Data sovereignty

What is SecNumCloud and what does it require from storage?

What SecNumCloud is, who needs it and what it requires from storage: EU jurisdiction, data location, admin vetting, keys, logs and support.

7 min read
Pristine teal block glowing in a dark data center

A French ministry wants to move a sensitive case management system to the cloud. A hospital group needs a hosting provider for patient records. A regional cloud provider wants to win public sector contracts. In each case, one word comes up early in the conversation: SecNumCloud. For anyone designing or buying storage in France for sensitive data, understanding what SecNumCloud requires, and what it means for the storage layer, is now essential.

This article explains what SecNumCloud is, why it matters, what its requirements imply for storage platforms and how cloud providers and public bodies can design storage that supports qualification. It is part of our series on data sovereignty; see also data sovereignty audits and sovereign cloud architecture.

What SecNumCloud is

SecNumCloud is a qualification for cloud service providers issued by ANSSI, France's national cybersecurity agency. Providers are assessed against a reference framework of security requirements, currently version 3.2, by approved evaluation bodies. Qualification is valid for three years, with annual surveillance audits.

The framework covers the full range of security controls expected of a trusted provider: governance, risk management, physical security, access control, encryption, logging, incident management, business continuity and personnel security. What sets it apart from many other cloud security schemes is its requirement for protection against non-European law. Version 3.2 added criteria to ensure that a qualified service is subject exclusively to European Union law, so that data cannot be accessed under foreign legislation with extraterritorial reach.

Why it matters

France's national cloud strategy, set out in a 2021 government circular often referred to as "cloud au centre", directs public administrations to use cloud services and to host sensitive data on services that offer protection against non-European legal access. SecNumCloud qualification is the main way providers demonstrate that protection. Subsequent legislation has reinforced the direction for sensitive public data. Beyond the public sector, operators of essential services, health organizations and companies handling sensitive data increasingly ask for SecNumCloud-qualified services in procurement.

Protection against extra-European law

According to ANSSI, the framework requires:

  • A registered office in an EU member state.
  • Limits on non-EU ownership, so that non-EU entities remain minority shareholders.
  • Limited reliance on non-EU service providers for the qualified service.
  • Autonomy and independence, so the service can continue operating and remain compliant.

For storage, this has practical consequences. The storage platform, its management plane, its support channels and any services it depends on must not create a path for non-European control or access.

What SecNumCloud means for storage

Data location in the EU

ANSSI states that customer data, administration and supervision data, customer and user directories, technical data such as logs and root certificates, and backups must remain within the EU. Storage must therefore keep every copy, replica and backup in approved locations, and must not send telemetry, metadata or logs outside the EU.

No hidden dependencies

Storage platforms that rely on cloud-hosted license servers, remote management consoles or vendor telemetry services outside the EU can undermine qualification. Providers should verify that the storage software operates fully on premises, with no mandatory external connections.

Administrator vetting and access control

SecNumCloud requires administrators to be vetted in proportion to their privileges. Storage platforms should support fine-grained role-based access, strong authentication, separation of duties and complete audit logs of administrative actions, so providers can demonstrate who can do what.

Controlled support access

Third-party interventions, including vendor support, must be performed by equivalently vetted staff or under direct supervision of the provider's qualified staff. Storage vendors should support models where remote access is disabled by default, enabled only on request and fully logged.

Encryption and key management

Data must be protected with strong encryption, and key management must remain under the provider's control within the qualified perimeter. Storage should support encryption at rest and in transit, with keys held in systems the provider controls.

Logging and traceability

Security events must be logged, protected and retained. Storage platforms should produce detailed access and administrative logs that can be exported to the provider's security monitoring within the EU.

Resilience

Business continuity requirements call for resilient infrastructure and tested recovery. Storage with erasure coding, multi-site deployment and immutable copies supports these requirements.

