SecNumCloud

SecNumCloud is a French cybersecurity qualification for cloud computing services, awarded by the Agence nationale de la sécurité des systèmes d'information (ANSSI), France's national cybersecurity agency. It applies to a specific cloud service, not to a provider as a whole, and can cover Infrastructure as a service (IaaS), Platform as a service (PaaS), Software as a service (SaaS) and container services.[1]

Version 3.2, published in March 2022, combines technical and organisational security controls with requirements intended to limit exposure to non-European extraterritorial regulations. These include rules on the provider's establishment, ownership and operational autonomy.[2]

SecNumCloud grew out of the Secure Cloud proposal developed under France's Cloud Computing industrial plan. ANSSI tested an initial framework in 2014, published the first applicable SecNumCloud version in December 2016 and awarded the first qualification in January 2019.[3][4] It remains a French qualification, but its requirements now also play a regulatory role for some sensitive public-sector cloud uses.[5]

History

Origins

SecNumCloud traces its origins to the Cloud Computing plan of the Nouvelle France industrielle, launched in 2013. The plan was led by Thierry Breton, then chief executive of Atos, and Octave Klaba, founder of OVH. In April 2014, Breton told a Senate committee that one of the plan's main conclusions was the creation of a secure cloud label, which he compared to a licence to operate.[6]

Alban Schmutz, then SVP for development and public affairs at OVH, was also involved in this work. At a National Assembly hearing in July 2014, he described ten lines of proposals defined within the Cloud plan and said that concrete proposals had been submitted earlier that year to economy minister Arnaud Montebourg.[7]

Cybersecurity was covered by a separate plan within the same industrial programme. Guillaume Poupard, appointed director-general of ANSSI in 2014, was its project leader.[8] During the same period, ANSSI tested the first Secure Cloud requirements under operating conditions before reworking the framework with cloud providers and evaluation bodies.[3]

Version history of the requirements framework[2]
Version Date Main development
1.3 30 July 2014 Initial framework published for comment
2.0 20 March 2015 Experimental Secure Cloud version
3.0 8 December 2016 First applicable SecNumCloud version
3.1 11 June 2018 Revised framework
3.2 8 March 2022 Stronger protection from non-European law

The first qualification was awarded to Oodrive in January 2019 for three SaaS services. 3DS Outscale followed in December 2019 with the first qualified IaaS offering. OVHcloud's Hosted Private Cloud was qualified in January 2021.[4][9]

Qualification and requirements

SecNumCloud covers security governance, personnel and physical security, access management, cryptography, network and operational security, incident management, business continuity, subcontracting and contractual controls.[2]

The qualification is limited to the service that has actually been assessed. An application running on qualified infrastructure does not automatically inherit the qualification. ANSSI also allows qualification by composition, so controls already assessed in an underlying qualified service can be reused when another service is evaluated. A qualification is valid for up to three years, with annual surveillance.[1]

Version 3.2 introduced specific restrictions on non-EU control. The provider must be established in an EU member state. A single non-EU entity may not hold more than 24% of its capital or voting rights, while non-EU entities collectively may not exceed 39%. Other forms of decisive control, including certain veto rights, are also restricted.[10]

French public policy

The 2021 cloud au centre doctrine made cloud computing the default approach for new state digital services while requiring stronger safeguards for particularly sensitive information.[11] Article 31 of the 2024 SREN Act placed part of this policy on a statutory basis.[12]

Decree No. 2026-272 of 14 April 2026 set out its implementation. An order of 12 August 2026 then approved SecNumCloud 3.2 as the relevant requirements framework. Compliance can also be demonstrated through an EU or EEA certification recognised by ANSSI as equivalent.[13][5]

European initiatives

Franco-German work started before SecNumCloud was formally launched. At the 2015 International Cybersecurity Forum, French Secretary of State for Digital Affairs Axelle Lemaire announced work on a Franco-German secure-cloud area of trust. At the same event, Poupard described closer cybersecurity cooperation between France and Germany.[14]

In December 2016, ANSSI and Germany's BSI presented European Secure Cloud (ESCloud), a set of fifteen common rules drawing on SecNumCloud and Germany's C5 catalogue. ESCloud did not become an EU-wide certification scheme.[15][16]

Under the 2019 EU Cybersecurity Act, ENISA began developing the European Cybersecurity Certification Scheme for Cloud Services (EUCS). ANSSI states that France has contributed SecNumCloud criteria to this work since 2019, while ENISA's 2020 candidate scheme drew on both SecNumCloud and C5.[1][17] A March 2024 draft removed the main sovereignty requirements. as of August 2026, EUCS remained under development.[18][19] The Commission's 2026 Cloud and AI Development Act proposal separately provides for national schemes to be used until a European cloud scheme is available.[20]

Gaia-X follows a different route. Its Level 3 European Control criteria cite SecNumCloud section 19.6, including 19.6(d), for European establishment and operational autonomy. Sections 19.1 and 19.2 are referenced for EU/EEA data-location requirements.[21] Gaia-X remains a separate compliance framework rather than an extension of the ANSSI qualification.

