Blog

What is Sovereign Cloud? A Practical Guide

Chargement...

10 min read

What is Sovereign Cloud? A Practical Guide

Your data is hosted in France or elsewhere in Europe. Does that make your cloud sovereign?

Not necessarily.

Data location matters, but it is only one part of the equation. You also need to consider who can access your data, which laws apply, which providers and technologies the service relies on, and how much control you retain.

This is what makes “sovereign cloud” so difficult to define. Two services can legally carry the same label while offering very different levels of control, independence, and protection.

To understand how "sovereign" a cloud provider really is, you need to look beyond where the data is stored and examine the guarantees behind the label.

Let's starts with understanding how the concept has evolved over time and, more importantly, what to look for when evaluating a provider’s claims.

What is a sovereign cloud?

There is currently no single official definition of a “sovereign cloud”, nor is the term governed by one common standard.

That is why you will see many very different providers marketing their services as “sovereign”, including companies based outside Europe. AWS, for example, launched its “European Sovereign Cloud” in 2026.

However, the concept is starting to become clearer in Europe. Several criteria now come up repeatedly when cloud sovereignty is discussed: data location, the legal framework, operational control and technological dependencies.

The way these criteria are understood has also evolved considerably over time.

A quick look back helps explain how:


2015: sovereignty starts with where data is hosted

In 2015, the concept was relatively straightforward: a sovereign cloud was first and foremost a cloud where data was hosted in France and the provider was subject to French law.

Technological dependency was already part of the discussion, but sovereignty was still largely viewed through a national lens.

2022: protection from foreign laws became part of the equation

Cloud sovereignty discussions increasingly came to include protection against certain foreign laws.

This shift can be seen in SecNumCloud, the ANSSI qualification for cloud services. Initially focused primarily on cybersecurity, the framework strengthened its requirements around protection from non-European laws.

2025: critical dependencies came into focus

By 2025, the idea of digital sovereignty had broadened further. The focus increasingly shifted to the suppliers, software and infrastructure a cloud service relies on, and, above all, how much control it retains over those dependencies.

A dependency remains relatively limited if the underlying technology can easily be replaced. It becomes much more critical when a component is essential, difficult to substitute, or when a supplier could stop providing it, either by choice or as the result of a government decision, to the point of threatening service continuity.

At that point, the issue is no longer purely technical. It also becomes economic and commercial. If an essential service or technology suddenly becomes unavailable, the impact can extend to the businesses and public services that rely on it. At national scale, the consequences are easy to imagine.

2025–2026: Europe starts defining common sovereignty criteria

Faced with these risks, cloud sovereignty is beginning to take shape at European level.

  • Sovereign Cloud Framework

In 2025, the European Commission developed a Sovereign Cloud Framework to incorporate sovereignty criteria into its own cloud purchases. The framework evaluates services against 48 criteria grouped into eight sovereignty objectives and assigns them a sovereignty level from SEAL-0 to SEAL-4, ranging from no sovereignty guarantees to full control of the service and its critical dependencies within the European Union.

For one of its cloud tenders, for example, the Commission set SEAL-2, corresponding to data sovereignty, as the minimum level required to qualify.

  • Cloud and AI Development Act (CADA)

With the Cloud and AI Development Act (CADA), proposed in 2026, the Commission aims to go further by introducing a common framework across EU Member States.

The idea is that the same sovereignty level should correspond to the same requirements regardless of where in the EU a public-sector buyer is located.

The proposal introduces four increasing assurance levels. Level 1 would represent the minimum for ordinary public procurement, while more sensitive use cases could require levels 2, 3 or 4 depending on the risks involved.

As the level increases, the requirements progressively take into account the location of data and infrastructure, independence from third countries, control of the provider, and control over the software supply chain, in other words, the provider’s technological dependencies.

Though CADA is not yet in force, it is worth watching because it gives a very concrete indication of how the European Union is beginning to structure the concept of cloud sovereignty.

This evolution helps explain why “sovereign cloud” can mean so many different things today, and why the term alone is not enough to assess the guarantees a provider actually offers.

But if we had to sum up what cloud sovereignty means to us (and, increasingly, the European Union), this is how we would define it at Scalingo:

"A sovereign cloud is a cloud that allows an organisation to retain control over its data, applications and hosting environment, while limiting its technological dependencies and its exposure to external actors or jurisdictions."

Can you measure cloud sovereignty?

Since there is still no official dividing line between “sovereign” and “non-sovereign” clouds, to assess "Cloud Sovereignty", the most useful approach is to look at what a service actually allows you to control.

Five questions provide a good starting point:

Where is my data? Who can access it? Which laws apply? Who does the service depend on? And can I switch providers if I need to?

