A French ministry wants to move a sensitive case management system to the cloud. A hospital group needs a hosting provider for patient records. A regional cloud provider wants to win public sector contracts. In each case, one word comes up early in the conversation: SecNumCloud. For anyone designing or buying storage in France for sensitive data, understanding what SecNumCloud requires, and what it means for the storage layer, is now essential.
This article explains what SecNumCloud is, why it matters, what its requirements imply for storage platforms and how cloud providers and public bodies can design storage that supports qualification. It is part of our series on data sovereignty; see also data sovereignty audits and sovereign cloud architecture.
SecNumCloud is a qualification for cloud service providers issued by ANSSI, France's national cybersecurity agency. Providers are assessed against a reference framework of security requirements, currently version 3.2, by approved evaluation bodies. Qualification is valid for three years, with annual surveillance audits.
The framework covers the full range of security controls expected of a trusted provider: governance, risk management, physical security, access control, encryption, logging, incident management, business continuity and personnel security. What sets it apart from many other cloud security schemes is its requirement for protection against non-European law. Version 3.2 added criteria to ensure that a qualified service is subject exclusively to European Union law, so that data cannot be accessed under foreign legislation with extraterritorial reach.
France's national cloud strategy, set out in a 2021 government circular often referred to as "cloud au centre", directs public administrations to use cloud services and to host sensitive data on services that offer protection against non-European legal access. SecNumCloud qualification is the main way providers demonstrate that protection. Subsequent legislation has reinforced the direction for sensitive public data. Beyond the public sector, operators of essential services, health organizations and companies handling sensitive data increasingly ask for SecNumCloud-qualified services in procurement.
According to ANSSI, the framework requires:
For storage, this has practical consequences. The storage platform, its management plane, its support channels and any services it depends on must not create a path for non-European control or access.
ANSSI states that customer data, administration and supervision data, customer and user directories, technical data such as logs and root certificates, and backups must remain within the EU. Storage must therefore keep every copy, replica and backup in approved locations, and must not send telemetry, metadata or logs outside the EU.
Storage platforms that rely on cloud-hosted license servers, remote management consoles or vendor telemetry services outside the EU can undermine qualification. Providers should verify that the storage software operates fully on premises, with no mandatory external connections.
SecNumCloud requires administrators to be vetted in proportion to their privileges. Storage platforms should support fine-grained role-based access, strong authentication, separation of duties and complete audit logs of administrative actions, so providers can demonstrate who can do what.
Third-party interventions, including vendor support, must be performed by equivalently vetted staff or under direct supervision of the provider's qualified staff. Storage vendors should support models where remote access is disabled by default, enabled only on request and fully logged.
Data must be protected with strong encryption, and key management must remain under the provider's control within the qualified perimeter. Storage should support encryption at rest and in transit, with keys held in systems the provider controls.
Security events must be logged, protected and retained. Storage platforms should produce detailed access and administrative logs that can be exported to the provider's security monitoring within the EU.
Business continuity requirements call for resilient infrastructure and tested recovery. Storage with erasure coding, multi-site deployment and immutable copies supports these requirements.
| Requirement area | What to verify in the storage platform |
|---|---|
| Data location | All data, replicas, backups, metadata and logs stay in approved EU sites |
| Independence | No mandatory connections to non-EU services for licensing, management or telemetry |
| Access control | Role-based access, strong authentication, separation of duties |
| Support | Remote access off by default, supervised and logged |
| Encryption | At rest and in transit, keys under provider control |
| Logging | Complete, exportable, tamper-resistant logs |
| Resilience | Erasure coding, multi-site options, immutable copies |
For a cloud provider preparing for qualification, storage design usually follows a few steps:
Not every organization buys a qualified service. Some ministries, agencies and hospital groups run their own private cloud infrastructure in national data centers. The same principles apply even without formal qualification: keep data and logs in France or the EU, avoid external dependencies, vet and log administrators, control vendor support and hold encryption keys locally. Aligning internal infrastructure with SecNumCloud requirements also makes it easier to move workloads to or from qualified providers later.
SecNumCloud is a French scheme, but it influences discussions about a European cloud certification and sits alongside national approaches in other countries, such as Germany's C5 catalogue. Organizations operating in several EU countries often map requirements across schemes so one storage design can serve all of them.
Scality is headquartered in France, and RING is software-defined object storage that runs entirely on infrastructure chosen and operated by the provider or organization. It does not require external cloud services to operate, supports multi-site deployments within national borders, provides S3-compatible access with compliance-mode object lock and offers role-based administration and audit logging. That makes RING suitable as the storage layer for providers building services within a SecNumCloud perimeter and for public bodies running sovereign infrastructure. Qualification applies to the cloud service as a whole, operated by the provider; storage is one component that must support the provider's controls.
SecNumCloud is France's benchmark for trusted cloud services, combining a demanding security framework with protection against non-European law. For storage, it means keeping every copy of data, metadata and logs in the EU, removing hidden external dependencies, vetting and logging administrators, controlling support access, holding keys locally and designing for resilience. Choosing storage that runs fully under the provider's control makes those requirements far easier to meet.
ANSSI, France's national cybersecurity agency, through approved evaluation bodies.
Three years, with annual surveillance audits.
Qualification applies to the cloud service. The storage platform must support the provider's controls for data location, access, support, encryption and logging.
Customer data, administration and supervision data, directories, technical data such as logs and root certificates, and backups.
Public administrations hosting sensitive data under France's cloud strategy, and increasingly operators of essential services and organizations handling sensitive data.