Schemes · Cloud & Connectivity

SecNumCloud & C5 — the cloud trust that actually exists

While Europe debates EUCS, France's qualification and Germany's attestation decide real cloud procurements every week. They are different instruments with different philosophies — and knowing which to anchor on is a revenue decision, not a compliance one.

At a glance

SecNumCloud

ANSSI qualification

Version 3.2 includes immunity-from-non-EU-law requirements; gate to French sensitive workloads

C5

BSI attestation

C5:2020 criteria, audited in ISAE-style engagements; German federal & regulated de-facto standard

Philosophies

Qualification vs. attestation

State approval of the provider vs. auditor’s report on controls

Sovereignty

Explicit in SecNumCloud

C5 discloses jurisdiction risks; SecNumCloud excludes them by design

Effort

Years vs. audit cycles

SecNumCloud is an architectural commitment; C5 is achievable on a mature ISO base

EUCS relation

Both fed the draft

Their control sets are the substance EUCS or its successor will absorb

What it is

Two national answers to the question Brussels can't settle

SecNumCloud is a qualification: ANSSI approves the provider after evaluation against a demanding referential covering security controls, operations and — since version 3.2 — structural immunity from extra-EU legal reach (ownership, jurisdiction, data location). It is the entry ticket to French sensitive workloads, the “cloud de confiance” doctrine, and increasingly the reference for sovereignty-minded buyers beyond France.

C5 is an attestation: BSI defines the criteria catalogue, independent auditors examine the provider’s controls in ISAE-style engagements, and the customer receives a detailed report — including transparency criteria on jurisdiction and subcontractors — to feed their own risk decision. No state approval, no sovereignty gate; instead, audit depth and market ubiquity in German federal and regulated sectors.

The philosophical split — state qualifies vs. market reads audits — is exactly the disagreement that has kept EUCS unadopted for six years. Which means both schemes are not stopgaps but the durable reality: their control substance is what any eventual European scheme will absorb, and providers with clean SecNumCloud or C5 positions convert first whenever that happens.

When it's the right tool

Anchor where the revenue is, map everything else

SecNumCloud for French sensitive markets

Public sector, OIV/OSE, health data hosting ambitions — no qualification, no conversation. Budget it as a multi-year architectural programme, including corporate structure.

C5 for German regulated demand

Federal customers, financial and health sectors, and every German enterprise whose auditors grew up on it. On a mature ISO 27001 base, one audit cycle away.

Both, sequenced, for pan-European players

A unified control framework mapped to both (plus ISO 27017/18 and the EUCS draft) turns the second scheme into a delta project instead of a second mountain.

Neither, knowingly, for some

If your buyers accept ISO + SOC 2 and sovereignty never surfaces in deals, say so explicitly in your assurance strategy — and revisit yearly, because the market is moving the other way.

Where it matters

SecNumCloud & C5 in your industry

The full strategic picture

EUCS deadlock, DORA, NIS2 and the anchor-scheme strategy — how national attestations fit the European assurance stack.

Where trust services live

QTSPs and wallet backends host on qualified infrastructure — SecNumCloud and C5 evidence flows into eIDAS supervision files.

Telco cloud & edge

5G cores on cloud infrastructure inherit the sovereignty question — operator procurement increasingly reads these schemes.

The scheme-design lesson

Two schemes, two philosophies, one deadlocked EU process — the sharpest live case study in European scheme politics.

Expert notes

What we tell clients before they commit

SecNumCloud 3.2: the immunity requirements are structural

The 3.2 referential’s protection against extra-EU legal reach is not a control you implement but a corporate condition you satisfy: ownership thresholds, governance independence, contractual and technical arrangements that survive legal analysis. For non-EU-headquartered groups this means joint-venture or licensing structures — decisions made in boardrooms, not security teams, on timescales that dwarf the technical work.

Our position: run the legal-structural feasibility analysis before any control gap assessment. We have seen the reverse order waste a year of engineering on a qualification the corporate structure could never receive.

A C5 attestation’s commercial value lives in how customer risk teams consume the report: scope precision, complementary customer controls, subcontractor transparency, and the handling of deviations. A technically clean report with a fuzzy system description generates more customer questions than it answers — and those questions arrive as sales friction. The best providers treat the C5 report as a customer-facing product with an editorial owner.

Our position: design the audit scope around your customers’ regulatory needs (DORA annexes, NIS2 supply-chain files) so one report feeds their obligations directly. That is what turns an attestation from a cost into a sales asset.

Cloud assurance where it counts

Anchor-scheme strategy, structural feasibility, unified control frameworks, audit preparation — thirty minutes to a map.

Contact us

Request this document

We’ll send you access by email.