Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Technology · 2 min read · Updated 16 August 2026

Certifications

In shortA certificate examines operations, not the ownership chain.

At a glance

BSI C5
Criteria catalogue for cloud security; attested by auditors, covering a point in time or a period
ISO/IEC 27001
Management system for information security; examines processes, not individual products
SecNumCloud
French scheme from ANSSI, with requirements covering ownership and immunity from third-country law
EUCS
European certification scheme for cloud services, still in progress; the sovereignty requirements are the point of contention
What they share
They examine at a point in time and within a defined scope
What remains to be checked
Ownership chain, applicable law, export path — none of which appear in the attestation

Certificates are the most popular argument in procurement conversations because they reduce a complex question to a document. That is useful, and it is routinely overstretched.

The reason is simple: an attestation describes how a provider works. It does not describe who owns it.

What certificates examine processes, documentation, operational security, evidence at a point in time What they do not examine who owns the provider and which law the parent answers to What follows a certificate does not replace an ownership check — they answer different questions
Certificates are statements about operations, not about legal order. That does not make them worthless, it makes them bounded.

The schemes, briefly

BSI C5 is a criteria catalogue for cloud security attested by auditors. It exists as a statement about a point in time and as a statement about a period; the second is considerably more meaningful.

ISO/IEC 27001 examines an information security management system — processes and their effectiveness, not individual products. The scope decides the value of the statement.

SecNumCloud from France is the only widely used scheme that goes beyond operations and sets requirements on ownership and control, with the declared aim of immunity from third-country law.

EUCS, the European scheme, has been in progress for years. The dispute is precisely about whether sovereignty requirements are included — which shows how politically contested the point is.

What an attestation does not answer

Who owns the operating company today, and when did that last change? Which law does the parent answer to? How do you get your data in a dispute?

Those three decide what happens when it matters, and none of them appears in a C5 or ISO attestation. How to check them is set out under Sovereign cloud and, for the exit part, under Exit strategy.

How to read attestations properly

Two details on the first page matter more than the rest: scope and date.

An attestation for data-centre operations says nothing about the application running on top. One from 2023 says little about operations today — least of all if the provider has changed hands since.

For your own side

Small companies regularly ask whether they should get certified. The sober answer: only if a customer explicitly demands it and the contract carries the cost.

For everything else, two well-written pages on responsibility, reporting route, provider access, backup including the last restore, and the leaver process will do. They answer the questionnaires travelling down the supply chain under NIS2 just as well, and cost a day rather than a project.

Common questions

Is a provider with a C5 attestation sovereign?
No, those are two different questions. C5 examines operational security and evidence. A provider with an excellent attestation can still belong to a parent in a third country and fall under the CLOUD Act.
What sets SecNumCloud apart?
It sets explicit requirements on ownership and control, aiming at immunity from third-country law. That makes it the only widely used scheme that addresses the ownership question at all.
Is certifying ourselves worth it for a small company?
Usually not, unless a customer explicitly demands it. Two well-written pages on responsibility, reporting route, provider access, backup including the last restore, and the leaver process answer the usual questionnaires just as well and cost a day.
What do I look at in an attestation I am shown?
Scope and date. An attestation for a data centre says nothing about the application, and one from three years ago says little about today. Both are on the first page.

Sources

See also

Related terms