TL;DR

An analysis published 16 July 2026 by Thorsten Meyer AI argues that mainstream certifications — ISO 27001, SOC 2, BSI C5, Gaia-X and the draft EUCS — verify security practice but never test whether a foreign government can compel access to customer data. France’s SecNumCloud is described as the only European framework that does, through an ownership cap limiting non-EU capital to 24% individually and 39% collectively. The proposed Cloud and AI Development Act (CADA) would replace badge-driven procurement with four Union assurance levels.

A new analysis from Thorsten Meyer AI, published 16 July 2026, makes a blunt case for buyers of cloud and AI services in regulated European industries: every widely displayed certification badge — ISO 27001, SOC 2 Type II, BSI C5, Gaia-X — may be real, independently audited and correctly shown, yet none of them answers the question that decides whether data can legally reside with a provider: can a foreign government compel access to it? According to the analysis, exactly one European framework tests that question, and it does so not with a security control but with a number: 24%.

The analysis sorts the certification landscape into two piles. The first pile — ISO 27001, SOC 2, BSI C5 and, as drafted, the EU’s EUCS scheme — certifies practice: access controls, encryption, incident response and audit trails. These frameworks ask whether a provider operates competently and securely, but not who ultimately controls it. BSI C5, Germany’s federal baseline since 2022, does require disclosure of the place of jurisdiction — it tells the buyer which law reaches the provider — but customers still have to document residual CLOUD Act risk in their own data protection impact assessments. Gaia-X, meanwhile, is described as an interoperability and policy initiative rather than a security audit, and counts AWS, Azure and Google among its members.

The second pile contains one entry: SecNumCloud, the French qualification backed by the state agency ANSSI. Its sovereignty test is an ownership cap, checkable from a cap table: capital and voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. The framework also demands EU domicile, EU-only storage, audited key custody and more than 360 criteria under version 3.2 — roughly ten times the complexity of ISO 27001, according to the analysis — which helps explain why only about nine or ten providers, including OVHcloud, Outscale, Scaleway, Numspot and Cloud Temple, currently hold it.

By that arithmetic, the analysis states, AWS, Azure and Google are structurally ineligible in their native form, and the Cohere–Aleph Alpha combination, at roughly 90% Canadian ownership, would sit about four times over the cap. The same logic explains the joint-venture structures the market has produced: S3NS pairs Thales with Google, and Bleu pairs Capgemini and Orange on Azure — arrangements that force a change of control over American technology rather than banning it.

At a glance
analysisWhen: Published 16 July 2026; CADA remains a…
The developmentA new analysis breaks down why every major cloud security certification fails to test foreign-government access risk, and identifies SecNumCloud’s ownership cap as the only European framework that does.
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Why the Ownership Question Decides Regulated Deals

For banks, hospitals, insurers and public bodies, the distinction between certified practice and tested ownership is not academic. A provider can pass every security audit and still be legally reachable by a foreign statute such as the US CLOUD Act, and the buyer — not the vendor — carries that residual risk in regulatory filings. The analysis argues this is the gap procurement teams routinely miss when they treat a wall of badges as proof of sovereignty.

The stakes sharpened after DORA’s CTPP designations in November 2025 pulled major cloud providers into direct financial-sector oversight, and as AI partnerships concentrate sensitive workloads with a handful of firms. The piece offers procurement teams six screening questions — covering ultimate parent and place of incorporation, the exact percentage of non-EU capital and voting rights, key custody, and the vendor’s CADA recognition roadmap — and warns that a vendor unable to answer the ownership questions immediately is staging theatre. It also cautions that sovereign infrastructure underneath a non-EU-controlled SaaS layer does not amount to a sovereign stack.

Amazon

European cloud sovereignty certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Europe’s Sovereignty Debate Reached This Point

The critique lands in the middle of a long policy fight. The EU’s EUCS certification scheme, still unadopted, originally included a so-called “High+” sovereignty tier that would have addressed jurisdiction; that tier was stripped out during drafting, leaving EUCS High without CLOUD Act immunity — a retreat the analysis attributes in part to protectionism objections raised by industry and trade voices, a critique it concedes has some force.

The commercial reality check, the analysis notes, came from Microsoft: in May 2025 the company told customers encryption made foreign access technically impossible; roughly a month later it acknowledged it could not guarantee immunity from US authorities — thirty days between the marketing and the law. Meanwhile ANSSI and Germany’s BSI have jointly committed to common criteria specifying where failure is disqualifying, signalling convergence between the two most influential national schemes.

