TL;DR
An analysis published 16 July 2026 by Thorsten Meyer AI argues that mainstream certifications — ISO 27001, SOC 2, BSI C5, Gaia-X and the draft EUCS — verify security practice but never test whether a foreign government can compel access to customer data. France’s SecNumCloud is described as the only European framework that does, through an ownership cap limiting non-EU capital to 24% individually and 39% collectively. The proposed Cloud and AI Development Act (CADA) would replace badge-driven procurement with four Union assurance levels.
A new analysis from Thorsten Meyer AI, published 16 July 2026, makes a blunt case for buyers of cloud and AI services in regulated European industries: every widely displayed certification badge — ISO 27001, SOC 2 Type II, BSI C5, Gaia-X — may be real, independently audited and correctly shown, yet none of them answers the question that decides whether data can legally reside with a provider: can a foreign government compel access to it? According to the analysis, exactly one European framework tests that question, and it does so not with a security control but with a number: 24%.
The analysis sorts the certification landscape into two piles. The first pile — ISO 27001, SOC 2, BSI C5 and, as drafted, the EU’s EUCS scheme — certifies practice: access controls, encryption, incident response and audit trails. These frameworks ask whether a provider operates competently and securely, but not who ultimately controls it. BSI C5, Germany’s federal baseline since 2022, does require disclosure of the place of jurisdiction — it tells the buyer which law reaches the provider — but customers still have to document residual CLOUD Act risk in their own data protection impact assessments. Gaia-X, meanwhile, is described as an interoperability and policy initiative rather than a security audit, and counts AWS, Azure and Google among its members.
The second pile contains one entry: SecNumCloud, the French qualification backed by the state agency ANSSI. Its sovereignty test is an ownership cap, checkable from a cap table: capital and voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. The framework also demands EU domicile, EU-only storage, audited key custody and more than 360 criteria under version 3.2 — roughly ten times the complexity of ISO 27001, according to the analysis — which helps explain why only about nine or ten providers, including OVHcloud, Outscale, Scaleway, Numspot and Cloud Temple, currently hold it.
By that arithmetic, the analysis states, AWS, Azure and Google are structurally ineligible in their native form, and the Cohere–Aleph Alpha combination, at roughly 90% Canadian ownership, would sit about four times over the cap. The same logic explains the joint-venture structures the market has produced: S3NS pairs Thales with Google, and Bleu pairs Capgemini and Orange on Azure — arrangements that force a change of control over American technology rather than banning it.
The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty
ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.
C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.
Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.
The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.
Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.
Why the Ownership Question Decides Regulated Deals
For banks, hospitals, insurers and public bodies, the distinction between certified practice and tested ownership is not academic. A provider can pass every security audit and still be legally reachable by a foreign statute such as the US CLOUD Act, and the buyer — not the vendor — carries that residual risk in regulatory filings. The analysis argues this is the gap procurement teams routinely miss when they treat a wall of badges as proof of sovereignty.
The stakes sharpened after DORA’s CTPP designations in November 2025 pulled major cloud providers into direct financial-sector oversight, and as AI partnerships concentrate sensitive workloads with a handful of firms. The piece offers procurement teams six screening questions — covering ultimate parent and place of incorporation, the exact percentage of non-EU capital and voting rights, key custody, and the vendor’s CADA recognition roadmap — and warns that a vendor unable to answer the ownership questions immediately is staging theatre. It also cautions that sovereign infrastructure underneath a non-EU-controlled SaaS layer does not amount to a sovereign stack.
European cloud sovereignty certification
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How Europe’s Sovereignty Debate Reached This Point
The critique lands in the middle of a long policy fight. The EU’s EUCS certification scheme, still unadopted, originally included a so-called “High+” sovereignty tier that would have addressed jurisdiction; that tier was stripped out during drafting, leaving EUCS High without CLOUD Act immunity — a retreat the analysis attributes in part to protectionism objections raised by industry and trade voices, a critique it concedes has some force.