1. Where is my data?

Let’s start with the most obvious question: in which country is your data stored and processed?

The answer needs to be precise enough for you to know where not only your primary data is located, but also every copy of it.

That includes:

  • databases

  • backups

  • logs

  • any replicas

A primary database hosted in Paris, with backups stored on another continent, obviously does not provide the same sovereignty guarantees as a service where all data remains within a clearly defined geographic area.

2. Who can access my data?

Knowing where your data is stored is one thing. Knowing who can access it is another.

Cloud providers may need access to certain data or resources in order to provide support, perform maintenance, or respond to incidents.

So the real question becomes: what level of access is acceptable for your project?

For public or low-sensitivity data, this may not be a major concern. But for confidential, strategic or regulated data, several questions deserve closer attention:

  • who can access it

  • under what circumstances

  • from which countries

  • how access is authorised and logged

  • whether subcontractors may also be involved

There is no single access model that works for every project. But the more sensitive the data, the more important it becomes to know exactly who can do what, under which conditions, and with which safeguards.

That, too, is part of sovereignty.

3. Which laws apply?

As we have already seen, two services can both host their data in France without being subject to the same legal framework.

The reason is simple: the physical location of the data does not, by itself, determine which laws may apply to the provider. You also need to look at where the company is established, which laws it is subject to and, in some cases, who controls it.

A European company can, for example, be owned by a non-European group. This is where so-called extraterritorial laws, such as the U.S. CLOUD Act, become relevant.

What is the CLOUD Act?

Adopted in the United States in 2018, the CLOUD Act (Clarifying Lawful Overseas Use of Data Act) allows U.S. authorities, through a lawful legal process, to request certain data held or controlled by a provider subject to U.S. law, even when that data is stored outside the United States.

The CLOUD Act illustrates an important point about sovereignty: where your data is stored and which laws your provider is subject to are two different questions.

For sensitive processing, this is why the CNIL, France’s data protection authority, recommends favouring providers that are exclusively subject to European law, in order to reduce the risk of access by authorities in third countries.

4. Who does the service depend on?

A cloud service almost never relies on a single provider.

Behind an application, several technical layers may be involved, each with its own suppliers and technologies.

For a PaaS such as Scalingo, for example, the chain might look like this: Your application → PaaS / DBaaS → IaaS → Data Center

Around that chain, additional services are used to operate, monitor and secure each layer.

Does that mean every technology and every supplier involved needs to be European, or even exclusively subject to French law?

Not necessarily. In practice, building a fully European supply chain would be extremely difficult. And, more importantly, not all dependencies carry the same weight.

A peripheral tool that can easily be replaced does not create the same level of risk as a critical component that can access sensitive data, is difficult or expensive to replace, or whose failure could threaten the continuity of the service.

Take a simple example: a French cloud provider may host and operate its service in France while still relying on foreign software to run part of its infrastructure.

If that software is essential to the service, and its vendor can withdraw access, significantly change its terms, or make replacement prohibitively difficult or expensive, part of the service is no longer fully under the provider’s control.

This is another important dimension of sovereignty: limiting the risk that a technical or commercial dependency gives an external actor too much control over how the service operates.

Tools such as the Digital Resilience Index, developed by the Digital Resilience Initiative can help organisations measure their digital dependencies and the level of control they retain.

5. Can I easily switch providers?

When people talk about sovereign cloud, one question is often overlooked: what happens if you want to leave your provider?

Can you easily retrieve your data? In which formats? Does your application rely on standard technologies, or on proprietary services that are difficult to replace? How much work would it take to redeploy your application elsewhere?

This is known as reversibility and highlights something that may seem counterintuitive: choosing a French provider does not automatically protect you from technological lock-in.

Sovereignty also depends on how much freedom you retain to switch providers.

Open source and reversibility

Open, widely adopted technologies based on established standards generally make it easier to understand how your environment works, find equivalent components elsewhere, and migrate when needed.

This approach is important at Scalingo. Wherever possible, we favour these types of technologies to limit vendor lock-in and give our users greater freedom.

So a sovereign cloud in France does not necessarily have to be French? And a French cloud is not necessarily sovereign?

Exactly. Some organisations may be looking for a strictly French approach to sovereignty. For certain projects, having a French operator or French-based infrastructure may be an important requirement.

But “sovereign” does not necessarily mean “entirely French”.

The French government body responsible for digital strategy and transformation, the DINUM, now refers to “sovereign European offerings”, reflecting the growing European dimension of the French State’s cloud strategy.

