Certifications and Sovereignty: the way out
Five different things are all called “sovereign cloud”. Only one of them actually removes the jurisdiction of a foreign state. This page puts them in order — and shows that the solution already exists, has a name, and has already been built elsewhere.
The ladder: five levels, only two protect you
| # | Model | Examples | Exposure to the CLOUD Act |
|---|---|---|---|
| 0 | Global US cloud | Azure, AWS, Google Cloud | Full |
| 1 | Data residency in the EU | “EU Data Boundary”, European regions | Full — it protects geography, not jurisdiction |
| 2 | Contractual sovereignty offered by the hyperscalers | AWS European Sovereign Cloud, Microsoft Cloud for Sovereignty, Google Assured Workloads | Full — the parent company remains American |
| 3 | Trusted cloud: US technology under licence, operated by an independent European entity | Bleu (Orange + Capgemini on Azure) S3NS (Thales, on Google technology) | Excluded — if SecNumCloud-qualified |
| 4 | Native European infrastructure | OVHcloud, IONOS, Scaleway, Deutsche Telekom, Aruba, Seeweb | None |
Levels 1 and 2 are the two most common misunderstandings: where the data sits and what the contract says do not change who is legally compelled to hand it over.
The clearest statement that data localisation does not protect against foreign jurisdiction does not come from us. It comes from a Google Cloud whitepaper addressed to its own customers:
“the CLOUD Act clarifies that the U.S. government can compel production of data where the data is under the ‘possession, custody, or control’ of a provider subject to US jurisdiction, regardless of where that data is physically stored. In other words, data localization requirements do not impact whether a cloud provider may have to disclose data in response to a government request.”The same document offers encryption so that data stays unreadable “even if Google is compelled to turn over the data”. The defence on offer is technical, not legal — which is precisely the distinction this page is about.
Google Cloud, Government Requests for Cloud Customer Data, February 2022, p. 5 — official whitepaper.
Microsoft operates “national clouds”: instances that are physically and logically isolated, confined within a country's borders and run by local personnel. In China, Microsoft does not operate the service at all — it licenses the technology to a local company.
“Microsoft is the technology provider, but Microsoft doesn't operate the service. 21Vianet independently operates, provides, and manages the delivery of Microsoft cloud services… and operate Azure and Office 365 datacenters that keep data within China.”Microsoft Learn — Microsoft national clouds (official vendor documentation).
The United States demanded a cloud run under its own rules: Microsoft built it. China demanded a cloud run by a Chinese company: Microsoft licensed the technology and stepped out of operations. France demanded it: Bleu and S3NS were created. Italy has not demanded it — and does not have it. This is not a technical or commercial obstacle: it is a matter of political demand.
Which certification actually contains the immunity clause
| Scheme | Country | Immunity from non-EU law |
|---|---|---|
| SecNumCloud 3.2 (ANSSI) | 🇫🇷 France | YES — immunity from extraterritorial legislation, European control of capital, European operational staff. The only national scheme that structurally excludes the CLOUD Act |
| HDS | 🇫🇷 France | Mandatory for health data; separate from SecNumCloud |
| BSI C5 | 🇩🇪 Germany | NO — a catalogue of requirements with independent auditor attestations |
| EUCS | 🇪🇺 EU | NO — and the scheme does not yet exist. In June 2026 the Commission states that EUCS “has not yet been adopted”: no legal act, no certificates issued. The sovereignty requirements were removed in March 2024 and never reinstated |
| ACN qualification | 🇮🇹 Italy | NO — verified on the full text of the regulation (88 pages, all four annexes). The words “extraterritorial”, “CLOUD Act”, “nationality”, “registered office”, “parent company”, “capital” and “third country” never appear |
SecNumCloud-qualified as of mid-2026: OVHcloud; S3NS (Thales, qualified on 17 December 2025 — the first qualification covering IaaS, PaaS and CaaS together). Bleu applied in 2025–2026 and had not yet obtained qualification.
France and Italy, article by article
We read both texts in full: the Italian cloud Regulation (Directorial Decree 21007/24, 88 pages including all four annexes) and the French SecNumCloud 3.2 reference framework (ANSSI, 8 March 2022, 55 pages). This is what they say.
A lexical scan of the entire primary text returns zero occurrences of:
extraterritoriale · CLOUD Act · nazionalità · sede legale · capogruppo · capitale · assetto proprietario · paese terzo · sovranità · PSN
Where such a requirement should have appeared — Annex 4, the subjective requirements for qualification levels QC1–QC4 — what one finds instead are ISO certifications (9001, 27001, 22301, 20000) and CSA STAR L2. The only geographic requirement concerns the certifying body, not the supplier — and it accepts the IAF MLA, which includes the American accreditation body.
