SecNumCloud is a security qualification (“Visa de sécurité”) issued by ANSSI (Agence Nationale de la Sécurité des Systèmes d’Information), France’s national cybersecurity agency. Created in 2016 and currently in version 3.2 (published March 2022), it is the most demanding cloud security standard in France. SecNumCloud applies to cloud service providers offering IaaS, PaaS, SaaS, or CaaS (Container as a Service) and evaluates them against 354 requirements organized across 15 chapters (chapters 5–19) structured on ISO/IEC 27002:2013 Annex A (chapters 5–18: security policies, organization, HR security, asset management, access control, cryptography, physical security, operational security, communications security, system acquisition/development/maintenance, supplier relationships, incident management, business continuity, conformity) plus an additional chapter 19 with sovereignty-specific requirements (data localization, reversibility, and protection from extraterritorial law). The qualification is voluntary in principle — no law forces all cloud providers to obtain it — but it is effectively mandatory for providers serving French public administration, Opérateurs d’Importance Vitale (OIV), and entities handling sensitive government data, as French procurement policy (the “doctrine cloud de confiance”) requires the use of SecNumCloud-qualified providers. Version 3.2’s most significant addition is chapter 19.6, which mandates that qualified providers be headquartered in the EU, owned by European entities (individual non-EU shareholding ≤24 %, collective ≤39 %), and be immune from non-European extraterritorial legislation such as the US CLOUD Act or FISA. SecNumCloud is the model upon which France advocates for the “high+sovereignty” tier in the EU-wide EUCS scheme. Qualification is valid for 3 years with annual audits conducted by PASSI-accredited assessors.
Red Hat is not itself a cloud service provider seeking SecNumCloud qualification, but it is a technology enabler for providers who are. The most notable Red Hat integration in the SecNumCloud ecosystem is Cloud Temple, which in 2024 became the first French provider to achieve SecNumCloud 3.2 qualification for a PaaS offering based on Red Hat OpenShift — enabling clients to run sensitive containerized workloads on a qualified platform. Cloud Temple (part of Neurones group, winner of the Red Hat Innovation Award France 2024) leverages OpenShift as its strategic platform for accelerating digital transformation through CI/CD pipelines, integrated operators, and container orchestration. Other qualified providers (OVHcloud, 3DS Outscale, S3NS) use different technology stacks — OVHcloud builds on OpenStack with its own integrated software layer, for instance — so Red Hat is not universal across all SecNumCloud providers. Red Hat’s technical capabilities map directly to SecNumCloud chapter requirements: for chapter 10 (Cryptologie), RHEL provides system-wide crypto policies and FIPS-capable modules; for chapter 9 (Contrôle d’accès), SELinux provides mandatory access control and environment isolation; for chapter 12 (Sécurité liée à l’exploitation), the Compliance Operator and OpenSCAP enable automated conformity checks against ANSSI’s hardening guides; and for chapter 19.6 (Protection vis-à-vis du droit extra-européen), Red Hat’s open-source model means providers can inspect and verify the entire software stack without dependency on opaque proprietary components. For organizations building SecNumCloud-qualified offerings on Red Hat, the “composability” principle in version 3.2 is key — a SaaS provider deploying on a SecNumCloud-qualified OpenShift platform (such as Cloud Temple’s) can focus its qualification efforts on its application layer rather than re-certifying the entire infrastructure.
