The sales slide shows four logos: ISO 27001, HDS, SOC 2, "GDPR compliant." The decision-maker exhales. Six months later, the auditor asks for the certificate: ISO only covers the Roubaix datacenter, HDS only Private Cloud, and your shared VPS appears nowhere. That is not fraud — it is misread scope.
Host certifications are dated snapshots of an audited system. Not a global promise on the whole brand.
Three certifications, three different questions
ISO 27001 — Is security management structured on defined scope? Useful for governance, not proof that your entry-level product is included.
HDS — Is hosting of personal health data audited under the French framework? Mandatory for patient records; irrelevant for a blog — but dangerous if sold as "health ready" without certificate number.
SecNumCloud — Does ANSSI qualification cover a cloud offer against extraterritorial access risks? Relevant for some public sector and critical operators; narrow, costly scope.
| Certification | Question it answers | Frequent out-of-scope |
|---|---|---|
| ISO 27001 | Security governance of certified scope | Other DCs, unlisted product lines |
| HDS | Regulated health hosting | Generic VPS, email, CDN |
| SecNumCloud | ANSSI qualified sovereign cloud | Standard non-qualified offers |
How to read a certificate without being misled
- Number and expiry — certification under renewal is not continuous validity.
- Scope annex — products, sites, managed services, backups.
- Declared subprocessors — who actually operates the underlying layer?
- Match with your architecture — production, backup, logs, admin support.
OVHcloud and 3DS Outscale illustrate partial HDS/SecNumCloud scopes on wide portfolios: work starts after the logo.
Many teams buy the badge. Few read the scope annex.
The summit: logo is on the brand, audit is on one brick
Decide and move forward without blind spots
List your regulatory obligations (GDPR, HDS, public sector) and, for each finalist, request current attestation, scope annex and DPA before any final shortlist. Map your stack — application, database, files, backups, logs — onto the certified scope line by line. Reject "health compatible" or "ISO ready" wording without certificate number. Cross-check with GDPR, HDS, SecNumCloud and filter providers via our directory by reading the annex, not the commercial slide.
Frequently asked questions
Does ISO 27001 cover a host's entire cloud offer?
No. Certification applies to a defined ISMS — often one datacenter, subsidiary, or product line. Budget shared hosting may be out of scope even if the logo is on the homepage.
HDS vs ISO 27001 for a health project?
HDS is mandatory for hosting personal health data in France. ISO 27001 is a generic security framework — useful but not a substitute for health HDS.
How do you verify a certification is currently valid?
Request certificate number, certification body, expiry date, and scope document — not a marketing screenshot. Cross-check public registries when available.
Does SecNumCloud guarantee data sovereignty?
It attests an ANSSI framework on a qualified scope — enhanced protection against extraterritorial access. It does not replace region choice, DPA, or analysis of your own app subprocessors.
Four logos on the slide? Ask for the scope annex — not the handshake.
