Under attack, France changes the rules of cybersecurity for public sector

The French government expands SecNumCloud 3.2 to widely cover central public services… without putting out all existing issues

An order issued by the Prime Minister on 12 August 2026 approves version 3.2 of the SecNumCloud framework. The text is technical, but its implications are not. It shifts the protection of sensitive public data from a matter of policy to a legal obligation, reshuffles the cards in a hitherto restricted market, and reveals a political mechanism: when Parliament comes to a standstill, the executive legislates through technical standards.

What the text does

The framework forms part of a three-tiered structure: Article 31 of the SREN Act (aimed at securing and regulating the digital space) establishes the principle; the Decree of 14 April 2026 sets out the conditions for its application; and the Order of 12 August 2026 approves the technical reference framework.

Immediate consequence: all central government departments, their operators and public interest groups must (most of all Central state administrations and direct subsidiaries, excluding local governments, hospitals and Fire Service) when entrusting ‘particularly sensitive’ data to a private cloud service provider, must use services certified to the SecNumCloud 3.2 standard. This applies to all data where a breach would undermine public order, public security, people’s health or lives, as well as the protection of intellectual property. The main question is where the obligations ends. PAC understands that local governments and their direct subsidiaries, such as fire, social, and health & hospital services, are excluded, even though they face daily attacks and struggle to meet their basic digital security needs. These « weak spots » are a key issue for citizens and local users, with a strong impact on their daily lives when disrupted. The French administrative organisation, with a central State and local governments, makes a clear segregation. For this situation, local governments (Conseils généraux, conseils municipaux) are responsible for securing their own digital systems. The central governmental staff (ANSSI, self-nicknamed « the Digital Fireman ») will come to the rescue in case of an attack and provide technical support, but will not force the adoption of any cybersecurity standard nor provide direct budgetary and financial support. 

The regulatory route bypasses the deadlocked parliamentary process

On the legislative front, progress has stalled. The ‘Resilience’ bill, which transposes the NIS2 directive into French law, remains bogged down, with a scheduled debate in Parliament in October 2026, years after the transposition deadline. The French NIS 2 Transposition law would have considered, beyond the pure NIS 2 text, local governments and their subsidiaries, embedding hospitals, direct services and social services, exclusion made off small cities and villages. Earlier this summer, the EU took France to court over this transposition delay. Had NIS2 been applied to the public sector, it would have significantly strengthened the security of state information systems and, above all, mandated the adoption of MFA (multi-factor authentication) where needed, which was so sorely lacking during the France Titres and DFIP crises. SecNumCloud will enforce the use of MFA. And stopped the fire on local digital services.

On the regulatory front , the machinery is running of its own accord against a backdrop of a general cyber storm affecting the entire French public online service. French cyber policy is currently being driven forward by instruments that require neither a majority vote nor debate. This is effective in the short term. It is also fragile in three respects.

  • What is enacted by order can be repealed by order. A requirement laid down by a technical order lacks the stability of a requirement laid down by law. With less than a year to go before the French presidential election and a likely change of government, it is reasonable to assume that the measure is temporary, at least pending confirmation in the summer of 2027.
  • There is no public debate on the issue. But internal debate already killed NIS2 in France. Behind closed doors, the debate appears already to be very heated within French government circles, leading to an initial deadlock over the Resilience Bill due to the security and counter-terrorism services’ reluctance to adopt controversial technological options that may have limited their action. Germany, which is meticulous on this point and facing new forms of terrorism on its territory, has adopted NIS2 without compromising its response to state security issues. The German transposition law, (NIS2UmsuCG), based on exceptions already present in NIS2, has exempted national-security, defence, public-security, and law-enforcement functions, including judicial and security services, from the obligations of NIS2.
  • This creates an asymmetry: the public sector is subject to a demanding regime, whilst the transposition of NIS2 (which affects thousands of private entities) is still pending. The central State is applying to itself what it has not yet managed to impose on the rest of the economy. This is certainly to its credit, but it creates a three-tier framework (central state, local state, private). And the objective of comprehensively addressing the need to raise the overall level of security now applies only to the central public sector. Admittedly, the digital landscape of the French public service is proving to be severely behind in terms of cybersecurity. The urgency of the state’s cybersecurity situation since mid-August 2026 (attacks on France-Titres, DGFIP, National Education, SDIS, etc.) seems to be dictating this response from a state grappling with profound structural and organisational difficulties regarding its IT strategies and choices. But from a political perspective, a more comprehensive approach would have better aligned with the political objective of NIS2, championed by the French Presidency of the European Union in 2022.

The SecNumCloud market is (smoothly) expanding beyond its traditional sphere

Until now, SecNumCloud operated within a limited sphere: government departments, operators of critical importance, and a few major strategic clients. It was a niche market (high-value but low-volume) where qualification served as much as a sales pitch as an operational requirement.

The expansion of the scope is smoothly changing the nature of the market. Demand is becoming captive and predictable across smaller market segments, for what central state services are concerned. Meeting this demand, which comes with more limited budgets and expertise, will be a challenge.

Three effects follow from this, though they are not unfolding at the same pace.

