The Lawxy Times

The European Commission, on 29 September 2026, approved Google’s takeover of Wiz under the EU Merger Regulation. The decision confirms that the concentration does not breach EU competition rules. Google and Wiz may now close the transaction, ending regulatory uncertainty for cloud‑security market participants. The ruling also delineates the Commission’s assessment methodology for cloud‑cybersecurity mergers.

Full News Breakdown

The Commission opened a formal review after competitors raised concerns that merging Google’s cloud platform with Wiz’s security software could diminish rivalry in the EU cloud‑security market. The parties argued that the combined entity would retain sufficient competitive pressure, while the Commission’s initial draft raised doubts about market foreclosure. After a detailed market test, the Commission concluded that the merger would not substantially lessen competition and issued its final decision.

  • Case Name: Google–Wiz takeover

  • Court: European Commission, Directorate‑General for Competition

  • Panel: Competition Directorate, Merger Review Unit

  • Date: 29 September 2026

  • Citation: Commission Decision M.11964

  • EU Instruments / UK Legislation Cited: Council Regulation (EC) No 139/2004 (EU Merger Regulation)

  • Key Provisions: Article 3(1), Article 4(1)

  • Primary Legal Issue: Whether the concentration would significantly impede effective competition in the cloud‑security market

  • Applicant/Plaintiff Arguments: Competitors claimed the merger would create a dominant provider capable of bundling services and raising prices

  • Respondent/Defendant Arguments: Google and Wiz contended that market shares remained below the thresholds for concern and that entry barriers were high

  • Court's Reasoning: The Commission applied the “significant impediment” test, examined market definition, assessed post‑merger concentration, and found that effective competition would persist due to strong secondary rivals and low switching costs

  • Holding: The merger is cleared without conditions

  • Operative Order: Parties may consummate the transaction immediately; the decision is binding on all EU Member States

  • Practical Outcome: Regulatory clearance removes the need for further antitrust filings in the EU

How Does This Affect You?

Before this decision, parties faced uncertainty about how the Commission would treat cloud‑cybersecurity concentrations, especially regarding market definition and the weight given to entry barriers. The Commission now clarifies that a combined market share below the 30 % threshold, coupled with robust secondary competition, is sufficient to satisfy the “significant impediment” test. Practically, this means that similar future transactions can rely on the same analytical framework to assess EU competition risk.

For Lawyers & Advocates

  • Re‑evaluate pending cloud‑service mergers against the 30 % post‑merger share benchmark, advising clients that a share below this level, together with demonstrable entry barriers, may now be deemed acceptable.

  • Amend merger‑notification checklists to include a detailed mapping of secondary rivals and an analysis of switching costs, reflecting the Commission’s emphasis on these factors.

  • Cite the Commission’s reasoning as persuasive authority when defending comparable concentrations before national competition authorities, highlighting the “significant impediment” test application.

  • Advise clients that conditional clearance is unlikely in this sector, reducing the need to prepare remedial commitments for similar deals.

  • Update internal risk‑assessment models to weight market definition narrowly, as the decision shows the Commission favours a product‑level approach for cloud‑security services.

For Law Students

The case illustrates how EU competition authorities apply the “significant impediment” test within the Merger Regulation framework. The core doctrinal focus is the interaction between market share thresholds and the assessment of secondary competition.

The decision is particularly relevant for the study of:

  • EU competition law – merger control

  • Market definition methodology

  • Assessment of entry barriers and switching costs

  • Comparative analysis of horizontal versus vertical effects

Comparable cases include:

  • Microsoft/LinkedIn (2016, Commission) – highlighted the role of ancillary services in market definition.

  • Amazon/Deliveroo (2024, Commission) – examined the impact of platform dominance on downstream competition.

Comparing these judgments reveals how the Commission balances quantitative thresholds with qualitative market dynamics.

For Businesses

  • Cloud‑service providers should review their market‑share calculations; a post‑merger share under 30 % now offers a stronger presumption of clearance, prompting boards to green‑light deals earlier.

  • Cybersecurity firms must document the existence of viable secondary competitors and low switching costs in internal competition assessments to support future merger filings.

  • Companies planning cross‑border acquisitions should align their EU merger‑notification dossiers with the Commission’s analytical template, reducing the likelihood of prolonged investigations.

Key Takeaways

  • The Commission clarified that a post‑merger market share below 30 % combined with robust secondary competition satisfies the “significant impediment” test under the Regulation.

  • Practitioners must incorporate a focused analysis of secondary rivals and switching costs into merger‑notification dossiers for cloud‑security transactions.

  • Regulators can now rely on this analytical framework to reject objections that ignore quantitative thresholds and qualitative competition factors.

  • Watch for the European Commission’s forthcoming guidance on digital market definitions, expected in early 2027, which may refine the approach to cloud‑service markets.

  • In‑house counsel should revise internal merger‑clearance protocols before the next fiscal year to reflect the new benchmark and avoid unnecessary delays.

Source: Google sees EU decision on Wiz takeover published

Author Image
Lawxy Times Reporter

EU Clears Google’s Acquisition of Cloud Security Firm Wiz

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested