HDS, NIS2, DORA, Data Act: Turning Cloud Compliance Into an Engineering Discipline
Souveraineté & Conformité

HDS, NIS2, DORA, Data Act: Turning Cloud Compliance Into an Engineering Discipline

September 20, 20269 min readHDSNIS2DORA

HDS, NIS2, DORA and the Data Act are usually treated as four separate compliance projects. They ask the same four questions — and the answers are engineering practices, not paperwork.

Five texts, one underlying question: can you prove you control your cloud?

HDS, NIS2, DORA, the Data Act and the growing body of sovereignty expectations are usually presented as five separate compliance projects, each with its own steering committee, its own consultant and its own spreadsheet. That framing is expensive and, more importantly, wrong. Read the underlying requirements rather than the headlines and the same four demands appear again and again: know where your data physically is and which law applies to it, know who your critical providers are and what they subcontract, be able to detect and report an incident within hours, and be able to leave a provider without losing the service.

In other words, European regulation has stopped asking whether you have a policy document and started asking whether you can demonstrate an operational capability. That is a platform engineering problem far more than a legal one. This article maps the five texts onto the contractual clauses and the engineering practices that actually satisfy them.

HDS: the entry ticket for health data

The Hébergement de Données de Santé certification is required in France whenever personal health data collected in the context of prevention, diagnosis or care is hosted on behalf of a third party. It replaced the old ministerial approval regime and is now a certification issued by a COFRAC-accredited body, built on ISO 27001, ISO 20000-1 and ISO 27018 plus health-specific controls, and broken down into six hosting activities ranging from physical datacentre provision to application administration and outsourced backup.

Two practical points are consistently underestimated. First, the certificate is scoped: a provider certified for activities 1 and 2 (physical infrastructure and virtualised infrastructure) does not cover the administration of your application platform. If you run Kubernetes on top of a certified IaaS and a third party operates your clusters, that operator needs its own coverage for the relevant activities. Chain-of-certification gaps are the single most common finding in health procurement reviews.

Second, the referential was updated in 2024 and tightened exactly the points that matter to sovereignty: hosting and processing inside the EU, transparency on any administrative or support access from outside the EU, and explicit handling of exposure to extraterritorial law. If your health workload sits on a hyperscaler with a global follow-the-sun support model, that is now a documented risk that has to be mitigated, not a footnote.

NIS2: the perimeter explodes

Directive (EU) 2022/2555 replaces NIS1 and multiplies the number of regulated organisations by roughly an order of magnitude across Europe. It applies to medium and large entities in eighteen sectors, split between essential entities (energy, transport, banking, health, drinking water, digital infrastructure, public administration…) and important entities (postal services, waste, manufacturing, digital providers, food…). Managed service providers and cloud providers are explicitly in scope, which means many of your suppliers are becoming regulated at the same time you are.

The substance is in Article 21: a minimum set of risk-management measures including incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, cryptography, multi-factor authentication and secured communications. Article 23 sets the reporting cadence that everyone remembers: an early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, a final report within one month. Management bodies must approve the measures and can be held personally accountable — that provision alone has done more for security budgets than a decade of awareness campaigns.

France transposed late, through its critical-infrastructure resilience and cybersecurity law, with ANSSI as the competent authority. Late transposition is not a reason to wait: the 24/72-hour clock is only achievable if detection, triage and legal validation are already rehearsed.

DORA: resilience written into the contract

Regulation (EU) 2022/2554 has applied to the financial sector since January 2025 and is the most prescriptive of the five. Its five pillars — ICT risk management, incident classification and reporting, digital operational resilience testing, third-party risk management, and information sharing — turn resilience into an audited process.

Two pillars have direct cloud consequences. Chapter V imposes a register of information listing every contractual arrangement with ICT providers, including subcontractors supporting critical functions, the data locations, and the substitutability assessment. It is submitted to competent authorities and it is unforgiving: teams discover their real supplier graph — the observability SaaS, the CI runner fleet, the LLM API called from a payment flow — when they try to fill it in. Article 30 then lists mandatory contractual terms: service levels with quantitative targets, full audit and inspection rights for the entity and the regulator, notification of material subcontracting changes, data location commitments, and exit strategies with a transition period during which the provider continues to deliver the service.

Chapter IV adds threat-led penetration testing (TLPT, aligned with TIBER-EU) for significant entities, every three years, on live production systems. Critical third-party providers — a short list of hyperscalers and major software vendors — are placed under direct oversight by the European Supervisory Authorities, which changes the negotiating dynamic for everyone downstream.

The Data Act: reversibility becomes a default right

Regulation (EU) 2023/2854 has been applicable since September 2025 and its Chapter VI is the most concrete sovereignty lever European buyers have ever had. It gives customers of data processing services a statutory right to switch provider or move to on-premise: a maximum notice period, a mandatory transition period of at least 30 days with an extension mechanism when migration is genuinely complex, an obligation to export all exportable data and digital assets in a structured, commonly used, machine-readable format, and — the part providers dislike — the progressive removal of switching and egress charges, to be fully withdrawn in early 2027.

