{
  "node_id": "fr-anssi-secnumcloud-qualification-cloud-service-providers",
  "title": "France ANSSI SecNumCloud — Qualification for Cloud Service Providers (Sovereign Cloud Reference)",
  "domain": "Cloud & SaaS",
  "version": "1.0.0",
  "last_updated": "2026-06-08",
  "bluf": "SecNumCloud is the French national qualification scheme administered by the Agence Nationale de la Securite des Systemes d'Information (ANSSI) under which qualified cloud service providers (IaaS, PaaS, SaaS) receive an official ANSSI Visa de securite. The qualification embeds three sovereignty / immunity criteria designed to protect against extraterritorial law application and adversarial state interference: (i) immunity from non-EU extraterritorial law (the CSP and the legal entity providing the service must not be subject to extraterritorial regulation that would compel disclosure of customer data including the US CLOUD Act and the US FISA Section 702), (ii) capital ownership thresholds requiring EU-controlled corporate structure (typically constructed so that no extra-EU shareholder holds blocking minority or controlling rights over the qualified entity), and (iii) physical hosting and operational control within the EU including data residency, administrative access, and key management. SecNumCloud version 3.2 (March 2022) is the operative reference for current qualification decisions; the criteria framework spans organisational, physical, technical, cryptographic, identity and access management, incident response, business continuity, and supplier-management dimensions. SecNumCloud underpins France's Cloud au centre doctrine that mandates SecNumCloud-qualified offerings for sovereign-grade public sector workloads, sensitive non-classified data of state importance, and critical infrastructure operators classified as Operators of Vital Importance (OIV) and Essential Service Operators (OSE) under the French transposition of the EU NIS2 Directive. SecNumCloud is widely treated by EU institutions and member state procurement teams as the high-assurance benchmark for sovereign cloud and has been awarded to a small number of CSPs (notably 3DS Outscale, OVHcloud, Cloud Temple, NumSpot, S3NS Bleu in development as a Google-Capgemini-Orange JV, Sens by Orange, and Microsoft / Bleu pending). The scheme intersects the harmonised European Cybersecurity Certification Scheme for Cloud Services (EUCS) under negotiation and serves as one of the principal national references shaping the EUCS high-assurance level requirements.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-iec-42001-2023-ai-management-system",
    "iso-iec-23894-ai-risk-management-2023",
    "nist-sp-800-53-r5",
    "eu-cra-2024-2847-article-3-essential-requirements-products-digital-elements",
    "fips-203-ml-kem-standard"
  ],
  "primary_citations_count": 10
}