What ANSSI And BSI Actually Tested
On 17 August 2026, France's cybersecurity agency ANSSI awarded Nextcloud Files version 31.0.7.2 its CSPN certification, the country's standard first-level security bar for software sold into public tenders. Testers ran vulnerability and penetration tests across five specific functions, authentication, access control, stored-data protection, HTTPS communications and logging, in an on-site hosting configuration, and reported no issues. Separately, a Nextcloud deployment operated by Dataport, the public-sector IT provider serving several German states, now runs inside an environment certified under BSI's IT-Grundschutz framework, embedded in Dataport's own information security management system rather than certified as a standalone product.
One Certification, Two Countries
What turns two separate national approvals into one story is recognition, not coincidence. Germany's BSI formally treats ANSSI's CSPN as equivalent to its own accelerated certification scheme, the Beschleunigte Sicherheitszertifizierung, because both map onto the same European standard, EN 17640, built to be compatible with the EU Cybersecurity Act. In practice that means a vendor no longer has to run two separate national audits to prove the same security claim in both of the EU's largest public-procurement markets; one certification event now does the work of two.
The EU Cybersecurity Act's Promise, Tested
The Cybersecurity Act was written on the premise that a single EU-wide certification scheme could replace 27 fragmented national ones, cutting duplicate compliance cost for any vendor selling across borders. Most of that promise has stayed theoretical since the Act's schemes are still being built out; the ANSSI-BSI recognition is one of the first cases where it visibly worked for a real product, and the vendor it worked for was not a hyperscaler but an open-source collaboration platform that most European public buyers still do not default to.
What This Changes For A Buyer
For any EU or UK organization weighing an EU-hosted alternative to Microsoft 365 or Google Workspace for compliance reasons, the practical change is smaller procurement friction: a certification your German public-sector counterpart already trusts now travels into a French tender, and the reverse, without a fresh audit cycle. It does not make Nextcloud more secure than the incumbents by itself, and it covers a specific product version and a specific hosting configuration, not every deployment. But it is the first cross-border reference case a procurement team can actually point to, rather than a vendor's own compliance claim.
Read next: France Moves Its Health Database Off Microsoft Azure | A Sovereign AI Layer Now Speaks OpenAI's Own API



