|7 min read|Yvann Lièvre

SecNumCloud: The Sovereign Label Changing the Game

ANSSI SecNumCloud certification, CLOUD Act protection, certified providers OVHcloud and 3DS Outscale, European EUCS framework, and NIS2 impact on sovereign hosting.

SecNumCloudSouveraineté

In a geopolitical context where digital sovereignty has become a strategic issue, ANSSI's SecNumCloud label has established itself as the reference for secure hosting of sensitive data in France. Here is a breakdown of a certification that is redefining cloud rules.

What is SecNumCloud?

SecNumCloud is a security visa issued by ANSSI (France's National Cybersecurity Agency) certifying that a cloud service provider meets the strictest security requirements. Version 3.2 of the framework, published in 2022, introduced unprecedented sovereignty criteria: the provider must be not subject to extra-European legislation, effectively excluding subsidiaries of American companies from the US CLOUD Act.

  • Technical security: encryption, isolation, access management, logging

  • Organizational security: governance, incident management, business continuity

  • Legal immunity: European headquarters and shareholding, no access possible by a foreign jurisdiction

Why the CLOUD Act is a problem

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) of 2018 allows US authorities to demand access to data stored by American companies, regardless of the country where the data is hosted. In practice, if you host your data with AWS, Azure, or GCP, even in a Paris datacenter, the US government can legally access it.

GDPR prohibits such transfers without an adequate legal basis. This legal contradiction places European companies in an impossible situation, unless they choose a truly sovereign host.

Certified SecNumCloud providers

To date, only a few providers have obtained SecNumCloud 3.2 certification:

  • OVHcloud: first certified European hyperscaler, offering SecNumCloud-qualified IaaS and PaaS on French datacenters

  • 3DS Outscale (Dassault Systemes subsidiary): certified IaaS, positioned for defense and government markets

  • Scaleway (Iliad): in the qualification process, offering an alternative positioning

  • Cloud Temple: certified for infrastructure offerings

The audit process is rigorous: it averages 18 months and involves penetration testing, documentary audits, and shareholding chain verification.

EUCS: the European counterpart

The European Union Cybersecurity Certification Scheme for Cloud Services (EUCS) is the European certification framework being finalized by ENISA. Its goal: create a harmonized EU-wide framework with three assurance levels (Basic, Substantial, High). The High level should align with SecNumCloud sovereignty requirements, but negotiations between member states on legal immunity criteria remain tense.

NIS2 impact on hosting

The NIS2 directive strengthens obligations for essential and important entities regarding supply chain security. Specifically:

  • Regulated organizations must assess the risk of their cloud providers

  • Health data hosting is subject to enhanced requirements via the HDS (Health Data Hosting) framework, itself based on ISO 27001 certification

  • The French government's "Cloud au centre" doctrine mandates SecNumCloud for sensitive government data

How to choose sovereign hosting

Choosing a SecNumCloud host should be part of a comprehensive security strategy:

  • Classify your data: not everything needs SecNumCloud. Reserve it for sensitive data (health, defense, critical personal data)

  • Evaluate reversibility: a sovereign cloud should not become lock-in. Verify export formats and API compatibility

  • Integrate monitoring: certified hosting does not exempt you from active security monitoring. ThreatClaw monitors your workloads even on sovereign clouds

  • Anticipate costs: SecNumCloud offerings average 20-40% more expensive than US hyperscalers. That is the price of sovereignty

FAQ

Is SecNumCloud mandatory?

It is not mandatory for the private sector in general, but it is progressively required for French government agencies ("Cloud au centre" doctrine) and recommended for critical infrastructure operators and essential entities under NIS2. For health data, the HDS framework may suffice depending on the use case.

Can AWS or Azure obtain SecNumCloud?

No, in their current form. The 3.2 framework requires the provider to be controlled by European capital with headquarters in Europe. The "sovereign" offerings from AWS (Dedicated Local Zones) and Azure do not meet these criteria, as the parent company remains American and subject to the CLOUD Act.

What is the difference between SecNumCloud and ISO 27001?

ISO 27001 is an international information security management standard. SecNumCloud goes further: it includes cloud-specific technical requirements (isolation, client-side encryption) and legal sovereignty criteria absent from ISO 27001. SecNumCloud 3.2 builds on ISO 27001 but significantly exceeds it.

Is ThreatClaw compatible with SecNumCloud clouds?

Yes. ThreatClaw is deployable on any infrastructure, including SecNumCloud-certified clouds. The agent installs locally on your machines and communicates via encrypted APIs. Check our plans for deployment details.

Related articles