Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Technology · 1 min read

C5, EUCS and SecNumCloud

In shortAn attestation audits operations, not jurisdiction. Two different questions.

The same acronyms appear in every tender. They do not measure the same thing, and none of them answers the question this site is about.

C5 (Germany)

The BSI's criteria catalogue, audited by an accountant under ISAE 3000. Among other things it requires statements on jurisdiction, on where processing takes place, and on requests from foreign authorities — the so-called environment parameters.

Note the wording: C5 requires the provider to disclose these facts, not that they come out favourably. A US provider can hold a flawless C5 attestation and still be subject to the CLOUD Act. The attestation will even tell you so — you just have to read that section. See US CLOUD Act.

EUCS (European Union)

The planned EU-wide certification scheme for cloud services. It has been stuck for years, and stuck on exactly the question that matters here: should the highest level require that the provider be beyond the legal reach of a third country? France and several other states say yes, others no. While that is open, there is no EUCS.

That dispute is the sovereignty debate in pure form, fought out over an annex.

SecNumCloud (France)

ANSSI's French scheme already answers the question, and answers yes. It requires that the provider not be under the control of a non-EU jurisdiction, and it caps non-European shareholdings. That makes it the strictest label in the field, and it is why almost only French providers carry it.

How to use them

Ask for the attestation, not the logo. Read the environment parameters and the sub-processor list inside it. Those two sections carry more information about your actual dependency than the rest of the document together. See Data residency and data sovereignty.

Sources

See also

Related terms