/ SecNumCloud: The Complete Guide to ANSSI’s Sovereign Cloud Qualification

SecNumCloud: The Complete Guide to ANSSI’s Sovereign Cloud Qualification

SecNumCloud is the French state’s highest security qualification for cloud services, and ANSSI only grants it after a state-supervised evaluation. Since August 2026 it’s also law for part of the French public sector. State bodies now have to keep their most sensitive data on services that meet the SecNumCloud 3.2 requirements.

Everyone else, from French hospitals to US and UK SaaS vendors chasing French public contracts, now treats SecNumCloud as the working definition of a “sovereign cloud.” It’s also one of the hardest qualifications in Europe to get, because ANSSI checks who owns the provider and which foreign laws could reach it, on top of the technical controls.

This guide walks through what SecNumCloud is and who needs it, what the requirements ask for, how qualification works and what it costs, and the options open to companies headquartered outside the EU.

SecNumCloud at a Glance

In short, SecNumCloud is a three-year qualification the French state grants to one specific cloud service. It’s built on ISO 27001 and adds sovereignty rules that no other European scheme enforces today.
Attribute Detail
Issued by ANSSI, France’s national cybersecurity agency
Type Qualification (an ANSSI Visa de sécurité), not a certification
Current version SecNumCloud 3.2, dated 8 March 2022
What gets qualified A named cloud service, not a company or a data center
Service models IaaS, PaaS, CaaS, SaaS
Foundation ISO 27001 Annex A, plus cloud-specific and sovereignty requirements
Sovereignty rules EU registered office, non-EU shareholders kept to a minority, EU data location, immunity from non-EU laws
Evaluation ANSSI-approved evaluation center, decision by ANSSI
Validity 3 years, with annual surveillance audits
Typical duration About a year after formal acceptance (J0), longer including preparation
Legal status Mandatory for particularly sensitive French state data since August 2026
Official list Published and maintained on ANSSI’s website

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

What Is SecNumCloud?

SecNumCloud is a security qualification that ANSSI grants to a specific cloud service after an approved evaluator has checked it against the SecNumCloud 3.2 requirements framework (the référentiel d’exigences). It covers four service models: IaaS, PaaS, CaaS, and SaaS.

It starts from ISO 27001 Annex A. On top of that sit cloud-specific controls and legal requirements meant to keep the service out of reach of non-European laws. According to ANSSI’s SecNumCloud FAQ, a qualified service should hold up against lone attackers and hacktivists, competent cybercriminals, and foreign legal orders that would compromise its availability, confidentiality, or integrity.

What Is ANSSI?

ANSSI (Agence nationale de la sécurité des systèmes d’information) is France’s national cybersecurity agency, set up in 2009. It’s part of the SGDSN, the national defense and security secretariat that reports to the Prime Minister.

Alongside incident response and regulation, ANSSI runs the evaluation schemes behind its Visas de sécurité, the seals it gives to products and services that have proven a high level of security. SecNumCloud is the one for cloud services.

Qualification vs Certification: Why the Distinction Matters

Most security frameworks end with a document from a private body: an ISO 27001 certificate from a certification body, or a SOC 2 report from a CPA firm. SecNumCloud ends with a decision signed by ANSSI. An ANSSI-approved evaluation center performs the audit, but the state reviews the work and makes the call.

That has two practical effects. The qualification belongs to a named service with a defined scope, and the company selling it can’t stretch it to anything else. Only services with a formal ANSSI decision can use the SecNumCloud name or the Visa de sécurité logo, so being “in qualification” doesn’t count.

SecNumCloud and France’s “Cloud de Confiance” Doctrine

In July 2021, the government issued circular n° 6282-SG, known as the cloud au centre doctrine. It made cloud the default hosting choice for state IT and steered sensitive systems toward trusted offers.

Cloud de confiance (trusted cloud) became the label for offers that pair high security with immunity from non-EU laws. SecNumCloud 3.2 is how the state checks that claim instead of taking a provider’s marketing at its word.

How SecNumCloud Has Evolved

SecNumCloud started in 2016 as a voluntary benchmark and became a legal requirement for part of the French state in August 2026. The milestones below run newest first.

