Why Cloud Sovereignty Is Back at the Center of the Conversation
Over the past two years, digital sovereignty has moved from regulatory circles straight into boardroom discussions. Three factors converge: regulatory pressure (GDPR, NIS2, the upcoming EUCS scheme), tighter sector-specific requirements (healthcare, finance, government), and a broader awareness of extraterritorial risk tied to the US Cloud Act. For French companies handling sensitive or regulated data, choosing a cloud provider is no longer just about performance or cost — it has become a compliance and risk-management decision in its own right.
The Regulatory Framework: SecNumCloud and the Upcoming EUCS Scheme
The SecNumCloud qualification, issued by ANSSI (the French cybersecurity agency), remains the French reference standard. It imposes strict technical security requirements, but more importantly demands immunity from non-European extraterritorial laws: a SecNumCloud-qualified operator must be owned and operated in a way that shields it from the Cloud Act or extra-European administrative orders.
At the European level, the EUCS (European Cybersecurity Certification Scheme for Cloud Services), driven by ENISA, is moving toward harmonizing sovereignty requirements across the EU. Debate over the "High+" level (full immunity from third-country laws) remains the main friction point between member states, but the underlying trend is clear: public administrations and critical sectors will increasingly need to demonstrate a high level of sovereignty for their most sensitive data.
Overview of Offerings on the French Market
The landscape has structured itself around several models:
| Offering | Players | Model | Positioning |
|---|---|---|---|
| AWS European Sovereign Cloud | AWS (dedicated European legal and operational structure) | EU-localized infrastructure and governance, European staff and operators | Native AWS services with enhanced data residency and operational autonomy guarantees |
| Bleu | Capgemini & Orange, licensed Microsoft Azure technology | French joint venture | Targets public administrations and OIVs needing SecNumCloud-qualified Microsoft 365 / Azure |
| S3ns | Thales & Docaposte, licensed Google Cloud technology | French joint venture | Pursuing SecNumCloud qualification for Google Cloud services (data, AI, productivity) |
| OVHcloud | French, 100% EU capital and operations | Native sovereign cloud | SecNumCloud-qualified IaaS/PaaS, strong presence in the public sector |
| Outscale | Dassault Systèmes | Native sovereign cloud | SecNumCloud, focused on regulated sectors and industry |
| Scaleway | Iliad Group | Native sovereign cloud | Managed IaaS/Kubernetes, strong adoption among French scale-ups |
An essential point of caution: "hosted in Europe" offerings are not all equivalent to true legal sovereignty. Storing data within the EU protects you under GDPR from a geographic standpoint, but only genuinely European legal and operational governance protects against extraterritorial requisition.
Sovereign Cloud Doesn't Mean Isolated Cloud
A persistent misconception pits sovereignty against innovation, as if choosing a sovereign cloud meant giving up advanced managed services, generative AI, or the pace of innovation of hyperscalers. The reality is more nuanced: joint ventures like Bleu and S3ns exist precisely to reconcile both, providing access to the Azure and Google Cloud software stacks under French legal governance. Meanwhile, native sovereign offerings (OVHcloud, Outscale, Scaleway) have considerably expanded their managed catalogs (Kubernetes, databases, AI) in recent years.
The right approach is therefore rarely a binary choice, but rather a tiered architecture by data sensitivity: the most critical data and workloads (healthcare, defense, high-risk personal data) on SecNumCloud-qualified infrastructure, with the rest of the information system on whichever platform best fits business and technical needs.
Decision Framework for CIOs
- Nature and sensitivity of data: healthcare data, government data, industrial secrets, and high-risk personal data call for the highest level of sovereignty.
- Sector-specific constraints: some public tenders already require SecNumCloud qualification or a contractual sovereignty clause.
- Existing multi-cloud strategy: an architecture already spread across several providers makes it easier to introduce a sovereign cloud for a targeted scope, without a full migration.
- Dependence on advanced managed services: precisely assess which services (AI, data warehousing, observability) are truly needed and check their availability and maturity with the sovereign operator under consideration.
- Internal skills: DevOps teams need training on the operational specifics (APIs, IaC tooling, monitoring) of each chosen sovereign platform.
- Total cost of ownership: beyond resource pricing, factor in migration costs, potential dual-run periods, and team training.
Checklist for a Migration to a SecNumCloud-Qualified Cloud
- Map data and applications by sensitivity level and identify the scope actually subject to sovereignty requirements.
- Audit current providers' contracts and terms of use to assess real exposure to extraterritorial laws.
- Compare sovereign offerings' managed service catalogs against identified application needs.
- Design a reversible architecture (Terraform, Kubernetes, containerization) to limit lock-in and ease any future migration.
- Plan a phased migration by batches, starting with the most sensitive or easiest-to-isolate workloads.
- Set up dedicated FinOps and security governance for the new environment, with compliance indicators tracked over time.
Conclusion
Cloud sovereignty is no longer a theoretical topic — it now shapes concrete architecture decisions for French companies facing strong regulatory or sector-specific requirements. Between native sovereign offerings, joint ventures built on hyperscaler technology, and the upcoming requirements of the EUCS scheme, the landscape will keep evolving quickly. Move2Cloud helps its clients analyze their exposure, map their sensitive data, and design hybrid cloud architectures that reconcile compliance, performance, and cost control.
