A cloud region in Paris, a contract in French, a European flag on the sales presentation: enough to reassure an executive committee. Not necessarily enough to protect its data. Looking ahead to September 2026, sovereign cloud poses a very practical question for businesses: what risk does the price premium actually reduce? The answers differ depending on whether the focus is local hosting, promised legal immunity or technical autonomy. This article distinguishes established arrangements from prospective developments, without assuming that announced offerings or qualifications will materialize.
Three types of sovereignty, three different bills
The word “sovereign” brings together needs that do not overlap. Location concerns where data is stored and processed. Legal protection depends on the laws applicable to the provider and to entities that may access the information. Operational autonomy means the ability to administer the service, keep it running and leave it without excessive dependency.
A business can secure the first without the other two. Its databases are hosted in France, but maintenance involves an overseas team; backups remain in Europe, but some technical logs follow a different route. Conversely, a French provider may offer reassuring governance while using proprietary software that is difficult to replace. Buying “sovereign” therefore does not mean buying total independence: it means choosing acceptable dependencies.
Location: necessary, rarely sufficient
For a CIO, data residency remains the easiest point to explain. It helps meet certain contractual requirements, sometimes reduces latency and makes audits clearer. But a data center address does not describe the entire chain. Backup copies, metadata, support tickets and administrative access also need scrutiny.
The GDPR does not, as a general rule, require all personal data to remain within the European Union. Among other things, it regulates transfers to third countries. After the Court of Justice of the European Union invalidated the Privacy Shield in 2020, the Commission adopted a new adequacy decision in July 2023 for US organizations participating in the transatlantic framework. This mechanism concerns personal data transfers, not a general certification of sovereignty.
The right question for vendors then becomes: “What data can leave, through what mechanism, and who can access it?” A precise answer, appended to the contract, is worth more than a blanket promise of European storage. The premium is justified if it funds verifiable operational separation, access restrictions and auditable evidence.
The law: buying protection, not invulnerability
The US CLOUD Act is a focal point for concern. Under the conditions set out in law, it can allow US authorities to demand data under the control of a provider subject to their jurisdiction, even when that data is stored abroad. It does not provide permanent, automatic access to every European server. But it is a reminder that the geography of hardware does not override the geography of the law.
Examining a provider’s stated nationality is therefore not enough. Businesses need to understand its ownership and control, subcontractors, legal obligations and, above all, who actually has the ability to hand over intelligible data. A European subsidiary of a foreign group does not automatically offer the same separation as an independent operator. Conversely, the use of foreign technology does not, on its own, prove that its vendor has access to the data.
What SecNumCloud really provides
In France, ANSSI’s SecNumCloud qualification provides a stronger benchmark than a marketing self-declaration. Its framework combines technical, operational and legal requirements, particularly to address risks associated with extraterritorial laws. The scope nevertheless matters: a qualification covers a specific offering, not a group’s entire portfolio. Starting the process or announcing qualification as a goal is not the same as obtaining it.
The Bleu project, backed by Orange and Capgemini and built around Microsoft technologies, and S3NS, created by Thales with Google Cloud, illustrate a strategy already underway: combining global technologies with French operations and governance. Their promise must be assessed service by service, based on the safeguards actually available and the qualifications obtained at the time of purchase. The industrial partnership is no substitute for that verification.
Encryption does not solve everything
“You keep the keys”: the argument sounds decisive. Yet businesses still need to ask which keys, where they are held and who uses them. Encryption at rest helps protect against the exposure of storage media; it does not necessarily prevent the platform from processing data in plaintext. A customer-managed key may itself be used by the service while it is running.
Keys held outside the cloud, robust authentication and tightly controlled privileged access strengthen protection. Confidential computing can also reduce certain risks during processing. None of these measures, however, removes the need to examine the application, recovery procedures and administrators’ powers. A useful safeguard addresses a threat scenario, rather than simply invoking the word “encryption.”
Technical dependency, an often overlooked cost
A business can legally protect its data while remaining locked into its architecture. Proprietary databases, serverless functions, artificial intelligence tools and platform-specific interfaces make migration lengthy and risky. Lock-in stems as much from acquired skills and existing code as from transfer fees. A European cloud can create this dependency too.
The European Data Act, scheduled to apply generally from September 2025, includes provisions to reduce barriers to switching data processing service providers. Its practical impact will depend on the services and their implementation. An obligation to facilitate exit does not make two platforms technically interchangeable. When preparing a purchase for 2026, it is better to test an export and a restore on another platform than to rely solely on an exit clause.
When is the premium worth paying?
The right calculation compares risks and total costs, not just the price of a virtual machine. An offering subject to stricter controls may cost more to operate, provide fewer services or require applications to be adapted. It may also avoid repeated audits, help secure a sensitive contract and limit the consequences of an incident.
- Worth paying for: enforceable commitments, a relevant qualified scope, controlled administration and tested continuity.
- Worth negotiating: audit evidence, notification deadlines, exit assistance and migration costs.
- Keep in perspective: flags, in-house labels and vague promises of absolute independence.
What next? For September 2026 and beyond, the most plausible scenario is not a wholesale shift to sovereign cloud, but finer segmentation. Trade secrets, sensitive data and critical functions would call for stronger protections; other uses could prioritize cost and breadth of functionality. Maturity will be less about buying a label than about being able to demonstrate, backed by a contract and an exit test, what each additional euro actually protects.


