Publicité
ERP IMPLEMENTATION
🇫🇷 Lire en français

France's SecNumCloud and SREN: What European CIOs Need to Know About Trusted Cloud for ERP

France's SREN decree makes SecNumCloud mandatory for some public organisations. A practical guide for European CIOs evaluating sovereign cloud options for their ERP.

France's SecNumCloud and SREN: What European CIOs Need to Know About Trusted Cloud for ERP

On 14 April 2026, France’s decree n° 2026-272 came into force, giving legal teeth to what the SREN Act had signalled since May 2024: for certain public organisations, hosting sensitive data on commercial cloud infrastructure not qualified under SecNumCloud by ANSSI (France’s national cybersecurity agency) is no longer permitted (source: economie.gouv.fr). An ERP managing finance, HR, or logistics that processes this data falls squarely within scope.

France is not the only European country grappling with these questions — Germany’s C5 framework, the EU’s EUCS certification scheme, and NIS2 all point in the same direction — but France has moved furthest in translating data sovereignty principles into binding ERP procurement constraints. For European CIOs evaluating cloud strategy or advising French subsidiaries and public-sector clients, understanding SecNumCloud is no longer optional context. It is a live procurement reality.

What “Trusted Cloud” Means — and What It Doesn’t

The French “cloud de confiance” (trusted cloud) designation refers to cloud hosting provided by an ANSSI-qualified SecNumCloud operator whose operations are shielded from extraterritorial legislation: the US CLOUD Act, China’s Cybersecurity Law, and similar foreign jurisdiction reach. This is not the same as:

  • “Sovereign cloud” (data hosted in France) — geographic location alone does not confer legal immunity
  • “European cloud” (datacenter in the EU) — EU-based datacenters operated by US-incorporated entities remain under US jurisdiction

The SREN Act (n° 2024-449, 21 May 2024 — Sécurisation et Régulation de l’Espace Numérique) established the principle. Article 31 obligated certain public entities to justify any use of commercial cloud for sensitive data processing. The April 2026 decree gave that obligation concrete shape by specifying two things:

  • Who is in scope: French State administrations, their operators, and six specifically named groupements d’intérêt public (GIPs), including the Agence du numérique en santé and the Centre d’accès sécurisé aux données.
  • The compliance timeline: 18 months where a qualified offer is already available on the market; one renewable year where no adequate qualified offer exists yet (source: derriennic.com).

Local authorities, healthcare facilities not directly operated by the State, and private sector OIVs (operators of vital importance) are not in direct scope of the SREN decree. Other frameworks apply to them — NIS2 for essential service operators, the HDS framework for health data hosting, and the “cloud au centre” doctrine for deconcentrated administrations.

Why AWS, Azure, and GCP Cannot Currently Qualify for SecNumCloud

SecNumCloud v3.2 imposes 197 technical and organisational requirements. The most discriminating one for major US cloud providers is not technical — it is the requirement of immunity from extraterritorial legislation.

A SecNumCloud-qualified provider must not be compellable by a foreign authority to disclose customer data without customer consent. The US CLOUD Act (2018) grants precisely that power to US authorities over any cloud provider incorporated as a US entity, regardless of where their servers are physically located. Amazon Web Services, Microsoft Azure, and Google Cloud are all US-incorporated entities. Their European subsidiaries or EU-based datacenters do not escape US jurisdiction.

In practice: these three hyperscalers cannot currently obtain SecNumCloud qualification. ANSSI has confirmed this in public communications. Oracle Cloud is in the same position. For a CIO whose organisation falls within SREN scope, an ERP hosted on these platforms cannot process the relevant sensitive data.

The State of SecNumCloud-Qualified Offers for ERP — September 2026

Approximately 21 offers are currently qualified under SecNumCloud, according to the ANSSI register (source: cyber.gouv.fr). For a CIO looking to host an ERP within this framework, the practical options are:

OVHcloud: the most operationally mature option for qualified IaaS. Its “SAP HANA on VMware” offer in the SecNumCloud zone enables SAP S/4HANA deployments. The SNC Cloud Platform also provides a qualified IaaS and managed database catalogue. This is currently the most viable path for SAP or self-hosted Odoo in a SecNumCloud-compliant architecture.

S3NS (Thales/Google): SecNumCloud 3.2 qualification obtained in late 2025 on the PREMI3NS offer, with 30 services available as of mid-2026 (source: s3ns.io). A roadmap toward 150 services and planned Vertex AI access makes this an option to watch for ERPs requiring advanced analytical capabilities.

Cloud Temple: qualified IaaS, positioned primarily for public sector and defence use cases. Fewer managed services than OVHcloud, but contractual arrangements suited to public procurement frameworks.

Outscale (Dassault Systèmes): industry and defence-oriented IaaS. Relevant for industrial ERPs deployed at BITD (defence industrial and technology base) subcontractors.

Bleu (Orange/Capgemini, built on Microsoft Azure technology): the J0 SecNumCloud qualification milestone was validated on 17 April 2025. Commercial availability was scheduled for the second half of 2026 at the time of writing (source: blog.whaller.com). Bleu is not yet fully SecNumCloud-qualified today. This means Microsoft Dynamics 365 within a fully compliant French sovereign cloud architecture is not yet available through this route.

