SecNumCloud is a qualification: ANSSI approves the provider after evaluation against a demanding referential covering security controls, operations and — since version 3.2 — structural immunity from extra-EU legal reach (ownership, jurisdiction, data location). It is the entry ticket to French sensitive workloads, the “cloud de confiance” doctrine, and increasingly the reference for sovereignty-minded buyers beyond France.
C5 is an attestation: BSI defines the criteria catalogue, independent auditors examine the provider’s controls in ISAE-style engagements, and the customer receives a detailed report — including transparency criteria on jurisdiction and subcontractors — to feed their own risk decision. No state approval, no sovereignty gate; instead, audit depth and market ubiquity in German federal and regulated sectors.
The philosophical split — state qualifies vs. market reads audits — is exactly the disagreement that has kept EUCS unadopted for six years. Which means both schemes are not stopgaps but the durable reality: their control substance is what any eventual European scheme will absorb, and providers with clean SecNumCloud or C5 positions convert first whenever that happens.