[{"data":1,"prerenderedAt":521},["ShallowReactive",2],{"navigation-docs_en":3,"/en/blog/cada-eu-tech-sovereignty-package-public-sector-2026-posts_en":51,"/en/blog/cada-eu-tech-sovereignty-package-public-sector-2026-surround-posts_en":511},[4],{"title":5,"path":6,"stem":7,"children":8,"page":25},"En","/en","en",[9],{"title":10,"path":11,"stem":12,"children":13,"page":25},"Docs","/en/docs","en/1.docs",[14,26],{"title":15,"path":16,"stem":17,"children":18,"icon":25},"Getting Started","/en/docs/getting-started","en/1.docs/1.getting-started/1.index",[19,21],{"title":20,"path":16,"stem":17,"children":-1},"Introduction",{"title":22,"path":23,"stem":24,"children":-1},"Migration Roadmap","/en/docs/getting-started/migration-fahrplan","en/1.docs/1.getting-started/2.migration-fahrplan",false,{"title":27,"path":28,"stem":29,"children":30,"page":25},"Technologies","/en/docs/technologies","en/1.docs/2.technologies",[31,35,39,43,47],{"title":32,"path":33,"stem":34,"children":-1},"Nextcloud","/en/docs/technologies/nextcloud","en/1.docs/2.technologies/1.nextcloud",{"title":36,"path":37,"stem":38,"children":-1},"Matrix / Element","/en/docs/technologies/matrix","en/1.docs/2.technologies/2.matrix",{"title":40,"path":41,"stem":42,"children":-1},"ONLYOFFICE","/en/docs/technologies/onlyoffice","en/1.docs/2.technologies/3.onlyoffice",{"title":44,"path":45,"stem":46,"children":-1},"Ubuntu Linux","/en/docs/technologies/ubuntu","en/1.docs/2.technologies/4.ubuntu",{"title":48,"path":49,"stem":50,"children":-1},"Keycloak","/en/docs/technologies/keycloak","en/1.docs/2.technologies/5.keycloak",{"id":52,"title":53,"authors":54,"badge":60,"body":62,"date":461,"description":462,"extension":463,"faq":464,"howto":480,"image":503,"meta":505,"navigation":506,"path":507,"seo":508,"stem":509,"__hash__":510},"posts_en/en/3.blog/15.cada-eu-tech-sovereignty-package-public-sector-2026.md","CADA and the EU Tech Sovereignty Package – Why Tier 3 Forces a Microsoft 365 Decision on German Public Authorities in 2026",[55],{"name":56,"to":57,"avatar":58},"europioneer Team","/",{"src":59},"/favicon.svg",{"label":61},"EU Regulation",{"type":63,"value":64,"toc":437},"minimark",[65,69,98,117,122,125,157,160,164,167,172,175,179,189,193,200,204,207,211,228,231,251,258,262,265,269,272,276,279,283,289,293,296,300,303,307,315,319,357,361,372,376,386,391,394,399],[66,67,53],"h1",{"id":68},"cada-and-the-eu-tech-sovereignty-package-why-tier-3-forces-a-microsoft-365-decision-on-german-public-authorities-in-2026",[70,71,72,73,77,78,81,82,85,86,89,90,93,94,97],"p",{},"On ",[74,75,76],"strong",{},"3 June 2026"," the European Commission tabled the ",[74,79,80],{},"European Technological Sovereignty Package",". It bundles four building blocks – the ",[74,83,84],{},"Chips Act 2.0",", the ",[74,87,88],{},"Cloud and AI Development Act (CADA)",", an ",[74,91,92],{},"EU Open Source Strategy"," and the strategic roadmap for digitalisation and AI in the energy sector. For German administrations and for SMEs serving the public sector, CADA is the most consequential piece of the package because it anchors a ",[74,95,96],{},"four-tier sovereignty framework for public cloud procurement"," for the first time. Tier 3 demands European ownership of the provider. Tier 3 is the minimum tier for critical public infrastructure.",[70,99,100,101,106,107,111,112,116],{},"We break down what the package changes structurally, how it interacts with the ",[102,103,105],"a",{"href":104},"/en/blog/cloud-act-2026","CLOUD Act",", ",[102,108,110],{"href":109},"/en/blog/dora-microsoft-365-exit-strategy-banks-2026","DORA"," and ",[102,113,115],{"href":114},"/en/blog/nis2-gdpr-microsoft-paradox","NIS2",", and what concrete steps a municipal IT shop, a state authority or a school-trust operator must take now in order not to walk into a CADA trap at the next procurement round.",[118,119,121],"h2",{"id":120},"what-was-actually-tabled-on-3-june-2026","What was actually tabled on 3 June 2026",[70,123,124],{},"The Sovereignty Package consists of several acts that run in parallel and cross-reference each other. The split that matters to cloud and IT leads in public bodies and SMEs is this:",[126,127,128,135,141,147],"ul",{},[129,130,131,134],"li",{},[74,132,133],{},"CADA – Cloud and AI Development Act",": defines the sovereignty tiers, a legal basis for tripling European data-centre capacity by 2030, and procurement rules for the