Skip to main content
Sovereign Cloud

SecNumCloud: What does the certification require, and who actually has it?

Who issues the SecNumCloud certification, what requirements it entails, how it differs from ISO 27001 and HDS, and since when it has been mandatory for the government.

October 9, 2026 5-minute read The Ohmycad Team
SecNumCloud: What does the certification require, and who actually has it?

Key Points
  • SecNumCloud is a security certification issued by ANSSI, with audits conducted by AFNOR Certification. It is neither an international standard like ISO 27001 nor a sector-specific requirement like HDS.
  • Effective August 15, 2026 (decree of August 12, 2026, published in the Official Journal on August 14), it has been a legal requirement, and no longer merely a recommendation, to host the most sensitive data of the government, its operators, and public interest groups.
  • ISO 27001, HDS, and SecNumCloud address three different issues: general security, the hosting of health data, and immunity from foreign laws.
  • The Outscale Dassault Systèmes cloud meets all three requirements, plus SOC 2 Type II, CISPE, and TISAX, within specific scopes, while SecNumCloud remains an option that can be enabled on a regional basis.

What exactly is SecNumCloud?

SecNumCloud is a security certification for cloud services (IaaS, PaaS, SaaS) issued by ANSSI, the French cybersecurity agency. It is based on a set of technical, operational, and legal security rules, and its distinctive feature is that it requires protection against extraterritorial laws, notably the U.S. Cloud Act. ANSSI is clear about one important limitation: the certification applies to the cloud service itself; it does not guarantee the security level of what the customer builds on top of it.

Who issues the certification, and how do you obtain it?

ANSSI develops the standards and grants certification, but it is the auditors from AFNOR Certification who conduct the assessment on its behalf. The process involves several steps: submission of the application and verification of eligibility, development of an audit strategy tailored to the applicant’s scope, an initial on-site audit, approval of the report by ANSSI, and finally, granting of the certification and the corresponding security badge. The qualification is not permanent: it is subject to annual maintenance audits, with a full renewal every three years.

ISO 27001, HDS, SecNumCloud: What is the purpose of each certification?

These three references complement each other; they are not interchangeable.

ISO 27001 HDS SecNumCloud 3.2
Framework sponsored by International standard (ISO), audited by accredited certification bodies Ministry of Health (Delegation for Digital Health / Digital Health Agency) ANSSI, audits conducted by AFNOR Certification
Covers An information security management system for any industry Hosting of Personal Health Data Cloud services that handle sensitive data
Required for Not legally required, but expected of any reputable professional web hosting provider Any person who stores health data on behalf of third parties (Public Health Code) Effective August 15, 2026, the government, its operators, and public interest groups must comply with these requirements for their most sensitive data (decree of August 12, 2026); recommended for OIVs
Addresses the issue of the Cloud Act No No, even though its Version 2 (2024) already requires data to be stored within the European Economic Area Yes, that's its purpose
The Outscale Cloud by Dassault Systèmes Qualified across the entire infrastructure Qualified Qualified for the cloudgouv-eu-west-1 region (optional)

Since when has SecNumCloud been mandatory, and for whom?

Until August 2026, SecNumCloud remained a strong recommendation from ANSSI, not a legal requirement. The decree of August 12, 2026, «approving the requirements framework for cloud computing service providers,» published in the Official Journal on August 14 and effective the following day, changes this situation: it approves version 3.2 of the SecNumCloud requirements framework and makes it enforceable, pursuant to Article 31 of the SREN Act of May 21, 2024, and its accompanying decree of April 14, 2026, for hosting particularly sensitive data belonging to the State, its operators, and public interest groups, whenever a breach would threaten public order, public safety, health, human life, or the protection of intellectual property. Compliance is demonstrated by an ANSSI qualification or by a European certification recognized as equivalent by the agency.

Does the Outscale Dassault Systèmes cloud really have this certification?

Yes, in its cloudgouv-eu-west-1 region, which is SecNumCloud 3.2-certified. The standard France region (eu-west-2) remains certified to ISO 27001, ISO 27017, ISO 27018, and HDS, but does not have SecNumCloud certification; the two environments are distinct, and switching from one to the other requires redeployment. In addition to these certifications, Outscale is also SOC 2 Type II audited, compliant with the CISPE code of conduct (for data processed and stored in the European Economic Area), and TISAX certified for hosting sensitive data in the automotive sector. Few cloud infrastructures boast such a broad range of certifications, spanning both general-purpose and industry-specific requirements. At Ohmycad, the SecNumCloud region remains an option: it is activated when your regulations or your end customer require it, and is never included by default.

Conclusion

SecNumCloud’s status changed in 2026: it evolved from a best-practice recommendation to a legally enforceable requirement for part of the public sector. This trend is not going to stop there, and organizations that process sensitive data would be wise to prepare for it before regulations require them to do so.

The Outscale Dassault Systèmes cloud maintains this level of compliance in its cloudgouv-eu-west-1 region, in addition to meeting ISO 27001, ISO 27017, ISO 27018, and HDS standards across its entire infrastructure. The Ohmycad sovereign cloud offering builds on this foundation to provide optional certification, without imposing it on those who do not need it.

The right approach: Check which certification actually meets your legal requirement before paying for a level that the law does not require.

Learn more about Ohmycad's sovereign cloud offering →

For more information: The Trusted Cloud Label · the Cloud Act

Sources

FAQ

Frequently asked Questions

Where can I find the list of SecNumCloud-certified service providers?

ANSSI publishes and maintains the official catalog of qualified offerings on its own website. This is the only reliable source; a third-party page that claims to list «the best» SecNumCloud service providers has no official standing.

Is SecNumCloud mandatory for all companies?

No. As of August 15, 2026, the legal requirement applies only to the government, its operators, and public interest groups, with respect to their particularly sensitive data. For other organizations, SecNumCloud remains a recommended option when the data being processed is sensitive or regulated, but it is not a general requirement.

What is the difference between SecNumCloud and the "Trusted Cloud" label?

SecNumCloud is the ANSSI certification. «Trusted Cloud» is the label used in the 2021 government policy, which referred to the combination of SecNumCloud and immunity from extraterritorial laws such as the Cloud Act. Since version 3.2 of the standard, this immunity has been included as a requirement of SecNumCloud itself. Details can be found in our article on the trusted cloud.

Is Ohmycad's sovereign cloud offering certified as SecNumCloud by default?

No. The certification applies to the cloudgouv-eu-west-1 region of the Outscale Dassault Systèmes cloud, which is enabled as an option when required by your regulations or your end customer.

Is ISO 27001 sufficient if my data isn't sensitive?

In most cases, yes, this is a standard feature expected from any reputable professional hosting provider. The key question isn’t the volume of data but its sensitivity: as soon as particularly sensitive health or government data comes into play, HDS or SecNumCloud becomes mandatory or strongly recommended, respectively.

Need sovereign, managed, and encrypted hosting within your organization? An Ohmycad engineer will get back to you with a customized quote, not a generic price list: to be called back. The full list of offerings is on the page sovereign cloud.

Take Action
Get an estimate for your SOLIDWORKS or CATIA license in 2 minutes
An immediate estimate, followed by Ohmycare support from a dedicated engineer.
Estimate my license
Sovereign Cloud
Share
Written by the Ohmycad team
The Leading 3DEXPERIENCE Expert Network — SOLIDWORKS, CATIA, 3DEXPERIENCE. Updated on October 9, 2026.