Cloud Sovereignty in Europe: SecNumCloud, AWS European Sovereign Cloud, and Choosing the Right Fit
Cloud

Cloud Sovereignty in Europe: SecNumCloud, AWS European Sovereign Cloud, and Choosing the Right Fit

June 19, 20269 min readSouverainetéSecNumCloudCloud

Between the arrival of AWS European Sovereign Cloud, the rise of Bleu and S3ns, and the upcoming European EUCS certification scheme, cloud sovereignty has become a central decision criterion for French CIOs. An overview of the offerings and a decision framework.

Why Cloud Sovereignty Is Back at the Center of the Conversation

Over the past two years, digital sovereignty has moved from regulatory circles straight into boardroom discussions. Three factors converge: regulatory pressure (GDPR, NIS2, the upcoming EUCS scheme), tighter sector-specific requirements (healthcare, finance, government), and a broader awareness of extraterritorial risk tied to the US Cloud Act. For French companies handling sensitive or regulated data, choosing a cloud provider is no longer just about performance or cost — it has become a compliance and risk-management decision in its own right.

The Regulatory Framework: SecNumCloud and the Upcoming EUCS Scheme

The SecNumCloud qualification, issued by ANSSI (the French cybersecurity agency), remains the French reference standard. It imposes strict technical security requirements, but more importantly demands immunity from non-European extraterritorial laws: a SecNumCloud-qualified operator must be owned and operated in a way that shields it from the Cloud Act or extra-European administrative orders.

At the European level, the EUCS (European Cybersecurity Certification Scheme for Cloud Services), driven by ENISA, is moving toward harmonizing sovereignty requirements across the EU. Debate over the "High+" level (full immunity from third-country laws) remains the main friction point between member states, but the underlying trend is clear: public administrations and critical sectors will increasingly need to demonstrate a high level of sovereignty for their most sensitive data.

Overview of Offerings on the French Market

The landscape has structured itself around several models:

OfferingPlayersModelPositioning
AWS European Sovereign CloudAWS (dedicated European legal and operational structure)EU-localized infrastructure and governance, European staff and operatorsNative AWS services with enhanced data residency and operational autonomy guarantees
BleuCapgemini & Orange, licensed Microsoft Azure technologyFrench joint ventureTargets public administrations and OIVs needing SecNumCloud-qualified Microsoft 365 / Azure
S3nsThales & Docaposte, licensed Google Cloud technologyFrench joint venturePursuing SecNumCloud qualification for Google Cloud services (data, AI, productivity)
OVHcloudFrench, 100% EU capital and operationsNative sovereign cloudSecNumCloud-qualified IaaS/PaaS, strong presence in the public sector
OutscaleDassault SystèmesNative sovereign cloudSecNumCloud, focused on regulated sectors and industry
ScalewayIliad GroupNative sovereign cloudManaged IaaS/Kubernetes, strong adoption among French scale-ups

An essential point of caution: "hosted in Europe" offerings are not all equivalent to true legal sovereignty. Storing data within the EU protects you under GDPR from a geographic standpoint, but only genuinely European legal and operational governance protects against extraterritorial requisition.

Sovereign Cloud Doesn't Mean Isolated Cloud

A persistent misconception pits sovereignty against innovation, as if choosing a sovereign cloud meant giving up advanced managed services, generative AI, or the pace of innovation of hyperscalers. The reality is more nuanced: joint ventures like Bleu and S3ns exist precisely to reconcile both, providing access to the Azure and Google Cloud software stacks under French legal governance. Meanwhile, native sovereign offerings (OVHcloud, Outscale, Scaleway) have considerably expanded their managed catalogs (Kubernetes, databases, AI) in recent years.

The right approach is therefore rarely a binary choice, but rather a tiered architecture by data sensitivity: the most critical data and workloads (healthcare, defense, high-risk personal data) on SecNumCloud-qualified infrastructure, with the rest of the information system on whichever platform best fits business and technical needs.

Decision Framework for CIOs

  • Nature and sensitivity of data: healthcare data, government data, industrial secrets, and high-risk personal data call for the highest level of sovereignty.
  • Sector-specific constraints: some public tenders already require SecNumCloud qualification or a contractual sovereignty clause.
  • Existing multi-cloud strategy: an architecture already spread across several providers makes it easier to introduce a sovereign cloud for a targeted scope, without a full migration.
  • Dependence on advanced managed services: precisely assess which services (AI, data warehousing, observability) are truly needed and check their availability and maturity with the sovereign operator under consideration.
  • Internal skills: DevOps teams need training on the operational specifics (APIs, IaC tooling, monitoring) of each chosen sovereign platform.
  • Total cost of ownership: beyond resource pricing, factor in migration costs, potential dual-run periods, and team training.

Checklist for a Migration to a SecNumCloud-Qualified Cloud

  1. Map data and applications by sensitivity level and identify the scope actually subject to sovereignty requirements.
  2. Audit current providers' contracts and terms of use to assess real exposure to extraterritorial laws.
  3. Compare sovereign offerings' managed service catalogs against identified application needs.
  4. Design a reversible architecture (Terraform, Kubernetes, containerization) to limit lock-in and ease any future migration.
  5. Plan a phased migration by batches, starting with the most sensitive or easiest-to-isolate workloads.
  6. Set up dedicated FinOps and security governance for the new environment, with compliance indicators tracked over time.

Conclusion

Cloud sovereignty is no longer a theoretical topic — it now shapes concrete architecture decisions for French companies facing strong regulatory or sector-specific requirements. Between native sovereign offerings, joint ventures built on hyperscaler technology, and the upcoming requirements of the EUCS scheme, the landscape will keep evolving quickly. Move2Cloud helps its clients analyze their exposure, map their sensitive data, and design hybrid cloud architectures that reconcile compliance, performance, and cost control.

← Back to blog