That distinction is useful: “hosted in France”, “French cloud”, “European cloud” and “sovereign cloud” do not mean the same thing.

Term

What it tells you

What it does not guarantee on its own

Data hosted in France

Where the data is stored

Which jurisdiction applies to the provider

French cloud

The provider is French

That all of its technologies and dependencies are French

European cloud

The service has a European base

That it has no non-European dependencies

Sovereign cloud

An effort to retain control over data and dependencies

A single official definition or certification

What is the relationship between SecNumCloud and sovereign cloud?

Another term that often comes up when sovereign cloud is discussed in France is SecNumCloud.

The two are closely related, but they are not the same thing.

As we have seen, “sovereign cloud” is a broad concept with no single official definition.

SecNumCloud, on the other hand, is a qualification awarded by ANSSI, France’s national cybersecurity agency, to a specific cloud service that meets detailed requirements around security, data location, operational control and legal protection.

That is what makes SecNumCloud useful: it provides a concrete way to verify several of the guarantees commonly associated with cloud sovereignty.

But SecNumCloud and sovereign cloud are not interchangeable terms. A provider can market an offering as sovereign without holding SecNumCloud qualification, and SecNumCloud itself does not define what a “sovereign cloud” is.

→ Learn more about SecNumCloud

What about “trusted cloud” or “cloud de confiance”?

These are something else again.

Under the French State’s cloud policy, “trusted commercial cloud” refers to commercial cloud offerings that hold SecNumCloud qualification AND are protected against extraterritorial regulations.

These services can, in particular, be used to host certain sensitive government data.

In short: “Sovereign cloud” is a concept. SecNumCloud is a qualification. “Trusted cloud” is a category of cloud offering defined by the French State.

The French State also operates its own cloud infrastructure.

The interministerial cloud is reserved for government departments and can host sensitive services, processing workloads and data on infrastructure controlled and operated by the State.

It includes Nubo, operated by the DGFiP (France’s Directorate General of Public Finances, responsible for tax and public finance administration), and Cloud π (Pi), operated by the French Ministry of the Interior.

Depending on the nature and sensitivity of a project, the State can therefore choose between its own cloud infrastructure and commercial cloud services, whether or not they fall into the “trusted cloud” category.

→ See how a key French public service runs on Scalingo

Who should choose a sovereign cloud?

Cloud sovereignty is especially relevant for government bodies, local authorities, healthcare organisations, strategic industries, and companies handling sensitive data.

But it is not limited to those use cases.

A SaaS company may want to reassure European customers about where their data is stored and processed.

An SME may want to reduce its dependence on a single provider.

A technical team may favour standard technologies to keep more flexibility in its architecture.

A French or European organisation may also decide that supporting a local cloud ecosystem is part of its broader strategy.

There is no single level of sovereignty that suits every organisation. The right level of control depends on your use case, the sensitivity of your data, and the risks you need to manage.

Is Scalingo a sovereign cloud provider?

Yes. Based on the criteria outlined above, Scalingo follows a French and European approach to cloud sovereignty.

We are a French company based in Strasbourg 🇫🇷

Our cloud regions are located in France and run on infrastructure provided by OUTSCALE, a French cloud infrastructure provider. The osc-secnum-fr1 region, in particular, runs on SecNumCloud-qualified IaaS infrastructure.

We also aim to limit critical dependencies and preserve reversibility. Wherever possible, we rely on widely adopted open-source technologies and open standards, making it easier to move your applications and data elsewhere if you choose to.

Our philosophy is simple:

A PaaS should give you good reasons to stay because it makes your life easier, not because it prevents you from leaving.

That is what sovereign cloud means to us at Scalingo: a French and European environment designed around control over hosting, critical dependencies, and reversibility.

Sovereign cloud: five things to remember

If you remember only five things about sovereign cloud, make them these:

  1. Hosting your data in France (or Europe) is not enough to make a cloud sovereign.

  2. Sovereignty is fundamentally about control: control over data, operations, the legal framework and critical dependencies.

  3. Sovereign cloud, trusted cloud and SecNumCloud are not the same thing.

  4. Sovereignty needs to be assessed across the entire cloud chain, from the data center to the platform and the services used by the application.

  5. There is no single level of sovereignty that suits every project. The right level depends on your data, risks and constraints.

So the question to ask a cloud provider is not simply: “Where is my data hosted?”

It is: “How much control will I actually retain over my data, my applications, and the services they depend on?”

______

Sovereign cloud FAQ

Still have questions about sovereign cloud? Here are some quick answers to the most common ones.

Does a sovereign cloud have to be French?

No. There is no official definition requiring a sovereign cloud to be 100% French.

