More protective of extra-European laws

SecNumCloud version 3.2 explicit protection criteria vis-à-vis non-European laws. These requirements thus ensure that the cloud service provider and the data it processes cannot be subject to non-European laws. SecNumCloud 3.2 also integrates feedback from the first assessments and specifies the requirement for the implementation of penetration tests throughout the qualification life cycle. Concerning the solutions already qualified SecNumCloud, they keep their security Visa and the ANSSI will support if necessary the companies concerned to ensure the transition.

“In order to foster a protective digital environment that is in step with technological developments, including for the most critical data and applications, the identification of trusted cloud services is essential. The SecNumCloud qualification contributes to meeting this need by attesting to a very high level of requirement in terms of digital security, both from a technical, operational and legal point of view” specifies Guillaume Poupard, Director General of ANSSI.

The SecNumCloud evaluation strategy

All cloud services are eligible for SecNumCloud qualification. Indeed, the qualification is adaptable to the different offers: SaaS (Software