Storage design checklist for SecNumCloud

Requirement areaWhat to verify in the storage platform
Data locationAll data, replicas, backups, metadata and logs stay in approved EU sites
IndependenceNo mandatory connections to non-EU services for licensing, management or telemetry
Access controlRole-based access, strong authentication, separation of duties
SupportRemote access off by default, supervised and logged
EncryptionAt rest and in transit, keys under provider control
LoggingComplete, exportable, tamper-resistant logs
ResilienceErasure coding, multi-site options, immutable copies

Building a SecNumCloud-ready storage service

For a cloud provider preparing for qualification, storage design usually follows a few steps:

  • Define the perimeter. Decide which services, sites and teams fall within the qualified scope, and make sure storage for those services runs only inside it.
  • Map every data flow. Trace where customer data, metadata, logs, backups, support bundles and monitoring data go, and remove any flow that leaves the EU or the perimeter.
  • Harden administration. Separate storage administrator roles, enforce strong authentication and send all administrative logs to the provider's security monitoring.
  • Lock down support. Agree with the storage vendor how support will be delivered, with remote access disabled by default and supervised sessions when needed.
  • Document everything. Evaluators will ask for architecture diagrams, procedures and evidence. Storage that produces clear configuration reports and logs shortens the audit.

Public bodies running their own infrastructure

Not every organization buys a qualified service. Some ministries, agencies and hospital groups run their own private cloud infrastructure in national data centers. The same principles apply even without formal qualification: keep data and logs in France or the EU, avoid external dependencies, vet and log administrators, control vendor support and hold encryption keys locally. Aligning internal infrastructure with SecNumCloud requirements also makes it easier to move workloads to or from qualified providers later.

SecNumCloud and European schemes

SecNumCloud is a French scheme, but it influences discussions about a European cloud certification and sits alongside national approaches in other countries, such as Germany's C5 catalogue. Organizations operating in several EU countries often map requirements across schemes so one storage design can serve all of them.

Common pitfalls

  • Telemetry or license checks that call services outside the EU.
  • Support processes that give vendors unsupervised remote access.
  • Backups or replicas stored in a location outside the qualified perimeter.
  • Keys managed by a third party outside the provider's control.
  • Logs that are incomplete or not exported to the provider's monitoring.

How Scality fits

Scality is headquartered in France, and RING is software-defined object storage that runs entirely on infrastructure chosen and operated by the provider or organization. It does not require external cloud services to operate, supports multi-site deployments within national borders, provides S3-compatible access with compliance-mode object lock and offers role-based administration and audit logging. That makes RING suitable as the storage layer for providers building services within a SecNumCloud perimeter and for public bodies running sovereign infrastructure. Qualification applies to the cloud service as a whole, operated by the provider; storage is one component that must support the provider's controls.

Questions to ask a storage vendor

  • Does the platform run fully on premises with no mandatory external connections?
  • Where is any telemetry sent, and can it be disabled?
  • How is support delivered, and can remote access be fully controlled and logged?
  • Which encryption and key management options keep keys under our control?
  • What audit logs are available, and how are they exported?
  • Can the platform be deployed across multiple sites within France or the EU?

Putting it together

SecNumCloud is France's benchmark for trusted cloud services, combining a demanding security framework with protection against non-European law. For storage, it means keeping every copy of data, metadata and logs in the EU, removing hidden external dependencies, vetting and logging administrators, controlling support access, holding keys locally and designing for resilience. Choosing storage that runs fully under the provider's control makes those requirements far easier to meet.

Frequently asked questions

Who issues SecNumCloud qualification?

ANSSI, France's national cybersecurity agency, through approved evaluation bodies.

How long is SecNumCloud qualification valid?

Three years, with annual surveillance audits.

Does storage need its own SecNumCloud qualification?

Qualification applies to the cloud service. The storage platform must support the provider's controls for data location, access, support, encryption and logging.

What data must stay in the EU under SecNumCloud?

Customer data, administration and supervision data, directories, technical data such as logs and root certificates, and backups.

Who needs SecNumCloud?

Public administrations hosting sensitive data under France's cloud strategy, and increasingly operators of essential services and organizations handling sensitive data.

Further reading

Related reading

See Scality in action

Exabyte-scale object storage for AI data and cyber resilience. Talk to our team about what it can do for yours.

Request a demo