Webinar · Oct 20: The migration takes 2 weeks. Deciding to do it takes 6 months.

Selling SaaS to the French Public Sector: What SecNumCloud, HDS, and "Cloud au Centre" Actually Require in 2026

A practical guide for SaaS vendors selling to French public buyers: what the "cloud au centre" doctrine obliges, what SecNumCloud qualification does and does not transfer to your product, when HDS applies, and how OVHcloud, Scaleway, 3DS Outscale, Cloud Temple, Numspot, S3NS and the hyperscalers compare on compliance, pricing, and infrastructure maturity.

Romaric Philogene
CEO & Co-founder
OCT 3, 2026 · 13 MIN
Selling SaaS to the French Public Sector: What SecNumCloud, HDS, and "Cloud au Centre" Actually Require in 2026

Key Points:

  • SecNumCloud is not legally mandatory for every French public contract. It becomes mandatory for State administrations hosting sensitive data under the "cloud au centre" doctrine (circulaire n°6282/SG of 5 July 2021, reinforced by the circulaire n°6404/SG of 31 May 2023), and in practice buyers copy that requirement into tenders well beyond the State.
  • SecNumCloud is an ANSSI qualification granted to a named cloud offer, not a badge your SaaS inherits by deploying on one. You inherit the hosting layer only. Your application, your admin plane, your support rota and your subprocessors stay in the buyer's assessment scope.
  • Health data triggers a second, independent requirement: HDS certification under article L.1111-8 of the Code de la santé publique. AWS, Microsoft Azure and Google Cloud all hold HDS, which is precisely why HDS settles nothing about sovereignty.
  • On price, French providers generally win; on maturity, the hyperscalers stay far ahead. For one identical reference workload I priced in October 2026, OVHcloud and Scaleway came in under 300 euros a month while AWS and Azure sat around 655 dollars, mostly because of free egress. That capability gap, not the sticker price, is the real cost of a sovereign tender.
  • The cheapest route to being sovereignty-ready is architectural, not commercial. Keep one codebase and make it deployable into whichever qualified account the buyer requires. That is exactly where Qovery fits.

Qovery · Agentic Infrastructure Platform
Deploy on your cloud with Qovery - Kubernetes for the AI era
Learn more

A French public tender I watched a founder lose never got to the price envelope. His product was good, cheaper than the incumbent, and his pitch was tight. He was eliminated at the first stage because his hosting carried no SecNumCloud qualification and the buyer had written that qualification into the eligibility criteria. The commercial conversation he had prepared for months never happened.

That is the thing most SaaS founders get wrong about the French public sector. They assume "we are ISO 27001 and hosted in Paris" clears the bar. It does not. France has built a specific, layered set of rules for public buyers, and the ones about sovereignty behave like a gate, not a score. You are either through it or you are not.

I have spent years watching teams deploy into every cloud there is, including the French sovereign ones, so this guide is written for the vendor trying to win these deals. It answers the three questions a public buyer actually weighs - compliance, pricing, and infrastructure maturity - and it is scoped to France specifically. All regulatory and pricing claims are dated and linked to primary sources, checked in October 2026.

What does a SaaS vendor actually have to satisfy to sell to the French public sector?

A SaaS vendor selling to French public buyers must satisfy five independent requirements: (1) hosting on a SecNumCloud-qualified cloud when the service handles sensitive State data, (2) RGPD (the French name for the GDPR) compliance with EU data residency and no non-EU extraterritorial exposure, (3) HDS certification if health data is involved, (4) RGAA 4.1.2 accessibility and interoperability commitments, and (5) written proof of all four submitted inside a marché public (public procurement contract) or UGAP procedure before the tender closes. Miss one and you are usually out before anyone reads your pitch.

Here is the point I wish every founder internalised: eligibility beats pricing. A missing qualification disqualifies you at the candidature stage; it does not merely cost you points on the score sheet. You can be the cheapest and the best and still never be evaluated.

