AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

The 24% ownership rule in France’s SecNumCloud framework exposes the limitations of current European sovereignty certifications. Despite claims of sovereignty, US-based providers can still control data through structural ownership arrangements, challenging the promise of true data sovereignty.

European cloud sovereignty frameworks such as France’s SecNumCloud include a key ownership cap of 24% for foreign entities, which aims to limit non-EU control over cloud providers. However, this rule does not prevent US-based companies from exerting control through structural arrangements, exposing a gap between certification claims and actual sovereignty.

SecNumCloud, managed by France’s ANSSI, is a government-backed qualification designed to ensure legal sovereignty over cloud services hosting sensitive data within the EU. Its defining feature is the ownership control rule: foreign companies cannot hold more than 24% ownership individually, or 39% collectively, to maintain sovereignty. This arithmetic-based control measure is unique among European certifications and is intended to prevent non-EU legal reach.

Despite this, US technology giants like Amazon, Microsoft, and Google have found ways to maintain control by restructuring ownership. For example, joint ventures such as Thales-Google’s S3NS and Capgemini-Orange’s Bleu, where US firms hold operational or strategic control, are certified under the framework. These arrangements allow US companies to retain significant influence while complying with the ownership cap, raising questions about the effectiveness of the sovereignty claim.

Experts like Scalingo’s CEO emphasize that achieving compliance with SecNumCloud’s ownership rules is extremely complex—comparable to a level 10 on a 1-10 scale of difficulty—making genuine sovereignty difficult for many providers. As of mid-2026, roughly ten providers, including OVHcloud and Scaleway, hold active certifications, but the structure of control remains a concern.

At a glance
analysisWhen: developing; as of mid-2026
The developmentThe article examines how the 24% ownership cap in France’s SecNumCloud framework reveals the limitations of European cloud sovereignty certifications, especially for US tech giants.

Implications of the 24% Control Limit for Data Sovereignty

The 24% ownership rule in SecNumCloud highlights a fundamental challenge in achieving true European data sovereignty. While certifications like SecNumCloud and C5 attest to technical and organizational controls, they do not fully address the legal reach of foreign governments. US-based firms can still exert control through ownership structures, undermining the sovereignty claims that these certifications promote. This gap matters because it affects how governments, businesses, and regulators interpret security and sovereignty assurances in cloud services.

For European regulators and clients, the key takeaway is that certifications alone do not guarantee immunity from extraterritorial laws like the CLOUD Act. The ownership cap is a step toward sovereignty but does not eliminate control risks entirely. This discrepancy could influence procurement decisions and the future development of European cloud policies, especially as US tech giants adapt their structures to meet these rules.

Amazon

European cloud sovereignty certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

European Cloud Certifications and Sovereignty Challenges

European cloud security standards such as ISO 27001, SOC 2, and BSI C5 focus on security practices—covering access controls, encryption, incident response, and auditability—without addressing legal jurisdiction or control. In contrast, France’s SecNumCloud introduces a legal sovereignty criterion through the ownership control rule, reflecting a broader push for sovereignty within the EU.

However, US hyperscalers like AWS, Microsoft, and Google are structurally ineligible for direct SecNumCloud certification due to their US-based ownership and control. These companies have responded by creating joint ventures or restructuring ownership to stay within the 24% limit while maintaining operational control, effectively bypassing the sovereignty intent of the regulation.

This situation exposes a tension between technical compliance and legal sovereignty, raising questions about whether current frameworks can truly prevent foreign legal influence over EU data infrastructure.

“If the complexity of achieving ISO 27001 is a 1, SecNumCloud is a 10.”

— Scalingo CEO

Amazon

data sovereignty compliance tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent of Actual Sovereignty Achieved Under the 24% Rule

It remains unclear how effectively the 24% ownership cap prevents foreign influence in practice, especially given the creative structuring of ownership by US firms. While the rule limits direct control, the impact of indirect influence through operational control or strategic partnerships is still under assessment. Moreover, legal and political challenges to these arrangements are evolving, and the full implications are yet to be seen.

Amazon

cloud security certification software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Future Developments in European Cloud Sovereignty Policies

Regulators and policymakers are likely to scrutinize ownership structures more closely and may introduce additional measures to reinforce sovereignty, such as stricter controls on operational influence or new legal barriers. US firms are expected to adapt further, possibly by increasing local ownership or establishing European subsidiaries to meet sovereignty standards more transparently. The ongoing debate over the effectiveness of current certifications will influence future regulatory frameworks and procurement practices.

Amazon

ownership control compliance solutions

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Does SecNumCloud certification guarantee data sovereignty?

No, certification primarily attests to security practices and legal compliance within the EU, but US firms can still exert control through ownership and operational arrangements.

Can US-based cloud providers fully comply with European sovereignty rules?

Not entirely, due to legal restrictions like the CLOUD Act. They often use joint ventures or restructuring to meet ownership limits but may still retain influence.

What is the significance of the 24% ownership cap?

It is designed to limit foreign control over cloud providers, but its effectiveness depends on how ownership and control are structured and enforced.

Are there alternatives to current European sovereignty certifications?

Yes, some proposals include stricter legal restrictions, local ownership requirements, or new frameworks that address operational influence more directly.

How does this affect European public sector data hosting?

Under France’s Cloud au Centre doctrine, SecNumCloud is mandatory for hosting sensitive public data, but the ownership control limits still leave some sovereignty gaps open.

Source: ThorstenMeyerAI.com

You May Also Like

How to Build a Safe Local Backup Rotation With External Drives

Secure your data with a reliable local backup rotation; discover essential strategies to ensure your backups remain protected and ready for any situation.

The 90-Day Window Closed. Nobody Sent a Notice.

The 90-day window for responsible disclosure has closed with no notices sent, raising concerns about vulnerability discovery and patching in cybersecurity.

Mysteries of Telegram Data Centers (2022)

An in-depth look at the confirmed facts and ongoing questions surrounding Telegram’s data centers in 2022, exploring their locations, security, and significance.

Web App Hardening – Security Headers, CORS & Content Security Policy

Next-level web app security relies on proper headers, CORS, and CSP configurations to prevent vulnerabilities and protect your digital assets effectively.