Market perspective
ISO/IEC 42001 and SOC 2 implementation for France
For a French AI or cloud provider, the crucial first step is to distinguish governance of AI use, assurance over a service, privacy duties, and any cloud qualification sought. ISO/IEC 42001, SOC 2, CNIL guidance, and ANSSI SecNumCloud each address a different part of that picture.
Connect the AI management system to real development decisions
ISO/IEC 42001 implementation should trace an AI system from purpose and data selection through development, evaluation, release, monitoring, and retirement. French teams developing AI with personal data should also consider CNIL guidance on GDPR questions during system development. Document who decides whether personal data is necessary, which sources are used, and how risks to people are examined.
An AI management system can provide a repeatable record of these decisions, but it does not replace GDPR analysis or determine EU AI Act obligations by itself. The legal assessment and the management system should exchange facts without being presented as the same outcome.
Separate SecNumCloud from hosted-service claims
ANSSI's SecNumCloud qualification applies to a specific cloud service offering. ANSSI explains that a digital service hosted on a qualified cloud offering does not automatically inherit that qualification. For a French cloud or SaaS provider, this distinction should appear in service descriptions and procurement responses.
If SecNumCloud is a buyer requirement, establish which offering is in scope and which controls belong to the infrastructure provider, SaaS provider, and customer. The resulting responsibility model can inform ISO/IEC 27001 supplier work and SOC 2 subservice descriptions, but it does not collapse the assessment processes.
Use SOC 2 for international customer assurance
A French service organization may choose SOC 2 when a customer asks for a report on security and other relevant trust criteria for a defined service. Readiness starts with a precise system description, control owners, supplier dependencies, and evidence from normal operations.
A SOC 2 report is issued by an independent CPA firm. It can support customer due diligence, but it is not a finding that the organization complies with French privacy law, the EU AI Act, or SecNumCloud. Claims should say what the report actually covers.
Make the control library explain overlap
ISO/IEC 27001 can provide the information security management base for access, vulnerability, incident, supplier, and continuity practices. Add AI-specific impact, performance, and oversight controls for ISO/IEC 42001. Keep a mapping between controls and obligations, with the evidence source and applicable scope stated for each row.
Before external assessment, test a sample AI product release and a customer assurance request. If the team cannot reconstruct approval, data choice, testing, monitoring, and the answer sent to the buyer, the program needs operational repair rather than more policy text.
Prepare for French NIS2 without treating ReCyF as enacted law
ANSSI says national NIS2 transposition is forthcoming. It published the Référentiel Cyber France (ReCyF) on 17 March 2026 as a working document listing recommended measures, and it offers a pre-registration service for entities preparing for NIS2. ANSSI describes ReCyF as non-binding by default at this stage. A French implementation plan should therefore distinguish current law, preparatory guidance, and any future enacted obligations.
Start by testing whether each entity and service may be within the future essential or important entity scope, then assign owners for risk management, incident handling, continuity, supplier security, and documentation. ReCyF's comparison tool can help map existing ISO/IEC 27001 controls, but neither that mapping nor a SOC 2 report establishes a French NIS2 certification or an opinion on duties that have yet to be finalized.
Common questions
Clarify the outcome before the work.
Does hosting on a SecNumCloud service qualify our SaaS?
No. ANSSI says qualification applies to the assessed service offering; a service hosted on it does not automatically inherit qualification.
Does ISO/IEC 42001 establish GDPR compliance?
No. It provides an AI management system. Personal-data processing still needs its own GDPR analysis and controls.
Can a French provider pursue SOC 2?
Yes. The question is whether its customers need a SOC 2 report for the defined service.
Is ReCyF currently a mandatory French NIS2 certification?
No. ANSSI describes it as a non-binding working document while national transposition is pending.
Read next
A practical path from here.
ISO/IEC 42001
ISO/IEC 42001 in Europe: AI governance alongside the EU AI Act
Where an AI management system can support European governance work, and where AI Act analysis must remain separate.
SOC 2
SOC 2 for European SaaS companies: when it helps and how to prepare
A buyer-led guide to SOC 2 in Europe: the right trigger, a defensible scope, and how it sits beside ISO 27001 and GDPR.
ISO/IEC 42001
How to build an AI inventory for ISO/IEC 42001
The fields, ownership decisions, and review triggers that make an AI inventory useful beyond an initial assessment.
Work with Normstone
Make the next assurance decision clear.
Tell us your service, AI use, and customer requirements. We’ll help shape the scope.