DateMilestone
August 2026Arrêté of 12 August 2026 approves SecNumCloud 3.2 as the binding framework; published in the Journal officiel on 14 August
April 2026Decree n° 2026-272 of 14 April 2026 implements article 31 of the SREN law and lists six public interest groups in scope
December 2025S3NS, a Thales company built on Google Cloud technology, obtains qualification for its PREMI3NS offer
May 2024SREN law (loi n° 2024-449 of 21 May 2024) creates the legal obligation in article 31
December 2022Government launches a €3.5 million support program to help startups and SMEs qualify
March 2022Version 3.2 published, adding immunity from non-European laws and lifecycle penetration testing
July 2021

Circular n° 6282-SG sets the cloud au centre doctrine for state IT

2016ANSSI publishes the first SecNumCloud requirements framework

From the First Repository to Version 3.2

ANSSI built the original framework so public and private organizations could tell which cloud providers they could trust with outsourced data and systems. It makes no assumptions about technology, so the rules are the same whether a service runs on VMware, OpenStack, or Kubernetes.

For its first six years, SecNumCloud was mostly a security standard. Strong controls and good documentation were enough, whoever owned the provider.

Why Version 3.2 Added Sovereignty Criteria

Version 3.2 came out of the 2021 national cloud strategy and France’s push for a high assurance level in the EU’s own cloud certification scheme. According to ANSSI, it added two big things: explicit technical and legal criteria for immunity from non-European laws, and penetration testing for the whole life of the qualification.

The laws in question are ones like the US CLOUD Act and Section 702 of FISA, which can force US-controlled companies to hand over data stored abroad. Since 3.2, a provider can pass every technical control and still fail because of who’s on its shareholder register.

SecNumCloud Becomes Binding: The SREN Law and the August 2026 Arrêté

Article 31 of the SREN law requires state administrations, their operators, and designated public interest groups to use cloud services that protect data of particular sensitivity against unauthorized access by non-EU public authorities. For almost two years that stayed on paper, waiting for the texts that would put it into effect.

Decree n° 2026-272 of 14 April 2026 set the conditions and the derogation process, as the French Ministry of Economy’s legal department explains. The arrêté of 12 August 2026 then approved SecNumCloud 3.2 as the required framework.

Providers prove compliance with an ANSSI qualification, or with an EU or EEA certification that ANSSI recognizes as equivalent. The requirements didn’t change in 2026; only their legal status did.

Who Needs SecNumCloud?

The law only forces SecNumCloud on one narrow group: French state bodies hosting particularly sensitive data. The commercial pull is much wider. It reaches critical operators and regulated industries, and through them, the cloud vendors who sell to them.

State Administrations and Public Operators

Since the August 2026 arrêté, state administrations, the state’s public operators, and designated public interest groups (GIPs) must use a SecNumCloud-qualified or equivalent service when a private cloud provider processes their data of particular sensitivity.

The decree names six GIPs: the Agence du numérique en santé, the Centre d’accès sécurisé aux données, the Centre ressources prévention de la radicalisation, the Collecteur analyseur de données, the GIP Modernisation des déclarations sociales, and the national social housing application register. The Health Data Hub was already named in the law itself.

If a project was already under way when the rules took effect, the organization can ask the responsible minister for a temporary derogation. DINUM, the state’s digital directorate, gives an opinion, and the Prime Minister has to sign off. The derogation can’t run more than 18 months past the date an acceptable offer becomes available in France.

What Counts as Data of “Particular Sensitivity”?

The SREN law uses two tests, and the data has to meet both. First, it must either fall under secrets protected by law (national defense, medical, business, and judicial secrets, or privacy) or be necessary for the state’s essential missions, such as national security, public order, and protecting health and life.

Second, a breach would have to be likely to harm public order, public security, people’s health or lives, or the protection of intellectual property. The Ministry of Economy’s legal department calls this second test the main filter, and plenty of confidential government data won’t pass it.

OIVs, OSEs, and NIS2 Essential Entities

Operators of vital importance (OIVs), operators of essential services (OSEs), and the essential and important entities created by NIS2 aren’t legally required to use SecNumCloud. They’re still the buyers most likely to ask for it.

ANSSI’s own recommendations on hosting sensitive information systems in the cloud use qualified offers as the reference point. It also points out that a qualified offer makes the customer’s own security accreditation (homologation) easier, since part of the stack has already been checked.

