Five texts, one underlying question: can you prove you control your cloud?
HDS, NIS2, DORA, the Data Act and the growing body of sovereignty expectations are usually presented as five separate compliance projects, each with its own steering committee, its own consultant and its own spreadsheet. That framing is expensive and, more importantly, wrong. Read the underlying requirements rather than the headlines and the same four demands appear again and again: know where your data physically is and which law applies to it, know who your critical providers are and what they subcontract, be able to detect and report an incident within hours, and be able to leave a provider without losing the service.
In other words, European regulation has stopped asking whether you have a policy document and started asking whether you can demonstrate an operational capability. That is a platform engineering problem far more than a legal one. This article maps the five texts onto the contractual clauses and the engineering practices that actually satisfy them.
HDS: the entry ticket for health data
The Hébergement de Données de Santé certification is required in France whenever personal health data collected in the context of prevention, diagnosis or care is hosted on behalf of a third party. It replaced the old ministerial approval regime and is now a certification issued by a COFRAC-accredited body, built on ISO 27001, ISO 20000-1 and ISO 27018 plus health-specific controls, and broken down into six hosting activities ranging from physical datacentre provision to application administration and outsourced backup.
Two practical points are consistently underestimated. First, the certificate is scoped: a provider certified for activities 1 and 2 (physical infrastructure and virtualised infrastructure) does not cover the administration of your application platform. If you run Kubernetes on top of a certified IaaS and a third party operates your clusters, that operator needs its own coverage for the relevant activities. Chain-of-certification gaps are the single most common finding in health procurement reviews.
Second, the referential was updated in 2024 and tightened exactly the points that matter to sovereignty: hosting and processing inside the EU, transparency on any administrative or support access from outside the EU, and explicit handling of exposure to extraterritorial law. If your health workload sits on a hyperscaler with a global follow-the-sun support model, that is now a documented risk that has to be mitigated, not a footnote.
NIS2: the perimeter explodes
Directive (EU) 2022/2555 replaces NIS1 and multiplies the number of regulated organisations by roughly an order of magnitude across Europe. It applies to medium and large entities in eighteen sectors, split between essential entities (energy, transport, banking, health, drinking water, digital infrastructure, public administration…) and important entities (postal services, waste, manufacturing, digital providers, food…). Managed service providers and cloud providers are explicitly in scope, which means many of your suppliers are becoming regulated at the same time you are.
The substance is in Article 21: a minimum set of risk-management measures including incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, cryptography, multi-factor authentication and secured communications. Article 23 sets the reporting cadence that everyone remembers: an early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, a final report within one month. Management bodies must approve the measures and can be held personally accountable — that provision alone has done more for security budgets than a decade of awareness campaigns.
France transposed late, through its critical-infrastructure resilience and cybersecurity law, with ANSSI as the competent authority. Late transposition is not a reason to wait: the 24/72-hour clock is only achievable if detection, triage and legal validation are already rehearsed.
DORA: resilience written into the contract
Regulation (EU) 2022/2554 has applied to the financial sector since January 2025 and is the most prescriptive of the five. Its five pillars — ICT risk management, incident classification and reporting, digital operational resilience testing, third-party risk management, and information sharing — turn resilience into an audited process.
Two pillars have direct cloud consequences. Chapter V imposes a register of information listing every contractual arrangement with ICT providers, including subcontractors supporting critical functions, the data locations, and the substitutability assessment. It is submitted to competent authorities and it is unforgiving: teams discover their real supplier graph — the observability SaaS, the CI runner fleet, the LLM API called from a payment flow — when they try to fill it in. Article 30 then lists mandatory contractual terms: service levels with quantitative targets, full audit and inspection rights for the entity and the regulator, notification of material subcontracting changes, data location commitments, and exit strategies with a transition period during which the provider continues to deliver the service.
Chapter IV adds threat-led penetration testing (TLPT, aligned with TIBER-EU) for significant entities, every three years, on live production systems. Critical third-party providers — a short list of hyperscalers and major software vendors — are placed under direct oversight by the European Supervisory Authorities, which changes the negotiating dynamic for everyone downstream.
The Data Act: reversibility becomes a default right
Regulation (EU) 2023/2854 has been applicable since September 2025 and its Chapter VI is the most concrete sovereignty lever European buyers have ever had. It gives customers of data processing services a statutory right to switch provider or move to on-premise: a maximum notice period, a mandatory transition period of at least 30 days with an extension mechanism when migration is genuinely complex, an obligation to export all exportable data and digital assets in a structured, commonly used, machine-readable format, and — the part providers dislike — the progressive removal of switching and egress charges, to be fully withdrawn in early 2027.
For infrastructure services the regulation goes further and requires functional equivalence: after switching, the customer should be able to obtain a materially comparable level of service. It does not require providers to open-source their PaaS, but it does require them to document interfaces, open standards and compatibility so that the customer can rebuild. Chapter VII, often overlooked, adds safeguards against unlawful third-country government access to non-personal data held in the EU — a direct echo of the HDS 2024 requirements and of the SecNumCloud qualification's protection against extraterritorial law.
