Summary
- OVHcloud’s SNC Cloud Platform has secured France’s SecNumCloud qualification from cybersecurity agency ANSSI.
- France now requires certified cloud services for defined sensitive state data, turning security assurance into a procurement condition.
- OVHcloud plans deployments in Italy, Germany, and Poland as European cloud sovereignty becomes increasingly tied to infrastructure and certification.
France’s tightening rules around sensitive state data have given OVHcloud a new route into public-sector and regulated workloads, after its SNC Cloud Platform secured SecNumCloud qualification and began moving towards a wider European rollout.
OVHcloud said France’s national cybersecurity agency ANSSI had qualified the trusted public cloud platform, which the company now plans to deploy across additional European regions. Italy, Germany, and Poland are identified as the next markets, with each deployment expected to follow the applicable national framework.
The certification arrives as French law turns cloud security from a procurement preference into a formal requirement for some government workloads. Article 31 of Law No. 2024-449 and an implementing decree adopted in April 2026 require certified cloud services for sensitive data belonging to the French state and its operators.
That creates a commercial opening for providers able to combine public cloud economics with assurance recognised by national authorities. Healthcare, finance, industry, energy, and software suppliers working with administrations are also facing greater scrutiny over where sensitive workloads run, who operates the infrastructure, which jurisdiction applies to it, and how readily data can be moved elsewhere.
SNC Cloud Platform becomes OVHcloud’s third SecNumCloud-qualified service, after Bare Metal Pod and VMware on OVHcloud. The newer platform is billed on a pay-as-you-go basis and relies on open APIs and open-source standards, which the company says support interoperability and data reversibility.
Certification enters the buying decision
European cloud sovereignty has often been reduced to the nationality of a supplier, although procurement is increasingly governed by more granular requirements around data location, operational control, security assurance, subcontractors, portability, and exposure to non-European law. Those distinctions become especially important when workloads contain government information or regulated data rather than routine business applications.
OVHcloud is attempting to turn that shift into a broader European proposition. Octave Klaba, founder, chairman and chief executive of OVHcloud, said: “After France, we will make this platform available across all our European regions.”
SecNumCloud itself remains a French qualification, which means expansion cannot consist simply of carrying the certificate across borders. OVHcloud says each deployment will meet applicable national frameworks, requiring a common technical platform to sit beneath assurance regimes that may differ from one European market to another.
That could become both an advantage and an operating burden. National certification can create defensible access to sensitive contracts, but fragmented requirements make it harder to deliver a completely standardised European cloud service. Providers working across several public sectors may have to retain common infrastructure while satisfying different controls, audits, contractual terms, and expectations around jurisdiction.
Competition remains formidable because Amazon Web Services, Microsoft, and Google offer broad product portfolios, deep ecosystems, and global scale. European suppliers have consequently placed greater emphasis on sovereignty, certification, portability, and jurisdiction where procurement rules can change the basis on which providers compete.
Those concerns increasingly extend from the legal location of data to the availability of physical infrastructure. Recent investments such as Schwarz Group’s €5.6 billion commitment to German AI and cloud infrastructure show how control over compute capacity is becoming part of the same discussion.
AI increases demand for trusted infrastructure
Enterprise AI adds another reason for governments and regulated organisations to examine infrastructure more closely because model training, inference, retrieval systems, and software agents can touch commercially or personally sensitive information. The relevant questions therefore reach beyond where data sits to who can administer the system and what controls surround its use.
OVHcloud explicitly links its European rollout to rising demand for trusted infrastructure as AI adoption expands. Certification cannot settle model governance, application security, access permissions, or data quality, but it can establish whether particular infrastructure meets the assurance threshold required before a sensitive workload is allowed to run.
The consumption model is also notable because certified or sovereign infrastructure has often been associated with isolated environments and bespoke procurement. Extending stronger assurance into a conventional public cloud model could make it easier to apply those controls to variable workloads without maintaining fixed private estates solely for compliance purposes.
Qualification, however, cannot remove the practical barriers to switching cloud providers. Price, service breadth, migration complexity, existing contracts, technical dependencies, and the availability of skilled operators will continue to shape purchasing decisions even when a competing platform carries stronger national certification.
France has now made certified cloud a requirement for a defined class of state data, giving providers a clearer commercial incentive to meet the standard. As OVHcloud takes SNC Cloud Platform into Germany, Italy, and Poland, the next test will be whether trusted public cloud can become a repeatable European service without dissolving into a collection of national exceptions.












