The French public sector represents a significant market for SaaS, cloud and technology providers.
For international providers, however, selling to a French public-sector customer may raise issues that do not typically arise — or do not arise in the same way — in private-sector negotiations.
Public procurement rules are only part of the picture. The contractual framework, cybersecurity requirements, data protection, hosting arrangements and, in some cases, digital sovereignty requirements can all affect whether and how a service can be offered.
The key is to identify these constraints before committing to contractual or technical requirements that the provider may not be able to meet.
The first point is an important one: there is no single set of technology requirements applicable to every French public-sector customer.
The relevant framework may differ depending on whether the customer is:
The nature of the service and the sensitivity of the data processed are equally important.
Requirements applicable to a cloud service handling sensitive government or health data may therefore be very different from those applicable to a standard SaaS solution used for non-sensitive administrative functions.
International providers should avoid assuming either that all French public-sector projects require a sovereign cloud solution — or that a standard commercial cloud architecture will always be acceptable.
Public-sector contracts are generally awarded within a regulated procurement framework.
For a SaaS or technology provider, this has practical consequences.
Unlike a private customer negotiation, the provider may have limited ability to renegotiate contractual requirements once the procurement procedure is underway.
Tender documentation may include:
Potential legal or operational difficulties should therefore be identified during the procurement process rather than after award.
This is particularly important for international providers using global contractual templates. The customer's procurement documents may become the primary contractual framework, leaving less room to rely on the provider's standard SaaS agreement.
French public contracts may incorporate contractual mechanisms and standard documents that are unfamiliar to an international provider.
The terminology and risk allocation may also differ from those used in a global MSA or SaaS agreement.
Particular attention may be required in relation to:
The objective is not merely to translate the tender documents.
The provider needs to understand which provisions are imposed by the procurement framework, which derive from the customer's specific requirements and which may still be clarified or negotiated.
France has developed specific policies governing the use of cloud services by the State.
Under the French government's “Cloud at the Centre” policy, cloud is the default approach for new State digital projects and significant application redesigns.
This does not mean that every cloud service sold to a French public-sector customer must hold the same security qualification.
The applicable requirements depend in particular on the entity concerned and the nature and sensitivity of the data and services.
Where particularly sensitive data is involved within the scope of the State cloud policy, commercial cloud services may be required to meet SecNumCloud — or an equivalent European qualification — and to provide protection against unauthorised access by third-country public authorities.
International providers should therefore determine the applicable requirements for the particular project before assuming that their existing hosting model is either compliant or excluded.
For non-EU technology providers, digital sovereignty deserves particular attention.
The issue is not simply where servers are physically located.
The customer's requirements may also concern:
A service hosted in the European Union is therefore not necessarily sufficient, by itself, to satisfy every public-sector sovereignty requirement.
Conversely, sovereignty requirements should not automatically be assumed to apply to every public-sector SaaS procurement.
The assessment needs to be made in the context of the particular customer, data and service.
For a detailed analysis of third-country governmental access to EU-held data, see Third-Country Government Access under the EU Data Act: What International SaaS and Cloud Providers Need to Know.
Public-sector procurement may also involve personal data.
Where the provider acts as a processor, the contract will need to address the requirements of Article 28 GDPR, including processing instructions, security, subprocessors, assistance, deletion or return of data and audit arrangements.
International transfers may require separate consideration.
Additional sector-specific hosting requirements may also apply. For example, services involving health data may be subject to French health-data hosting requirements.
These questions should be distinguished from cloud sovereignty requirements: they may overlap, but they do not have the same legal basis or scope.
Public-sector customers may impose detailed cybersecurity requirements through tender specifications, security schedules or contractual annexes.
These may concern:
Before accepting these commitments, the provider should verify that they correspond to its actual technical and organisational framework.
This is particularly important for global SaaS providers operating a standardised multi-tenant service: customer-specific security commitments can be difficult to implement if they are inconsistent with the architecture used for the rest of the customer base.
Public-sector technology contracts commonly include detailed reversibility and exit requirements.
For SaaS and cloud providers, these requirements now need to be considered alongside the EU Data Act where that regulation applies.
The contract may need to address:
International providers should ensure that contractual commitments remain consistent with the technical capabilities of the service and with their wider EU switching framework.
See SaaS Switching under the EU Data Act: Protecting Contractual Commitments and the Subscription Model.
For international providers, the most effective approach is to review the legal and technical requirements before submitting a binding tender.
This makes it possible to identify:
and, where necessary,
This analysis can also prevent commercial teams from committing to customer requirements that cannot subsequently be implemented by product, security or infrastructure teams.
For providers entering the French market more broadly, see Doing Business in France: A Legal Guide for International SaaS and Technology Providers.
Withlaw assists international SaaS, cloud and technology providers seeking to contract with French public-sector customers, including by:
The objective is to identify the requirements that genuinely affect the service early enough for the provider to make informed legal, commercial and technical decisions when approaching the French public-sector market.