📊 Full opportunity report: Debunking Myths: The 24% Rule And AI Cloud Sovereignty Certifications on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
This article clarifies the actual significance of the French SecNumCloud ownership cap, debunks myths around the 24% rule, and explains the differences between sovereignty certifications. It highlights why these standards matter for European data control and legal jurisdiction.
European cybersecurity standards are often misunderstood, particularly the French SecNumCloud framework’s unique ownership cap of 24%. This rule is a key legal sovereignty test, and recent discussions clarify its purpose and impact for cloud providers operating in Europe.
SecNumCloud, created by France’s ANSSI in 2016, is a government-issued qualification that certifies not just security practices but legal sovereignty. The core requirement is that companies controlling the service must have no more than 24% ownership by non-EU entities, checked via a simple arithmetic cap table.
Unlike other certifications such as ISO 27001 or BSI C5, which verify operational security, SecNumCloud explicitly tests ownership and jurisdiction. It mandates EU data residency, EU legal control, and immunity from non-EU extraterritorial laws, making it a unique legal sovereignty benchmark.
As of mid-2026, only a handful of providers, including OVHcloud and Scaleway, hold an active SecNumCloud qualification. This requirement is mandatory for hosting sensitive French public-sector data and is being extended to critical infrastructure under the Cloud au Centre doctrine.
The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty
ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.
C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.
Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.
The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.
Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.
Implications of the 24% Ownership Cap for Cloud Providers
The 24% ownership rule is a practical and measurable way to ensure legal sovereignty over data in European cloud services. It directly influences how international companies structure their control and ownership, affecting their ability to operate within French and broader European markets. This rule challenges U.S.-based hyperscalers, who must adjust ownership structures or partner with European firms to meet sovereignty standards. It underscores the shift toward legal control as a key component of data sovereignty, beyond traditional security certifications.
European data sovereignty certification
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
European Sovereignty Certifications and Their Legal Focus
European cloud sovereignty standards have evolved to address the legal and political risks of data control. Certifications like ISO 27001 and BSI C5 focus on operational security, but do not address jurisdiction or ownership. SecNumCloud, by contrast, explicitly tests ownership and legal control through its 24% cap, reflecting a broader move toward embedding sovereignty into certification frameworks.
While certifications like C5 require disclosure of jurisdiction, they do not prevent control by foreign entities. SecNumCloud’s unique approach makes it a harder barrier for non-EU owners to control sensitive data, emphasizing legal immunity and sovereignty.
“The 24% rule is a simple yet powerful arithmetic test that directly measures ownership control, making it a unique legal sovereignty benchmark.”
— Thorsten Meyer, AI security expert

IRIS: The AI Bot Defense Guide: Stop Wasting Your Cloud Budget on AI Noise: A Field Manual for Digital Sovereignty Using NIST CSF 2.0 Principles
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Remaining Questions About the 24% Rule and Future Adoption
It is still unclear how widely the ownership cap will influence international cloud providers’ strategies beyond France. The exact impact on U.S.-based hyperscalers attempting to meet sovereignty requirements remains uncertain, especially regarding their ability to restructure ownership or form European joint ventures. Additionally, the potential for other European countries to adopt similar sovereignty tests or standards is still developing.

Build Your Own Private Cloud with Docker and Linux (2026 Edition): Deploy Secure Self Hosted Services and Take Back Control of Your Data
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Upcoming Developments in European Cloud Sovereignty Standards
Expect further adoption of SecNumCloud or similar sovereignty frameworks across Europe, especially as the European Union advances its Data Governance Act and related legislation. Major providers are likely to pursue partnerships or restructuring to meet the 24% ownership threshold. Meanwhile, legal debates about sovereignty, jurisdiction, and control will continue to shape policy and certification standards in the coming months.

THE CLOUD EXIT STRATEGY: The Architect’s Guide to Multi-Cloud Portability, Provider-Agnostic Networking, and Data Act Compliance (The Sovereign Cloud Architect Series)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What is the main purpose of the 24% ownership rule in SecNumCloud?
The 24% ownership rule is designed to ensure legal sovereignty by preventing non-EU entities from exerting control over cloud services hosting sensitive European data.
Does holding a SecNumCloud qualification mean a provider is immune from US or other foreign laws?
No. SecNumCloud certifies control and sovereignty within the EU context. Providers like AWS with US parent companies remain subject to US laws, such as the CLOUD Act, despite the qualification.
Can non-European providers meet the SecNumCloud requirements?
Yes, but they must structure ownership so that no individual or group outside the EU exceeds the 24% cap, and they must comply with EU residency and legal controls.
Will the 24% rule apply outside France?
Currently, the rule is specific to France’s SecNumCloud framework, but similar sovereignty standards are being discussed at the European level, potentially influencing broader policies.
What is the difference between security certifications and sovereignty certifications?
Security certifications like ISO 27001 verify operational security practices, while sovereignty certifications like SecNumCloud test ownership, jurisdiction, and control to ensure legal sovereignty over data.
Source: ThorstenMeyerAI.com