# strubel-secnumcloud-anssi-linkedin-2026-01-06

## Veille

SecNumCloud ANSSI - cloud security qualification, extraterritorial risks, hybrid offerings

## Titre Article

SecNumCloud en (pas si) bref

## Date

2026-01-06

## URL

https://www.linkedin.com/pulse/secnumcloud-en-pas-si-bref-vincent-strubel-505ge/

## Keywords

SecNumCloud, ANSSI, qualification, sovereign cloud, cybersecurity, CLOUD Act, extraterritoriality, sensitive data, hybrid offerings, data localization, GDPR

## Authors

Vincent Strubel

## Ton

Profile: Educational LinkedIn article, expert yet accessible register, institutional authority perspective (ANSSI director).
Style: Structured didactic tone with an integrated FAQ. Organization into clear thematic sections covering definition, risks, limitations, and frequently asked questions. Uses concrete metaphors ("house with armored shutters but door closed by a curtain"). Balance between technical rigor and accessibility. Clarification of persistent misunderstandings. Target audience: CIOs, CISOs, IT decision-makers, cloud professionals.

## Pense-betes

- **Context**: SecNumCloud qualification of a "hybrid" offering (US tech operated by a European provider) generated debates
- **Definition**: ANSSI qualification certifying a high level of security for sensitive uses by the French State and companies
- **Reference framework**: More than 1200 requirements verified in the evaluation process
- **Extraterritorial risk**: Protection against the CLOUD Act and American FISA laws
- **Kill switch**: European provider cannot be forced to cut services for sanctions/export restrictions
- **Capitalistic requirements**: European registered office and capitalization, inaccessibility of data to non-EU subcontractors
- **Key limitation**: "SecNumCloud does not mean the absence of dependency" - impossible to fork the entire stack from Linux
- **EU localization**: Mandatory - subjects infrastructure to European law, facilitates CERT-FR intervention
- **Cyberattacks**: Main threat covered by strong segregation, isolated administration, systematic encryption
- **Human risk**: Entire HR management chapter so no employee can compromise the service without detection
- **Sovereignty**: 3 issues (not being an easy victim, applying one's own rules, freedom of choice) - SecNumCloud addresses the first two
- **Hybrid offerings**: Satisfy exactly the same requirements as other qualified offerings
- **Metaphor**: Purely capitalistic or technical criteria alone = house with armored shutters + bars but a curtain for a door

## RésuméDe400mots

Vincent Strubel, Director General of ANSSI, published a clarifying article on LinkedIn following debates triggered by the SecNumCloud qualification of a "hybrid" cloud offering using American technology operated by a European provider.

SecNumCloud is a qualification issued by ANSSI certifying that a cloud service presents a high level of security suited to sensitive uses by the French State and companies. The evaluation process verifies more than 1200 requirements covering technical, legal, and organizational risks.

Regarding extraterritorial law, SecNumCloud guarantees that data is not subject to non-European provisions against which customers would have no recourse. The requirement for a European provider (registered office and capitalization), the inaccessibility of data to non-European subcontractors, and operational autonomy protect against injunctions under the CLOUD Act or American FISA laws. The "kill switch" scenario is also covered: a qualified European provider cannot be forced to cut its services due to sanctions or export restrictions.

Strubel nonetheless acknowledges an important limitation: "SecNumCloud does not mean the absence of dependency." No player can "fork and maintain in autarky the entire cloud technology stack, from the Linux kernel to Openstack." A cutoff of access to non-European suppliers would lead to a progressive degradation of security.

Data localization within the European Union is mandatory, subjecting physical infrastructure to European law and facilitating intervention by CERT-FR and other state services in the event of an incident.

On the technical level, cyberattacks constitute "the most tangible threat weighing on sensitive cloud uses." The reference framework imposes strong segregation between customers, an isolated administration chain, secure update management, and systematic data encryption. Human risk is covered by an entire chapter on human resources management.

In response to frequently asked questions, Strubel specifies that hybrid offerings satisfy exactly the same requirements as other qualified offerings. He uses an illuminating metaphor: having only capitalistic criteria or only technical criteria would be like having a house "with armored shutters and bars on the windows, but whose door would be closed by a curtain."

SecNumCloud addresses two of the three digital sovereignty issues (not being an easy victim, applying one's own rules) but does not create alternative technological solutions. It is a formalized cybersecurity tool, not an industrial policy.

## GrapheDeConnaissance

- Vincent Strubel —dirige→ ANSSI (ORGANISATION, 0.98)
- ANSSI —a_créé→ SecNumCloud (CONCEPT, 0.98)
- SecNumCloud —mesure→ plus de 1 200 exigences vérifiées (MESURE, 0.95)
- SecNumCloud —résout→ risque extraterritorial (CLOUD Act, FISA) (CONCEPT, 0.95)
- siège social et capitalisation européens —fait_partie_de→ SecNumCloud (CONCEPT, 0.93)
- localisation des données en UE —fait_partie_de→ SecNumCloud (CONCEPT, 0.93)
- Vincent Strubel —affirme_que→ « SecNumCloud ne signifie pas l'absence de dépendance » (CITATION, 0.9)
- Vincent Strubel —affirme_que→ les offres hybrides satisfont exactement les mêmes exigences que les autres offres qualifiées (AFFIRMATION, 0.92)
- SecNumCloud —résout→ 2 des 3 enjeux de souveraineté numérique (CONCEPT, 0.88)
- localisation des données en UE —permet→ CERT-FR (CONCEPT, 0.85)

---
Canonical: https://www.thekb.eu/en/fiches/strubel-secnumcloud-anssi-linkedin-2026-01-06/