Private Companies and Regulated Sectors

For private companies, SecNumCloud is voluntary, and ANSSI says the framework works as a set of good practices even when no regulation applies. Demand is highest where contracts already ask for protection from extraterritorial access, especially in health, defense, and energy.

Health is the clearest case. A February 2026 Prime Minister’s circular on state digital procurement reaffirmed SecNumCloud for sensitive data, including health data, and the Health Data Hub is expected to move to a qualified host.

Cloud and SaaS Providers Selling Into the French Market

If you sell to French ministries, public operators, or hospitals, you’ll now see SecNumCloud in procurement documents. Without a qualified offer, you can still win that business when the data falls outside the SREN definition. What you can’t do is call your product SecNumCloud compliant just because it runs on a qualified infrastructure provider.

Insider Note: For SaaS companies selling into France, SecNumCloud often shows up as a single line in a security questionnaire, after sales has already promised “sovereign hosting” for a product running in a US hyperscaler’s Paris region. A Paris region fixes data location. It does nothing about ownership or extraterritorial access, and that’s exactly where SecNumCloud draws its line.

Which Cloud Services Can Be SecNumCloud Qualified?

ANSSI qualifies individual cloud offers. A provider can hold a qualification for one service and sell several unqualified ones right next to it.

IaaS, PaaS, SaaS, and CaaS​

The framework defines four service models: infrastructure (IaaS), platform (PaaS), containers (CaaS), and software (SaaS). Recent ANSSI decisions show the spread, from an OVHcloud bare-metal IaaS and a Cloud Temple OpenShift PaaS to SaaS products such as Whaller’s collaboration platform and Index Education’s PRONOTE school software.

Each decision also spells out what’s outside scope, and managed services or outsourcing sold around the qualified service are routinely left out. If your offer is a newer type, ANSSI suggests talking to its industry team before you apply to see how it fits the framework.

Does a Service Inherit Qualification From Its Hosting Provider?

No. ANSSI is explicit: an offer hosted on a SecNumCloud-qualified service isn’t qualified itself and can’t use the name or logo. The qualification also tells you nothing about how secure a customer’s own application on top is.

There’s a shortcut, though, called qualification by composition. A SaaS or PaaS built on an already-qualified IaaS still goes through ANSSI’s process, but the evaluation treats the qualified layer as already assessed and looks at how you use it, mostly by reviewing your service agreement with that provider.

ANSSI expects this to cut evaluation effort and cost, especially on things like data center physical security. The organizational and documentation work is still heavy, though, because the framework rests on ISO 27001 Annex A even when the scope is one SaaS product.

Pro Tip: SaaS Product Qualification

If you plan to qualify a SaaS product, choose a qualified IaaS first and design for composition from day one. Put the risk of your host losing its qualification, or not renewing it, into your own risk analysis. ANSSI flags it as a point to watch, and evaluators will check for it.

SecNumCloud 3.2 Requirements, Domain by Domain

SecNumCloud 3.2 follows the structure of ISO 27001 Annex A, tightens each domain for multi-tenant cloud, and ends with rules on service agreements and sovereignty. Here’s what each domain asks for in practice. For exact wording, go to the full requirements framework.

Governance, Risk Management, and Security Organization

The provider needs a documented security policy, a formal risk analysis for the qualified service, and clear security roles. It’s the part of SecNumCloud that looks most like an ISO 27001 information security management system (ISMS), so a provider with a mature, certified ISMS starts well ahead.

Personnel Security

Anyone who administers the service gets a background check that scales with their privileges. People with high privileges also sign a commitment tied to French labor-code rules on business secrets and intellectual property.

Contractors have to pass the same checks or work under a vetted employee’s supervision, and that rule alone can change how a provider uses outsourced support.

Access Control and Identity Management

The provider’s administration interfaces must be separate from the ones customers use, and both need protection. The same goes for directories, since administrator accounts and customer user accounts can’t live in the same one.

Admins work from dedicated, hardened workstations that aren’t used for anything else. Remote administration is allowed under a documented policy, as long as traffic runs through an encrypted tunnel users can’t turn off or get around and the device has full-disk encryption.

Encryption and Key Management

Cryptography has to follow ANSSI’s rules on algorithms and key management. In an architecture review, the real question is who controls the keys and whether anyone outside the EU could be forced to use them.

