ANSSI and SecNumCloud: a trusted infrastructure requires building your own security
As organizations move their data, their applications and their operations to the cloud, one question becomes increasingly hard to avoid: how far can you really trust the infrastructure that hosts the company’s digital assets? The answer no longer depends solely on server performance, availability or the commercial quality of the provider. It touches on cybersecurity, data protection, the legal conditions to which that data may be exposed, the people who administer the infrastructure and, ultimately, an organization’s ability to retain enough control over its digital environment.
It is precisely from this perspective that the French national cybersecurity agency, ANSSI, developed SecNumCloud. This framework establishes a particularly high level of requirements for certain cloud computing service offerings and gives organizations significant guarantees when they wish to entrust sensitive data or systems to a cloud provider.
It is important, however, to understand clearly what this qualification means. A SecNumCloud offering provides a particularly robust foundation of trust. It does not automatically secure the applications, identities, data and processes the organization will build on top of it. This distinction between security of the cloud and security in the cloud is essential, because it determines precisely where the trust provided by the vendor ends and where the organization’s ongoing responsibility begins.
SecNumCloud is a framework developed by ANSSI in order to qualify cloud service offerings that present a high level of security and trust. Its requirements go well beyond the technical protection of servers. They also cover the provider’s organization, its human resources, its processes, its access controls, cryptography, physical security, operations, communications, development, suppliers, incident management and business continuity. Version 3.2 also strengthened the consideration of certain risks associated with non-European law, thereby adding a legal and sovereignty dimension to technical and organizational security.
One initial distinction deserves executives’ attention, however: SecNumCloud qualifies a specific offering or scope. The qualification does not mean that all of a provider’s services universally become “certified secure.” A single provider may operate several cloud offerings, some of which fall within the qualified scope and some of which do not. The customer must therefore carefully check the specific service it intends to use and the guarantees that apply to it.
This rigor recalls a fundamental principle of modern security: trust must always be associated with a clearly defined context and scope. An organization, a user, an application or a supplier can be considered trustworthy in certain circumstances without that trust automatically extending to all of its activities and all of its interactions. This view connects directly to the principles of Zero Trust and, more broadly, of Continuous Trust: trust has a defined scope and must be open to continuous verification and reassessment.
SecNumCloud’s demanding nature is also explained by the particular nature of the cloud. When an organization outsources its infrastructure, it entrusts a considerable part of its technology environment to another player. Physical servers, networks, virtualization, administration interfaces and various operational layers may from then on be operated by the provider. This relationship brings significant advantages in terms of capacity, agility and operations, but it also creates dependencies that must be understood and governed.
Digital sovereignty adds to this relationship a dimension that traditional cybersecurity does not fully cover. Data can be extremely well protected technically while remaining exposed to a legal or jurisdictional risk. We must therefore examine, at the same time, where the data is located, who can technically access it, which organization operates the infrastructure, which jurisdictions may apply, who controls the cryptographic mechanisms and which technological dependencies connect the customer to its provider.
Another question then becomes particularly important: what happens if the organization one day wants to change providers? Can it move its data and workloads? Are its architectures sufficiently documented? Do its interfaces allow migration? Are the necessary skills still present within the organization? Are the proprietary dependencies known? Digital sovereignty is also measured by the ability to preserve options. It does not necessarily require owning or operating everything yourself; it requires understanding your dependencies well enough to preserve a genuine ability to decide.
This line of thinking brings us directly back to the difference between security of the cloud and security in the cloud. A qualified infrastructure can provide excellent guarantees while an application deployed on it remains vulnerable. Accounts may have too many privileges, secrets may be poorly managed, an API may be exposed, data may be needlessly duplicated, or a misconfiguration may open access that should never have existed. An artificial intelligence system may also have far broader access to information than its use requires.
The provider protects the components that fall within its scope of responsibility. The customer organization must continue to protect what it builds, configures, connects and operates. Identities, permissions, applications, data, APIs, cryptographic mechanisms, integrations with other environments and operational procedures therefore remain essential dimensions of cybersecurity, even when the underlying infrastructure offers a particularly high level of trust.