public sector.",[129,136,137,140],{},[74,138,139],{},"CSA2 – Cyber Solidarity Act 2"," (proposal of 20 January 2026): extends supply-chain risk assessment, strengthens ENISA, and introduces fines of up to seven percent of worldwide group turnover.",[129,142,143,146],{},[74,144,145],{},"EUCS – European Cybersecurity Certification Scheme for Cloud Services",": remains the technical certification scheme. It supplies the technical audit that a CADA Tier 3 evaluation additionally references.",[129,148,149,151,152,156],{},[74,150,92],{},": for the first time officially endorses open source as a structural lever for sovereignty. Tightly linked to the ",[102,153,155],{"href":154},"/en/blog/opendesk-partner-program-2026","openDesk partner program 2026",".",[70,158,159],{},"CADA is a proposal, not law in force. Trilogue is expected to open in Q3 2026, with a final text not before late 2027. Application typically follows twelve to twenty-four months later – realistically 2029. But: framework contracts with five- or seven-year terms signed today already run into the CADA application window.",[118,161,163],{"id":162},"the-four-sovereignty-tiers-in-detail","The four sovereignty tiers in detail",[70,165,166],{},"The CADA draft defines four cumulative assurance levels. Each tier contains the requirements of the tier below.",[168,169,171],"h3",{"id":170},"tier-1-eu-location","Tier 1 – EU location",[70,173,174],{},"Data is stored and processed in EU data centres. Microsoft Azure with EU Data Boundary already covers this tier – with the known weaknesses around diagnostic telemetry and third-country support access.",[168,176,178],{"id":177},"tier-2-independence-from-third-countries","Tier 2 – Independence from third countries",[70,180,181,182,185,186,156],{},"Additionally technical and organisational independence from third countries and full transparency over the software supply chain. ",[74,183,184],{},"Microsoft Copilot Flex Routing",", which can route between EU Boundary and US data centres, fails here – see ",[102,187,184],{"href":188},"/en/blog/microsoft-copilot-flex-routing",[168,190,192],{"id":191},"tier-3-european-ownership","Tier 3 – European ownership",[70,194,195,196,199],{},"Additionally European ownership and control of the provider. Exceptions for third-country providers are possible but tied to strict conditions. ",[74,197,198],{},"This is the minimum tier for critical public infrastructure"," – electronic files, OZG online-services workloads, social and tax data, health workloads, law-enforcement systems.",[168,201,203],{"id":202},"tier-4-full-sovereignty","Tier 4 – Full sovereignty",[70,205,206],{},"Additionally full control of the software supply chain and verifiable absence of foreign interference. This tier is reserved for the most sensitive workloads – classified material, defence-relevant infrastructure, highly sensitive judicial data.",[118,208,210],{"id":209},"why-microsoft-azure-and-microsoft-365-structurally-cannot-reach-tier-3","Why Microsoft Azure and Microsoft 365 structurally cannot reach Tier 3",[70,212,213,214,106,217,111,220,223,224,156],{},"Microsoft Ireland Operations Limited is a subsidiary of the US parent Microsoft Corporation. US law applies – the ",[74,215,216],{},"CLOUD Act 2018",[74,218,219],{},"FISA 702",[74,221,222],{},"Executive Order 12333"," compel the parent to surrender data on order, regardless of where the data is stored. We have spelled out the legal assessment in our analysis after the latest CJEU ruling in ",[102,225,227],{"href":226},"/en/blog/schrems-iii-cjeu-ruling","Schrems III",[70,229,230],{},"Concretely, for the Microsoft constructions widely deployed in Germany:",[126,232,233,239,245],{},[129,234,235,238],{},[74,236,237],{},"Microsoft 365 EU Data Boundary",": at best satisfies Tier 1. Residual telemetry and support access make Tier 2 contested.",[129,240,241,244],{},[74,242,243],{},"Microsoft Cloud for Sovereignty",": an overlay on top of Azure with additional controls. Reaches parts of Tier 2. Tier 3 is structurally out of reach because the provider, by ownership, is not European.",[129,246,247,250],{},[74,248,249],{},"Microsoft Sovereign Cloud Partner",": licensed resellers, where parts of the operation are in European hands. Whether such a setup clears Tier 3 will depend in each case on whether legal control truly passes to the European partner – or whether it is, in effect, a