Reception

The Cours des Comptes described SecNumCloud as demanding and potentially costly. It counted 360 distinct requirements across fourteen areas and a four-stage qualification process, and reported estimates of €1–2 million in investment over about eighteen months. The report noted that this could be a barrier for smaller providers. It also cited estimates of a 25–40% price premium for qualified offerings compared with non-qualified services from the same provider.[22]

In January 2026, ANSSI director-general Vincent Strubel also pointed to the limits of the qualification. European cloud operators still depend on hardware, software and updates that are not wholly controlled in Europe, he noted, meaning that protection from third-country interference cannot be absolute.[23]

See also

References

  1. ^ a b c "FAQ avant de se lancer dans la qualification SecNumCloud" (in French). Agence nationale de la sécurité des systèmes d'information. Retrieved 25 August 2026.
  2. ^ a b c Prestataires de services d'informatique en nuage (SecNumCloud) – référentiel d'exigences, version 3.2 (PDF) (Report) (in French). Agence nationale de la sécurité des systèmes d'information. 8 March 2022.
  3. ^ a b Le devoir de souveraineté numérique (Report) (in French). French Senate. 1 October 2019.
  4. ^ a b Rieß-Marchive, Valéry (23 January 2019). "FIC 2019 : l'Anssi décerne ses labels". LeMagIT (in French).
  5. ^ a b "Arrêté du 12 août 2026 portant approbation du référentiel d'exigences relatif aux prestataires de services d'informatique en nuage" (in French). Légifrance. 12 August 2026. Retrieved 25 August 2026.
  6. ^ "Audition de M. Thierry Breton, président-directeur général d'Atos" (in French). French Senate. 8 April 2014.
  7. ^ "Audition de M. Alban Schmutz, senior vice-président d'OVH.com group" (in French). French National Assembly. 10 July 2014.
  8. ^ La Nouvelle France industrielle (PDF) (Report) (in French). French Ministry of the Economy. September 2014.
  9. ^ Cheminat, Jacques (12 January 2021). "OVH obtient la qualification SecNumCloud". Le Monde Informatique (in French).
  10. ^ Prestataires de services d'informatique en nuage (SecNumCloud) – référentiel d'exigences, version 3.2 (PDF) (Report) (in French). Agence nationale de la sécurité des systèmes d'information. 8 March 2022. §19.6, pp. 50–51.
  11. ^ "La doctrine « Cloud au centre »" (in French). Direction interministérielle du numérique. Retrieved 25 August 2026.
  12. ^ "Article 31 – Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numérique" (in French). Légifrance. 21 May 2024. Retrieved 25 August 2026.
  13. ^ "Décret n° 2026-272 du 14 avril 2026 relatif à la protection des données d'une sensibilité particulière des administrations, opérateurs et groupements d'intérêt public de l'État traitées par un service d'informatique en nuage fourni par un prestataire privé" (in French). Légifrance. 14 April 2026. Retrieved 25 August 2026.
  14. ^ Rieß-Marchive, Valéry (22 January 2015). "FIC 2015 : vers une Europe de la cybersécurité". LeMagIT (in French).
  15. ^ Rieß-Marchive, Valéry (15 December 2016). "France et Allemagne se rejoignent sur le cloud de confiance". LeMagIT (in French).
  16. ^ Calcara, Antonio (2026). "European cloud computing policy: failing in Europe to succeed nationally?". West European Politics. 49 (4): 994–1018. doi:10.1080/01402382.2025.2491962.
  17. ^ EUCS – Cloud Services Scheme (Report). European Union Agency for Cybersecurity. December 2020.
  18. ^ "EU drops sovereignty requirements in cybersecurity certification scheme, document shows". Reuters. 3 April 2024.
  19. ^ "Cybersecurity Certification Framework". European Union Agency for Cybersecurity. Retrieved 25 August 2026.
  20. ^ "Proposal for a Regulation establishing a framework of measures for strengthening Europe's cloud and AI ecosystem (Cloud and AI Development Act)". European Commission. 3 June 2026. COM(2026) 502 final. Retrieved 25 August 2026.
  21. ^ "Compliance for Cloud Services". Gaia-X Compliance Document. 3.1.0. Gaia-X European Association for Data and Cloud. Retrieved 25 August 2026.
  22. ^ Les enjeux de souveraineté des systèmes d'information civils de l'État (PDF) (Report) (in French). Cour des comptes. 31 October 2025. pp. 60, 62–63.
  23. ^ Fléchaux, Reynald (8 January 2026). "SecNumCloud, une protection pas si hermétique au droit extraterritorial". Le Monde Informatique (in French).

Content Disclaimer

Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.

  1. The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
  2. There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
  3. It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
  4. Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
  5. Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.