  1. In terms of cyber security, the effect is immediate and has long been anticipated. A legally enforceable requirement is driving behaviour that ten years of recommendations had failed to bring about. Unfortunately, only the central government digital system will be covered by this new obligation. It is expected that additional regulations will be introduced to enhance ad support by means of law or order the situation of local public services. In some situations, hospitals and local governments have modified their procurement rules to require vendors and partners to adhere to minimum cyber hygiene standards. But the financial capacity to invest massively in the cybersecurity backlog is still not solved
  2. On the supply side, the effect is delayed. Obtaining qualification and certification takes time and ties up capital. Some SecNumCloud qualifications have taken over three years to complete, which is quite a long time. The 26 SecNumCloud-qualified services (not all IaaS+Paas+CaaS+Saas fully certified) providers will be able to spread themselves across a wider market than just the sovereign sector and large-account OIVs. The question of cross-border qualification that would expand the addressable market for those who invest in a long and expensive qualification process is still pending.
  3. As for certification bodies: the effect is inevitable. The volume of audits is now on a extended  scale to what we have seen before. But this is also where the real bottleneck in the system lies. Currently, 17 services are under assessment for qualification. On this specific point, a decision by ANSSI deserves attention: the introduction of a fast-track qualification process for SaaS (Software as a Service) providers that rely on an IaaS (Infrastructure as a Service) infrastructure or a PaaS (Platform as a Service) platform that has already been qualified. This is precisely the measure that was missing. It recognises that a SaaS service hosted on an already audited platform does not need to go through the entire process again, and it transforms certification from an individual hurdle into a chain reaction. This is the lever most likely to deliver on the promise of expansion.

A European approach to cybersecurity will be built through bilateral agreements and in the traditional way… or later with CADA

The real glass ceiling is not French; it is European.

A SecNumCloud-certified provider is certified for the French market and that market alone. It is not possible to scale up to the European level because the certification stops at the border. Yet the standard that was supposed to resolve this problem has stalled: the European EUCS High+ scheme (European Cybersecurity Certification Scheme for Cloud Services), in its high-level version accompanied by sovereignty requirements, is in a deep, self-imposed coma. Due to a lack of agreement among Member States on the criteria for immunity from non-European legal claims, the matter has stalled.

Hence the realistic course of action: a manual, bilateral alignment along the Paris–Berlin and Paris–London axes (the British have implemented NIS1 and are in the process of updating their regulatory and legislative framework on cybersecurity). In other words, old-fashioned bilateral negotiations.

This is where the BSI’s C5 (and, to a lesser extent, C3A, as it is more recent) come into play. C5 is the catalogue of cloud security requirements published by ANSSI’s German counterpart. It is the de facto standard for the German public sector, and the only heavyweight comparable to SecNumCloud in Europe. Hardly Comparable an dont equivalent – and that is precisely the problem. (See infographic here)

SecNumCloud, C5 and C3A do not have the same status or follow the same process for obtaining them.

  • SecNumCloud is a qualification: A government agency requires a thorough assessment by a qualified and controlled private « assessment house » and issues a qualification after reviewing the assessment and any necessary corrections. Currently, 17 qualification requests are under evaluation.
  • C5 is an attestation (not a certification), without any decision or registration by the BSI; C3A is currently a voluntary framework for assessing cloud autonomy, built upon C5 and without a finalised standardised BSI certification scheme.

On the subject of sovereignty controls (also named « escape to US Kill Switch » or « Waterproofing against extraterritorial laws »), the approaches taken by SecNumCloud 3.2 (normative and prescriptive) and the C5 (declarative) are at odds, but the two certifications can overlap, and the ANSSI and BSI agencies are very active in this regard.

Until recently, the German government and its cybersecurity agency had been very cautious on the subject of controlling technology expenditure and had kept their distance from the ‘French-style’ sovereignty trends; however, they have recently shifted their political stance to align with France on the need for non-technological controls capable of ensuring a form of technological independence.

What to watch out for: SecNumCloud 3.3 & CADA

Substantial work is currently underway in France to update to SecNumCloud 3.3. This natural evolution of the certification scheme, which dates back to 2022, is anticipated both in terms of sovereignty and its ability to build bridges with the German and British sectors. Cloud service providers of all sizes (supported in this regard by ANSSI) are complaining about the high cost of certification and are hoping to be able to replicate their commercial offerings outside France in order to offset these high certification costs.

Within the broader field considered by the EU, the CADA Cloud and AI Development Act is a proposed EU regulation aimed at strengthening Europe’s cloud and AI infrastructure. It plans to triple EU data-centre capacity in five to seven years and streamline access to energy, permits, and funding. The act introduces a tiered sovereignty framework to assess factors such as location, control, ownership, supply chains, and the risk of third-country interference. Member States will identify public-sector and critical-use cases that require specific sovereignty levels, thereby guiding public procurement decisions. CADA works alongside NIS2, the AI Act, and the Data Act, focusing mainly on expanding industrial capacity, ensuring technological independence, and reducing reliance on external cloud and AI sources. CADA is not yet at the legislative stage but was adopted by Member States in June 2026.

Several French cloud providers have taken a first step for their geographical expansion: S3NS, the joint venture between Google and Thales, which holds SecNumCloud 3.2 qualification; Thales has launched a SecNumCloud-certified cloud service in Germany, with ANSSI’s tacit approval. Local compliance/alignement with the BSI C3A framework is expected.  For its part, the cloud service provider (CSP) Cloud Temple has obtained dual compliance/alignement (SecNumCloud in France and C5 in Germany) enabling it to operate in both markets. OVH, Outscale and Scaleway have followed the same path towards dual certification.

The European cybersecurity framework, which could have been built between member states, the Commission and the dedicated agency ENISA, is instead being constructed on the basis of old-fashioned bilateral arrangements. The policy objective of NIS2, designed and adopted during the French EU Presidency in 2022, was to collectively raise the overall level of security in order to boost European citizens’ confidence in their institutions and information systems.

The current situation creates asymmetry and frustration in the overall capacity of citizens to build trust and confidence in the public digital ecosystem. The challenge is far beyond technical considerations and should be addressed at the political level. The current campaign for the French presidential election (May 2017) is an opportunity to address deep political posture.

Share via ...