Physical and Environmental Security

The data centers behind the service need physical access control, monitoring, and protection against environmental risks. For a SaaS qualified by composition, the underlying qualified IaaS covers most of this.

Operations Security, Network Segregation, and Incident Management

SecNumCloud wants the traffic that runs the service kept strictly apart from the traffic customers generate. In practice, that means separate networks for customer usage, service management, and infrastructure management.

Logging, vulnerability management, and incident handling live here too. Version 3.2 also requires penetration testing for as long as the qualification lasts, rather than once before the first audit.

Business Continuity

Backups and continuity plans have to keep the service available and recoverable. Backups follow the same EU location rules as production data, so cheap backup storage outside the EU is off the table.

Supplier Relationships, Service Agreements, and Reversibility

Any third party that could reach customer data is in scope, and evaluators look at whether a non-EU company could get at the data in practice. Each customer agreement has to set out the qualified scope, who’s responsible for what, and reversibility, which is how the customer gets its data back when it leaves.

Protection Against Non-European Law

This is chapter 19.6, and it’s the one most providers can’t fix by spending more. ANSSI splits it into five areas:

  • Registered office: the provider’s head office must be in an EU member state.
  • Capital: non-EU third parties can only hold minority stakes.
  • Third-party services: the provider has to limit its reliance on non-EU companies that could get hold of the data.
  • Autonomy: the provider must be able to keep operating the service on its own.
  • Independence: the service has to stay free of outside interference and respect EU law, fundamental rights, and values.

Data location rules sit next to it. Customer data, stored or processed, has to stay in the EU, and so do administrator directories, customer user directories, and technical data like logs and root certificate authorities.

How to Get SecNumCloud Qualification

Qualification runs through four ANSSI milestones, J0 to J3, and an ANSSI-approved evaluation center does the audit itself. Getting ready for J0 often takes as long as everything after it.

Step 1: Submit Your Application to ANSSI

Start by contacting ANSSI’s industry team to present the project and check that the offer fits the framework. If it does, you send a formal application file to ANSSI’s qualification team.

J0 means ANSSI has accepted the file, with or without reservations, and assigned a qualification officer. From then on, the provider can talk publicly about its application and ask to appear on ANSSI’s list of offers in qualification. It still can’t use the SecNumCloud name or logo.

Step 2: Close the Compliance Gaps

Remediation usually starts well before J0 and keeps going after it. Think network segregation, dedicated admin infrastructure, EU-only directories and logs, and new contract terms with subcontractors. Meanwhile, the provider and its evaluation center agree on an evaluation strategy that sets the scope, the test plan, and how composition applies.

J1 is ANSSI signing off on that strategy. Expect your commercial launch to overlap with qualification, since LeMagIT has reported that ANSSI wants a candidate environment to have some real customers before it grants qualification.

Step 3: Evaluation by an ANSSI-Approved Assessment Provider

The evaluation center audits the service against every requirement that applies. That usually means a detailed documentation review, then on-site technical audits and penetration tests. The provider gets the findings back and fixes them before the report is final.

J2 is ANSSI accepting the evaluation work. ANSSI reads the evaluator’s report closely and can ask for more before it agrees.

Step 4: Qualification Decision

J3 is the qualification decision itself. It names the service and its type, sets conditions of use, and lists what’s out of scope.

ANSSI then lists the offer on its website, and the provider can use the Visa de sécurité logo under ANSSI’s branding rules. Any press release that mentions SecNumCloud has to go to ANSSI for approval first.

Important: A clean ISO 27001 audit history doesn’t mean the SecNumCloud evaluation will go smoothly. Projects usually stall on things ISO 27001 never asked about, like separating administration from customer usage, moving directories and logs into the EU, and proving that no non-EU party can reach the data.

Maintaining SecNumCloud Qualification

A SecNumCloud qualification lasts three years, and ANSSI keeps watching the whole time, so budget for staying qualified as an ongoing cost.

Validity Period and Renewal

Those three years only hold if the provider keeps its commitments the whole way through. At the end, it applies for renewal, and the service goes through a new evaluation.

Surveillance Audits and Ongoing Obligations

Every qualified service gets an annual surveillance audit, and under version 3.2 the penetration testing carries on as well.

If something could affect compliance, like a new hosting site, a big architecture change, a new subcontractor, or a change in ownership, the provider has to flag it rather than let the next audit find it. It helps to put the qualified scope under formal change control.

