On 15 August 2026, an order approving SecNumCloud 3.2 took effect in France, completing a legal chain that began with article 31 of the SREN law of 21 May 2024. It lands in a market where European providers held 15% of their own cloud market in 2022, down from 29% in 2017.
Sovereign cloud is now the law for the French state's most sensitive data. Demand is no longer the question: qualified capacity is, and so are the people who build and run it.
This dossier reads the three legal texts in the order they were published, then the market they land in, then the balance sheet of the largest European provider that sells into it, then the calendar of a newcomer trying to qualify. It ends with the jobs that this arithmetic creates, and with what it does not prove.
The law moved in three steps
For most of the last decade, "cloud de confiance" was a doctrine. It was set out in government policy and repeated in speeches, but no statute named who was bound or what test a provider had to pass. That changed with article 31 of the SREN law, published in the Journal officiel on 22 May 2024. The article places an obligation on the state's administrations and on certain operators: when they entrust their most sensitive data to a commercial cloud, the provider must protect that data against access by public authorities of states outside the European Union.
A law of this kind does little on its own. It needs a decree to say who is bound and under what conditions, and a technical standard to say what "protected" means in practice. The decree came first. Decree n° 2026-272 of 14 April 2026 was published on 16 April and entered into force on 17 April. It names the bodies that are bound: the state's administrations, its public operators and six named public interest groupings. It also sets the rule for projects that were already under way.
The technical standard came last. On 12 August 2026 the Prime Minister signed an order approving version 3.2 of the SecNumCloud requirements, the ANSSI reference for cloud providers. It was published on 14 August and took effect on 15 August. Under the order, conformity is attested either by ANSSI qualification or by a recognised equivalent from another member state of the European Union or the European Economic Area. Some trade coverage gave 22 August as the start date. The Journal officiel says otherwise, and this dossier follows the Journal officiel.
Three texts turned a cloud doctrine into binding law
21 May 2024
SREN law, article 31
State bodies must host their most sensitive data on a cloud protected from non-EU law.
17 April 2026
Decree n° 2026-272 in force
Names who is bound and sets the derogation rule for earlier projects.
15 August 2026
SecNumCloud 3.2 approval order in force
Conformity is attested by ANSSI qualification or a recognised EU or EEA equivalent.
Sources 4 Légifrance (service public de la diffusion du droit) · 5 Légifrance (service public de la diffusion du droit) · 6 Légifrance (service public de la diffusion du droit)
The sequence matters because each step removed an excuse. Before the law, a ministry could treat sovereignty as a preference. Before the decree, it could argue that it did not know whether it was covered. Before the order, it could say that nobody had defined the test. Since 15 August, none of those arguments is available to a covered body that is starting a new project.
What the decree does not say
A careful reader should notice three limits, because the market's enthusiasm tends to skip them.
First, the scope is narrow. The obligation covers the state, its operators and the six named groupings. Hospitals and local authorities are outside it. A regional council that moves its data to a non-European hyperscaler is not breaking this law.
Second, there is no general migration deadline. One vendor claimed that covered bodies have 18 months to move everything. The decree says something different. A project begun before the rule can obtain a derogation. It lasts up to 18 months from the day an acceptable offer exists in France, or one year, renewable, where no such offer exists yet. Each derogation decision must be published with its reasons. That is a transparency rule with a clock attached, not an eviction notice.
Third, the text binds a buyer, not a market. It says what a covered body must buy for its most sensitive data. It says nothing about what everyone else buys. So the demand it creates is real but bounded, and it is concentrated on one test: qualification.
The market it lands in is concentrated
Synergy Research Group, which tracks cloud revenue by region, published its reading of the European market on 24 July 2025. The market was worth 61 bn EUR in 2024. Amazon, Microsoft and Google together held 70% of it. The largest European names, SAP and Deutsche Telekom, held 2% each.
The trend is the more important number. European providers held 29% of their own market in 2017 and 15% in 2022. Synergy's later reading is that the local share has since held steady at about that level. In other words, European providers did not shrink. The market grew around them, and most of the growth went to three American companies.
European providers’ share of their own market halved in five years
- Local providers, 2017: 29% % of the European cloud market
- Local providers, 2022: 15% % of the European cloud market
% of the European cloud market
Source 3 Synergy Research Group
This is the context in which the order took effect. The state is asking a small group of providers, the ones that can pass SecNumCloud, to carry its most sensitive workloads. Those providers are not the market leaders. They are the part of the market that lost share for five years. The law creates a protected segment. It does not create the capacity to serve it.
Sovereign capacity is capital heavy
To understand what serving that segment costs, the best public evidence is the accounts of OVHcloud, a European provider that runs its own data centres and sells into the SecNumCloud segment. Its results for the financial year ended 31 August 2025 were published on 21 October 2025, together with its consolidated financial statements.
OVHcloud reported revenue of 1,084.6 M EUR1, up from 993.1 M EUR1 the year before, and an adjusted EBITDA margin of 40.4%. Those are healthy operating numbers. The problem sits below them. Capital expenditure was 361.4 M EUR, or 33.3% of revenue. Depreciation, the accounting charge for servers and buildings wearing out, was 354.4 M EUR. Borrowing costs rose to 53.7 M EUR from 30.1 M EUR. Net income was 0.4 M EUR.