For infrastructure services the regulation goes further and requires functional equivalence: after switching, the customer should be able to obtain a materially comparable level of service. It does not require providers to open-source their PaaS, but it does require them to document interfaces, open standards and compatibility so that the customer can rebuild. Chapter VII, often overlooked, adds safeguards against unlawful third-country government access to non-personal data held in the EU — a direct echo of the HDS 2024 requirements and of the SecNumCloud qualification's protection against extraterritorial law.

Comparing the five regimes

FrameworkNatureWho is in scopeCore cloud obligationEnforcement
HDSFrench certification (Public Health Code)Anyone hosting personal health data for a third partyCertified scope per activity, EU hosting, transparency on extra-EU accessLoss of certification, contract illegality, CNIL
NIS2EU directive, national transpositionMedium/large entities in 18 sectorsSupply-chain security, 24h/72h/1-month reporting, board accountabilityUp to €10M or 2% of global turnover (essential entities)
DORADirectly applicable EU regulationFinancial entities and their ICT providersRegister of information, Article 30 contract clauses, tested exit strategies, TLPTSupervisory measures, penalties, oversight of critical providers
Data ActDirectly applicable EU regulationAll data processing service customers and providersSwitching rights, 30-day transition, format portability, removal of egress feesNational authorities, penalties set by member states
SecNumCloudVoluntary French qualificationProviders seeking sensitive-data workloadsTechnical, organisational and legal immunity from extraterritorial lawMarket access (public sector, "cloud de confiance" doctrine)

What actually changes in your contracts

Compliance failures in this space are rarely technical — they are clauses that were never negotiated. A minimum viable clause set for any new cloud or SaaS contract touching regulated data:

  • Data localisation and processing: named regions and availability zones, including for backups, logs, telemetry and support tooling. Telemetry is where residency commitments quietly break.
  • Subcontracting transparency: an up-to-date list, prior notice of material changes, and a right to object when a new subcontractor changes the risk profile.
  • Audit and inspection rights extended to the regulator, with pooled audits accepted as an alternative for hyperscalers.
  • Incident notification within a contractual window compatible with 24 hours — asking a provider for "prompt" notification is worthless when you owe ANSSI an early warning the next morning.
  • Exit plan: documented, versioned, with export formats, a maximum transition period, continuity of service during transition, assisted migration, and certified deletion afterwards.
  • No exit tax: egress and switching charges aligned with Data Act timelines, with the cost model made explicit now rather than discovered during the migration.

Turning obligations into engineering practice

The only exit plan that counts is the one you have executed. Treat reversibility as a non-functional requirement with a test, not as a PDF annex. Three practices carry most of the value.

1. Policy-as-code for residency and provider scope. Enforce region allowlists in CI on your Terraform plans so no one ships a bucket, a managed database or a log sink outside the certified perimeter:

package m2c.residency

allowed_regions := {"eu-west-3", "eu-west-1", "eu-central-1"}

deny[msg] {
  r := input.resource_changes[_]
  r.change.actions[_] != "delete"
  region := r.change.after.region
  not allowed_regions[region]
  msg := sprintf("%s deployed in %s: outside the HDS/DORA certified perimeter", [r.address, region])
}

deny[msg] {
  r := input.resource_changes[_]
  r.type == "aws_s3_bucket"
  not r.change.after.tags.data_classification
  msg := sprintf("%s has no data_classification tag (health/PII/other)", [r.address])
}

2. A scheduled reversibility drill. Once or twice a year, rebuild a representative slice of the platform on the alternative target defined in the exit plan, restore from the exported artefacts, and measure the real RTO. The output is evidence for the DORA register, for the NIS2 continuity measure and for the HDS audit at the same time.

name: exit-drill
on:
  schedule: [{ cron: "0 3 1 */6 *" }]
jobs:
  rebuild-on-alternate-provider:
    runs-on: self-hosted-eu
    steps:
      - run: make export-managed-data      # DB dumps, object store, secrets metadata
      - run: terraform -chdir=exit/ovh apply -auto-approve
      - run: make restore-and-verify       # schema, row counts, checksums
      - run: make slo-smoke-test           # functional equivalence check
      - run: make publish-evidence         # RTO, RPO, gaps -> compliance register

3. One supplier register, many consumers. Maintain the DORA register of information as the single source of truth and generate the NIS2 supply-chain inventory, the HDS subcontractor annex and the GDPR Article 30 record from it. Storing it as structured data in Git rather than in a shared spreadsheet is what makes that possible.

A pragmatic twelve-month sequence

Start with the map: an accurate inventory of services, data classification and provider graph, because every other obligation depends on it. Then close the contractual gaps on the top ten critical providers, negotiating notification windows, subcontracting transparency and exit terms at renewal rather than in crisis. In parallel, industrialise detection and the incident chain so the 24-hour clock is credible, including out-of-hours legal validation. Finally, run the first reversibility drill on one significant workload — not the whole estate — and publish the gaps honestly.

Done in that order, the five texts stop being five projects. HDS defines the perimeter, NIS2 the security baseline, DORA the proof and the contract, the Data Act the exit ramp, and SecNumCloud the answer to the extraterritoriality question when the data justifies it. The organisations that suffer are the ones treating each as a paperwork exercise; the ones that benefit end up with a platform they can actually move, audit and defend.

← Back to blog