One provision does address foreign access, and it applies only to data classified as strategic: the supplier must report to ACN and to the administration “any request for access to data or metadata by non-EU entities”, granting access “only following explicit authorisation”.
It is a procedural obligation that presupposes and admits foreign access, rather than structurally excluding it. And it is unenforceable in exactly the case it is meant for: a CLOUD Act order accompanied by a gag order legally forbids the provider from making that very report. The rule asks for a notification that American law prohibits.
What the French framework requires instead
SecNumCloud 3.2, §19.6 “Protection vis-à-vis du droit extra-européen”, imposes cumulative conditions:
- registered office, central administration and principal place of business within the EU;
- non-EU capital and voting rights capped at 24% individually and 39% collectively, whether direct or indirect, with no veto rights and no power to appoint the majority of the governing bodies;
- technical impossibility for a non-EU third company to obtain the data;
- operational autonomy, or cascading qualification of subcontractors;
- links with foreign governments treated as an assessment factor.
And §19.2.c adds: “Les opérations d'administration et de supervision du service doivent être réalisées depuis l'Union Européenne” — administration and supervision of the service must be carried out from within the EU. This requirement too is absent from the Italian text.
The difference in one sentence
ANSSI pulls three levers: corporate (who owns the supplier), technical (who can decrypt) and operational (who administers the service). ACN pulls only the technical one, in an attenuated form, and replaces the corporate lever with a procedural notification. The corporate lever — the only one that actually neutralises the CLOUD Act — is entirely absent.
Three further findings
- Strategic data does not require the National Strategic Hub. Qualification levels QC3 or QC4 are sufficient (art. 17(4)(c)). The PSN is never mentioned in the regulation.
- Exclusive key custody (HYOK) is required only at QC4. Strategic data may therefore legitimately reside on a QC3 service with BYOK alone — a model under which the provider retains the technical ability to access the data.
- EU localisation is waivable — “save for substantiated and documented reasons of a regulatory or technical nature” — and it is territorial, not jurisdictional: an Irish datacentre belonging to a US-owned subsidiary satisfies it while remaining fully within the CLOUD Act's reach.
Sources: Directorial Decree 21007/24 and annexes (ACN, in force since 1 August 2024) — acn.gov.it; SecNumCloud 3.2 reference framework (ANSSI, 8 March 2022) — cyber.gouv.fr.
EUCS High+: what it actually is
“High+” is not a higher technical tier — and it was never a formal level at all: the Cybersecurity Act provides for three (Basic, Substantial, High). “High+” was the negotiating label for the immunity criteria: the legal protection that France already has in SecNumCloud, raised to a European standard.
The criteria were removed in March 2024 and never reinstated. The Cloud and AI Development Act proposed in June 2026 formalises the opposite principle — “cybersecurity must be distinguished from sovereignty requirements” — and moves sovereignty elsewhere: into its own Union assurance levels 1 to 4.
Its level 4 is, in substance, the High+ that never happened: EU establishment, EU-citizen personnel, no third-country control, technical support provided only from within the EU, and effective separation between the parent company and its non-EU subsidiaries. Two caveats matter: it binds public procurement, not the market at large, and it is still a proposal under negotiation.
The open letter of 10 June 2024 makes two points that dismantle it. First, the scheme is voluntary:
“Cloud providers not meeting the High+ criteria will remain fully able to offer their solutions to us without any market distortion.”
Second, the request comes largely from cloud users — banks, insurers, defence contractors, public bodies — not from European vendors defending a market. And the letter itself notes that “several non-EU providers are progressively setting up corporate partnerships within the EU”: the door for Microsoft, Google and AWS is explicitly open, provided someone else operates the service.
Who is asking for it: 62 organisations
The initiative is coordinated by the Brussels office of Airbus. Among the supporters:
Defence and aerospace
Airbus · Dassault Aviation · MBDA · Saab · Kongsberg · Navantia · Leonardo · Fincantieri · ASD
Banking, insurance, public services
Banque de France · Crédit Agricole · Caisse des Dépôts · Generali · France Assureurs · Groupe La Poste · Post Luxembourg · EDF · Veolia · Air France-KLM
European cloud and telecoms
Aruba · OVHcloud · IONOS · Deutsche Telekom · Orange · Proximus · A1 · Stackit · Cloud Temple · CloudFerro · Clarence · Oodrive · Docaposte · OpenNebula
Aruba is the largest Italian cloud provider — and it is asking Brussels for the immunity criterion that has not been written in Rome.
