HomeFrameworksNational Cyber & Cloud SchemesSecNumCloud

Framework  National Cyber & Cloud Schemes

SecNumCloud

SecNumCloud is the French national security qualification for cloud service providers, issued by ANSSI, the national cybersecurity agency.

The current requirements framework is version 3.2, published in March 2022, with more than 360 requirements covering the provider's organization, personnel, physical and logical security, development, operations, and incident handling, built on ISO/IEC 27001 and 27017 and adding French requirements.

Version 3.2 also introduced the immunity criteria: qualified providers must host and operate within the European Union and be structured so that they are not subject to non-EU laws with extraterritorial reach, which in practice excludes providers controlled by non-EU parents.

SecNumCloud is the technical backbone of the French "cloud de confiance" doctrine and is required or strongly preferred for hosting sensitive state data, for certain health data platforms, and increasingly in public procurement; as of mid-2026 a small number of providers (around nine, with a dozen applications in progress) hold the qualification (verify the current list on the ANSSI site).

Qualification is a formal ANSSI process. The provider applies, an evaluation is carried out by an ANSSI-qualified audit provider (PASSI) under ANSSI supervision, ANSSI reviews the results and any nonconformities, and the qualification is granted for three years with annual surveillance audits.

In writing, a provider needs a full ISMS scoped to the qualified services, a requirements matrix with evidence for each SecNumCloud requirement, documentation of its legal structure and ownership to demonstrate the immunity criteria, personnel security procedures, secure development and operations procedures, data location and segregation evidence, incident notification procedures to ANSSI and customers, business continuity plans, and the audit reports.

AI-compiled
Share
Sponsored
SecNumClou
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with SecNumCloud
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary, but effectively required for cloud providers hosting French state sensitive data (under the cloud au centre doctrine), for certain health data and regulated workloads, and for suppliers to public bodies that specify it. Applicants must satisfy the EU control and location requirements, so it is mainly pursued by French and EU-owned providers.

What the assessor asks to see

Service scope and architecture; ISMS documentation (policy, risk assessment, statement of applicability, procedures); requirements matrix with evidence for each 3.2 requirement; legal and ownership documentation for the immunity criteria; personnel security (screening, training, access) records; physical security of data centers in the EU; logical segregation and tenant isolation; cryptography and key management; secure development and change management; logging, monitoring, and vulnerability management; incident response and notification records; business continuity and disaster recovery tests; supplier and subcontractor controls; internal audit and management review; PASSI audit reports and corrective action plans.

Immunity criteria (version 3.2)

Version 3.2 requires qualified providers to be established and operated in the European Union and to demonstrate that they are not exposed to non-EU laws with extraterritorial effect, through ownership and control conditions and contractual and technical measures. This is the requirement that distinguishes SecNumCloud from ISO/IEC 27001-based schemes and from the German C5.

Assessors

Who assesses SecNumCloud

Evaluation by ANSSI with audits performed by PASSI-qualified audit providers (Prestataires d'audit de la sécurité des systèmes d'information, qualified by ANSSI); the qualification decision is ANSSI's. No other body can issue SecNumCloud.

Accredited by ANSSI qualifies both the audit providers (PASSI) and the cloud providers; PASSI qualification itself relies on accreditation by COFRAC under ISO/IEC 17065.

Public register of assessors: https://cyber.gouv.fr/enjeux-technologiques/cloud/faq-qualification-secnumcloud/

No firm has claimed a SecNumCloud assessor listing yet. Claim yours →

Consultants

Who helps with SecNumCloud

French cybersecurity consultancies with ISO/IEC 27001 and ANSSI-referential expertise prepare providers: gap analysis against the 3.2 requirements, legal structuring advice for the immunity criteria, and pre-audits. Preparation commonly takes twelve to twenty-four months.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a SecNumCloud consultant listing yet. Claim yours →

Software

Tools for SecNumCloud

Tools that name this framework in their own material.

No firm has claimed a SecNumCloud tool listing yet. Claim yours →

Related reading

  1. SecNumCloud qualification (ANSSI): complete guideA qualified provider's first-hand account of the 3.2 criteria, the PASSI audit and the legal sovereignty tests it had to pass.Scalingo
  2. SecNumCloud, la qualification ANSSI pour un cloud securiseFrench trade press on why the scheme mixes technical controls with immunity from extraterritorial law, and who is obliged to use it.Cloud Magazine

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for SecNumCloud

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with SecNumCloud

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.