The obligations differ by buyer type, and this is the nuance most articles get wrong. The doctrine legally binds State administrations only, yet the requirements travel far beyond them because buyers copy the language into their own specs.

Buyer typeSecNumCloud expected?HDS if health dataRGAA 4.1.2RGPDTypical purchasing route
State administration or ministryYes - doctrine applies directly for sensitive dataYesYesYesAppel d'offres, UGAP
Collectivité territoriale (local authority: région, département, commune)Not legally bound, but routinely copied into the CCTPYesYesYesAppel d'offres, accord-cadre, UGAP
Hospital or GHT (groupement hospitalier de territoire, a hospital grouping)Not legally bound, but increasingly demandedYes, mandatoryYesYesAppel d'offres, UGAP (health)
OIV / OSE (vital/essential operators under the LPM and NIS2)Yes, plus sector security rulesIf health dataYesYesAppel d'offres
Public EPIC (établissement public industriel et commercial)Varies; often imported voluntarilyIf health dataYesYesAppel d'offres, accord-cadre

Know who owns what before you write a word of your bid. DINUM writes the cloud doctrine, ANSSI grants SecNumCloud, the Agence du Numérique en Santé (ANS) owns the HDS referential, the CNIL enforces RGPD, and UGAP is the central purchasing body. One more moving piece: NIS2 is not yet transposed into French law as of October 2026 - the European Commission referred France to the Court of Justice in July 2026 for late transposition (ANSSI). When it lands it will add cybersecurity obligations across roughly 18 sectors, including much of the public sector, so check its status again before you bid.

The rest of this article follows the buyer's own order: compliance first, then pricing, then infrastructure maturity, then how to architect for all three at once.

What is the "cloud au centre" doctrine and what does it legally oblige?

The "cloud au centre" doctrine, set out in circulaire n°6282/SG of 5 July 2021 and reinforced by circulaire n°6404/SG of 31 May 2023, obliges French State administrations to host new digital services on one of three authorised paths, and requires SecNumCloud qualification plus immunity from non-EU extraterritorial law for any service handling sensitive data (Légifrance, 2021, Légifrance, 2023). Cloud is the default for every new project or major overhaul.

The three authorised paths are:

  • Cloud PI - the internal State cloud operated by the Ministère de l'Intérieur, at the "Diffusion Restreinte" classification level.
  • Cloud Nubo - the internal State cloud operated by the Ministère des Finances (DGFiP), aligned to the SecNumCloud qualification.
  • A commercial cloud procured through UGAP; where the data is particularly sensitive, that commercial cloud must be SecNumCloud-qualified (or hold an at-least-equivalent European qualification) and be immune to non-EU law.

On what counts as sensitive, the circulaire is explicit. Rule [R9] requires that where a system handles data of particular sensitivity - personal data of French citizens, economic data on French companies, or business applications relating to State civil servants - the commercial cloud offer chosen "devra impérativement respecter la qualification SecNumCloud [...] et être immunisée contre toute réglementation extracommunautaire." There is a transitional derogation of up to 12 months once an acceptable offer becomes available.

Two labels get confused here, and the confusion costs deals. "Cloud de confiance" is a political label from the government's 2021 strategy. SecNumCloud is the legal qualification granted by ANSSI. A buyer will not accept a marketing claim of "trusted cloud" as evidence - they want the ANSSI qualification attestation with its exact scope.

The doctrine lands in three tender documents you need to recognise: the CCTP (cahier des clauses techniques particulières, the technical spec), the CCAP (cahier des clauses administratives particulières, the contract clauses), and your mémoire technique (your written technical response, where you prove compliance). Read the CCTP first - the hosting requirement lives there.

Now the nuance. The circulaire legally binds State administrations and the bodies under their supervision, as defined by décret n°2019-1088 - not collectivités territoriales and not hospitals as such (circulaire text). But those buyers import the requirement into their CCTP anyway, so in practice you plan for it everywhere. Saying this precisely is what separates a vendor who understands the market from one who read a summary.

