SecNumCloud: who is really concerned in 2026?
Quick reply
The decree of 14 April 2026 makes SecNumCloud mandatory for the French state and its operators. Who it covers, at what level, and how to obtain a waiver.


SecNumCloud is not a blanket legal obligation. Since decree no. 2026-272 of 14 April 2026 (the SREN law), it is mandatory for central government administrations, their operators and 6 public interest groupings handling sensitive data. It is strongly recommended, and indirectly imposed, for operators of vital importance, operators of essential services, healthcare facilities, financial institutions (under DORA) and entities covered by NIS2. For every other company it remains a strategic choice, but an increasingly decisive one when it comes to winning public contracts and sensitive clients.
What changed in 2026: from principle to obligation
Until recently, using SecNumCloud was a matter of the "cloud at the centre" doctrine (the Prime Minister's circular of 5 July 2021): a strong recommendation for government administrations, with no general binding force and no penalty attached.
The implementing decree for article 31 of the SREN law, published in the Official Journal on 16 April 2026 (decree no. 2026-272 of 14 April 2026), changes that. It now makes it enforceable for central government administrations, their operators and six named public interest groupings to use a cloud provider compliant with the ANSSI framework when they handle data of a particularly sensitive nature.
The two cumulative conditions that trigger the obligation
- The data is particularly sensitive — it has to fall under secrets protected by law or be necessary to an essential function of the state.
- There is a characterised risk in the event of a breach — harm to public order, public safety, people's health or lives, or the protection of intellectual property, and that risk has to be real rather than merely hypothetical.
A practical point worth knowing: as soon as one piece of data in your system triggers both conditions, everything hosted on the same infrastructure has to be protected to the same level, unless effective technical partitioning can be demonstrated.
The decree provides for a waiver mechanism: if a compliant offer already exists on the market, the organisation has 18 months to comply; where no suitable offer exists, a waiver is granted for up to a year, renewable, by a reasoned decision that is made public.
Discover our SecNumCloud-compatible solutions
Overview
Category Who is concerned? Level of requirement Reference text Strict obligation Central administrations, state operators, 6 named public interest groupings SecNumCloud mandatory for sensitive data Decree no. 2026-272 of 14/04/2026 (art. 31, SREN law) Strong obligation (sector-specific) Operators of vital importance, operators of essential services, healthcare (HDS), finance (DORA), NIS2 entities SecNumCloud required or closely aligned by sector regulation Sector regulations in their own right (SecNumCloud not named) De facto standard Mid-sized companies and SMEs bidding for public contracts, suppliers to operators of vital importance, vendors of sensitive SaaS Recommended "Cloud at the centre" doctrine, contractual client requirements
Since the decree of 14 April 2026, the following have to use a provider compliant with the SecNumCloud framework (or a European certification of at least equivalent level) for their sensitive data:
- Central administrations: ministries and decentralised national services
- State operators
- Six public interest groupings named in the decree, when they handle sensitive data as defined above
Organisations under a strict obligation
Since the decree of 14 April 2026, the following have to use a provider compliant with the SecNumCloud framework (or a European certification of at least equivalent level) for their sensitive data:
- Central administrations: ministries and decentralised national services
- State operators
- Six public interest groupings named in the decree, when they handle sensitive data as defined above
Organisations under a strong obligation
These organisations are not named directly in the SREN decree, but their own sector regulation creates equivalent pressure towards the security and sovereignty standards SecNumCloud embodies:
- Operators of vital importance: energy, water, transport, health, telecommunications, finance, strategic industry
- Operators of essential services: health, transport, energy, digital infrastructure, providers of critical services
- Healthcare facilities, through HDS certification
- Financial institutions covered by DORA
- Essential and important entities covered by NIS2
Recommendations that are becoming a de facto standard
- Mid-sized companies and SMEs bidding for public contracts or working with operators of vital importance
- Any organisation wanting to demonstrate a higher level of security to its clients
- SaaS vendors targeting sensitive markets
Frequently asked questions
Is SecNumCloud mandatory for every company? No. The legal obligation created by the SREN decree covers only central government administrations, their operators and certain public interest groupings handling sensitive data. For private companies, SecNumCloud remains voluntary, though it is becoming a de facto standard in regulated sectors and for suppliers to the state.
What happens if my organisation does not meet the obligation? The decree provides for no direct criminal penalty, but it conditions compliance for the public contracts concerned. A reasoned waiver, made public, can be granted if no compliant offer is available on the market.
Are ISO 27001 or HDS enough in place of SecNumCloud? No, not within the scope of the SREN decree. These certifications cover information security or health data hosting, but they do not guarantee protection against unauthorised access by the public authorities of third countries, which is specific to SecNumCloud.
The takeaway
SecNumCloud remains, to this day, a voluntary qualification for the vast majority of private companies. But the SREN decree of 2026 marks a turning point: it turns part of the public sector scope into an enforceable legal obligation, and in doing so increases the pressure on the whole ecosystem working with that sector, including the mid-sized companies and SaaS vendors not directly covered by it.
Other articles you might like
SecNumCloud, ISO 27001, HDS: what are the differences?
ISO 27001, HDS, SecNumCloud: the question each standard answers, what it really covers, and which one to aim for in your sector.


But let's be honest, our cloud-based file storage and sharing solution is much easier.


