Prior assessment
Critical providers — those that host customer data, hold secrets or access the code — are required to hold a current security certification or equivalent evidence, to locate production data in the EU, and to sign a processing agreement where they process personal data. Taking on a critical provider requires collegiate approval by the Security Council.