Comparing the five regimes
| Framework | Nature | Who is in scope | Core cloud obligation | Enforcement |
|---|---|---|---|---|
| HDS | French certification (Public Health Code) | Anyone hosting personal health data for a third party | Certified scope per activity, EU hosting, transparency on extra-EU access | Loss of certification, contract illegality, CNIL |
| NIS2 | EU directive, national transposition | Medium/large entities in 18 sectors | Supply-chain security, 24h/72h/1-month reporting, board accountability | Up to €10M or 2% of global turnover (essential entities) |
| DORA | Directly applicable EU regulation | Financial entities and their ICT providers | Register of information, Article 30 contract clauses, tested exit strategies, TLPT | Supervisory measures, penalties, oversight of critical providers |
| Data Act | Directly applicable EU regulation | All data processing service customers and providers | Switching rights, 30-day transition, format portability, removal of egress fees | National authorities, penalties set by member states |
| SecNumCloud | Voluntary French qualification | Providers seeking sensitive-data workloads | Technical, organisational and legal immunity from extraterritorial law | Market access (public sector, "cloud de confiance" doctrine) |
What actually changes in your contracts
Compliance failures in this space are rarely technical — they are clauses that were never negotiated. A minimum viable clause set for any new cloud or SaaS contract touching regulated data:
- Data localisation and processing: named regions and availability zones, including for backups, logs, telemetry and support tooling. Telemetry is where residency commitments quietly break.
- Subcontracting transparency: an up-to-date list, prior notice of material changes, and a right to object when a new subcontractor changes the risk profile.
- Audit and inspection rights extended to the regulator, with pooled audits accepted as an alternative for hyperscalers.
- Incident notification within a contractual window compatible with 24 hours — asking a provider for "prompt" notification is worthless when you owe ANSSI an early warning the next morning.
- Exit plan: documented, versioned, with export formats, a maximum transition period, continuity of service during transition, assisted migration, and certified deletion afterwards.
- No exit tax: egress and switching charges aligned with Data Act timelines, with the cost model made explicit now rather than discovered during the migration.
Turning obligations into engineering practice
The only exit plan that counts is the one you have executed. Treat reversibility as a non-functional requirement with a test, not as a PDF annex. Three practices carry most of the value.
1. Policy-as-code for residency and provider scope. Enforce region allowlists in CI on your Terraform plans so no one ships a bucket, a managed database or a log sink outside the certified perimeter:
package m2c.residency
allowed_regions := {"eu-west-3", "eu-west-1", "eu-central-1"}
deny[msg] {
r := input.resource_changes[_]
r.change.actions[_] != "delete"
region := r.change.after.region
not allowed_regions[region]
msg := sprintf("%s deployed in %s: outside the HDS/DORA certified perimeter", [r.address, region])
}
deny[msg] {
r := input.resource_changes[_]
r.type == "aws_s3_bucket"
not r.change.after.tags.data_classification
msg := sprintf("%s has no data_classification tag (health/PII/other)", [r.address])
}2. A scheduled reversibility drill. Once or twice a year, rebuild a representative slice of the platform on the alternative target defined in the exit plan, restore from the exported artefacts, and measure the real RTO. The output is evidence for the DORA register, for the NIS2 continuity measure and for the HDS audit at the same time.
name: exit-drill
on:
schedule: [{ cron: "0 3 1 */6 *" }]
jobs:
rebuild-on-alternate-provider:
runs-on: self-hosted-eu
steps:
- run: make export-managed-data # DB dumps, object store, secrets metadata
- run: terraform -chdir=exit/ovh apply -auto-approve
- run: make restore-and-verify # schema, row counts, checksums
- run: make slo-smoke-test # functional equivalence check
- run: make publish-evidence # RTO, RPO, gaps -> compliance register3. One supplier register, many consumers. Maintain the DORA register of information as the single source of truth and generate the NIS2 supply-chain inventory, the HDS subcontractor annex and the GDPR Article 30 record from it. Storing it as structured data in Git rather than in a shared spreadsheet is what makes that possible.
A pragmatic twelve-month sequence
Start with the map: an accurate inventory of services, data classification and provider graph, because every other obligation depends on it. Then close the contractual gaps on the top ten critical providers, negotiating notification windows, subcontracting transparency and exit terms at renewal rather than in crisis. In parallel, industrialise detection and the incident chain so the 24-hour clock is credible, including out-of-hours legal validation. Finally, run the first reversibility drill on one significant workload — not the whole estate — and publish the gaps honestly.
Done in that order, the five texts stop being five projects. HDS defines the perimeter, NIS2 the security baseline, DORA the proof and the contract, the Data Act the exit ramp, and SecNumCloud the answer to the extraterritoriality question when the data justifies it. The organisations that suffer are the ones treating each as a paperwork exercise; the ones that benefit end up with a platform they can actually move, audit and defend.