Microsoft tenant under a different name.",[70,252,253,254,257],{},"In other words: anyone running a Tier 3 workload on Microsoft 365 today has a ",[74,255,256],{},"documentable replacement date"," in the procurement plan – at the latest when the current framework contracts run out.",[118,259,261],{"id":260},"what-a-german-public-authority-must-do-in-the-second-half-of-2026","What a German public authority must do in the second half of 2026",[70,263,264],{},"The HowTo block above structures this in six steps; here is the summary with a focus on the German public-sector and SME context.",[168,266,268],{"id":267},"step-1-inventory-by-processing-purpose-step-1","Step 1: Inventory by processing purpose {#step-1}",[70,270,271],{},"Each cloud contract is mapped to a processing purpose. Office is not a business application, and a business application is not classified material.",[168,273,275],{"id":274},"step-2-name-the-sovereignty-gap-per-workload-step-2","Step 2: Name the sovereignty gap per workload {#step-2}",[70,277,278],{},"For each workload determine the likely CADA tier. OZG online services, social data, tax data, health data, law enforcement tend to fall into Tier 3 or above.",[168,280,282],{"id":281},"step-3-validate-the-replacement-stack-step-3","Step 3: Validate the replacement stack {#step-3}",[70,284,285,286,156],{},"A European open-source stack per Tier 3 workload – openDesk, Nextcloud, Element/Matrix, Keycloak, Open-Xchange or Mailcow. Component overview at ",[102,287,288],{"href":288},"/en/alternativen",[168,290,292],{"id":291},"step-4-re-cut-tender-documents-along-cada-tiers-step-4","Step 4: Re-cut tender documents along CADA tiers {#step-4}",[70,294,295],{},"Extend the evaluation criteria with sovereignty tier and EUCS certificate. The procurement chamber checks that the wording is admissible – it is, because it rests on an objective EU-law-backed schema.",[168,297,299],{"id":298},"step-5-plan-a-transition-phase-step-5","Step 5: Plan a transition phase {#step-5}",[70,301,302],{},"At least 18 months of transition. Identity first, then mail, then collaboration. A big-bang migration is unrealistic for Tier 3 workloads.",[168,304,306],{"id":305},"step-6-four-regime-documentation-step-6","Step 6: Four-regime documentation {#step-6}",[70,308,309,310,314],{},"GDPR Art. 30, NIS2 Art. 21, ",[102,311,313],{"href":312},"/en/blog/bsi-it-grundschutz-microsoft-365","BSI IT-Grundschutz"," and the CADA tier per workload in one database. Duplicate paperwork is the single biggest drag on public-sector IT efficiency.",[118,316,318],{"id":317},"terms-briefly-defined","Terms – briefly defined",[126,320,321,327,333,339,345,351],{},[129,322,323,326],{},[74,324,325],{},"CADA",": Cloud and AI Development Act, draft regulation of the European Commission of 3 June 2026. Defines a four-tier sovereignty framework and procurement rules for the public sector, plus the legal basis for tripling EU data-centre capacity by 2030.",[129,328,329,332],{},[74,330,331],{},"Sovereignty Tier 3",": minimum tier for critical public infrastructure under CADA. Demands European ownership and control of the provider, with narrowly drawn third-country exceptions.",[129,334,335,338],{},[74,336,337],{},"CSA2",": Cyber Solidarity Act 2. Proposal of 20 January 2026. Extends supply-chain risk assessment, strengthens ENISA, fines up to seven percent of worldwide annual turnover.",[129,340,341,344],{},[74,342,343],{},"EUCS",": European Cybersecurity Certification Scheme for Cloud Services. Technical certification scheme that feeds into a CADA Tier 3 evaluation.",[129,346,347,350],{},[74,348,349],{},"EU Data Boundary",": Microsoft's construct for storing and processing EU customer data inside the EU. Addresses Tier 1, with residual concerns around telemetry and support access.",[129,352,353,356],{},[74,354,355],{},"OZG",": Onlinezugangsgesetz, the German framework law on digitising public-administration services. Many OZG workloads tend to fall into CADA Tier 3.",[118,358,360],{"id":359},"where-europioneer-fits-in","Where europioneer fits in",[70,362,363,364,367,368,156],{},"europioneer runs a European-sovereign stack based on Nextcloud, Open-Xchange, Element/Matrix, Keycloak and Collabora Online – as a managed hosted service in German and EU data centres, without hyperscaler sub-processors. For public authorities and SMEs we take on the technical validation in step 3 and