What Happens if You Fall Out of Compliance

A qualification decision only holds under the conditions written into it, and a provider that breaks them puts the qualification at risk. The most dramatic case would be a change of control that hands a non-EU investor a majority stake.

Customers feel it too. A state body bound by the SREN law would have to move to another qualified service or ask for a derogation, and any SaaS qualified by composition on that provider would face the same problem.

How Long Does SecNumCloud Qualification Take, and What Does It Cost?

Plan for 18 months to two years of work and a budget that can reach millions of euros, depending on how far your setup is from the framework. ANSSI doesn’t publish prices, and evaluation centers quote case by case.

Typical Timeline

After J0, the formal process usually takes about a year if nothing goes wrong, according to French tech outlet Next. Preparation before J0 comes on top of that.

Journal du Net put the full effort at roughly 18 months of heavy work, including maturity assessments and mock audits. cegedim.cloud said its own 3.2 qualification took two years. Providers that already have a mature ISO 27001 ISMS and EU-only ownership tend to land at the shorter end.

Main Cost Drivers

There aren’t many public figures. A source close to ANSSI, quoted anonymously by Journal du Net, put the total at a few million euros, varying a lot with maturity.

Most of that goes on architecture work such as network segregation, dedicated admin infrastructure, and EU-only directories, logs, and backups. Then come the evaluation center’s fees for the documentation review, on-site audits, and penetration tests, plus a lot of internal time from security, legal, operations, and engineering staff, often for well over a year. Some providers also have to rework ownership, subcontracting, or contracts to meet the sovereignty rules.

Building on an already-qualified IaaS and qualifying by composition is the most dependable way to cut the evaluation part of the bill.

Is Government Funding Available?

In December 2022, the French government launched a €3.5 million support program for startups and SMEs going after SecNumCloud, run by Bpifrance. It paid for an initial maturity audit, consulting support, and part of the qualification itself, up to €180,000 per company. Out of more than 40 applications, 21 projects got in.

Funding windows open and close, so check Bpifrance and ANSSI’s industrial policy pages for live calls before you build a business case around them. Even then, the grant only ever covered a fraction of the total cost.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

Benefits and Limitations of SecNumCloud

SecNumCloud opens up a protected market and gives buyers the strongest proof of sovereignty they can get in Europe. It’s also expensive, it narrows the service catalog, and it’s still a French scheme in a European market.

Benefits for Cloud Providers

The obvious benefit is access. Since August 2026 a qualified offer is the default way to win state contracts involving particularly sensitive data, and the same requirement is turning up in tenders from health bodies and critical operators.

It also swaps a marketing claim for a state decision. A provider on ANSSI’s list doesn’t have to argue that its cloud is “sovereign,” because it can just show the decision. For SaaS vendors, a qualified offer makes each customer’s security accreditation simpler, which shortens sales cycles with public buyers.

Benefits for Cloud Customers

Customers get assurance the state has actually checked, instead of a provider’s own say-so. That covers the technical controls and the legal side too: who owns the provider, where data and logs live, and whether a non-EU authority could force access.

For bodies covered by the SREN law, it’s also the simplest way to prove compliance. And their own accreditation work gets lighter, since the service underneath has already been evaluated.

Common Criticisms and Limitations

The most common complaint is cost and duration. Journal du Net, among others, has asked whether ANSSI demands too much, since the effort shuts out many small providers. That leaves a small pool of around ten qualified offers, and their catalogs rarely match a global hyperscaler’s range. Newer services such as managed AI often sit outside the qualified scope, and qualified services usually cost more than the same provider’s standard offer.

There are limits on what it covers, too. SecNumCloud doesn’t secure the customer’s own application, and outside France its weight depends on who’s buying. Then there’s the politics. Several member states and US industry groups opposed the sovereignty criteria at EU level as protectionist, which is one reason the EU-level equivalent has stalled.

Can Non-EU Companies Get SecNumCloud Qualification?

Not directly. A company headquartered outside the EU, or controlled by non-EU shareholders, can’t meet the sovereignty chapter. That rules out US and GCC companies, and UK ones too since Brexit.

Ownership and Control Requirements

The framework requires an EU-registered office and caps non-EU shareholders at minority stakes. It also asks whether a non-EU company could reach the data in practice through services the provider depends on, and whether the provider could keep the service running on its own.

