the technical validation in step 3 and the transition phase in step 5 – including tender-ready component lists that reference CADA sovereignty tiers rather than vendor-specific requirements. Packages and pricing at /en/pricing. Migration call at /en/contact.
Bottom line
3 June 2026 marks the point at which European sovereignty turns from political demand into an operational procurement criterion. CADA is still only a proposal. But every German authority, every school trust, every SME with public-sector business that signs a five- or seven-year framework contract today is already signing it into the CADA application window. Whoever moves the pilot unit onto a European stack now does not have a 2029 migration panic. Whoever waits, does. Background on the bigger picture – Eurostack.
Request a CADA migration call →
Related posts:
- CLOUD Act 2026 – the legal situation for German cloud customers
- Eurostack – why European digital sovereignty is becoming concrete
- NIS2 and GDPR – the Microsoft paradox in the German supply chain
- BSI IT-Grundschutz and Microsoft 365 – where it breaks
- openDesk Partner Program 2026 – the sovereign workplace for SMEs
- DORA and Microsoft 365 – exit strategy for banks in 2026
- Microsoft 365 in schools – where privacy and education collide
DORA, CTPP Designation and Microsoft 365 – Why Banks Need a Tested Exit Strategy in 2026
Since late 2025, Microsoft is an officially designated critical ICT third-party provider under DORA. What that means for BaFin, the ESAs and your concentration-risk file.
Euro-Office 1.0 – the sovereign Microsoft 365 alternative in a technical hands-on review
Euro-Office 1.0 launched on 9 June 2026 as a European Microsoft 365 alternative. What the suite delivers technically and who should adopt it now.