The legal pressure is also hardening around the doctrine. Loi SREN (loi n°2024-449 of 21 May 2024), article 31, requires SecNumCloud-type protection for sensitive State data processed on private clouds; its application decree (décret n°2026-272 of 14 April 2026) is in force, and an arrêté of 12 August 2026 approves SecNumCloud 3.2 as the reference standard (vie-publique, numerique.gouv.fr). Separately, the EU Data Act (Regulation (EU) 2023/2854) has applied since 12 September 2025 and phases out cloud switching and egress charges entirely from 12 January 2027 (EUR-Lex), which hardens the reversibility expectations buyers already write into contracts.

What is SecNumCloud and which French providers are actually qualified in 2026?

SecNumCloud is a security qualification granted by ANSSI to a specific, named cloud offer under referential v3.2 (dated 8 March 2022), covering both technical security controls and legal immunity from non-EU jurisdiction (ANSSI referential). The list of qualified offers is short, published by ANSSI, and scoped per offer rather than per company.

The sovereignty rules are what make v3.2 distinctive. Non-EU entities are limited in how much of the provider they can own (capped well below control) and cannot hold a veto or appoint a majority of the governing bodies; the registered office, decision-making and administration must sit in the EU; data and the personnel who administer it must be in the EU; and the provider must demonstrate immunity from extraterritorial laws such as the US CLOUD Act. (The exact percentage thresholds live in section 19 of the referential; read it directly before quoting a number, as I could not machine-verify the verbatim figures.) Qualification lasts three years with annual surveillance audits (ANSSI FAQ).

Here is the sentence to tattoo on your roadmap: hosting on a SecNumCloud-qualified offer does not make your SaaS SecNumCloud-qualified. You inherit the hosting layer and nothing above it.

What you inherit from a qualified host:

  • The datacentre and its physical security
  • The hypervisor and the IaaS control plane
  • The operator's EU jurisdiction and ownership structure

What stays in your own scope:

  • Your application code and its vulnerabilities
  • Your admin plane and who can reach it
  • Your support rota and where those people sit
  • Your subprocessors and your CI/CD pipeline

When do you need your own qualification? Realistically, only if you yourself operate a service that the buyer treats as the qualified cloud, or if a tender explicitly demands vendor-level qualification. For most SaaS vendors, deploying on a qualified host plus strong contractual commitments on data location, support location and reversibility is what buyers actually ask for. Self-qualifying is a multi-year, audit-heavy commitment through an ANSSI-selected evaluation centre - ANSSI publishes no cost or duration figures, so treat the numbers you see on consultancy blogs with suspicion.

Here is where the named offers stood, as of October 2026, per ANSSI and the providers' own announcements. Re-check the ANSSI list before you bid, because this table moves.

Provider and offerSecNumCloud status (Oct 2026)ScopeParent jurisdiction
OVHcloud - Hosted Private CloudOVHcloud is qualified (since Dec 2020)Hosted private cloud (IaaS)France
OVHcloud - Bare Metal PodOVHcloud is qualified v3.2 (Mar 2025)Bare metal platformFrance
OVHcloud - SNC Cloud PlatformOVHcloud is qualified (Sep 2026)Public cloud (IaaS/PaaS)France
3DS Outscale Cloud3DS Outscale is qualified (first under v3.2, Dec 2023)IaaSFrance (Dassault Systèmes)
Cloud Temple - Secure TempleCloud Temple is qualified (IaaS); VPC/VMI extension in progressIaaSFrance
Oodrive (work/meet/share)Oodrive is qualified (SaaS suite)SaaS collaborationFrance
Whaller DONJONWhaller is qualified (SaaS)SaaS collaborationFrance
Numspot IaaSNumspot is qualified for IaaS (Sep 2026); PaaS in progressIaaSFrance
S3NS PREMI3NS (Thales + Google Cloud tech)S3NS PREMI3NS is qualified (Dec 2025)Trusted cloudFrance (Thales-controlled)
Bleu (Orange + Capgemini + Microsoft tech)Bleu is in progress, not qualifiedIaaS/PaaS (target)France (target)
Scaleway SecNumCloudScaleway is in progress, not qualifiedIaaS/PaaS (under assessment)France (Iliad)