These rules are about control as much as cap-table percentages. A European subsidiary that takes orders, software updates, or support access from a non-EU parent will struggle on the autonomy and third-party criteria even if its legal ownership looks clean.

The Joint Venture Model: Bleu and S3NS

Two offers show how US technology can end up inside a qualified service. S3NS, a Thales-controlled company built on Google Cloud technology, got its PREMI3NS offer qualified on 17 December 2025 across IaaS, CaaS, and PaaS services.

Bleu, set up by Orange and Capgemini to run Microsoft Azure and Microsoft 365 technology in an isolated environment, passed J0 in April 2025 and announced J1 in November 2025. As of October 2026, it hadn’t announced a qualification.

Both use the same model. A European company owns and runs the service, and the US partner licenses technology without getting control or data access. In May 2025, ANSSI’s director general told a French Senate inquiry that both met the capital requirements on paper.

Selling to French Buyers Without Your Own Qualification

Most non-EU SaaS companies won’t set up an EU-controlled entity to chase SecNumCloud, and plenty don’t need to. There are three realistic routes:

  1. Target data outside the SREN definition. Most public-sector and enterprise data is confidential without being “particularly sensitive,” and buyers in that space look at ISO 27001, HDS for health data, and their own security reviews.
  2. Host on a qualified provider. This doesn’t qualify your product, but it settles data location and gives the buyer a qualified infrastructure layer to assess.
  3. Partner with an EU operator. A licensing or distribution deal with an EU-controlled company that runs and qualifies the service is the Bleu and S3NS approach on a smaller scale.

Whichever route you take, French buyers will want a recognized security baseline first. For most US, UK, and GCC SaaS companies that means ISO 27001 certification, which lines up directly with the Annex A foundation underneath SecNumCloud.

SecNumCloud vs Other Security Frameworks

SecNumCloud shares a lot of technical ground with the major security frameworks. Where it parts ways with all of them is legal immunity.

FrameworkIssued byWhat you getImmunity from non-EU lawWhere it carries weight
SecNumCloud 3.2ANSSI (France)State qualification of one cloud serviceRequiredFrench public sector, sensitive data
ISO 27001Accredited certification bodiesCertificate for an ISMSNot addressedGlobal baseline
SOC 2CPA firms, AICPA criteriaAttestation reportNot addressedUS buyers, global SaaS
C5BSI (Germany)Auditor attestationDisclosure onlyGerman public sector and enterprise
HDSFrench health certification schemeCertificate for health data hostsEEA hosting onlyFrench personal health data

SecNumCloud vs ISO 27001

ISO 27001 certifies a management system, while SecNumCloud qualifies one specific cloud service. Since SecNumCloud is built on ISO 27001 Annex A, a certified ISMS takes care of much of the governance and documentation work. What ISO 27001 doesn’t touch is the sovereignty chapter, the strict split between administration and customer usage, and state review.

A US hyperscaler can hold ISO 27001 and still be subject to the CLOUD Act. That’s the gap SecNumCloud was built to close.

SecNumCloud vs SOC 2

SOC 2 is an attestation rather than a certification. A CPA firm reports on how your controls perform against the AICPA Trust Services Criteria. US buyers take it seriously and French public procurement barely notices it, so SaaS companies selling on both sides of the Atlantic usually need a SOC 2 report for US deals, whatever they decide about France.

SecNumCloud vs C5

Germany’s C5 catalog, published by BSI, is the closest match to SecNumCloud in technical depth. It runs on auditor attestations and asks providers to disclose jurisdiction and data location instead of requiring immunity. That’s why the big US hyperscalers hold C5 attestations for their global services but not SecNumCloud qualifications.

SecNumCloud vs HDS

You need HDS certification to host personal health data in France. Its 2024 update requires hosting in the European Economic Area and documented safeguards against third-country access, but it stops short of SecNumCloud’s ownership and immunity rules. So an HDS-certified host isn’t SecNumCloud-qualified by default, and particularly sensitive health data held by the state needs both.

SecNumCloud and GDPR

SecNumCloud doesn’t make a provider GDPR compliant, and being GDPR compliant says nothing about SecNumCloud. GDPR is about how personal data gets processed, while SecNumCloud checks the security and legal exposure of the cloud service underneath. Where they overlap is third-country access, and there a qualified service takes away much of the risk the CLOUD Act poses for EU personal data.

