Your public-sector client asks for "sovereign cloud". Do you need SecNumCloud (OVHcloud, Scaleway, Clever Cloud) or does standard European cloud suffice?
The answer is not in a LinkedIn thread about the Cloud Act and your contract. It is in the tender document — word for word — and the exact scope qualification covers.
Many teams confuse marketing sovereignty with contractual obligation. A datacenter in France or Germany often satisfies GDPR; SecNumCloud adds an ANSSI framework when a public buyer or vital operator mandates it. Starting with qualification without a written requirement buys complexity; ignoring it when required buys exclusion from the tender.
Standard European cloud: GDPR baseline
A well-chosen EU cloud offers European datacenters, a signed DPA, documented subcontractor choices and a readable government-request policy. That is sufficient for an SMB, e-commerce or standard B2B SaaS — if the full chain is mapped without uncontrolled extraterritorial access.
OVHcloud, Scaleway, Hetzner, Infomaniak and other European vendors serve millions of projects without SecNumCloud. GDPR does not require ANSSI qualification for an online shop or B2B API. What matters is the real location of data, backups and admin access — not the badge on the sales slide.
To frame this baseline, cross-check European hosting and real location investigation before adding a SecNumCloud layer.
SecNumCloud: when ANSSI formalises the requirement
SecNumCloud is an ANSSI qualification: reinforced requirements against extraterritorial access (Cloud Act, UK CLOUD Act, etc.). It becomes required when a sensitive public contract or vital operator explicitly mandates it in the contract or procurement framework.
Cost and scope stay more restricted than a general cloud offer. It is not a default marketing option: qualified offers cover specific services (compute, storage, backup depending on vendor), not necessarily the vendor's full catalogue.
| Situation | Standard EU cloud | SecNumCloud |
|---|---|---|
| B2B SMB | Often yes | Oversized |
| Sensitive public tender | Insufficient if required | Required |
| HDS health | Complementary | Complementary |
| Startups | Rarely day 1 | If contract mandates |
Read the contract before the logo
Request valid attestation, not a homepage screenshot. Verify technical scope: shared hosting, VPS, Kubernetes, object storage, backups, admin support? One vendor may offer qualified and non-qualified offers on separate billing lines.
Cross-check SecNumCloud reversibility and Scaleway sovereignty to compare contractual guarantees, exit timelines and backup copy location. Qualification covers what is in the attestation — not what your team later deploys on a non-qualified offer by mistake.
Cost, timeline and reversibility
SecNumCloud often adds cost and architectural constraints: narrower scope, longer procurement, documentation for audit. Over thirty-six months, compare total cost (compute, storage, egress, support) between a qualified offer and standard EU cloud — not just the first promotional month.
Also anticipate exit: vendor change, migration to a non-qualified offer if requirements evolve, key and log export. Qualification useful today can become a bottleneck tomorrow if reversibility was not negotiated in the initial contract.
The peak: qualification decides at contract, not fear
Decide and move forward without blind spots
Read the tender line by line and spot explicit mentions of SecNumCloud, operational sovereignty or ANSSI frameworks. Require valid attestation and covered technical scope (compute, storage, backups, support). Map subcontractors, backup copy location and admin access outside the European Union.
Compare total cost over thirty-six months, not the first promotional month. See SecNumCloud reversibility, Scaleway sovereignty and the directory to shortlist vendors matching your real constraint.
Frequently asked questions
Is SecNumCloud mandatory for every SMB?
No. Qualification becomes mandatory mainly for certain sensitive public contracts and vital operators, depending on what the tender requires. For most SMBs handling standard personal data, GDPR and a well-documented European cloud suffice — as long as the subcontractor and backup chain is mapped.
Are OVHcloud and Scaleway SecNumCloud?
Both offer qualified services on certain scopes, but not their full catalogue. Request official attestation and verify which service line is covered: a general VPS and a qualified service can coexist at the same vendor. A homepage screenshot does not replace the contractual document.
Does SecNumCloud replace HDS?
No. HDS addresses French health data hosting; SecNumCloud formalises operational sovereignty against extraterritorial access. A health project may require both on different scopes — for example HDS for patient data and SecNumCloud for an admin platform under a public contract.
Is EU cloud without SecNumCloud "non-sovereign"?
Sovereignty is a spectrum: contract jurisdiction, US subcontractors, key management, support location. SecNumCloud formalises an ANSSI-required level in certain contexts — not the only definition of the word, nor a universal prerequisite for GDPR compliance.
SecNumCloud is decided at the contract line — not by generic Cloud Act fear.