
When Compliance Becomes Architecture
When Compliance Becomes Architecture was a live session on the Cloud and AI Development Act, or CADA. CADA is the EU proposal that turns the word "sovereignty" into three things a buyer can check: where your data sits, who can reach it, and which country's law applies to it. The event read CADA as an engineering question, not a legal one. It was built for anyone who sells software or cloud services to a public sector body, or to a supplier who does.During the session, Fractal Cloud read CADA the way an architect reads a spec: a list of problems, each matched with a working solution. The talk walked through the four-level assurance ladder, the core of CADA. It runs from a self-signed declaration at level one to full EU-only access at level four. The European Commission expects seven public buyers out of ten to stop at that first level. The talk also explained why the pressure behind the law is real: three non-EU providers now control more than 70% of the cloud market in Europe.The session then showed how Fractal Cloud turns this from a yearly project into daily work. Every environment starts from a Blueprint, the definition that deploys the system. Fractal Cloud checks every Live System, the running version of that environment, against its Blueprint on an ongoing basis. An auditor asks for three things: architecture diagrams, change history, and proof of monitoring. On Fractal Cloud, all three arrive as a ready export you review each year, not as a report you rebuild from scratch. The talk closed by pointing out that the same evidence lines up with DORA and NIS2, for teams that answer to more than one regulator. Watch the session on demand →
