Public, Private, Hybrid: The Fundamentals
Before delving into advanced models, three basic concepts set the stage. The public cloud refers to shared IT resources provided on demand by a provider (AWS, Azure, Google Cloud) and billed on a pay-as-you-go basis. Its strength lies in elasticity: you consume what you need, when you need it.
The private cloud denotes an infrastructure dedicated to a single organization, hosted on-site or with a provider. It offers greater control – security, compliance, customization – at the cost of reduced elasticity and a heavier upfront investment.
The hybrid cloud, finally, combines these environments: some workloads stay private or on-site, others run in public clouds, with orchestration between the two. It is the dominant model today, because it allows placing each workload where it is most appropriate.
The market reflects this dominance: according to Mordor Intelligence, hybrid cloud is valued at nearly $173 billion in 2025 and is expected to exceed $310 billion by 2030, with annual growth above 12%. This dynamic signals a finding: very few organizations operate in a strictly “all public” or “all on-premises” mode. The reality is made of combinations, which the vocabulary — hybrid, multicloud, sovereign — is precisely meant to describe.
Multicloud: a Reality More Than a Strategy
The multicloud refers to the simultaneous use of multiple public cloud providers. It differs from hybrid: hybrid mixes types of environments (public, private, edge), while multicloud mixes public providers among themselves. The two are often combined.
Multicloud has moved from a voluntary strategy to an operational reality, often one that is endured. According to Flexera (2025), organizations use an average of 2.4 different public clouds. This dispersion results from mergers and acquisitions, the adoption of heterogeneous SaaS, and technical choices favoring the best service.
Its benefits are real: avoiding dependency on a single provider, selecting the best service for each need, negotiating prices. But the downside is increased complexity: multiple skill sets, fragmented governance, security more difficult to standardize, and costs less transparent. Multicloud is manageable; it is not something to simply endure.
It is also important to distinguish the imposed multicloud from the strategic multicloud. The former results from unmanaged accumulation and primarily accumulates drawbacks. The latter is a deliberate choice, for example distributing critical workloads across two providers for resilience, or placing each application with the provider best suited. This is the entire point of a cloud strategy: turning an undesirable dispersion into a well-governed architecture, where provider diversity serves a goal rather than the reverse.
The Sovereign Cloud: European Legal Control
The sovereign cloud adds to security and localization requirements a decisive dimension: European legal control. It guarantees immunity from non-European law and, most often, European ownership/control of the provider.
We distinguish the trusted cloud – which meets high security and localization demands – from the sovereign cloud in the strict sense, which adds this legal immunity. In France, the defining qualification is SecNumCloud, issued by the ANSSI (version 3.2), which imposes guarantees that American hyperscalers cannot structurally satisfy due to the CLOUD Act. At the European level, the EUCS (European Cybersecurity Certification Scheme for Cloud Services) aims to harmonize these requirements.
The need for sovereignty is driven by the regulatory and geopolitical context: GDPR, NIS2, DORA, AI Act, but also international tensions that rekindle the question of digital autonomy. Players such as OVHcloud, Scaleway, or Outscale (Dassault Group) offer qualified offerings, adopted by regulated sectors (health, defense, banking).
Sovereignty also unfolds in levels, not in a binary all-or-nothing approach. At one extreme, remaining with a hyperscaler while adding contractual and technical protections (encryption, keys under European control via BYOK) mitigates risk without eliminating it, the keys being theoretically requisitionable. At the other extreme, a SecNumCloud-qualified provider, with no dependence on a non-European entity, offers maximum protection, reserved for classified data, critical operators, and sensitive public sector information. Between the two, a range of solutions lets you tailor the sovereignty level to the real sensitivity of the data.
Benefits and Trade-offs: A Balanced View
Each model carries a profile of benefits and constraints that must be weighed against the context.
- Public cloud: maximum elasticity, rapid innovation, a broad catalog of services — but costs can be unpredictable and there may be legal exposure for sensitive data.
- Private / sovereign cloud: control, compliance, and legal sovereignty — but lower elasticity, higher costs, and a typically narrower service catalog.
- Hybrid and multicloud: flexibility and optimal workload placement, resilience — but governance, security, and cost-management complexity.
No model is superior in absolute terms. The public cloud excels in agility and innovation, sovereign in handling critical data, and hybrid in combining the two. The maturity lies in assembling these building blocks: sovereign for sensitive data, public for elasticity, while maintaining control over encryption keys, localization, and data flows.
Understanding these definitions is the prerequisite to any decision. The question is not “which model to adopt?” but “how to compose an architecture that meets my cost, performance, and sovereignty requirements?” It is the objective of a true cloud strategy, which goes beyond simply choosing a provider to become a governance element of the information system.
This content is published by Mentioned