FR
live

SecNumCloud 4.0 Mandates Operational Sovereignty for All Clouds Hosting Sensitive Data — the Framework Changes Everything by September 2026

On September 1, 2026, version 4.0 of the SecNumCloud framework takes effect for new qualifications. It mandates immunity to extraterritorial laws, capital independence, and software supply chain transparency. CISOs handling sensitive data must reconsider their cloud strategy before year-end.

A rack of servers in a cold datacenter, a single yellow indicator lit on a locked bay

September 1, 2026, SecNumCloud 4.0, three pillars: France’s ANSSI (National Cybersecurity Agency) publishes the final version of the framework that redefines cloud qualification. Version 3.2 was sufficient to tick a box in a public procurement tender. Version 4.0 transforms the SecNumCloud qualification into an enforceable digital sovereignty standard for any hosting of sensitive data — public or private sector.

This isn’t an incremental update. It’s a paradigm shift: a trusted cloud is no longer defined by technical security alone. It now requires structural independence from extraterritorial legislation. For CISOs and procurement officers across Europe, SecNumCloud 4.0 is the most demanding cloud certification framework ever written — and it’s about to become law in all but name.

What SecNumCloud 4.0 Actually Requires

The framework is structured around three control axes that go far beyond conventional security auditing:

1. Protection Against Extraterritorial Law

The cloud provider must demonstrate that no foreign law — including the U.S. Cloud Act (2018) or FISA Section 702 — can compel the disclosure of hosted data. In practice:

  • The parent company and all controlling entities must be incorporated under European law.
  • Encryption keys must be held and managed exclusively by a European entity, with no technical access possible from a non-European subsidiary.
  • The service contract must include a clause resisting extraterritorial injunctions, enforceable in court.

This first pillar de facto excludes any cloud offering operated by a European subsidiary of a U.S. hyperscaler, regardless of datacenter location. AWS Europe (Luxembourg) or Google Cloud France cannot qualify for SecNumCloud 4.0 as-is. The sovereignty requirement bites at the ownership level, not the infrastructure level.

2. Capital Independence and Autonomous Governance

The provider must prove that no non-European shareholder can impose a strategic decision contrary to sovereignty requirements. This includes:

  • A governance structure with an independent supervisory board, majority-composed of European residents.
  • No golden share or veto right held by a non-European entity.
  • A capital continuity plan describing the procedure in case of a change of control.

This is the clause that separates SecNumCloud from a standard ISO 27001 audit. It’s not about firewalls — it’s about who signs the checks and who can override a decision to hand over data.

3. Software Supply Chain Transparency (SBOM)

Every piece of software deployed in the qualified infrastructure must be documented by a SBOM (Software Bill of Materials) in SPDX 3.0 or CycloneDX 1.6 format. The SBOM must include:

  • All dependencies, direct and transitive, with version and origin.
  • Known CVEs affecting each component, with remediation status.
  • Build provenance (SLSA Level 2 attestation minimum).

ANSSI is aligning here with the EU Cyber Resilience Act and the U.S. Executive Order 14028 — all three converging toward mandatory SBOM requirements by 2027. The message to software vendors is unambiguous: if you can’t produce a CycloneDX file, you can’t sell into qualified European clouds.

The Players in the Ring

The French market for SecNumCloud 3.2-qualified clouds today counts roughly ten providers: Outscale (Dassault Systèmes), Cloud Temple, OVHcloud, Scaleway, Numergy, 3DS Outscale, and Bleu (a Capgemini/Orange joint venture with Microsoft). All must re-qualify under the new framework.

The Bleu case is emblematic. This joint venture between Capgemini, Orange, and Microsoft aims to deliver an Azure cloud that is technically identical to the U.S. offering but operated in France by French entities. SecNumCloud 4.0 will stress-test the model: can Bleu demonstrate zero technical access by Microsoft Corp. to hosted data while maintaining compatibility with the Azure ecosystem? Skeptics point out that Azure’s control plane architecture wasn’t designed for this level of isolation — the technical separation must be proven, not asserted.

OVHcloud, for its part, announced in June 2026 that it had submitted its 4.0 qualification dossier for its Hosted Private Cloud offering. With a 100% European corporate structure, OVHcloud has a structural advantage on the “extraterritoriality” axis — but must demonstrate SBOM maturity across its entire infrastructure stack, including third-party components from non-European vendors.

On the hyperscaler side, Amazon Web Services officially launched its AWS European Sovereign Cloud in March 2026 — a cloud physically and logically separated from its global commercial regions, operated by Europe-based personnel, and governed by a German legal entity. AWS hasn’t announced a SecNumCloud 4.0 application, but the structure checks several key boxes. Google Cloud and Microsoft Azure have made similar sovereignty moves with their respective “EU Sovereign” offerings — though none have yet pursued formal ANSSI qualification.

The Regulatory Timeline Squeezing CISOs

The regulatory calendar sets the pace:

  • September 2026: SecNumCloud 4.0 takes effect for new qualification applications.
  • September 2027: Existing 3.2 qualifications expire. All providers must have migrated to 4.0.
  • 2027: The Cyber Resilience Act comes into phased effect, mandating SBOMs for all software products sold in the EU.
  • October 2027: Deadline for transposing the NIS3 directive into French law, extending security obligations to cloud services and managed service providers.

For a CISO managing healthcare data, defense-related data, or trade-secret-protected information, the message is clear: if your current cloud contract expires in 2027, you must bake SecNumCloud 4.0 into your RFP now. Waiting until the 3.2 deadline leaves no margin for migration — and the pool of qualified providers will be small.

Verdict: What Changes for You

The SecNumCloud 4.0 qualification isn’t a Franco-French niche debate. In a context where the Data Act, Cyber Resilience Act, and NIS3 are simultaneously redrawing the European regulatory landscape, SecNumCloud 4.0 becomes a case study of what digital sovereignty can demand from a cloud supply chain. Other EU member states are watching — Germany’s C5 framework and Italy’s AGID qualification are already studying alignment paths.

  • If you host healthcare, defense, or critical research data: demand SecNumCloud 4.0 in your upcoming RFPs. 3.2 compliance becomes worthless in 13 months. The transition window is short — start vendor evaluations now.
  • If you use a U.S. hyperscaler for sensitive data: evaluate the AWS European Sovereign Cloud and the Bleu offering as transitional alternatives. But don’t sign a three-year commitment without a SecNumCloud exit clause. If your data is truly sensitive, budget for a migration — not a workaround.
  • If you develop software for the European market: start producing CycloneDX SBOMs today. This is a prerequisite for entering the qualified cloud supply chain, and it will be mandatory for all software sold in the EU starting in 2027. The tools exist (Syft, Trivy, cdxgen); what’s missing in most organizations is the pipeline integration and the ownership assignment.

On September 1, 2026, the trusted cloud stops being a marketing promise. It becomes an auditable, enforceable, and measurable standard. The providers who pass will earn a premium. The ones who don’t will lose the public sector and the most profitable enterprise segments. This is regulatory competition at its sharpest — and the market will sort the rest.


References

  • ANSSI, “SecNumCloud — Requirements Framework V4.0,” expected publication September 2026
  • ANSSI, “SecNumCloud V3.2,” January 2024 — https://cyber.gouv.fr/
  • European Parliament, “Cyber Resilience Act — Regulation (EU) 2024/2847,” December 2024
  • AWS, “Announcing the AWS European Sovereign Cloud,” March 2026
  • OVHcloud, “SecNumCloud 4.0 Qualification Progress Update,” press release, June 2026

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

← Back to the feed

Type at least two characters.

navigate open esc dismiss