SecNumCloud: ANSSI's framework for trusted cloud

What ANSSI qualification guarantees, who should require it and how to obtain it.

· 9 min read
Illustration: four stacked glass servers, one in orange

SecNumCloud is the ANSSI framework used to qualify a “trusted” cloud service: high-level technical and organisational security, data processed in the European Union and protection from non-European extraterritorial laws. SecNumCloud qualification, valid for three years, is granted by ANSSI to a specific service, not to a provider. Since 2026, it has been the mandatory reference for sensitive French State data entrusted to a commercial cloud.

01

SecNumCloud: what a trusted cloud means

ANSSI, France's national cybersecurity agency, grants several “security seals” to products and services it has had evaluated. SecNumCloud is the one for cloud computing services. It covers infrastructure (IaaS), platform (PaaS) and software (SaaS) services, as well as container services.

Three ideas sum up what a SecNumCloud qualification covers:

  • a service, not a company: ANSSI is clear in its FAQ that SecNumCloud recognises a specific cloud service, not a cloud provider. The same provider may offer qualified services and others that are not;
  • technical and organisational security: governance, risk management, access control, encryption, operations, incident management, continuity, subcontracting;
  • legal protection: the data must not be obtainable by a third-country authority outside European law.

That last point is what makes the framework unique. It addresses a specific concern: laws such as the US CLOUD Act can compel a provider subject to them to hand over data, including data stored in Europe. A data centre in Paris is therefore not enough; what matters is the provider's legal and ownership structure.

Qualification does not, however, guarantee the security of what the client deploys on the service. ANSSI points out that the client organisation remains responsible for the security of its own systems, access and data.

Sovereign cloud, trusted cloud, SecNumCloud: not the same thing

The three terms are often used interchangeably. They should not be. “Sovereign cloud” is a marketing claim with no legal definition: it usually means a European provider or data hosted in France, and says nothing about the level of security or control by shareholders. “Trusted cloud” is the term the French State has used since 2021 for services protected both from cyberattacks and from extraterritorial laws; in public doctrine, it refers specifically to SecNumCloud. Finally, a SecNumCloud-qualified service is the only one of the three whose promises have been checked by an approved evaluator and then validated by ANSSI.

In practice, when a service is described as sovereign, the right question is not “where are your servers?” but “which exact service is qualified, since when, and on which layer?”.

02

The SecNumCloud 3.2 framework: criteria and changes

The current version of the SecNumCloud framework is 3.2, published by ANSSI in March 2022. It gained new weight in 2026: an order of 12 August 2026, published in the Official Journal on 14 August, approved it as the requirements framework for the French State's cloud providers, under the SREN law. As Silicon notes, the order does not change the framework's technical content; it changes its legal weight.

Protection from extraterritorial laws

This is the main addition in version 3.2. According to the ANSSI FAQ and analyses by Génération NT and Silicon, the provider must notably meet the following conditions:

  • its head office, decision-making centre and service administration are located in the European Union;
  • the share of its capital held by non-European entities is capped (24% for a single entity, 39% in total);
  • no non-European entity holds a veto over its decisions;
  • data is stored and processed in the European Union, and the service is operated from within the Union.

Other changes in version 3.2

  • Penetration testing throughout the qualification cycle, rather than at a single point in time.
  • Qualification by composition: a SaaS or PaaS vendor relying on infrastructure that is already qualified can inherit its guarantees and focus the evaluation on its own layer, reducing effort and cost.
  • Closer alignment with the future European EUCS scheme, especially its highest level.

In total, the framework includes more than 360 requirements according to Silicon, covering technical security, access management, governance, audit, the supply chain and business continuity.

A service hosted on a SecNumCloud service is not automatically SecNumCloud-qualified itself.

ANSSI, SecNumCloud qualification FAQ (translated)
03

Who must require a SecNumCloud-qualified cloud?

The State: from the “cloud first” doctrine to the SREN law

The requirement was built up in stages. Circular No. 6282/SG of 5 July 2021 set out the State's “cloud au centre” (cloud first) doctrine: cloud becomes the default hosting for new State digital projects. The circular of 31 May 2023 clarified it by defining particularly sensitive data (data covered by a legally protected secret, or needed for the State's essential missions), which must be hosted on a SecNumCloud-qualified service when entrusted to a commercial cloud, as Localtis explained at the time.