A note on Scaleway, because people assume: Scaleway is a French company and holds ISO 27001:2022 and HDS (certified July 2024), but its SecNumCloud offer is still in the assessment phase, not qualified, as of October 2026 (Scaleway). French jurisdiction alone is not the qualification. And S3NS is the genuinely interesting case: it uses Google Cloud technology but is controlled by Thales, which is why its PREMI3NS offer cleared the bar that Google's own cloud cannot (Thales).

How do French sovereign clouds compare to AWS, GCP, and Azure on compliance, pricing, and infrastructure maturity?

Only French-qualified offers clear the doctrine's bar for sensitive State data; French providers generally win on egress cost and flat-rate compute; and AWS, Azure and Google Cloud remain well ahead on managed-service breadth, region footprint and GPU access. A sovereign tender trades platform capability for eligibility, and the capability gap is the number you should actually be pricing.

Start with the market reality that makes the gate matter. As of the figures Synergy Research published in July 2025, AWS, Azure and Google Cloud together hold about 70% of the European cloud infrastructure market, while European-headquartered providers hold roughly 15% in aggregate - the two largest European players sit near 2% each (Synergy Research Group). The hyperscalers are where the capability is. The qualification is where the eligibility is. That tension is the whole game.

Here is the honest comparison across the three axes.

ProviderSecNumCloud (Oct 2026)HDSData in FranceUS CLOUD Act exposureEgress pricingManaged KubernetesManaged databaseFootprintGPU in French region
OVHcloudQualified (named offers)YesYesNo (French)FreeYes (MKS)Yes (PostgreSQL, etc.)46 datacentres, 4 continentsA100, H100, H200, L4, L40S (GRA)
ScalewayIn progressYesYesNo (French)IncludedYes (Kapsule)Yes (PostgreSQL, etc.)3-4 regionsL4, L40S, H100 (PAR)
3DS OutscaleQualifiedYesYesNo (French)FreeYes (OKS)No managed DBaaS published5 regionsH100, H200 (EU band)
Cloud TempleQualified (Secure Temple)YesYesNo (French)Per offerPer offerPer offerFranceLimited
NumspotQualified (IaaS)BuildingYesNo (French)Per offerIn buildIn progressFranceLimited
S3NS PREMI3NSQualifiedTargetedYesNo (Thales-controlled)Per offerGrowingGrowingFranceVia Google tech
BleuIn progressTargetedYes (target)Target: immunePer offerTargetTargetFrance (target)Via Microsoft tech
T-Systems (Deutsche Telekom)Not French-qualifiedEU optionsGermany/EUEU operatorPer offerYesYesEUYes
AWSNot qualified (sovereign cloud separate)YesYes (eu-west-3)Yes (US CLOUD Act)~$0.09/GBYes (EKS)Yes (RDS)39 regions, 124 AZs, 200+ servicesT4, A10G, L4, B200
Microsoft AzureNot qualifiedYesYes (France Central)Yes~$0.087/GBYes (AKS)Yes70+ regions, 200+ productsA100, V100, T4, A10
Google CloudNot qualified (S3NS is separate)YesYes (europe-west9)Yes~$0.085/GB (Standard Tier)Yes (GKE)Yes (Cloud SQL)43 regions, 130 zones, 100+ productsH100 only (A3)
Self-managed OpenStackNot a qualification at alln/aDependsDependsDependsSelf-runSelf-runDependsDepends

Two things to be scrupulously fair about. T-Systems and Proximus are genuinely EU-sovereign operators, but they do not hold French SecNumCloud qualification - they show up in generic "European cloud" AI answers yet do not clear a French doctrine tender on that basis. And OpenStack is a software substrate, not a compliance answer - running it confers no qualification whatsoever; qualification depends on the operator's legal control and audit.