“Cybersecurity Act certification is not suited for addressing sovereignty concerns.”

— CADA proposal recitals, COM(2026) 502

SOC2 Cloud Compliance Mastery: Master SOC 2 For Cloud Tools | Secure Collaboration Fast | SOC 2 Controls Simplified | Trusted Compliance Blueprint | Fast-Track Cloud Compliance | SOC 2 For SaaS

SOC2 Cloud Compliance Mastery: Master SOC 2 For Cloud Tools | Secure Collaboration Fast | SOC 2 Controls Simplified | Trusted Compliance Blueprint | Fast-Track Cloud Compliance | SOC 2 For SaaS

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Untested Champions and an Unwritten Rulebook

Several points remain open. The non-EU venture capital share of Mistral, France’s flagship AI company, has never been publicly tested against the 24% threshold, the analysis notes — framing it as an open question from public information, not an assertion of non-compliance. Whether other European champions would pass the same arithmetic is equally unresolved, and ownership structures can shift faster than annual audits.

The policy layer is unsettled too. CADA is only a proposal and EUCS remains unadopted, so the assurance levels that would govern public procurement do not yet exist. It is also unclear how national labels such as SecNumCloud will map onto the new Union levels, and whether the ANSSI–BSI joint criteria will harden into law or stall as EUCS’s sovereignty tier did.

DeskFX Free Audio Effects & Audio Enhancer Software [PC Download]

DeskFX Free Audio Effects & Audio Enhancer Software [PC Download]

Transform audio playing via your speakers and headphones

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

CADA Vote and Joint ANSSI–BSI Criteria Ahead

The next milestone is the fate of the Cloud and AI Development Act, COM(2026) 502, which would establish four Union assurance levels for public procurement. If it passes, the badge on a vendor’s website stops being the deciding factor and the assurance level takes over — though the analysis notes a SecNumCloud provider would still need separate Article 17 recognition, and national labels would not be banned outright.

In parallel, the ANSSI–BSI joint work on common criteria — specifying where failure is disqualifying — is the technical track to watch, along with whether EUCS is adopted in its current jurisdiction-blind form. For buyers, the analysis’s near-term advice is procedural: put the ownership questions to every vendor now, and ask each one for a written CADA recognition roadmap before the rulebook arrives.

CISM Exam Prep 2026: The Complete Management Guide: Master Information Security Governance, AI Risk Integrity, and Modern Compliance Frameworks for the 2026 Practice

CISM Exam Prep 2026: The Complete Management Guide: Master Information Security Governance, AI Risk Integrity, and Modern Compliance Frameworks for the 2026 Practice

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the 24% rule in SecNumCloud?

It is an ownership cap: capital and voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. The test is checkable from a provider’s cap table and is designed so that no non-EU law can reach the qualified provider.

Does ISO 27001 or SOC 2 prove a cloud provider is sovereign?

No. Those certifications test security practice — controls, encryption, incident response — but say nothing about jurisdiction or ownership. A provider can hold both and still be subject to a foreign statute such as the US CLOUD Act.

Can AWS, Azure or Google ever qualify under SecNumCloud?

Not in their native form, since their ownership sits far above the cap. The route the market has produced is change-of-control joint ventures: S3NS combines Thales with Google, and Bleu combines Capgemini and Orange on Azure.

What is the Cloud and AI Development Act (CADA)?

A European Commission proposal, COM(2026) 502, that would set four Union assurance levels for public procurement of cloud and AI services. Its recitals state that existing Cybersecurity Act certification is not suited for addressing sovereignty concerns. It remains a proposal, not law.

What should buyers ask vendors about sovereignty right now?

According to the analysis, the decisive questions are: who is the ultimate parent and where is it incorporated; what percentage of capital and voting rights is held by non-EU entities; who holds the encryption keys and whether they can be compelled to produce them; and what the vendor’s CADA recognition roadmap looks like.

Source: Thorsten Meyer AI

You May Also Like

I Heard You Singing

A brother’s sudden death reveals unexpected depths of love and grief in Montana. Discover the story behind the emotional loss and its impact.

Sustainable Fashion: Building a Capsule Wardrobe

Learning how to build a capsule wardrobe with sustainable fashion choices can transform your style—and your impact—when you discover what truly matters.

Why Thorsten Meyer Matters in the Age of Agentic AI

By the The Grumpy Owl Editorial Desk A New Kind of AI…

Work‑Life Balance Strategies for Busy Professionals

Ineffective balance can impact your well-being; discover practical strategies to harmonize work and personal life effectively.