Strictly French sovereignty may be desirable for certain projects, but public authorities now also refer to “sovereign European offerings.”

Can a European cloud be sovereign?

Yes. Having a European provider can contribute to a sovereignty strategy, particularly in terms of jurisdiction and autonomy.

But “European” does not guarantee everything on its own. You still need to look at where the data is stored, who can access it, which technologies are used and which other providers the service depends on.

Is a cloud hosted in France automatically sovereign?

Not necessarily. Hosting data in France gives you control over its location, but it does not tell you which laws apply to the provider, who can access the data, or which other providers and technologies the service depends on.

Does the GDPR require organisations to use a sovereign cloud?

No. The GDPR does not generally require organisations to use a service described as a “sovereign cloud”.

It does, however, impose obligations relating to the protection of personal data and, in particular, regulates transfers or access to that data outside the European Economic Area.

Can a U.S. cloud provider offer a sovereign cloud?

From a legal point of vue, yes.

It can market an offering as “sovereign”, because the term is not tied to a single official qualification.

That is precisely why it is important to look beyond the label.

A U.S. provider may, for example, host your data in France while still being subject to U.S. law in certain circumstances.

Its offering may therefore satisfy some sovereignty criteria without necessarily meeting all of the requirements that matter to you.

Ultimately, you need to decide where you want to draw the line.

Do certain types of data have to be hosted on a sovereign cloud?

Not under that specific name. There is no general rule requiring organisations to use a service carrying the “sovereign cloud” label.

However, some public-sector organisations and some particularly sensitive French State data are subject to stricter requirements.

Under the French State’s Cloud au centre policy, State administrations can use either the State’s internal cloud infrastructure or commercial cloud services that meet enhanced security and sovereignty requirements.

For particularly sensitive data, the rules are stricter. This includes data whose compromise could affect public order, public security, health or life, or intellectual property. Simply being personal data, sensitive personal data under the GDPR, or health data does not automatically mean these rules apply.

Since August 2026, SecNumCloud 3.2 has been the reference framework for these requirements when a private cloud provider is used.

In practice though, compliance can be demonstrated in two ways: through a qualification issued by ANSSI, such as SecNumCloud, or through an EU or EEA certification that ANSSI recognises as offering an equivalent level of protection.

Is an HDS-certified hosting provider necessarily sovereign?

No. HDS is a certification specifically designed for the hosting of health data. It is not a sovereign-cloud label.

The current framework, HDS 2.0, nevertheless strengthens several sovereignty-related requirements.

For example, data must be physically hosted within the European Economic Area, and hosting providers must provide greater transparency around data access or transfers from third countries.

A version 2.1 is also planned for October 2026. It is expected to go further, in particular by strengthening contractual transparency requirements relating to data transfers and potential exposure to non-European legislation.

However, HDS does not provide the same level of protection as SecNumCloud when it comes to legal extraterritoriality.

HDS addresses a specific requirement around the protection of health data. On its own, it does not guarantee every criterion that may be associated with a sovereign cloud.

Is a sovereign cloud more secure?

Not necessarily. Sovereignty and cybersecurity are closely related, but they do not answer exactly the same question.

A cloud can provide strong control over data location, jurisdiction and dependencies without that being enough to secure a poorly configured application.

Conversely, an infrastructure can be highly secure without providing the level of sovereignty you are looking for.

Who are the main sovereign-cloud providers in France?

The French sovereign-cloud market includes several types of providers.

Some specialise in infrastructure, others in application platforms or managed databases, while some operate across several layers of the cloud stack.

French providers active in this market include Scalingo, OVHcloud, OUTSCALE, Cloud Temple, Scaleway and Clever Cloud.

We will cover the main sovereign-cloud providers in France, and the criteria you can use to compare them, in a separate guide.

""

Jennifer Taylor

At Scalingo, Jennifer leads growth and marketing initiatives, helping shape the company’s voice in the fast-evolving PaaS and cloud ecosystem. She loves translating complex cloud concepts into clear, engaging insights.

Stay Updated

Get articles and platform updates in your inbox.

Ready to Deploy with Confidence?

Experience zero-downtime deployments, intelligent auto-scaling, and fully managed infrastructure. Start deploying your applications on Scalingo today.

No credit card required • Deploy in minutes • Cancel anytime

""

Deploy your first app or database

Let's start building together

Join developers who chose a platform built for fast delivery and calm production, with European values and human support.

""

Deploy your first app or database

Let's start building together

Join developers who chose a platform built for fast delivery and calm production, with European values and human support.

""

Deploy your first app or database

Let's start building together

Join developers who chose a platform built for fast delivery and calm production, with European values and human support.