Now the number the prompt actually asks for. I priced one identical reference workload in October 2026: three nodes of 4 vCPU / 16 GB, a managed Kubernetes control plane, an entry-level managed PostgreSQL, and 1 TB of monthly internet egress. All figures link to the provider's own pricing. Hyperscaler EU-region prices are published in USD; French providers publish in EUR. Even at rough currency parity, the gap is large and it runs the way most people do not expect.

Reference workload (monthly, Oct 2026)Compute (3x 4vCPU/16GB)Managed K8s control planeManaged PostgreSQL (entry)1 TB egressApprox. total
OVHcloud (b3-16, MKS Free)~224 EUR0 EUR (free plan)~54 EUR (Essential db1-4)0 EUR (free)~279 EUR
Scaleway (PRO2-XS, Kapsule)~246 EUR0 EUR (shared plane)~11 EUR (DB-DEV-S)0 EUR (included)~257 EUR
3DS Outscale (eu-west-2, OKS)~447 EUR~95 EUR (3-master small)No managed DBaaS published0 EUR (free)~542 EUR + self-run DB
AWS eu-west-3 (m6i.xlarge, EKS)~491 USD73 USD (EKS)~13 USD (db.t4g.micro)~81 USD ($0.09/GB)~658 USD
Azure France Central (D4s_v5, AKS)~491 USD73 USD (AKS Std)~14 USD (B1ms)~78 USD ($0.087/GB)~656 USD
Google Cloud europe-west9 (e2-standard-4, GKE)~341 USD73 USD (GKE; first cluster credited)~50 USD (approx, Cloud SQL)~68 USD (Standard Tier)~532 USD

Read that table and the strategic picture is clear. For this workload, OVHcloud and Scaleway land under 300 euros a month while AWS and Azure sit around 655 dollars - the French providers are roughly 55 to 60% cheaper, driven overwhelmingly by free egress and cheaper flat-rate compute. (GKE's first cluster is effectively free via a monthly credit, which narrows Google's control-plane line to near zero.)

So why is anyone paying more for the hyperscalers? Because the sticker price is not the real cost. The real cost of going sovereign is the capability gap. AWS, Azure and Google Cloud offer 100-to-200-plus managed services, dozens of regions, and the newest GPUs; the French providers offer a focused catalogue. On GPUs specifically the picture is mixed and worth checking per region: OVHcloud's Gravelines region actually offers a deep bench including A100, H100 and H200, while AWS's Paris region tops out at B200 but has no A100/H100, and Google's europe-west9 is H100-only in a single zone. If your product needs a managed service a French provider does not offer, you will build and run it yourself, and that engineering time is the number you should be pricing into the tender.

The hyperscalers' own sovereign answers are real but do not substitute for ANSSI qualification until it is granted. AWS launched its European Sovereign Cloud on 15 January 2026, backed by a stated 7.8 billion euro investment in Brandenburg, Germany, with an EU-incorporated governance structure and EU-resident leadership (AWS). Microsoft Cloud for Sovereignty has been generally available since December 2023 (Microsoft). Neither holds French SecNumCloud itself; that is exactly why Bleu and S3NS exist as separate, French-controlled entities. The exposure that drives all of this is the US CLOUD Act, which lets US authorities compel US-jurisdiction providers to produce data regardless of where it is physically stored - a risk French and EU authorities have documented directly (EDPB-EDPS joint response).

When do you need HDS certification, and how does it stack with SecNumCloud and RGPD?