The SREN law of 21 May 2024 gave this requirement a legal basis. Its Article 31 requires State administrations, their operators and certain public interest groupings that entrust particularly sensitive data to a commercial cloud to use services protected from any unauthorised access by third-country authorities. Decree No. 2026-272 of 14 April 2026 set out the details, with a temporary derogation regime when no suitable offer exists, and the order of 12 August 2026 named SecNumCloud 3.2 as the framework. Under the order, compliance is shown by an ANSSI qualification or by a European certification recognised as equivalent by ANSSI. The Ministry of the Economy's legal department has published a technical note and model clauses for public buyers.

Local authorities, healthcare, companies: no general obligation

Local authorities and healthcare institutions are not directly covered by Article 31. Many public buyers nevertheless require SecNumCloud hosting for sensitive data in their tenders, or reward it in scoring. In the private sector, neither NIS 2 nor DORA mandates SecNumCloud, but both require organisations to control supplier risk, and a qualified service is strong evidence for the most sensitive systems. Finally, companies bidding for public cloud contracts, or working as subcontractors, see these requirements passed down into their contracts, as Quantic Avocats points out.

For public bodies, the SecNumCloud question often comes up during the security accreditation of an information system: the hosting choice is one of the risks the accreditation authority accepts, or not. Phinasoft's risk analysis module helps document that decision.

04

The SecNumCloud qualification process, step by step

Qualification is a lengthy process, initiated by the cloud provider. It goes through numbered milestones, from J0 to J3, and involves an evaluation centre approved by ANSSI, which audits the service, and then ANSSI, which decides.

The steps of SecNumCloud qualification
  1. The provider contacts ANSSI to present its service and plans. If the approach is confirmed, it submits an application to enter qualification.

  2. ANSSI confirms official entry into the process by letter. The service can then appear on the public list of providers undergoing qualification.

  3. The provider and the approved evaluation centre in charge of the audit agree on the evaluation strategy: scope, documents, audit schedule.

  4. Compliance audits against the framework, penetration tests, then remediation plans. This is the longest phase: gaps found must be fixed before the final audit.

  5. The evaluation centre checks that every requirement of the framework is correctly implemented and delivers its report.

  6. ANSSI reviews the results and decides whether to qualify the service. Qualification is valid for three years.

  7. Annual surveillance audits check that the service remains compliant. Any significant change to the service must be reported.

  8. At the end of the three years, the provider can apply for renewal, which goes through the same milestones again.

Milestones as described by ANSSI and by providers that have gone through the process. Total duration varies widely depending on the service and its maturity.

Qualification is valid for three years, subject to annual surveillance audits, and can be renewed through the same milestones (ANSSI FAQ). The agency does not publish a typical duration; providers who have spoken publicly describe a process lasting more than a year and demanding significant resources.

05

SecNumCloud, HDS, ISO 27001, EUCS: what are the differences?

These four acronyms come up in the same tenders. They do not measure the same thing, and a provider can hold several. Pick a criterion to compare.

Comparison · SecNumCloud, HDS, ISO 27001, EUCS Pick a criterion
ANSSI qualification SecNumCloud

Protection required: head office, capital and decisions under European control

Health certification HDS

Transparency: foreign laws disclosed to the client, mitigation measures

International standard ISO 27001

Not addressed

European scheme EUCS

Under debate: sovereignty criteria discussed among member states

Simplified reading, for comparison. EUCS is a draft European cloud certification scheme, not adopted at the time of writing (October 2026).

SecNumCloud and HDS

HDS certification is mandatory in France for hosting health data on behalf of a third party. It requires storage in the EU or EEA and transparency about foreign laws, without requiring immunity. SecNumCloud goes further on sovereignty but does not replace HDS: a qualified cloud hosting health data must also be certified. In May 2026, according to France's Digital Health Agency, eight of the ten SecNumCloud-qualified hosts were also HDS certified.

SecNumCloud and ISO 27001

ISO 27001 certifies an information security management system, over a scope chosen by the organisation. It is a useful foundation that many providers already hold, but it says nothing about data location or extraterritorial laws. Phinasoft's compliance assessments help manage the ground the two share.

SecNumCloud and EUCS

EUCS is the European cloud certification scheme being prepared by ENISA under the Cybersecurity Act. In early 2026, its final version had still not been adopted: member states are debating whether to cover strategic risks on top of technical requirements, according to Cullen International. In January 2026 the Commission also proposed a revision of the Cybersecurity Act to speed up the development of schemes. The August 2026 order already provides that a European certification recognised as equivalent by ANSSI can demonstrate compliance.