SecNumCloud-Qualified Cloud Providers

Around ten offers held an active SecNumCloud 3.2 qualification in 2026, according to a count by Banque des Territoires. The only authoritative source is ANSSI’s list of SecNumCloud cloud service providers, which also shows offers still in qualification.

Current List of Qualified Services

These are examples confirmed by ANSSI decisions or official announcements. The table isn’t complete, and the list changes as decisions are issued, renewed, or lapse.

ProviderQualified offerService type
3DS OutscaleOutscale cloudIaaS
OVHcloudHosted Private Cloud SecNumCloud, Bare Metal PodIaaS
Cloud TempleIaaS and OpenShift PaaS offersIaaS, PaaS
WorldlineWorldline Cloud Secured ServicesIaaS
Orange BusinessCloud Avenue SecNumIaaS
S3NS (Thales, Google Cloud technology)PREMI3NSIaaS, CaaS, PaaS
WhallerWhaller DonjonSaaS
Index EducationPRONOTESaaS

How to Verify a Provider’s Qualification

Before you rely on a provider’s claim, check three things. First, that the provider and the specific offer are on ANSSI’s list. Second, that the qualification decision covers the exact service and service type you plan to buy.

Third, that the conditions of use in the decision’s annex match how you plan to use the service. Decisions routinely exclude managed services and outsourcing, so a qualified IaaS doesn’t make the provider’s managed Kubernetes or support desk qualified too. Ask for the decision itself instead of trusting a logo on a slide.

How to Choose a SecNumCloud-Qualified Provider

Start with the service model you need, then compare catalogs, since qualified ones are still narrower than standard public cloud. Make sure the services you depend on, like managed databases, containers, or AI tooling, are inside the qualified scope.

Then look at the commercial side, including the premium over the provider’s standard pricing, the reversibility terms, and how its renewals have gone. And plan your exit. Your own risk analysis should cover the provider losing its qualification, especially if you’re building a qualified SaaS on top.

Worth Knowing: Qualified Service

A qualified service only protects what runs inside its qualified scope. Teams often move a production database to a qualified provider and leave logs, backups, or admin tooling on a standard cloud account, which reintroduces the exposure they were paying to remove.

The Future of SecNumCloud

Expect the next changes to come from Paris and Brussels at once. In France, deputy Philippe Latombe, rapporteur on a bill about digital public procurement, has proposed extending the SecNumCloud obligation to regions, departments, larger towns, and other local bodies. In Brussels, the question is whether an EU scheme will ever match it.

Will EUCS Replace SecNumCloud?

Not anytime soon. EUCS, the EU cloud certification scheme ENISA has been drafting under the 2019 Cybersecurity Act, has been in the works since 2020 and still hasn’t been adopted. France has pushed since 2019 to get SecNumCloud’s criteria into its top assurance level.

Earlier drafts had sovereignty requirements modeled on SecNumCloud, but those came out in 2024 after pushback from member states such as Ireland, Sweden, and the Netherlands, and from US industry. The EU Institute for Security Studies’ analysis of the EUCS dispute explains how the scheme turned into a political test of European digital sovereignty.

The EU’s review of the Cybersecurity Act has reopened that fight. In the meantime, the 2026 French decree already accepts an equivalent EU or EEA certification, so an EUCS level with real sovereignty criteria could one day satisfy French law alongside SecNumCloud.

SecNumCloud and Sovereign AI Services​

AI is where the pressure is building next. Qualified providers now sell GPU capacity and hosted language models on SecNumCloud infrastructure, and S3NS has said it plans to add managed AI services to PREMI3NS.

For buyers it comes down to scope. A model running on qualified infrastructure isn’t a qualified AI service, and many AI features launch long before they show up in a qualification decision. Check the decision before you send sensitive data into any AI workload.

Conclusion

SecNumCloud is Europe’s toughest cloud qualification because it checks how well a service is secured and whether anyone outside the EU can reach its data. Since August 2026 it’s binding for particularly sensitive French state data, and it shapes procurement well beyond that.

If you’re a cloud provider with EU ownership, expect roughly 18 months of preparation and evaluation, and look at composition on a qualified IaaS as the cheapest way in. If you’re a SaaS company headquartered outside the EU, direct qualification is off the table. The practical play is a solid ISO 27001 baseline, qualified hosting where buyers ask for it, and a partnership for cases where the data truly needs a SecNumCloud service.