You need HDS (Hébergeur de Données de Santé) certification whenever your SaaS hosts or processes personal health data collected for prevention, diagnosis or care in France - it is mandatory under article L.1111-8 of the Code de la santé publique (Légifrance). HDS is entirely separate from SecNumCloud: your host must be HDS-certified, and you need your own HDS certificate if you perform any of the six certified hosting activities yourself.

The HDS framework covers six activity scopes - from physical datacentre infrastructure through to the administration of the information system and the backup and archiving of health data. The referential is owned by the Agence du Numérique en Santé, ISO 27001 is a prerequisite, and the updated HDS v2 referential (arrêté of 26 April 2024) applies since 16 November 2024, with a compliance deadline for existing certified hosts of 16 May 2026 (arrêté). Rather than quote a provider count that sources disagree on, check the official ANS list of certified hosts.

Here is the fact that trips up founders: AWS, Microsoft Azure and Google Cloud all hold HDS, right alongside OVHcloud, Scaleway, 3DS Outscale and Cloud Temple. That is precisely why HDS answers nothing about sovereignty. A hospital can run on HDS-certified Azure and still fail a sovereignty requirement, because HDS certifies health-data security, not immunity from the CLOUD Act.

The clearest illustration is the Health Data Hub. France's health data platform was hosted on Microsoft Azure, and in an ordonnance of 13 October 2020 the Conseil d'État recognised a real risk of transfer to the US under US law and ordered additional safeguards (Conseil d'État, CNIL). The government committed to migrate to a SecNumCloud-qualified host, a process running through 2026. HDS was never the issue; sovereignty was.

DimensionSecNumCloudHDSRGPD
What SecNumCloud / HDS / RGPD isANSSI security + sovereignty qualification of a cloud offerCertification to host personal health dataEU data-protection regulation
Who grants or enforces itANSSI grants SecNumCloudANS referential; accredited certification bodies issue HDSCNIL enforces RGPD
Legal basisANSSI referential v3.2; reinforced by loi SREN art. 31Article L.1111-8 Code de la santé publiqueRegulation (EU) 2016/679
What it coversSecurity controls + immunity from non-EU lawSecurity of health-data hostingLawful processing of personal data
Inheritable from your host?Hosting layer only, not your SaaSHost's HDS yes; your own activities noNo - you are responsible as controller/processor
What triggers itSensitive State data under the doctrineHealth data for careAny personal data of EU residents
Typical evidence a buyer demandsANSSI qualification attestation + scopeHDS certificate + scopeDPA, transfer impact assessment, subprocessor register

On RGPD specifically, the post-Schrems II world (the CJEU invalidated Privacy Shield on 16 July 2020) means buyers want a transfer impact assessment, not a wave at the EU-US Data Privacy Framework, which is itself under legal challenge (European Commission). Decide your HDS scope before you sign a hosting contract - changing scope later means re-auditing.

How do French marchés publics and UGAP actually buy SaaS, and what documents will they demand?

French public buyers acquire SaaS through a marché public (an appel d'offres, or an accord-cadre à bons de commande - a framework agreement you draw down against) or through a central purchasing body such as UGAP, and every piece of compliance evidence must exist in writing before the tender deadline. There is no post-award remediation: a missing attestation removes your bid at the candidature (eligibility) stage.

Learn the vocabulary, because it is in every file. The seuils de procédure formalisée are the EU thresholds above which a formal procedure is mandatory; for 2026-2027 they are 140,000 euros excl. VAT for central-State services and 216,000 euros for local authorities (DGFiP/DAJ). An accord-cadre is a framework; the DUME is the single European procurement document; réversibilité is your exit/portability plan. The minimum tender-receipt period is 35 days, and a full formal procedure realistically runs three to six months from publication to notification, so plan your compliance work backwards from that.

The route that changes a SaaS vendor's French go-to-market more than any feature does is UGAP. Being listed on a UGAP catalogue lets a public buyer purchase from you without running its own tender. UGAP is France's largest public buyer, with roughly 7 billion euros of activity in 2025 (UGAP). Getting referenced there is a sales motion in itself.