Sovereign capacity costs a third of revenue every year
| Line | FY2025 | Publisher |
|---|---|---|
| Revenue | 1,084.6 M EUR | OVHcloud |
| Capital expenditure | 361.4 M EUR (33.3% of revenue) | OVHcloud |
| Depreciation | 354.4 M EUR | OVH Groupe SA |
| Net income | 0.4 M EUR | OVHcloud |
Sources 1 OVHcloud · 2 OVHcloud
Read together, these lines describe a business that must spend about a third of every euro it earns on new machines and buildings simply to keep growing, and that sees almost all of its operating margin consumed by the cost of the machines it already owns and the debt that financed them. This is not a criticism of OVHcloud. It is the physics of running infrastructure. The hyperscalers face the same physics, but they spread it over a market share that is many times larger.
For the sovereignty argument, the implication is direct. Qualified capacity does not appear because a law asks for it. It appears when a provider commits hundreds of millions of euros in capital, years ahead of the revenue, and finds the engineers to run it. A protected segment helps that bet, because it makes some of the future revenue more predictable. It does not remove the bet.
Qualification is slow
The second constraint is time. SecNumCloud is not a certificate one buys. It is a qualification that ANSSI grants after a provider has shown, through a sequence of milestones and audits, that it meets the requirements. The reference was first created in 2016. The version the order approved is 3.2.
The clearest public calendar belongs to Bleu, the company owned 100% by Capgemini and Orange. Bleu announced on 17 April 2025 that its J0 milestone had been validated, and it targeted qualification for the first half of 2026. It announced on 17 November 2025 that its J1 milestone had been validated. It had also reported more than 130 staff since January 2024, with 200 targeted by the end of 2025.
As of 27 September 2026, the day this dossier was read against its sources, no official source reports that Bleu's qualification target was met. That absence is not evidence of failure. Qualification schedules can slip for ordinary reasons. But it is evidence of the point this section makes: even a well-funded provider, backed by two of France's largest companies, measures the road to qualification in years.
Qualification is measured in years, not quarters
January 2024
Bleu begins building its team
130+ staff since January 2024, with 200 targeted by the end of 2025.
17 April 2025
J0 milestone validated
Qualification targeted for the first half of 2026.
17 November 2025
J1 milestone validated
Owned 100% by Capgemini and Orange.
27 September 2026
No qualification announced
Read on this day: no official source reports the target met.
Hybrid is the practice
The most useful single example of how a large buyer actually behaves comes from Orange Business. On 25 November 2025 it announced that it would migrate 70% of its information technology to Bleu, after analysing more than 400 applications. The same release made clear that its most sensitive workloads would stay on Cloud Avenue, its own sovereign offer.
This is the real shape of demand. Buyers do not move everything to one qualified provider. They sort their applications by sensitivity, send the bulk to the most capable platform they trust, and keep the most sensitive part on the most protected platform they can find. The law formalises that sorting for the state. It will not make buyers stop sorting.
The counter-case
A dossier that argues for scarcity has to state the strongest case against it.
The first objection is scope. Because the law binds only the state, its operators and six groupings, the protected segment may be too small to justify the capital it requires. If hospitals and local authorities stay free to buy what they like, the qualified providers are competing for a narrow customer base.
The second objection is the derogation. A body that began its project before the rule can obtain up to 18 months from the day an acceptable offer exists, or a renewable year where none exists. If qualified offers remain scarce, derogations could become the norm and the obligation could stay mostly on paper for years.
The third objection is equivalence. The order accepts a recognised equivalent from another EU or EEA member state. That could open the French segment to providers qualified elsewhere, which would ease the capacity constraint rather than tighten it.
Each objection is fair, and none of them removes the core finding. A narrow segment still needs qualified capacity. A derogation still has to be published with its reasons, which makes delay visible. And an equivalent qualification from another member state still requires a provider to have passed a comparable test, which is exactly the scarce thing. So this dossier claims a scarcity of qualified capacity and of the people who build and run it. It does not claim that sovereign providers are about to take the market.
What would change the reading
Three dated events would move this analysis, and a reader can watch for each of them. The first is Bleu's qualification, or a published explanation of its delay. The second is the first published derogation decisions, which will show how many covered projects are waiting for an acceptable offer. The third is OVHcloud's results for the financial year ending 31 August 2026, which will show whether the capital intensity is falling as the protected segment grows.
What this means for your career
The cost structure described above creates work that is specific, visible and hard to automate. Three families of roles are named or implied by the sources this dossier reads.
Qualification teams. Bleu reported more than 130 staff since January 2024 and targeted 200 by the end of 2025. The releases do not say how that headcount divides between building a platform and selling it. It is building, documenting and auditing a platform to the SecNumCloud requirements. Security architects, compliance engineers and auditors who can read a reference and turn it into controls are the people these teams are built from. The skill that transfers is the ability to show evidence that a control works, not only to describe it.
Data centre and infrastructure engineering. A provider that spends 361.4 M EUR a year on capital needs people who can plan capacity, build and run facilities, and manage the hardware lifecycle that shows up as 354.4 M EUR of depreciation. These are engineering roles with long horizons, where capacity is committed years before the revenue it serves.
Public sector cloud buyers. Since 15 August 2026, a covered body that cannot yet buy a qualified offer must document a derogation, and that decision is published with its reasons. Someone has to classify the data, test the market for an acceptable offer, write the reasons and track the clock. That is procurement work with legal consequences, and it now has to be done in writing, for a decision that is published.
If one of these roles is where you want to go, CareerOn's job simulations let you practise the work before you apply: read a requirement, judge a piece of evidence, and write the decision a reviewer will read. Start with the simulation closest to the role, and use this dossier's sources as your briefing pack.