Frequently Asked Questions

What Does SecNumCloud Stand For?

The name combines the French sécurité numérique (digital security) with “cloud.” In practice it names both ANSSI’s requirements framework for cloud providers and the qualification awarded against it.

Their global services aren’t, because US ownership clashes with the framework’s sovereignty rules. You can use Google Cloud technology inside a qualified service through S3NS’s PREMI3NS offer, qualified in December 2025. Bleu, which runs Microsoft technology, was still going through qualification as of October 2026.

Around ten offers held an active SecNumCloud 3.2 qualification in 2026, according to Banque des Territoires. The number moves as decisions are issued and renewed, so ANSSI’s official list is the only reliable count.

It’s a French national scheme, so its legal force stops at the border. Elsewhere it depends on the buyer, though it’s often cited as Europe’s strictest cloud benchmark. The EU’s own scheme, EUCS, hasn’t been adopted, and its drafts dropped the equivalent sovereignty criteria.

Yes, if it has EU ownership, a long runway, and customers who actually need it. Building a SaaS on an already-qualified IaaS and qualifying by composition cuts the evaluation effort a lot. There has been public co-financing for startups and SMEs, but it only covers part of the cost.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

SecNumCloud is the French state’s highest security qualification for cloud services, and ANSSI only grants it after a state-supervised evaluation. Since August 2026 it’s also law for part of the French public sector. State bodies now have to keep their most sensitive data on services that meet the SecNumCloud 3.2 requirements. Everyone else, from French hospitals to US and UK SaaS vendors chasing French public contracts, now treats SecNumCloud as the working definition of a “sovereign cloud.” It’s also one of the hardest qualifications in Europe to get, because ANSSI checks who owns the provider and which foreign laws could reach it, on top of the technical controls. This guide walks through what SecNumCloud is and who needs it, what the requirements ask for, how qualification works and what it costs, and the options open to companies headquartered outside the EU. SecNumCloud at a Glance In short, SecNumCloud is a three-year qualification the French state grants to one specific cloud service. It’s built on ISO 27001 and adds sovereignty rules that no other European scheme enforces today. Attribute Detail Issued by ANSSI, France’s national cybersecurity agency Type Qualification (an ANSSI Visa de sécurité), not a certification Current version SecNumCloud 3.2,

SOC 2 has no fixed evidence retention period. The AICPA doesn’t tell service organizations to keep evidence for one year, three years, or seven. What it does require is proof that every in-scope control operated across the entire audit period. That’s stricter than it sounds, because a log that expires before your auditor samples it is a control you can no longer prove. That makes evidence retention one of the few SOC 2 topics where a configuration default can cost you a clean report. Below, we walk through what the AICPA and the Trust Services Criteria require and how long to keep each type of evidence. We also cover where HIPAA, PCI DSS, ISO 27001, and GDPR change the answer, and how to store and automate evidence so it holds up when the auditor tests it. For most SaaS teams, the short answer is this. Keep evidence for the current observation period plus at least one prior period, and keep security logs searchable for 12 months. Go longer only when a contract, a regulation, or a legal hold says you have to. What Is SOC 2 Evidence Retention vs. Data Retention: Key Distinctions Teams often lump the two into one

Vanta can tell you a control is failing within the hour. It cannot rewrite your access review process, decide which systems belong in audit scope, or explain to a CPA why a test that shows red is actually fine. That work falls to people, and choosing the right ones is the difference between a 6-week path to audit readiness and a 6-month slog that ends with your Vanta subscription renewing before you have a report. This guide ranks the 7 best Vanta deployment services for 2026, explains what each one is good at, and covers what most comparison pages skip: how long this really takes, what it costs, and how to spot a partner who’ll hand you a half-configured platform and disappear. What Is a Vanta Deployment Service? A Vanta deployment service is a hands-on engagement where a specialist firm sets up, configures, and operationalizes Vanta so your company reaches audit readiness for one or more compliance frameworks. Vanta itself is a compliance automation and trust management platform: it connects to your cloud, identity provider, code repositories, HR system, and endpoints, then runs automated tests and maps the evidence to frameworks such as SOC 2, ISO 27001, HIPAA, and GDPR.