the transition phase in step 5 – including tender-ready component lists that reference CADA sovereignty tiers rather than vendor-specific requirements. Packages and pricing at ",[102,365,366],{"href":366},"/en/pricing",". Migration call at ",[102,369,371],{"href":370},"/en/contact?subject=CADA-Migration","/en/contact",[118,373,375],{"id":374},"bottom-line","Bottom line",[70,377,378,381,382,156],{},[74,379,380],{},"3 June 2026 marks the point at which European sovereignty turns from political demand into an operational procurement criterion."," CADA is still only a proposal. But every German authority, every school trust, every SME with public-sector business that signs a five- or seven-year framework contract today is already signing it into the CADA application window. Whoever moves the pilot unit onto a European stack now does not have a 2029 migration panic. Whoever waits, does. Background on the bigger picture – ",[102,383,385],{"href":384},"/en/blog/eurostack-digital-sovereignty","Eurostack",[70,387,388],{},[102,389,390],{"href":370},"Request a CADA migration call →",[392,393],"hr",{},[70,395,396],{},[74,397,398],{},"Related posts:",[126,400,401,406,411,416,421,426,431],{},[129,402,403],{},[102,404,405],{"href":104},"CLOUD Act 2026 – the legal situation for German cloud customers",[129,407,408],{},[102,409,410],{"href":384},"Eurostack – why European digital sovereignty is becoming concrete",[129,412,413],{},[102,414,415],{"href":114},"NIS2 and GDPR – the Microsoft paradox in the German supply chain",[129,417,418],{},[102,419,420],{"href":312},"BSI IT-Grundschutz and Microsoft 365 – where it breaks",[129,422,423],{},[102,424,425],{"href":154},"openDesk Partner Program 2026 – the sovereign workplace for SMEs",[129,427,428],{},[102,429,430],{"href":109},"DORA and Microsoft 365 – exit strategy for banks in 2026",[129,432,433],{},[102,434,436],{"href":435},"/en/blog/microsoft-365-schools","Microsoft 365 in schools – where privacy and education collide",{"title":438,"searchDepth":439,"depth":439,"links":440},"",2,[441,442,449,450,458,459,460],{"id":120,"depth":439,"text":121},{"id":162,"depth":439,"text":163,"children":443},[444,446,447,448],{"id":170,"depth":445,"text":171},3,{"id":177,"depth":445,"text":178},{"id":191,"depth":445,"text":192},{"id":202,"depth":445,"text":203},{"id":209,"depth":439,"text":210},{"id":260,"depth":439,"text":261,"children":451},[452,453,454,455,456,457],{"id":267,"depth":445,"text":268},{"id":274,"depth":445,"text":275},{"id":281,"depth":445,"text":282},{"id":291,"depth":445,"text":292},{"id":298,"depth":445,"text":299},{"id":305,"depth":445,"text":306},{"id":317,"depth":439,"text":318},{"id":359,"depth":439,"text":360},{"id":374,"depth":439,"text":375},"2026-06-09T00:00:00.000Z","On 3 June 2026 the European Commission proposed the Cloud and AI Development Act. Four sovereignty tiers, Tier 3 demands EU ownership. What that means now for federal, state and SME buyers.","md",[465,468,471,474,477],{"q":466,"a":467},"What is the Cloud and AI Development Act (CADA)?","CADA is a draft regulation tabled by the European Commission on 3 June 2026 as part of the European Technological Sovereignty Package. It defines a four-tier sovereignty framework for public-sector cloud and AI procurement and creates the legal basis for tripling European data-centre capacity by 2030. CADA is read alongside the Cyber Solidarity Act 2 (CSA2) and a reworked EUCS certification.",{"q":469,"a":470},"What are the four sovereignty tiers under CADA?","Tier 1 requires storage and processing in EU infrastructure. Tier 2 adds independence from third countries and supply-chain transparency. Tier 3 demands European ownership and control of the provider, with narrowly drawn exceptions for third-country vendors. Tier 4 is the highest – full software-chain control and verified absence of foreign interference. Tier 3 is the minimum tier for critical public infrastructure.",{"q":472,"a":473},"Can Microsoft Azure reach Tier 3 or Tier 4?","Under the current draft, not without structural change. Tier 3 demands European ownership and control. Microsoft Ireland Operations Limited is a subsidiary of the US parent Microsoft Corporation and is therefore subject to the CLOUD Act, FISA 702 and Executive Order 12333. Microsoft Cloud for Sovereignty and the EU Data Boundary address Tier 1 and parts of Tier 2 – but not the ownership anchor at the