This responsibility becomes even more obvious in hybrid and multicloud architectures. Information may be created in a qualified infrastructure, transmitted to an external application, analyzed by an artificial intelligence system and then copied or transformed in another environment. Real security then depends on the entire journey. Excellent protection at the origin no longer guarantees security when data crosses several technical and organizational boundaries.
This is precisely where the discussion can progressively move from cybersecurity toward Hypersecurity. Cybersecurity mechanisms remain indispensable for protecting each environment, but overall protection must also cover the interactions and dependencies among these environments. Human and non-human identities, data, applications, APIs, AI agents, cloud, Edge, suppliers and cryptographic mechanisms progressively form a distributed system whose security depends as much on the relationships among its components as on each of them taken individually.
Zero Trust then becomes a means of controlling these interactions without generalizing trust. An administrator receives the permissions needed for their role, an application accesses only the data it needs, and a service communicates only with the systems necessary for it to function. The principle of least privilege reduces the potential reach of a compromise. In a dynamic architecture, this trust can also be reassessed based on the context, the system’s state, observed behavior and the level of risk. Trust is no longer simply granted: it must be continuously earned, verified and reassessed.
Identity thus becomes one of the main control points of the digital environment. Employees, administrators, suppliers, applications, APIs, machines and now artificial intelligence agents have identities and permissions. The question “who can do what?” is progressively evolving into “who—or what—can do what, in what context, on which resources and with what level of authority?”
This evolution becomes particularly important with AI agents. An agent able to consult documents, query a database, call an API or trigger an action has genuine digital authority. It should therefore have its own identity, permissions proportionate to its role and traceability making it possible to understand what it did. Its access must be able to evolve and be revoked quickly. A trusted infrastructure cannot deliver all of its benefits if the agents using it then hold excessive privileges.
The massive arrival of artificial intelligence also raises another sovereignty question. A company can keep its data in an infrastructure offering excellent guarantees and lose part of that control when an employee sends the data to an external AI service. It is therefore no longer enough to know where the information is stored. We must understand where it travels, which models can process it, which infrastructures run those models, which traces are retained and which organizations can technically or legally access it.
For sensitive environments, private or sovereign AI thus becomes a natural extension of the thinking about trusted infrastructure. The objective is to benefit from artificial intelligence capabilities while maintaining sufficiently clear governance of data, models, identities and access. This governance must also extend to the agents themselves when they begin acting directly within organizational processes.
Cryptography is another dimension that must be considered over time. An infrastructure may meet high cryptographic requirements today without the same mechanisms necessarily remaining appropriate throughout the lifetime of the systems and the data. The transition to post-quantum cryptography will progressively force organizations to know their cryptographic assets better: the algorithms, certificates, protocols, libraries, vendors, equipment and applications that depend on them.
This knowledge becomes particularly important when certain information must remain confidential for several years or several decades. Post-quantum readiness therefore does not simply consist in selecting new algorithms. It requires a cryptographic inventory, a mapping of dependencies, an understanding of exposure to the Harvest Now, Decrypt Later risk and, above all, the ability to update protection mechanisms when standards change. Crypto-agility thus becomes a property of the architecture.
The very logic of SecNumCloud in fact contains an interesting lesson on this subject: trust is not granted once and for all. A qualification has a defined duration and comes with ongoing monitoring. This logic implicitly recognizes that environments change. Technologies evolve, new vulnerabilities appear, infrastructures are modified, teams change and threats advance. Security must therefore be continuously maintained and reassessed.
This philosophy should also guide organizations that use a qualified infrastructure. Being compliant today does not guarantee tomorrow’s resilience. Compliance or qualification answers an essential question: are certain defined requirements met? Resilience poses another: what will happen when an unforeseen event occurs? An unknown vulnerability may be discovered, a privileged identity compromised, a provider may suffer an outage, human error may create a misconfiguration, or a cryptographic technology may become inadequate.
