Summary
- OVHcloud and Numspot both announced new SecNumCloud-qualified cloud services on 1 September.
- French rules increasingly make certified cloud infrastructure a procurement requirement for sensitive state data.
- OVHcloud plans to extend its qualified platform into Germany, Italy, and Poland under applicable national frameworks.
France’s market for highly assured cloud infrastructure has expanded after OVHcloud and Numspot secured SecNumCloud qualifications for new services, widening the pool of infrastructure available for sensitive public-sector and regulated workloads.
OVHcloud said on 1 September that its SNC Cloud Platform, a public cloud service designed for sensitive workloads, had qualified under the framework administered by France’s national cybersecurity agency, ANSSI. Numspot separately confirmed SecNumCloud qualification for its infrastructure-as-a-service platform on the same day.
The qualifications arrive as the distinction between a provider describing a service as sovereign or trusted and meeting a defined government security standard becomes increasingly consequential in French cloud procurement. Article 31 of French Law No. 2024-449, alongside an implementing decree adopted in April, requires certified cloud services for certain sensitive data belonging to the French state and its operators.
That requirement gives SecNumCloud a role extending beyond security assurance. For workloads within scope, qualification can determine which suppliers are eligible to compete, turning controls around data protection, operations, administration, and jurisdiction into procurement conditions rather than optional differentiators.
OVHcloud said SNC Cloud Platform is its third SecNumCloud-qualified service, following its Bare Metal Pod and VMware-based offering. The new platform uses open APIs and open-source standards and is billed on a consumption basis, bringing a more conventional public cloud operating model into an assurance regime historically associated with tightly controlled sensitive environments.
The company is also preparing deployments in Germany, Italy, and Poland. Those expansions will remain subject to applicable national frameworks rather than automatically transferring the French qualification across borders, but they demonstrate how domestic security requirements are influencing the architecture and geographic placement of European cloud services.
Numspot’s qualification adds another provider to the same market. The French company describes its platform around portability, reversibility, and the ability to operate workloads across public, private, and on-premises infrastructure. Its SecNumCloud qualification currently applies to its IaaS offering, while the company has indicated that work on higher-layer platform and AI services will continue.
The result is not an automatic displacement of the large US hyperscale platforms. European organisations continue to use those services extensively, and qualification requirements apply only to defined classes of workload. What is changing is the size and maturity of a separate market in which control of infrastructure, operational jurisdiction, and independently assessed security requirements carry greater weight.
That distinction has become sharper as public administrations and regulated sectors assess cloud dependency alongside resilience, supplier concentration, and legal control of data. Healthcare, finance, energy, industrial organisations, and software suppliers serving government can all encounter requirements that are more restrictive than those applying to ordinary commercial workloads.
SecNumCloud also makes security claims easier to compare. Terms such as sovereign cloud have been used across the market to describe markedly different ownership, hosting, support, and legal arrangements. A formal qualification does not eliminate operational risk, but it gives procurement teams an external benchmark against which technical and organisational controls have been assessed.
OVHcloud’s planned European expansion will test how far that model can scale while accommodating different national requirements. France has developed one of Europe’s clearest assurance regimes for sensitive cloud workloads, but the broader European market remains fragmented across national security requirements, sector rules, and EU-level regulation.
The two qualifications therefore increase immediate supplier choice in France while pointing to a wider shift in European cloud competition: sensitive workloads are increasingly being contested on demonstrable assurance, operational control, and regulatory eligibility rather than capacity and price alone.




