SecNumCloud 3.2: Paris Advances a Sovereign Cloud Through Regulation

A summer publication reshuffles the cards of France’s sovereign cloud. The decree of August 12, 2026, which took effect on August 22, approves version 3.2 of ANSSI’s SecNumCloud framework and, for the first time, gives it a fully binding scope over a broad portion of the central public sector.

The legal mechanism was built step by step, over nearly two years.

Article 31 of the SREN law of May 2024 laid down the principle: administrations handling sensitive data should rely on cloud service providers insulated from extraterritorial legislations, starting with the American Cloud Act.

The obligation now targets state administrations, its operators and public-interest groups that entrust private providers with data “of particular sensitivity.”

See also: The Health Data Hub moves toward SecNumCloud hosting

This notion is defined cumulatively. The data must fall under a law-protected secret or belong to a mission essential to the State, and its compromise must pose a real risk to public order, to public safety, to health or to life, or to intellectual property.

The April 2026 decree also explicitly named six public-interest groups subject to this obligation.*

A technical point will have immediate practical consequences: an administration cannot artificially isolate a few sensitive files to apply the strengthened rules to them, while leaving the rest of its information system on a less-protected infrastructure.

A deliberate bypass of parliamentary blockage

When sensitive data share space with ordinary data on the same cloud infrastructure, the entire infrastructure must rise to the SecNumCloud level of requirement. Unless the administration can demonstrate a truly airtight technical segmentation between the two.

In practice, this rule closes an obvious loophole and could push some agencies toward much broader migrations than anticipated, for lack of proof of a solid separation of their environments.

The text also provides an escape valve. If no compliant offer exists on the market, the concerned agency has a reasoned exemption, renewable, until a qualified solution appears; then it has 18 months to switch once it exists.

The choice of regulatory path is not neutral.

See also: The Trusted Cloud seeks a second life

The transposition of the NIS 2 directive, which is at stake in a dispute with Brussels, could have extended cybersecurity obligations to comparable levels but remains blocked in Parliament in the Resilience bill, whose examination is now only announced for October.

Meanwhile, the government moves forward by decree. An instrument that requires neither a majority nor parliamentary debate but which, by design, is more reversible than a law.

What the framework changes in concrete terms

The technical framework itself did not originate in 2026. ANSSI had published version 3.2 as early as March 2022. What it changes is its legal scope. Until now, an administration could rely on SecNumCloud without it being a legal requirement; now, for the sensitive data involved, using it is no longer optional but a condition of the legality of public procurement.

This content revolves around four axes. The most contested concerns the legal and capital sovereignty of providers.

Concretely, to be qualified, a provider must meet three conditions:

  • its registered office, its decision-making center and the administration of its services must be located within the European Union;
  • the share of its capital held by non-European actors is capped;
  • no entity outside the EU may hold a veto right over the company’s decisions. This criterion does not concern the technical aspects but ownership structure—and it is precisely what makes it, for providers, the hardest to satisfy: a security flaw can be fixed in weeks, a capital structure cannot be reorganized overnight. It is this lock that effectively excludes a good portion of major non-European cloud players from the outset.

Three other developments complete the picture.

First, intrusion tests, which were previously performed at a single moment, must now be conducted continuously throughout the qualification.

Next, a “composition of services” logic simplifies the life of SaaS publishers: if they rely on an IaaS or PaaS layer already SecNumCloud-qualified, they inherit its guarantees and no longer need to undergo a full audit — they only certify their own application layer.

See also: OpenStack: the SecNumCloud checklist from ANSSI

Finally, the framework deliberately aligns with the future European EUCS scheme, whose highest level, called “High,” remains the objective of convergence in the long term.

Altogether, a candidate supplier for qualification must meet more than 360 requirements, spread across technical security, governance, access management and regulatory compliance.

Persistent blind spots

However, the new framework leaves two gray areas.

First, intrusion tests, which were previously performed at a single moment, must now be carried out continuously throughout the qualification.

Then, a logic of “composition of services” simplifies the life of SaaS editors: if they rely on an IaaS or PaaS layer already SecNumCloud-qualified, they inherit its guarantees and no longer need to repeat a full audit — they only certify their own application layer.

Finally, the framework deliberately aligns with the future European EUCS scheme, whose highest level, called “High,” remains the convergence objective in the longer term.

Altogether, a candidate provider for qualification must meet more than 360 requirements, spread across technical security, governance, access management and regulatory compliance.

A market undergoing reconfiguration

For providers already qualified (about ten active offerings, including OVHcloud, Outscale, Scaleway or the Google-Thales joint venture S3NS) and the dozen of candidates in qualification, the widening changes the nature of the market.

What was a niche segment becomes a more predictable outlet, driven by captive public demand. But this outlet remains fragmented: it now reaches public actors with budgets and technical expertise very uneven, far from the strategic large accounts accustomed to this type of requirement.

A trap awaits public buyers: SecNumCloud qualification does not always apply to the entire offering. A provider can be qualified for its infrastructure (IaaS) layer without being qualified for its application services (PaaS, SaaS) or containers (CaaS). An administration cannot rely on the provider’s name alone: it must verify, market by market, which exact layer of the service is actually covered by the label.

There remains a fundamental question, raised by several observers: what one decree created, another decree can undo.

Unless there is less than a year until the presidential election and a possible change of majority, the durability of the arrangement will truly be tested only in the summer of 2027.

*Agency for Health Data (ANS), Secure Data Access Center (CASD), Center for Radicalization Prevention Resources, the Data Analysis Collector, the GIP Modernisation of Social Declarations and the National System for Recording the Demand for Social Housing

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.