The consequences of CADA and the compliance cascade in communications

The consequences of CADA and the compliance cascade in communications

In complex environments, change is never isolated.

For intricate structures, with so many intertwined elements and moving parts even the smallest update can change how things work for everybody involved. On a larger scale, a single shift can lead to another and another, creating an unstoppable momentum that gains strength as it ripples outwards into multiple ecosystems, bringing brand new challenges and opportunities to the surface.

Try as you might, when these pockets of large-scale momentum solidify, it’s pretty much always out of your hands. Instead, the ones making the choices are policymakers and elected officials who use this velocity to influence change. To make things more complicated, by the time anything is actioned the attitudes behind these policies have often already been living, growing and evolving inside of industry sentiment for a very long time. After all, it takes a while for rulings to be rolled out but it requires relatively little for people to form an opinion on what they believe is right and act upon it themselves.

Because of this, when a sentiment is baked into the zeitgeist we often see localised pockets of change happening long before sweeping legislation is passed. These separate pools of combined enthusiasm are then reinforced on the EU stage, reiterated, reworked and brought in line with existing policies and before you know it the dominos are falling and a cascade of change is underway. Better yet, it’s been underway for some time and it took a new enforcement for you to see the bigger picture that you are now, and always have been, very much a part of. This is a story that’s been told many times in many different ways where sentiment becomes action, action becomes policy, policy becomes expectancy.

We are currently seeing this play out in real time in the way that EU communications lives and breathes, but the first domino didn’t fall this year or even this decade. This cascade has been growing for a lot longer than you think and it’s now getting so big that it currently acts as both a delayed reaction to that market sentiment and a sign of things to come.

Make no mistake, I’m not saying that it’s too late for you to act. But even on a relatively short timeline how you adjust operationally is going to dictate your success going forward in very broad terms - from the people you can do business with, to how you’re able to set up and deploy your services even in your own country. In no uncertain terms, if you’re not ready for what’s coming you could see this particular cascade sink your operations at a European level.

CADA (The Cloud and AI Development Act) and the EU Tech Sovereignty Package are the latest items that will look to transform EU cloud (and these are the policies that you’ll need to learn about first) but the movement we’re now seeing isn’t isolated to these two things alone. This is because as more and more European organisations tie sovereignty directly to autonomy, risk management, resiliency and overall security, a lot of people are looking to ensure minimal non-EU influence as a baseline going forward. A baseline that they’re looking towards their providers to go above and beyond.

But what are the details of these EU-wide policies and the separate national reactions that together are looking to form the sovereign EU cloud? What’s happening outside of this legislation? What effects and impacts are we already seeing occur? What are some of the challenges and opportunities that communications providers can expect to arise because of all this?

CADA and the EU Tech Sovereignty Package

If you haven’t done so already, now would be a good time for you to check out our full breakdown of both CADA and the EU Tech Sovereignty Package. They’re central to the latest part of the communications compliance cascade and the full context is definitely important.

If you’re happy with just the short version:

  • CADA Is a proposal by the EU commission which aims to fully fortify European digital sovereignty. It will boost the research, innovation and capacity budgets that the EU will need to claim full digital independence and it introduces a sovereignty tiering system that the EU public sector will need to comply with.

  • The EU Tech Sovereignty Package is the overall bundle of initiatives that the EU Commission is looking to deliver. CADA is included here alongside the Chips Act 2.0 (which will bolster local semiconductor manufacturing), the EU Open Source Strategy (which encourages the use of open-source software and tech in public services) and a roadmap for implementing all of this change and for building energy infrastructure in a way that will have minimal impact on EU climate goals (including the implementation of AI, overall digitalisation and cross-border energy sharing).

Our focus is on CADA and not the full tech sovereignty package for a reason - this is the act that will impact communications providers the most. Over the years, multiple rulings have served to strengthen EU digital sovereignty and add to the momentum of the European compliance cascade but CADA acts as the centrepiece which not only combines and magnifies their powers but aligns them closer with modern needs and gives them the infrastructure necessary to create change.

CADA and the compliance cascade

Depending on how you look at it, your idea of what rules have actually contributed to the current state of the European cloud may differ. There’s dozens out there but there is a solid line that can be drawn between now and a starting point of nearly a decade ago. Here’s the picture it draws:

2018 - It all starts with GDPR (the General Data Protection Regulation) which brings in strict rules around personal data processing

2019 - The EU Cybersecurity act follows the next year and grants agencies permanent powers to evaluate provider security and foreign ownership risks

2022 - A few years later the NIS2 directive expands cybersecurity and risk assessment to specific providers, with a judging gaze cast over non-EU influences

2024 - In 2024 the EU Data Act legally eradicates vendor lock-in and adds requirements for maximum cloud-to-cloud data portability. The EU AI Act also began this year with provisions for it still being rolled out.

2026 - CADA is then proposed on the 3rd June 2026, bringing with it plans to increase research, innovation and capacity as well as a digital sovereignty framework which will be mandatory for public sectors.

Compliance Cascade Timeline

Why CADA is the crown jewel of the compliance cascade

If there is one thing that you take away from all of this, it should be an understanding of why CADA is different from everything else that’s come before it.

GDPR, the EU cybersecurity act, NIS2, they all focus on building rules and regulations. They set ordinances that are far from toothless, but they’re simply not set up for today’s technological or geopolitical landscape. CADA is the muscle that enforces EU data sovereignty, and it’s backed by sovereign architecture and infrastructure which is immune to non-EU influence and political compulsions.

