Every year, more than €70 billion leaves France to pay foreign digital providers, frequently in markets where a French alternative does exist. Part of that outflow comes down to a problem that is easy to name and hard to fix: any software vendor can describe itself as “sovereign”, “French” or “made in France” without a single third party ever checking the claim. The practice has a name in French — franco-lavage, or French-washing: displaying French credentials that no independent verification supports.
The Numérique France Garanti (NFG) certification, officially launched on 18 June 2026 by the Origine France Garantie association in partnership with Bureau Veritas, tackles that ambiguity head-on. Whaller has just become one of its first holders — a good moment to step back and consider what the certification actually verifies, how it differs from a security qualification such as SecNumCloud, and why both questions increasingly shape purchasing decisions.
A market where sovereignty is declared more often than it is proven
Over the past two years, public procurement and parts of the private sector have tightened their requirements on digital suppliers: data location, immunity from extraterritorial laws, governance not subject to foreign law. The French state’s cloud doctrine, and the growing debate around the Cloud Act applied to critical infrastructure, have written the subject into tender specifications. But for as long as no independent third party verified those declarations, a vendor could lay claim to French origin with nothing to substantiate it, and a buyer had no straightforward way of telling one from another.
That is the gap the Numérique France Garanti framework fills, on a principle industry has known for a long time: Origine France Garantie already certifies the origin of manufactured goods; what is new is applying the same independent-audit logic to digital products.
What the certification actually checks
Whaller has followed this work from the outset, as one of the sixteen pioneering companies involved in building the framework from the pilot phase onwards. The final framework, audited by Bureau Veritas, rests on three cumulative criteria:
- French location of key activities, governance and data hosting;
- compliance with high security and data protection requirements;
- a majority share of digital added value (design, development, operation, maintenance) generated on French soil.
The certification is not a trophy awarded once and for all: it is maintained through regular follow-up audits, on the model of conventional quality certifications. A vendor that moved its governance abroad, or outsourced the bulk of its development, would lose it.
Origin and security: two questions, two frameworks
This is the point most often misunderstood: an origin certification and a security qualification do not answer the same question, and one cannot stand in for the other in a tender specification.
| The question asked | 🇫🇷 Numérique France Garanti | 🔒 SecNumCloud 3.2 |
|---|---|---|
| Who audits it | Bureau Veritas, on behalf of Origine France Garantie | ANSSI |
| What is verified | French location of governance, of key activities and of the majority of added value | Technical and operational security, together with a requirement for European governance and capital and protection against extraterritoriality |
| What it does not tell you | The security level of the solution | That added value is mostly generated in France: the requirement applies at European scale, not French |
The distinction is worth underlining, because it is the one most often lost along the way: SecNumCloud protects against extraterritorial interference at European level, but it does not require governance or added value to be French. A provider with German or Dutch capital can hold SecNumCloud qualification without being eligible for Numérique France Garanti — and that is precisely the gap this second label fills.
At Whaller, digital security is carried exclusively by Whaller DONJON, the version of the platform qualified SecNumCloud 3.2 by ANSSI for organisations handling sensitive data. Numérique France Garanti certification, by contrast, covers the Whaller platform as a whole and answers a different question: who governs the company, where does it work, and where does the value it creates remain.
Why both answers matter to buyers
In public and private tender specifications alike, the two questions are now asked separately — and, more and more often, both at once. A public body subject to the NIS2 directive wants a security guarantee audited by ANSSI. That same body, or a company mindful of its strategic dependencies, also wants to know whether its supplier can be compelled by foreign law, or whether difficulties at a distant shareholder could threaten service continuity. A recent Ifop survey bears this out: digital sovereignty is no longer a specialist concern; it has worked its way into how the general public views digital tools.
Answering both questions with a claim on a sales brochure is no longer enough. Answering them with two attestations signed by two independent third parties, covering two different scopes, changes the nature of the conversation with the buyer.
Where Whaller stands
Whaller has obtained Numérique France Garanti certification following a full Bureau Veritas audit, alongside the SecNumCloud 3.2 qualification held by Whaller DONJON. As of 9 September 2026, Whaller is the only French collaborative platform vendor to hold both of these verifications, different in nature as they are. For the details of the attestation — scope, period of validity, monitoring arrangements — the official press release remains the reference.
One question remains, and it reaches well beyond Whaller: how many vendors presented as French today would agree to the same verification exercise tomorrow?




0 Comments