France’s national cyber security agency, ANSSI, has published version 3.2 of the SecNumCloud qualification framework for trusted cloud providers.
Key points
- Adds requirements to limit exposure to non-European extraterritorial laws.
- Providers must be established in an EU member state.
- Individual non-EU shareholders are limited to 24% of capital or voting rights, and non-EU shareholders collectively to 39%.
- Restricts other forms of decisive control, such as certain veto rights.
- Retains demanding technical and organisational security requirements.
SecNumCloud is increasingly expected for sensitive French public sector data. UK cloud providers and their customers should consider how ownership and control, as well as technical security, affect eligibility.
Source: SecNumCloud requirements v3.2 (ANSSI)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.