<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sovereignty on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/sovereignty/</link><description>Recent content in Sovereignty on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/sovereignty/index.xml" rel="self" type="application/rss+xml"/><item><title>ANSSI SecNumCloud</title><link>https://lesitedefrancois.be/en/compliance/secnumcloud/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/secnumcloud/</guid><description>&lt;p&gt;&lt;strong&gt;SecNumCloud&lt;/strong&gt; is a security qualification (&amp;ldquo;Visa de sécurité&amp;rdquo;) issued by &lt;strong&gt;ANSSI&lt;/strong&gt; (Agence Nationale de la Sécurité des Systèmes d&amp;rsquo;Information), France&amp;rsquo;s national cybersecurity agency. Created in 2016 and currently in version &lt;strong&gt;3.2&lt;/strong&gt; (published March 2022), it is the most demanding cloud security standard in France. SecNumCloud applies to cloud service providers offering &lt;strong&gt;IaaS, PaaS, SaaS, or CaaS&lt;/strong&gt; (Container as a Service) and evaluates them against &lt;strong&gt;354 requirements&lt;/strong&gt; organized across &lt;strong&gt;15 chapters&lt;/strong&gt; (chapters 5–19) structured on ISO/IEC 27002:2013 Annex A (chapters 5–18: security policies, organization, HR security, asset management, access control, cryptography, physical security, operational security, communications security, system acquisition/development/maintenance, supplier relationships, incident management, business continuity, conformity) plus an additional &lt;strong&gt;chapter 19&lt;/strong&gt; with sovereignty-specific requirements (data localization, reversibility, and protection from extraterritorial law). The qualification is &lt;strong&gt;voluntary&lt;/strong&gt; in principle — no law forces all cloud providers to obtain it — but it is &lt;strong&gt;effectively mandatory&lt;/strong&gt; for providers serving French public administration, Opérateurs d&amp;rsquo;Importance Vitale (OIV), and entities handling sensitive government data, as French procurement policy (the &amp;ldquo;doctrine cloud de confiance&amp;rdquo;) requires the use of SecNumCloud-qualified providers. Version 3.2&amp;rsquo;s most significant addition is &lt;strong&gt;chapter 19.6&lt;/strong&gt;, which mandates that qualified providers be headquartered in the EU, owned by European entities (individual non-EU shareholding ≤24 %, collective ≤39 %), and be immune from non-European extraterritorial legislation such as the US CLOUD Act or FISA. SecNumCloud is the model upon which France advocates for the &amp;ldquo;high+sovereignty&amp;rdquo; tier in the EU-wide EUCS scheme. Qualification is valid for 3 years with annual audits conducted by PASSI-accredited assessors.&lt;/p&gt;</description></item><item><title>EU Cloud Services Scheme (EUCS)</title><link>https://lesitedefrancois.be/en/compliance/eucs/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/eucs/</guid><description>&lt;p&gt;The &lt;strong&gt;European Cybersecurity Certification Scheme for Cloud Services (EUCS)&lt;/strong&gt; is a certification framework being developed under the 2019 EU Cybersecurity Act (CSA), led by ENISA. It is &lt;strong&gt;not yet adopted&lt;/strong&gt; — the scheme has been in drafting since 2020 and remains stalled as of mid-2026 due to unresolved political disagreements over digital sovereignty requirements. EUCS is designed as an EU-wide, &lt;strong&gt;voluntary&lt;/strong&gt; certification that would harmonize the fragmented national cloud certifications (such as France&amp;rsquo;s SecNumCloud or Germany&amp;rsquo;s C5) into three assurance levels: basic, substantial, and high. It applies to cloud service providers offering IaaS, PaaS, or SaaS on the European market. While EUCS is technically voluntary, its practical impact will be significant because the NIS2 Directive allows Member States to require entities in essential and important sectors to use only EUCS-certified cloud services. The core political controversy centers on whether the &amp;ldquo;high&amp;rdquo; assurance level should include sovereignty requirements — mandating EU headquarters, EU-only data processing, and immunity from non-EU extraterritorial laws (e.g. the US CLOUD Act). A March 2024 draft removed these requirements to achieve technical consensus, but the proposed recast of the Cybersecurity Act (CSA2), tabled in January 2026, would reinstate a formal sovereignty tier, with France leading advocacy for its inclusion.&lt;/p&gt;</description></item></channel></rss>