IT, industry and user associations
Capgemini · Thales · Sopra Steria · Eviden · Dassault Systèmes · Telecom Italia (TIM) · Secunet · SiPearl · Cigref · Beltug · CIO Platform Netherlands · European Digital SME Alliance
Source: eucshighplus.eu and the open letter of 10 June 2024.
On 16 July 2026, after a six-month tender in which some fifty providers were consulted, Airbus awarded the hosting of its own critical applications to the French provider Scaleway. It assessed the bidders on three dimensions — one of which was, verbatim, “European jurisdiction, data protection and protection against non-European extraterritorial legislation”.
Catherine Jestin, Executive Vice President Digital, Airbus:
“By integrating a trusted, high-performance cloud environment that keeps our critical data assets shielded from foreign extraterritorial laws, we are ensuring that our digital infrastructure keeps pace with our aerospace innovation, while maintaining control and resilience of our industrial operations.”
The organisation that asked for the criterion then used it as a client. It is not an opinion about sovereignty: it is a company that put its own criterion out to tender and signed a contract on it. The perimeter is around 70 critical applications by 2028, with a potential of up to about 900 over five to six years.
What this case does not say. Airbus is a private company, not a State: no legal obligation, no public procurement, no legal precedent — and it has an evident industrial interest in European providers. Nor did it “abandon” its previous provider: the official announcement does not name it, and Jestin states that Airbus does not intend to move away from all non-European solutions, but to choose according to how critical the data is.
Sources: Scaleway, official announcement, 16 July 2026 · Airbus, “Building resilience”, 17 June 2026.
It would be wrong to say that Italy did not ask for sovereignty. It asked for it, and it helped write it. In July 2021 Italy was co-author, with France, Germany and Spain, of the proposal that added immunity from foreign law to the EUCS “high” level. In December 2022 it did not sign the non-paper of the eleven member states opposing those requirements. And in April 2024, after the vote at the certification group, the Undersecretary for Innovation publicly objected that the proposal on the table “would allow providers — including those operating under the jurisdiction of governments outside the EU — to be certified as secure”, adding that other countries, “including Italy, have called for higher and stricter standards”.
Italian industry pulled in the same direction: Leonardo, Fincantieri, Generali and Telecom Italia supported the call for European immunity criteria — and Leonardo and TIM are shareholders of the National Strategic Hub. On the opposite side, AmCham Italy signed the May 2024 declaration to adopt the scheme without sovereignty requirements.
So the gap is not between Italy and its own words. It is between what Italy asked for in Brussels and what it wrote at home. For five years Italy pressed for an immunity clause at European level and lost that battle. In the same years it never introduced the equivalent clause into its own national qualification scheme — the one instrument that did not depend on anyone else's vote.
In one line
The point is not to stop using Microsoft. It is to stop letting Microsoft operate the service.
The model exists, it has a technical name (trusted cloud), a certification that measures it (SecNumCloud 3.2, and prospectively EUCS High+), and it has already been built — in the United States, in China and in France. In Italy what is missing is the political decision to require it.
Sources and further reading
- Microsoft Learn — national clouds
Vendor's own documentation: how Microsoft's national clouds work and who operates them.
- eucshighplus.eu
The campaign for the inclusion of High+ criteria, with the full list of supporters. Coordinated by Airbus.
- Open letter of 10 June 2024 (PDF)
The users' position: why voluntary High+ criteria do not distort the market.
- Comparison of European certifications: SecNumCloud, HDS, BSI C5
Specialist secondary source on the requirements of each scheme and which providers are certified.
- sota.io — EUCS assurance levels and which providers qualify
A detailed reading of the tiers and a provider-by-provider table. Read with care: the author is a commercial cloud provider that lists itself among the qualifying suppliers, and its description of the High tier conflicts with the documented removal of the sovereignty requirements in March 2024. Useful for understanding the debate, not to be used as an authoritative source on the scheme's current state.
Verification note. The absence of an immunity clause in the Italian scheme has been verified directly on the full primary text of Directorial Decree 21007/24, including all four annexes: it is a documented absence, not an inference. The status of the EUCS is taken from the Commission's own words in the Cloud and AI Development Act proposal of 3 June 2026, which states that the scheme “has not yet been adopted”. Commercial sources describing an EUCS “High” tier that already requires EU ownership are not reliable on this point. On Italy's negotiating position, the primary documents (the 2021 non-paper, the certification group minutes) are not public: what is reported here rests on institutional and press sources, and is being pursued through access to documents. We will update this page as verification proceeds.