Maturity therefore consists in building, on top of compliance, a permanent capacity for adaptation. Audits, tests, risk analyses and exercises continue to have value even when recognized certifications or qualifications are already in place. Compliance becomes a milestone making it possible to validate certain capabilities at a given moment, while resilience and Hypersecurity seek to maintain and evolve those capabilities over time.
It is precisely in this space that Quantum Beyond can create value alongside cloud providers and internal teams. Our role is not to duplicate the work of the SecNumCloud provider, nor to take the place of the professionals responsible for the organization’s cybersecurity. It consists in examining the broader architecture in which this trusted infrastructure will be used and connecting the various dimensions needed to protect it and help it evolve.
Enterprise security architecture, Zero Trust and Continuous Trust, IAM, segmentation, data governance, cyber resilience, digital sovereignty, technological dependencies, crypto-agility, post-quantum readiness and private or sovereign artificial intelligence can thus be examined as the various dimensions of a single environment. Hypersecurity here brings a layer of architecture and governance that makes it possible to connect these disciplines so that they operate as a coherent whole.
This work can begin before a migration. An analysis of risks and dependencies can help determine which workloads should be moved, which data requires particular protections, which identity mechanisms must be adapted and which relationships will have to persist with other environments. It can then continue during operations in order to verify that the architecture keeps evolving along with the organization’s needs, its technologies and the threats.
The question then becomes more ambitious than “are we compliant?” or even “are we using a secure infrastructure?” It becomes: are we really extracting the maximum security, resilience, sovereignty and value from the trusted infrastructure we are investing in?
This last dimension, that of value, also deserves executives’ attention. An infrastructure meeting high requirements necessarily comes at a cost, as do the additional investments the organization makes in cybersecurity and resilience. It would, however, be reductive to see this spending solely as a premium intended to avert a catastrophe.
A well-designed security architecture can produce far broader benefits. Better identity management simplifies certain forms of access. A documented architecture makes transformations easier. Better knowledge of data supports the adoption of artificial intelligence. Segmentation reduces the potential consequences of an incident. Crypto-agility lowers the difficulty of future migrations. Better knowledge of dependencies improves technology decisions and negotiating power with suppliers. Resilience reduces the duration and scope of outages.
The return on an investment in cybersecurity and Hypersecurity is therefore measured as much in losses avoided as in operational capacity preserved and options maintained for the future. For executives, this perspective progressively transforms the security budget: it also becomes an investment in the company’s ability to operate, evolve and keep creating value.
SecNumCloud is far more than a set of technical controls applied to a cloud infrastructure. ANSSI’s framework brings together technical, organizational, operational and legal requirements designed to establish a high level of security and trust for precisely qualified offerings. For organizations that handle sensitive information or that wish to strengthen their digital sovereignty, this foundation can be of considerable value.
A foundation, however excellent, nonetheless remains a foundation. The applications, identities, permissions, data, APIs, artificial intelligence systems, cryptographic dependencies and operational processes built on top of it will continue to evolve in an environment where new technologies, new vulnerabilities and new dependencies will appear.
This is why the distinction between cybersecurity and Hypersecurity becomes particularly useful here. Cybersecurity protects systems, data, identities and infrastructure against digital threats. Hypersecurity connects these mechanisms to resilience, sovereignty, governance, artificial intelligence and the organization’s capacity for continuous adaptation. It therefore replaces neither SecNumCloud, nor Zero Trust, nor IAM, nor the other security disciplines. It seeks to make them work together in a distributed digital environment that is continuously evolving.
Quantum Beyond can operate at this intersection, working with internal teams and infrastructure providers to extend the principles of trust throughout the organization’s entire architecture. The objective is to make full use of the quality of the chosen foundation while maintaining control of the identities, data, dependencies, artificial intelligence, cryptography and technology options that will determine the organization’s future capacity to evolve.
True digital maturity is ultimately not to be found in a moment when an organization could consider its security work finished. It resides in its ability to maintain an infrastructure known, controlled, documented and adaptable enough for trust to evolve along with what it protects.
A trusted infrastructure is an excellent starting point. Real security begins when an organization knows how to build on it, how to govern it and how to keep trusting it while its environment is being transformed.