EU sovereignty vs outside influence

If you’re wondering what the fuss is all about around Europe wanting to become digitally sovereign, there are three statistics that you should be paying attention to:

  1. Three non-EU companies currently control between 65-70% of the EU cloud services market

  2. No single European entity controls more than 2% of that same market

  3. The ownership stake that EU organisations have in the EU cloud is less than 15% total.

EU cloud market statistics

For a good example of what this kind of ownership means for a digitally sovereign Europe you simply need to look at the proposals that didn’t make it through, not because of nationwide demands or local resistance but because of foreign influence.

Namely, in 2024 the European Union Cybersecurity Certification Scheme for Cloud Services (EUCS) was updated to bring it more in line with modern needs. Lots of complexity here but the long and short of it is, after multiple years of negotiation the choice to remove sovereignty filters from the EUCS was made. The main backers of this adjustment? Mostly US hyperscalers who would stand to lose some of their control over the EU cloud.

I say all of this only to highlight what happens when EU sentiment is only stopped from being policy because of Non-EU pressures – A process where change isn’t halted but the time between new compliance actually shortens with each new iteration:

  • The time between the EU cybersecurity act and NIS2? Three years

  • Between NIS2 and the EU Data Act? Two years

  • The EU Data Act and the EU Tech Sovereignty Package proposal? One year

To the surprise of very few, the Tech Sovereignty Package contains sovereignty filters that are eerily similar to the ones that were previously in the original 2024 EUCS update. Continuing this established pattern, if this package doesn’t make it through there will just be another proposal with similar demands, then another and another in shorter and shorter time spans until Europe has what it feels is necessary to achieve its sovereignty goals.

That’s the compliance cascade in motion.

policy statistics

Digital sovereignty on a national scale

But this isn’t all about Europe as a whole. With all of this happening on such a high stage, it’s no surprise that a lot of us overlooked the fact that individual countries don’t actually need EU legislation to make their own sovereignty decisions. In fact, three key regions are already taking steps towards becoming sovereign without waiting for EU policymakers:

  • France has made a commitment to move all 2.5m of their civil servants to sovereign digital platforms by the end of 2027

  • Germany are moving 80% of their civil workforce to open-source solutions

  • France and Germany together are building their own framework for EU digital sovereignty that would serve to enforce EU regulations on tech providers

  • The Netherlands recently blocked a US acquisition of a Dutch company. The reason? Risks to public interest following a sovereignty review

All of this has been transpiring across the past year, and each instance shows a separate facet of how sovereignty can transform a digital landscape. This is because these changes don’t just reflect EU sentiment but also national makeup and overall principles, each of which you’ll have to consider if you’re looking to go into multiple European markets. For example, France has a more centralized approach and are able to enact massive singular motions which you’ll have to adjust to quickly. The Nordics? Their risk profile overall is minimal so they will look to take sovereignty measures one step further, something you’ll have to bear in mind when delivering services.

The future of EU sovereignty

A world in which Europe has full operational sovereignty takes a long time to build. But if you take a step back you’ll realise two things - We’re not anywhere close to the start of this journey and the possible outcomes for the next 5-10 years have already started pointing in the same direction.

The building blocks that already exist

Here’s what has already come to pass in terms of the current EU sovereignty cascade:

  • There are at least half a dozen pieces of active legislation that are acting as a strong, established foundation for a sovereign EU, with stronger legislation around the corner

  • Policies that are being activated are increasingly leaning towards holistic outcomes (infrastructure, physical location and practical elements as well as digital laws)

  • Both political and public sentiment is pro-sovereign and has been for some time

  • Solid country-level legislation has already been passed to build stronger sovereignty provisions

  • Organisations of all shapes and sizes are actively avoiding non-EU dependencies in line with their risk profiles

  • Exposure to geopolitical tensions is being tied directly to overall resiliency & security

The likely next steps

If we plot a course from everything that has already transpired and extend it into the future, there are a few things that now seem likely:

  • As EU cloud infrastructure becomes more mature and widespread, fully sovereign services will become more of an expectancy

  • Public sector functions will default to higher levels of sovereign requirements, with L3 and L4 of CADA turning into more of a baseline

  • Simply hosting your data in the EU will no longer be enough

  • Country-level sovereignty demands will become more widespread and nuanced

  • Complexity for delivering cloud communications will increase

  • Public sector will act as a testing ground. As the private sector starts to see the long-term benefits of sovereign solutions they will also become more demanding in key areas

The sovereign opportunities and challenges for Service Providers

So, with all this change on the horizon, how can providers prepare effectively? Unfortunately, there is no cut and dry answer as a lot depends on how you’re already set up, what your goals for the future are and where your organization plans to be in the next few years. A lot of it though boils down to two things – How you deliver services and how you manage them.

Delivering sovereign services

If you want to survive in the European markets, there are a number of things that you have to do to create a sovereign makeup. A rule of thumb is to ensure that you are not exposed to any non-EU laws such as the CLOUD Act and at the very least you need to be able to run at scale on European data centres with an eye on making your entire supply chain EU-native.

Are there ways to get around EU regulations for now? Yes absolutely, but the more workarounds you rely on, the more unstable your platform becomes as those loopholes start closing. There is also the national sovereignty levels that you should start considering if you’re operating in multiple countries – start thinking about how you’re going to be able to deliver your solution if you’re playing by multiple sets of rules simultaneously.

Managing sovereign services

So you’ve got everything set up in a way that you can now deliver your services with nothing but European DNA running through your data-lines. Now you have to start thinking about the rules that surround how those services are managed because there is already an increasing focus not just on technical setups but practical ones as well. Is everyone you’re in partnership with headquartered in the EU, or the country that you’re delivering to? What about the staff that’s needed to run that service end-to-end? If your answer is no then you may need to start thinking about how much time and effort it’s going to take to insulate yourself from practical non-compliance.

Looking to figure out your EU sovereign future? Get in touch with the experts and start planning for your long-term success.