Which ERP Data Triggers the SecNumCloud Requirement?

The key question every CIO must answer before making any procurement decision: “What data does our ERP process, and does any of it fall within the ‘particularly sensitive data’ categories defined by the SREN decree?”

The decree distinguishes two categories:

  1. Data covered by a legally protected secret: defence secrecy, medical confidentiality, trade secrets for OIVs, judicial investigation secrecy.
  2. Data necessary for the performance of essential state functions: national security, public order maintenance, protection of public health and human life.

For a ministry’s HR ERP, civil servant personal data and security clearances may fall within these categories. For a finance ERP managing defence procurement contracts, contract data enters this scope. By contrast, a local authority’s budget reporting module handling non-sensitive public expenditure data does not necessarily qualify.

A critical point for private-sector CIOs: for the 80%+ of European private companies that do not hold OIV or OES (operator of essential services) status, SecNumCloud is not a legal obligation for their ERP. It is a security policy choice. Some organisations are anticipating this requirement for future public procurement bids or preparing for potential regulatory scope expansion — that is a different calculation from a current legal mandate.

Major US ERP Vendors: Where Things Stand

The major US ERP vendors are in a structural holding pattern on SecNumCloud.

SAP: available on OVHcloud SecNumCloud via IaaS (S/4HANA on qualified infrastructure). This is not a turnkey SaaS offer — it requires infrastructure management. SAP is working with Capgemini on the Bleu roadmap, but no native SAP SaaS offer in SecNumCloud is available yet.

Oracle Cloud ERP: US-incorporated entity subject to the CLOUD Act, not qualifiable for SecNumCloud in its current form. Oracle’s French or European datacenters do not change the legal analysis.

Workday and Salesforce: same position. Both offer European data residency policies that address GDPR requirements — but European data residency is not equivalent to CLOUD Act immunity. The distinction is fundamental: hosting in Europe does not shield data from a US government access request.

For a French public organisation within SREN scope that currently runs Workday or Oracle in SaaS for payroll or finance, the 18-month compliance path requires either migrating to a compatible solution or demonstrating that its processed data does not fall within the sensitive categories defined by the decree.

Three Architectural Strategies That Enable SecNumCloud Compliance

Self-hosted on qualified IaaS: deploy SAP, Odoo, or on-premise Dynamics 365 on OVHcloud SecNumCloud or Cloud Temple. This preserves vendor functionality but transfers infrastructure operations to your internal team or a certified integrator.

French ERP vendors with contractual localisation commitments: vendors such as Cegid (France-hosted), Divalto, or Sylob host their solutions on French infrastructure. The essential question to ask: “Are you SecNumCloud-qualified, or simply France-hosted?” These are not legally equivalent statements — geographic hosting and CLOUD Act immunity are distinct qualities.

Segmented hybrid architecture: SecNumCloud-compliant infrastructure for ERP modules handling sensitive data (HR, finance, contracts); standard cloud for non-critical modules (analytics, reporting). This approach requires upstream data mapping — often skipped but essential — to determine which modules process which categories of data.

Two Expensive Confusions to Avoid

Confusion 1: assuming a French datacenter is sufficient. Azure France Central is physically in Paris. Data is geographically in France. But Microsoft Corporation is a US entity subject to the CLOUD Act. French geography provides no legal shield against a US government access request.

Confusion 2: treating “trusted cloud” and “sovereign cloud” as synonyms. A trusted cloud (the Bleu or S3NS model) uses foreign technology — Microsoft Azure or Google — operated by a French entity. A sovereign cloud (OVHcloud) develops its own technology in Europe. For defence data or Diffusion Restreinte-classified information, only a sovereign cloud using European technology meets the requirements. For sensitive but non-classified administrative data, a SecNumCloud-qualified trusted cloud is often sufficient — when a qualified offer is actually available.

What European CIOs Should Do Now

For organisations directly within SREN scope: begin a data mapping exercise immediately, categorising all data processed by your ERP systems by sensitivity level. This mapping determines which modules fall within regulatory scope. Without it, any conversation with a vendor or hosting provider is premature.

For organisations outside SREN scope (private sector, undesignated local authorities): document your current hosting decisions. If you process sensitive personal data or respond to public procurement bids involving defence data, audit your cloud contracts against SREN and NIS2 requirements. An increasing number of public tenders now include SecNumCloud compliance clauses for private-sector contractors.

For CIOs at European organisations with French subsidiaries or public-sector clients: the SREN framework directly affects any ERP or data platform shared between a French public-sector client and its service providers. Understanding where your data flows and which entities process it under what legal jurisdiction is the foundational question — regardless of whether your organisation itself is in scope.

The question is not “does SecNumCloud apply to us?” but “when and in what scope?” European regulatory frameworks are converging toward stricter data sovereignty requirements, not relaxing them. France’s SecNumCloud framework is one model for how that convergence is already playing out in procurement reality.

For more on cloud architecture decisions for ERP, see our guide to cloud vs on-premise vs hybrid for mid-market organisations and our analysis of CLOUD Act implications for European CIOs using Workday.