Regulations
Published on
26.06.2026

SecNumCloud, ISO 27001, HDS: what are the differences?

Caroline Boisramé Moreau

Quick reply

ISO 27001, HDS, SecNumCloud: the question each standard answers, what it really covers, and which one to aim for in your sector.

In this article

The short version: ISO 27001, HDS and SecNumCloud are not alternatives to one another, they form a pyramid. ISO 27001 certifies cyber governance. HDS adds the requirements specific to health data. SecNumCloud goes further still, with an extraterritorial immunity the other two do not cover at all.

When choosing a cloud provider, the same questions come up every time: is ISO 27001 certification enough? Should HDS be a requirement? And who is SecNumCloud actually for? The confusion is understandable, since all three frameworks talk about data security. But they answer different risks and they do not carry the same contractual weight.

What fundamentally separates them is not how technical they are: it is the question each one answers.

Three frameworks, three different questions

ISO 27001: "do you manage your security in a structured way?"

ISO 27001 certifies that an organisation identifies its risks, chooses appropriate measures and keeps them alive over time. Its logic is proportionate and modular: it does not prescribe an absolute level of security, but a process consistent with management's objectives. It is the foundation, within reach of any company, and recognised worldwide. Its limit: it imposes no requirement on where data is located and offers no protection against extraterritorial laws.

HDS: "can you host health data in full compliance?"

HDS certification takes ISO 27001 as a mandatory prerequisite and adds sector-specific requirements: stronger encryption, frequent audits, and compliance with the GDPR and French data protection law. It is mandatory for any organisation hosting personal health data. One caveat: an American provider can hold HDS certification, and that does not make it immune to the Cloud Act.

SecNumCloud: "can your data be demanded by a foreign state?"

SecNumCloud is a qualification awarded by ANSSI, the French cybersecurity agency, to cloud providers. It builds on 75% of the requirements in ISO 27001, goes beyond them with 354 precise technical criteria, and adds a dimension found nowhere else: extraterritorial immunity. The provider has to be majority European-owned (at least 76%), host the data in France or the EU, and contractually resist any order from a non-European state.

Comparison

Criterion ISO 27001 HDS SecNumCloud Nature International standard French sector certification ANSSI qualification Scope Every sector, every organisation Health data hosts Cloud providers (IaaS, PaaS, SaaS) Approach Risk management (modular ISMS) ISO 27001 + health requirements A framework of 354 precise technical requirements Extraterritorial protection None Partial (GDPR) Full: immunity from the Cloud Act and FISA 702 Data location No requirement EU recommended France / EU mandatory Ownership required None None European (over 76%) Legal obligation No (market standard) Yes for health data hosts Yes for the public sector (SREN decree, 2026) Prerequisite Base foundation Requires ISO 27001

Which framework for your company?

Your situation What you need Private mid-sized company, no sensitive public sector clients ISO 27001 Health or telemedicine SaaS startup ISO 27001 + HDS (legal obligation) Cloud supplier to the French state SecNumCloud (SREN decree, April 2026) Financial player (bank, insurer, fintech) ISO 27001 + DORA + SecNumCloud for sensitive workloads SaaS vendor targeting public contracts or operators of vital importance ISO 27001, then a path towards SecNumCloud

Frequently asked questions

Is ISO 27001 enough to bid for a public contract? In most cases, yes, for contracts that do not involve sensitive data. But since decree no. 2026-272 (SREN law, April 2026), contracts involving sensitive data belonging to a central government administration require a provider compliant with the SecNumCloud framework. ISO 27001 alone is not enough within that scope.

Can a provider hold both HDS and SecNumCloud? Yes, and that is the combination to aim for if you are targeting the sensitive end of the health market. The two are not redundant: HDS answers the sector's legal obligation, SecNumCloud adds extraterritorial immunity.

Does NIS2 require SecNumCloud? Not explicitly. But ANSSI recommends SecNumCloud for the critical cloud components of the essential and important entities covered by NIS2. It is a direct way of demonstrating compliance with the appropriate technical and organisational measures the directive requires.

Sources

ANSSI — SecNumCloud framework v3.2, March 2022. cyber.gouv.fr

Decree no. 2026-272 of 14 April 2026 (art. 31, SREN law). Légifrance

Agence du numérique en santé — HDS framework, 2023 revised version.

ISO/IEC 27001:2022 — Information security management systems.

No items found.
No items found.

Definition

No items found.

FAQ

No questions found.

Best practices / Common pitfalls

No items found.

Key figures

No items found.

Key takeaways

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

You could keep all your documents on a floppy disk.
Vintage office chair with a pile of folders and a beige corded telephone, handset off the hook on red carpet.

But let's be honest, our cloud-based file storage and sharing solution is much easier.