The commercial reality check, the analysis notes, came from Microsoft: in May 2025 the company told customers encryption made foreign access technically impossible; roughly a month later it acknowledged it could not guarantee immunity from US authorities — thirty days between the marketing and the law. Meanwhile ANSSI and Germany’s BSI have jointly committed to common criteria specifying where failure is disqualifying, signalling convergence between the two most influential national schemes.
“Cybersecurity Act certification is not suited for addressing sovereignty concerns.”
— CADA proposal recitals, COM(2026) 502

SOC2 Cloud Compliance Mastery: Master SOC 2 For Cloud Tools | Secure Collaboration Fast | SOC 2 Controls Simplified | Trusted Compliance Blueprint | Fast-Track Cloud Compliance | SOC 2 For SaaS
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Untested Champions and an Unwritten Rulebook
Several points remain open. The non-EU venture capital share of Mistral, France’s flagship AI company, has never been publicly tested against the 24% threshold, the analysis notes — framing it as an open question from public information, not an assertion of non-compliance. Whether other European champions would pass the same arithmetic is equally unresolved, and ownership structures can shift faster than annual audits.
The policy layer is unsettled too. CADA is only a proposal and EUCS remains unadopted, so the assurance levels that would govern public procurement do not yet exist. It is also unclear how national labels such as SecNumCloud will map onto the new Union levels, and whether the ANSSI–BSI joint criteria will harden into law or stall as EUCS’s sovereignty tier did.
![DeskFX Free Audio Effects & Audio Enhancer Software [PC Download]](https://m.media-amazon.com/images/I/41fXbDohyuS._SL500_.jpg)
DeskFX Free Audio Effects & Audio Enhancer Software [PC Download]
Transform audio playing via your speakers and headphones
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
CADA Vote and Joint ANSSI–BSI Criteria Ahead
The next milestone is the fate of the Cloud and AI Development Act, COM(2026) 502, which would establish four Union assurance levels for public procurement. If it passes, the badge on a vendor’s website stops being the deciding factor and the assurance level takes over — though the analysis notes a SecNumCloud provider would still need separate Article 17 recognition, and national labels would not be banned outright.
In parallel, the ANSSI–BSI joint work on common criteria — specifying where failure is disqualifying — is the technical track to watch, along with whether EUCS is adopted in its current jurisdiction-blind form. For buyers, the analysis’s near-term advice is procedural: put the ownership questions to every vendor now, and ask each one for a written CADA recognition roadmap before the rulebook arrives.

CISM Exam Prep 2026: The Complete Management Guide: Master Information Security Governance, AI Risk Integrity, and Modern Compliance Frameworks for the 2026 Practice
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What is the 24% rule in SecNumCloud?
It is an ownership cap: capital and voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. The test is checkable from a provider’s cap table and is designed so that no non-EU law can reach the qualified provider.
Does ISO 27001 or SOC 2 prove a cloud provider is sovereign?
No. Those certifications test security practice — controls, encryption, incident response — but say nothing about jurisdiction or ownership. A provider can hold both and still be subject to a foreign statute such as the US CLOUD Act.
Can AWS, Azure or Google ever qualify under SecNumCloud?
Not in their native form, since their ownership sits far above the cap. The route the market has produced is change-of-control joint ventures: S3NS combines Thales with Google, and Bleu combines Capgemini and Orange on Azure.
What is the Cloud and AI Development Act (CADA)?
A European Commission proposal, COM(2026) 502, that would set four Union assurance levels for public procurement of cloud and AI services. Its recitals state that existing Cybersecurity Act certification is not suited for addressing sovereignty concerns. It remains a proposal, not law.
What should buyers ask vendors about sovereignty right now?
According to the analysis, the decisive questions are: who is the ultimate parent and where is it incorporated; what percentage of capital and voting rights is held by non-EU entities; who holds the encryption keys and whether they can be compelled to produce them; and what the vendor’s CADA recognition roadmap looks like.
Source: Thorsten Meyer AI