Regulations
Published on
19.06.2026

SecNumCloud: who is really concerned in 2026?

Caroline Boisramé Moreau

Quick reply

The decree of 14 April 2026 makes SecNumCloud mandatory for the French state and its operators. Who it covers, at what level, and how to obtain a waiver.

In this article

Digital solution on a computer screen

SecNumCloud is not a blanket legal obligation. Since decree no. 2026-272 of 14 April 2026 (the SREN law), it is mandatory for central government administrations, their operators and 6 public interest groupings handling sensitive data. It is strongly recommended, and indirectly imposed, for operators of vital importance, operators of essential services, healthcare facilities, financial institutions (under DORA) and entities covered by NIS2. For every other company it remains a strategic choice, but an increasingly decisive one when it comes to winning public contracts and sensitive clients.

What changed in 2026: from principle to obligation

Until recently, using SecNumCloud was a matter of the "cloud at the centre" doctrine (the Prime Minister's circular of 5 July 2021): a strong recommendation for government administrations, with no general binding force and no penalty attached.

The implementing decree for article 31 of the SREN law, published in the Official Journal on 16 April 2026 (decree no. 2026-272 of 14 April 2026), changes that. It now makes it enforceable for central government administrations, their operators and six named public interest groupings to use a cloud provider compliant with the ANSSI framework when they handle data of a particularly sensitive nature.

The two cumulative conditions that trigger the obligation

  • The data is particularly sensitive — it has to fall under secrets protected by law or be necessary to an essential function of the state.
  • There is a characterised risk in the event of a breach — harm to public order, public safety, people's health or lives, or the protection of intellectual property, and that risk has to be real rather than merely hypothetical.

A practical point worth knowing: as soon as one piece of data in your system triggers both conditions, everything hosted on the same infrastructure has to be protected to the same level, unless effective technical partitioning can be demonstrated.

The decree provides for a waiver mechanism: if a compliant offer already exists on the market, the organisation has 18 months to comply; where no suitable offer exists, a waiver is granted for up to a year, renewable, by a reasoned decision that is made public.

Discover our SecNumCloud-compatible solutions

Overview

Category Who is concerned? Level of requirement Reference text Strict obligation Central administrations, state operators, 6 named public interest groupings SecNumCloud mandatory for sensitive data Decree no. 2026-272 of 14/04/2026 (art. 31, SREN law) Strong obligation (sector-specific) Operators of vital importance, operators of essential services, healthcare (HDS), finance (DORA), NIS2 entities SecNumCloud required or closely aligned by sector regulation Sector regulations in their own right (SecNumCloud not named) De facto standard Mid-sized companies and SMEs bidding for public contracts, suppliers to operators of vital importance, vendors of sensitive SaaS Recommended "Cloud at the centre" doctrine, contractual client requirements

Since the decree of 14 April 2026, the following have to use a provider compliant with the SecNumCloud framework (or a European certification of at least equivalent level) for their sensitive data:

  • Central administrations: ministries and decentralised national services
  • State operators
  • Six public interest groupings named in the decree, when they handle sensitive data as defined above

Organisations under a strict obligation

Since the decree of 14 April 2026, the following have to use a provider compliant with the SecNumCloud framework (or a European certification of at least equivalent level) for their sensitive data:

  • Central administrations: ministries and decentralised national services
  • State operators
  • Six public interest groupings named in the decree, when they handle sensitive data as defined above

Organisations under a strong obligation

These organisations are not named directly in the SREN decree, but their own sector regulation creates equivalent pressure towards the security and sovereignty standards SecNumCloud embodies:

  • Operators of vital importance: energy, water, transport, health, telecommunications, finance, strategic industry
  • Operators of essential services: health, transport, energy, digital infrastructure, providers of critical services
  • Healthcare facilities, through HDS certification
  • Financial institutions covered by DORA
  • Essential and important entities covered by NIS2

Recommendations that are becoming a de facto standard

  • Mid-sized companies and SMEs bidding for public contracts or working with operators of vital importance
  • Any organisation wanting to demonstrate a higher level of security to its clients
  • SaaS vendors targeting sensitive markets

Frequently asked questions

Is SecNumCloud mandatory for every company? No. The legal obligation created by the SREN decree covers only central government administrations, their operators and certain public interest groupings handling sensitive data. For private companies, SecNumCloud remains voluntary, though it is becoming a de facto standard in regulated sectors and for suppliers to the state.

What happens if my organisation does not meet the obligation? The decree provides for no direct criminal penalty, but it conditions compliance for the public contracts concerned. A reasoned waiver, made public, can be granted if no compliant offer is available on the market.

Are ISO 27001 or HDS enough in place of SecNumCloud? No, not within the scope of the SREN decree. These certifications cover information security or health data hosting, but they do not guarantee protection against unauthorised access by the public authorities of third countries, which is specific to SecNumCloud.

The takeaway

SecNumCloud remains, to this day, a voluntary qualification for the vast majority of private companies. But the SREN decree of 2026 marks a turning point: it turns part of the public sector scope into an enforceable legal obligation, and in doing so increases the pressure on the whole ecosystem working with that sector, including the mid-sized companies and SaaS vendors not directly covered by it.

Discover our SecNumCloud-compatible solutions

No items found.
No items found.

Definition

No items found.

FAQ

No questions found.

Best practices / Common pitfalls

No items found.

Key figures

No items found.

Key takeaways

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

You could keep all your documents on a floppy disk.
Vintage office chair with a pile of folders and a beige corded telephone, handset off the hook on red carpet.

But let's be honest, our cloud-based file storage and sharing solution is much easier.