Skip to main content

Public-Sector Network

·2 min read·344 words

The network of a public-sector organization (ministry, prefecture, municipality, government agency) requires ANSSI compliance, SecNumCloud qualification for cloud services, strict INTERNET/INTRANET separation, and integration with RIE (Réseau Interministériel de l'État). 2026 public-sector guide.

Requirements

  • ANSSI accreditation (PSSI-E: French State Information Systems Security Policy)
  • Référentiel Général de Sécurité (RGS)
  • ISO 27001, HDS for healthcare data
  • SecNumCloud for cloud services (OVH SecNumCloud, Outscale)
  • RIE: interministerial network connecting government entities
  • IGI 1300: classified national defense documents
  • Log retention for at least 1 year, or 5 years for audit trails

Mandatory network separation

  • INTERNET network (office applications, email)
  • INTRANET network (business applications)
  • DIFFUSION RESTREINTE network (DR, sensitive documents)
  • CONFIDENTIEL DÉFENSE network (air-gapped)
  • Dedicated gateways with a data diode or secure cross-domain gateway

Public-sector network architecture

  • Core: Cisco Catalyst 9600 or Juniper EX9200
  • Firewall: Stormshield (ANSSI-certified) or Palo Alto 5400 Enterprise
  • Segmentation by classification level
  • Storage: HDS/SecNumCloud-certified arrays for healthcare data
  • Workstations: hardened Linux or hardened Windows (Gendarmerie, Office of the Prime Minister)

Stormshield: certified French market leader

French firewall with ANSSI Standard Qualification:

  • SN Series: SN160, SN310, SN510, SN710, SN910, SN2100, SN3100
  • SNS: Stormshield Network Security (NGFW)
  • SES: Stormshield Endpoint Security (certified EDR)
  • SDS: Stormshield Data Security (DLP)
  • Common Criteria EAL3+ and ANSSI certification

SecNumCloud

ANSSI qualification for trusted cloud services:

  • Qualified providers: OVHcloud Enterprise, Outscale, CloudTemple
  • 100% hosted in France and operated by EU nationals
  • Protection against extraterritorial laws (Cloud Act, FISA)
  • Mandatory for sensitive government data (healthcare, defense, industry)

Trusted cloud (Bleu, Blanc, Bleu)

Hybrid offering: trusted Microsoft 365 cloud operated by Orange/Capgemini ("Bleu") and trusted Google Workspace ("S3NS" by Thales):

  • Isolation from the US (no Cloud Act exposure)
  • Operated by a French/European entity
  • Data stored in France
  • Roadmap: SecNumCloud qualification in 2025-2026

Regional ministry budget

  • Core + distribution: ~€1,500,000 excl. VAT
  • Stormshield firewalls + licenses: ~€400,000 excl. VAT
  • Certified SIEM + SOC: ~€1,200,000 excl. VAT/3 years
  • Hardened workstations: ~€500,000 excl. VAT
  • SecNumCloud migration: ~€800,000 excl. VAT
  • Total: €5-10M excl. VAT depending on size

Order from OPTINOC

Public-sector network: Stormshield + Cisco + SecNumCloud. ANSSI/RGS/IGI 1300 compliance. Support for UGAP procurement contracts. Quote within 1 week.

Frequently Asked Questions

Reply within 2 business hours

Need a quote?

Our technical team responds within 2 business hours. European delivery 24-72h.

Request a quote