Since 22 August 2026, the rules have changed for French government bodies that host their most sensitive data in the Cloud. An order published in the Official Journal approves the SecNumCloud framework as the reference framework for meeting the security and protection requirements set out in the new regulatory framework.
This legal shift, in preparation for several years, raises a very concrete question for government bodies, their operators, and the companies that work with them: who is affected, from when, and for exactly which data?
This guide reviews the legal framework, the scope of the obligation, how SecNumCloud compares with other security frameworks, and the outlook for this digital sovereignty doctrine.
What is SecNumCloud?
SecNumCloud is the qualification framework for Cloud service providers, developed and issued by ANSSI (Agence nationale de la sécurité des systèmes d’information — France’s national cybersecurity agency). Created in 2016, it has gone through several revisions, with version 3.2 now the framework in force.
One important point of vocabulary to clarify from the outset: SecNumCloud is a qualification, not a certification in the sense of ISO 27001 or HDS. An ANSSI qualification involves an assessment carried out by an accredited audit provider, on the basis of which the agency itself grants the recognition: a process that is more demanding and more tightly controlled than a certification issued by a standard accredited body.
In concrete terms, SecNumCloud attests to a high level of technical and organizational security, but above all, it guarantees immunity from foreign extraterritorial legislation, first and foremost the US Cloud Act and FISA. It is this dimension of legal independence that sets SecNumCloud apart.
The legal framework that made SecNumCloud mandatory
Since when has SecNumCloud really been mandatory, rather than recommended? Are there any exemptions? Could an equivalent European certification be enough?
These are the questions that come up most often on this topic. The answer lies in a precise timeline, built in three stages.
The obligation did not appear out of nowhere: it is the culmination of a trajectory that began in 2021, with the government’s “Cloud at the center” (“Cloud au centre”) doctrine, which already recommended that government bodies use qualified offerings for certain sensitive data. Three texts then built, step by step, the current legal framework:
- The SREN law (2024), in Article 31, establishes the principle of an obligation to use SecNumCloud-qualified providers to host the State’s sensitive data.
- Decree No. 2026-272 of 14 April 2026 sets out the terms of application: who is affected, what falls under the notion of sensitive data, and the applicable exemption regime.
- The Order of 12 August 2026, published in the Official Journal on 14 August, formally approves the SecNumCloud 3.2 framework as the technical framework for implementation. It is this text that gives binding force to what had, until then, remained a strongly recommended best practice.
The decree provides for an exemption regime for certain projects already under way. This is not a commercial loophole: the exemption must be justified, closely regulated, made public under the prescribed conditions, and approved at the required level. It does not allow sovereignty and security requirements to be permanently set aside.
This timeline is worth understanding as a whole: it shows a digital sovereignty doctrine built progressively, with each text refining and reinforcing the one before it.
Who is affected by the SecNumCloud obligation and what sensitive data is covered?
The scope of the obligation is precise. Those affected include, in particular:
- central government administrations and relocated national services;
- their State operators;
- certain public interest groupings (groupements d’intérêt public, or GIP) falling within the scope defined by the texts.
These entities are subject to the obligation when they use a private provider to host sensitive data as defined by the decree: that is, data whose breach would harm public order, public safety, or public health.
Are local authorities affected by the SecNumCloud obligation?
Local authorities (collectivités territoriales) are not directly covered by the current scope of Article 31 of the SREN law.
They may nonetheless choose to use SecNumCloud-qualified offerings to meet their own security, sovereignty, and data protection requirements.
Since the regulatory framework around the sovereignty of digital procurement is likely to evolve, this remains a topic for local authorities and their IT departments (DSI) to watch.
SecNumCloud compared with other frameworks
SecNumCloud is not in competition with ISO 27001 or HDS: these certifications serve different purposes, and an organization can very well hold several qualifications or certifications at once.
- ISO 27001 is an international standard for information security management, with no dimension of legal sovereignty.
- HDS (Hébergeur de Données de Santé, or Health Data Hosting) is a sector-specific certification, dedicated to health data.
- SecNumCloud is a qualification designed specifically for Cloud services, combining strict requirements on security, operations, and sovereignty.
At the European level, the EUCS (European Cybersecurity Certification Scheme for Cloud Services), a harmonized Cloud certification scheme, has been under discussion for several years to provide an EU-wide equivalent. It remains under negotiation, however, and is not intended to replace SecNumCloud in the short term.
What this actually changes for public-sector players and their providers
One point deserves clarification: the SecNumCloud obligation does not mean that a bidder for a public contract (a web development agency or a business software vendor, for example) must necessarily be qualified from end to end itself.
However, as soon as a project touches the State’s sensitive data, the requirement applies to one specific, non-negotiable link: hosting. The successful bidder will need to have that data hosted on Cloud infrastructure that itself holds the SecNumCloud qualification, or an equivalent recognized by ANSSI at the European level. It is this piece of infrastructure that constitutes the unavoidable compliance standard.
Conclusion
The Order of 12 August 2026 closes a legal process launched with the SREN law of 2024: SecNumCloud is no longer a recommended best practice — it is now a legal condition for hosting the State’s most sensitive data. The scope remains targeted for now, but the direction is clear.
Today, around ten offerings are SecNumCloud-qualified in France, including OUTSCALE’s public Cloud offering.
A pioneer, OUTSCALE was the first public Cloud provider to obtain the SecNumCloud qualification, in 2019, and also holds HDS certification, enabling it to meet the needs of organizations with specific requirements for hosting health data.