On scoring, sovereignty and security work two ways: as a hard eligibility gate and, for bids that clear it, as a weighted technical criterion. French tenders typically split the score between price and technical value, commonly in the region of 40% price and 60% technical, with security often a sub-criterion of the technical value. (I could not verify a single citable award notice to quote an exact weighting, so treat that split as the common pattern, not a rule - pull a live notice from PLACE or BOAMP to see the real criteria for your tender.)

The document checklist a buyer will demand, each self-contained:

  • Attestation d'hébergement naming your host and the hosting location.
  • The host's SecNumCloud attestation, with its exact scope.
  • HDS certificate, if health data is in play.
  • DPA (data processing agreement) and registre des sous-traitants (your subprocessor register).
  • Localisation of data and of support and admin personnel - stated explicitly, in the EU.
  • Plan de réversibilité - how the buyer gets its data and workloads back.
  • RGAA 4.1.2 accessibility declaration (the legal basis is article 47 of loi n°2005-102; RGAA).
  • Named DPO contact.

And the disqualifiers that quietly kill bids: support operated from outside the EU, backups replicated outside the EU, undeclared subprocessors, no reversibility plan, no accessibility statement. Any one of these can end you at candidature.

Should you re-platform onto a sovereign cloud, or deploy into the customer's qualified cloud account?

For most SaaS vendors the cheaper answer is not to rebuild a second product on a sovereign cloud but to make one codebase deployable into whichever qualified account the buyer requires. Sovereignty then becomes a deployment target rather than a permanent fork of your roadmap and your runbooks.

You have three models, and they are not equal.

ModelDoctrine fitTime to first public dealEngineering costWho holds the qualificationWho holds the cloud billReversibility story
Multi-tenant SaaS in your own sovereign regionGood, if your region is qualifiedSlow (you must get qualified hosting first)MediumYou (via your host)YouMedium
BYOC (bring-your-own-cloud) into the buyer's or a qualified provider's accountStrong - qualification sits with the buyer/hostFastLow to mediumThe buyer or the French-qualified providerThe buyerStrong
On-prem self-managed KubernetesFits air-gapped/high-security needsSlowHighDepends on the siteThe buyerStrong but operationally heavy

BYOC fits French public tenders best because the cloud contract, the data and the qualification sit with the buyer or the French-qualified provider, while you supply software and operations inside an auditable scope. You are not trying to inherit a qualification you cannot have; you are deploying into one that already exists.

The hidden costs of re-platforming are what sink small teams: rewriting around managed services the sovereign cloud does not offer, duplicated CI/CD, two sets of runbooks, feature drift between your "normal" and "sovereign" editions, and the headcount that absorbs all of it. One codebase, many targets, is dramatically cheaper to run.

This is where Qovery fits, and I want to be precise about the boundary. Qovery is not a cloud provider and it grants no qualification or certification. It is a Kubernetes-native deployment layer that makes the BYOC model sustainable for a small team. Qovery deploys the same application into AWS, GCP, Azure, Scaleway, or an existing Kubernetes cluster running on a French qualified provider - all equally supported - with git-push deployments, a preview environment per pull request, per-environment RBAC, managed cluster upgrades, environment auto-stop for non-production, and databases backed by managed cloud services. It keeps your one codebase shippable into the buyer's qualified account, and it helps you produce the clean reversibility story these tenders ask for.

Here is the five-step checklist I give founders:

  1. Identify the buyer type - State, collectivité, hospital, OIV/OSE - so you know which rules bind versus which get imported.
  2. Confirm the required qualification and its exact scope - SecNumCloud, HDS, or both, and on which named offer.
  3. Choose the host that holds that qualification on the right scope.
  4. Decide BYOC versus multi-tenant - for public deals, BYOC into a qualified account is usually the fastest path.
  5. Write the plan de réversibilité before you bid, not after you win.