heart of Tier 3.",{"q":475,"a":476},"When does CADA enter into force?","CADA has been an official draft since 3 June 2026. The trilogue between Parliament and Council is expected to open in Q3 2026, with a final text not before late 2027. Application typically follows twelve to twenty-four months after entry into force – realistically 2029. Anyone signing a procurement contract today with a five-year horizon is signing it into the CADA application window.",{"q":478,"a":479},"How does CADA relate to the Cyber Solidarity Act 2 and EUCS?","CSA2 from 20 January 2026 extends supply-chain risk assessment beyond purely technical security, increases ENISA's mandate and budget, and introduces fines of up to seven percent of worldwide turnover. EUCS remains the technical certification scheme. CADA sets the sovereignty tiers, EUCS supplies the technical audit, CSA2 enforces supply-chain security. A CADA Tier 3 assessment references an EUCS certificate as one input among several.",{"name":481,"description":482,"totalTime":483,"steps":484},"Prepare a public-authority or SME cloud for CADA Tier 3","Six steps from inventory to a procurement-ready replacement architecture, documented for internal audit and the audit office.","P270D",[485,488,491,494,497,500],{"name":486,"text":487},"Classify the cloud inventory by processing purpose","Sort every active cloud contract by processing purpose – general office, business application, KRITIS-critical, classified above public. For each entry capture today's provider, data location and likely CADA tier. Microsoft 365 today realistically falls into Tier 1 or Tier 2.",{"name":489,"text":490},"Name the sovereignty gap per workload","For each workload determine the likely CADA tier under the proposal. Tier 3 candidates – electronic file, OZG online-services workloads, social data, tax data, health data, law enforcement. The output is a gap list with target replacement dates.",{"name":492,"text":493},"Technically validate a European replacement stack","Name at least one open-source or European provider per Tier 3 workload and lab-test it. openDesk and Phoenix for office, Nextcloud for files and collaboration, Element on Matrix for chat, Keycloak for identity, Open-Xchange or Mailcow for email. Test means migrating a pilot unit with production-volume data.",{"name":495,"text":496},"Re-cut tender documents along CADA tiers","Add sovereignty tier and software-supply-chain to the evaluation criteria. Score not only on price but also on documented EUCS certification and verifiable provider ownership. Agree procurement-chamber-proof wording with the buyer instead of using hyperscaler-specific requirements.",{"name":498,"text":499},"Plan a transition phase","For existing contracts with US providers define a transition phase – standardised data export, parallel European stack, workload-by-workload migration. Plan at least 18 months because Tier 3 workloads are usually tightly coupled to identity and data flows.",{"name":501,"text":502},"Consolidated compliance documentation","Maintain the GDPR record of processing, NIS2 risk register, BSI IT-Grundschutz modelling and the new CADA tier per workload in a single database. A single system of record saves a mid-sized authority one to two FTEs per year.",{"src":504},"https://images.unsplash.com/photo-1529119368496-2dfda6ec2804?w=1200&q=80",{},true,"/en/blog/cada-eu-tech-sovereignty-package-public-sector-2026",{"title":53,"description":462},"en/3.blog/15.cada-eu-tech-sovereignty-package-public-sector-2026","wCWLyFlFlLz2vw8yCOXC6G3L4gQ59o-5I8fH7c2l9Tg",[512,516],{"title":513,"path":109,"stem":514,"description":515,"children":-1},"DORA, CTPP Designation and Microsoft 365 – Why Banks Need a Tested Exit Strategy in 2026","en/3.blog/14.dora-microsoft-365-exit-strategy-banks-2026","Since late 2025, Microsoft is an officially designated critical ICT third-party provider under DORA. What that means for BaFin, the ESAs and your concentration-risk file.",{"title":517,"path":518,"stem":519,"description":520,"children":-1},"Euro-Office 1.0 – the sovereign Microsoft 365 alternative in a technical hands-on review","/en/blog/euro-office-microsoft-365-alternative-2026","en/3.blog/16.euro-office-microsoft-365-alternative-2026","Euro-Office 1.0 launched on 9 June 2026 as a European Microsoft 365 alternative. What the suite delivers technically and who should adopt it now.",1784618210574]