SecNumCloud, HDS and ISO 27001 at a glance
CriterionSecNumCloudHDSISO 27001
NatureQualification (security seal)Mandatory certificationVoluntary certification
AuthorityANSSIAccredited body, ANS frameworkAccredited body
SubjectA cloud serviceHealth data hosting activitiesA management system
Extraterritorial lawsProtection requiredTransparency requiredNot addressed
Mandatory forSensitive State data (SREN law)Health data hostsNo one
Validity3 years3 years3 years
06

Choosing a SecNumCloud-qualified provider

The lists change as new qualifications are granted: rely on the official list of qualified services published by ANSSI, and on the list of providers undergoing qualification. During 2026, there were around ten qualified services. Before signing, check:

  • the qualified layer: an IaaS qualification does not automatically cover the same provider's PaaS or SaaS services;
  • the exact scope of the service you are buying, against the one that was evaluated;
  • the date and validity of the qualification, and the provider's commitments if it is lost;
  • reversibility: exit conditions, formats, timelines;
  • the provider's subcontractors, and their own exposure to extraterritorial laws.

These checks are part of third-party risk management. They matter all the more in light of supply chain attacks, where a compromised provider becomes the entry point to its clients.

Where Phinasoft fits in

Phinasoft is French cyber risk management software that helps public administrations and local authorities manage their cybersecurity governance. It can be installed on-premise on your own infrastructure or hosted on a French sovereign cloud (OVH or Outscale) with a SecNumCloud option. It supports your security accreditation work, your risk analyses with the ANSSI-labelled EBIOS RM module, your compliance assessments (IGI 1300, ANSSI hygiene guide, NIS 2, ISO 27001, security policy) and the assessment of your providers and subcontractors. To discuss your own context, you can request a demo.

Summary

01

An ANSSI seal

SecNumCloud qualifies a specific cloud service, not a provider, following an evaluation by an approved centre and a decision by ANSSI, for three years.

02

Legal protection on top

Beyond technical security, version 3.2 requires the service to be shielded from non-European extraterritorial laws: head office, capital and decisions under European control.

03

An obligation for the State

Since the SREN law, its April 2026 decree and the August 2026 order, the French State, its operators and certain public interest groupings must use a qualified service for their sensitive data.

Frequently asked questions

What is SecNumCloud?

SecNumCloud is a set of requirements published by ANSSI, France's national cybersecurity agency. It is used to qualify cloud services (IaaS, PaaS, SaaS) deemed trustworthy: high technical and organisational security, data processed in the European Union and protection from non-European extraterritorial laws. Qualification is granted by ANSSI for three years.

Is SecNumCloud mandatory?

It is mandatory for French State administrations, their operators and certain public interest groupings that entrust particularly sensitive data to a commercial cloud, under Article 31 of the SREN law. For private companies and local authorities there is no general obligation, but it is often required in public tenders or recommended for sensitive data.

What is the current version of SecNumCloud?

The current version is 3.2, published by ANSSI in March 2022. It was approved as the official requirements framework by an order of 12 August 2026, under the SREN law. It added the criteria on protection from extraterritorial laws and strengthened penetration testing throughout the qualification cycle.

How long does SecNumCloud qualification take?

Qualification is valid for three years, with annual surveillance audits, and can then be renewed. Obtaining it usually takes well over a year: the process goes through several milestones, from admissibility by ANSSI to the final audit, and any gaps found must be fixed before the decision.

Where can I find the list of SecNumCloud-qualified providers?

ANSSI publishes on cyber.gouv.fr the official list of SecNumCloud-qualified services, in its catalogue of qualified products and services, as well as a separate list of providers undergoing qualification. Always check which service layer is covered (IaaS, PaaS or SaaS) and the qualification date.

What is the difference between SecNumCloud and HDS?

SecNumCloud is an ANSSI qualification for cloud services, focused on security and sovereignty. HDS is a mandatory certification for hosting health data on behalf of a third party in France. The two add up: a SecNumCloud-qualified service hosting health data must also be HDS certified.

Is an application hosted on a SecNumCloud cloud qualified?

No. ANSSI makes this clear in its FAQ: a service hosted on a SecNumCloud service is not automatically qualified itself. A software vendor can, however, rely on the qualified infrastructure in its own qualification process, known as qualification by composition, and limit the evaluation to its own layer.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.