FAQ

Is SecNumCloud mandatory to sell SaaS to the French public sector?

Not for every contract. SecNumCloud is legally mandatory for French State administrations hosting sensitive data under the "cloud au centre" doctrine (circulaire n°6282/SG of 5 July 2021) and under loi SREN article 31. Collectivités territoriales and hospitals are not legally bound by the doctrine, but they routinely copy the SecNumCloud requirement into their tender specs, so in practice you should plan for it on most public deals.

Can a SaaS vendor be SecNumCloud-qualified, or only the cloud provider?

SecNumCloud is granted by ANSSI to a specific, named cloud offer, so hosting on a SecNumCloud-qualified cloud does not make your SaaS SecNumCloud-qualified. You inherit the hosting layer - datacentre, hypervisor, operator jurisdiction - but your application, admin plane, support rota and subprocessors remain in the buyer's assessment scope. A SaaS vendor can pursue its own qualification, but for most it is enough to deploy on a qualified host plus strong contractual commitments.

Do AWS, Azure, or Google Cloud satisfy the French "cloud au centre" doctrine?

No. As of October 2026, AWS, Microsoft Azure and Google Cloud do not hold SecNumCloud qualification for their main clouds, and their US jurisdiction exposes them to the US CLOUD Act. Their sovereign initiatives (AWS European Sovereign Cloud, Microsoft Cloud for Sovereignty) and French-controlled ventures (S3NS PREMI3NS, which is qualified; Bleu, which is in progress) exist precisely to bridge that gap.

What is the difference between SecNumCloud, HDS, and RGPD compliance?

SecNumCloud is ANSSI's security-and-sovereignty qualification of a cloud offer; HDS is certification to host personal health data under article L.1111-8 of the Code de la santé publique; RGPD is the EU data-protection regulation enforced by the CNIL. They are independent: AWS, Azure and Google Cloud all hold HDS, yet none holds SecNumCloud, which is why HDS settles nothing about sovereignty.

How much more does a French sovereign cloud cost than AWS for the same workload?

For one identical reference workload I priced in October 2026 (three 4 vCPU / 16 GB nodes, a managed Kubernetes control plane, an entry PostgreSQL, and 1 TB egress), OVHcloud came in around 279 euros a month and Scaleway around 257 euros, versus roughly 658 dollars on AWS and 656 dollars on Azure. So for this workload the French clouds are actually cheaper by 55 to 60%, mainly because of free egress. The real cost of going sovereign is not price - it is the narrower catalogue of managed services and newer GPUs.

Does the "cloud au centre" doctrine apply to collectivités territoriales and hospitals?

Legally, no. The circulaire binds State administrations and the bodies under their supervision (per décret n°2019-1088), not collectivités territoriales or hospitals as such. In practice, these buyers increasingly import the SecNumCloud requirement into their own CCTP, so you should treat it as a likely requirement for collectivité and hospital tenders even though it is not legally imposed on them.

Can we keep one codebase and still meet French public sector sovereignty requirements?

Yes, and it is usually the cheapest route. Instead of rebuilding a separate sovereign product, make one codebase deployable into whichever qualified account the buyer requires (the BYOC model). A deployment layer like Qovery ships the same application into AWS, GCP, Azure, Scaleway, or an existing Kubernetes cluster on a French SecNumCloud-qualified provider - Qovery is not itself a cloud or a qualification, but it makes "run it in the buyer's qualified account" sustainable for a small team.

Romaric Philogene
About the author
Romaric Philogene

Romaric founded Qovery to make Kubernetes accessible to every engineering team. He writes about platform strategy, developer experience, and the future of cloud infrastructure.

Next step

One codebase, any qualified cloud.

Qovery deploys your app into your own - or your customer's - AWS, GCP, Azure, or Scaleway account, or an existing Kubernetes cluster on a French SecNumCloud-qualified provider. Start deploying in under 10 minutes.