The pattern
Almost every government applies four gates to IT and cloud suppliers:
- A security certification or assessment, for cloud especially.
- Data-residency or sovereignty rules for sensitive data.
- Vendor or country bans, increasingly aimed at Chinese and Russian suppliers.
- An IT marketplace or framework where most purchases happen.
The table summarises them, and the sections below give the detail.
| Market | Key certification | Data rules | Main marketplace |
|---|---|---|---|
| United States | FedRAMP (cloud); CMMC (defence); Section 508 | Controlled unclassified information on FedRAMP Moderate or equivalent | GSA Multiple Award Schedule (IT) |
| United Kingdom | Cyber Essentials (Plus); NCSC Cloud Security Principles | No localisation for OFFICIAL data | G-Cloud 15, DOS7, Technology Services 4 |
| France | SecNumCloud (ANSSI) for sensitive data | France/EU, immune from non-EU law | UGAP, PLACE |
| Germany | BSI C5 attestation | Health cloud needs C5 | Kaufhaus des Bundes, e-Vergabe |
| Canada | Cyber Centre cloud assessment | Protected B/C data in Canada | SSC cloud framework agreements |
| Australia | IRAP; Hosting Certification Framework | Sovereignty checks for sensitive hosting | BuyICT |
| Japan | ISMAP (ISMAP-LIU for low-risk SaaS) | — | Government Procurement Portal |
| South Korea | CSAP (moving to NIS N2SF in 2027) | Separation requirements by data grade | KONEPS |
| Singapore | IM8 (via contract); MTCS commonly expected | Government on Commercial Cloud (GCC 2.0) | GeBIZ |
| India | MeitY cloud empanelment (STQC audit) | Data in India | GeM |
| UAE (Dubai) | DESC CSP Security Standard | Certified providers only | Dubai eSupply |
United States
FedRAMP, run by GSA, is required for cloud services used by federal agencies. The certification is free, though third-party assessors and preparation cost money. The 2026 changes:
- “FedRAMP Certified”: since February 2026, every authorisation carries this name, and impact levels became certification classes: A (a new entry tier), B (Low), C (Moderate) and D (High).
- The new rules: the Consolidated Rules for 2026 (published 25 June 2026) make the automated 20x path, based on key security indicators, the standard.
- Timeline: Class B and C applications opened in August 2026. The rules are mandatory from 1 January 2027, and no new Rev5 certifications start after 11 June 2027.
- Marketplace: about 538 certified services were listed in September 2026.
CMMC 2.0 applies to Department of Defense contracts:
- Levels: Level 1 (federal contract information: 15 requirements, annual self-assessment); Level 2 (controlled unclassified information: the 110 NIST SP 800-171 requirements, every three years); Level 3 (selected NIST SP 800-172 requirements, assessed by DCMA).
- Phase 2 begins 10 November 2026: third-party Level 2 certification starts appearing in contracts. The rule estimates $104,670 over three years for a small company.
- Who it covers: requirements flow down to subcontractors, including foreign ones that handle this information.
Vendor bans:
- Section 889 (FAR 52.204-25) bars equipment and services from Huawei, ZTE, Hytera, Hikvision and Dahua, whether you supply them or merely use them.
- Kaspersky and TikTok are also barred.
- The Trade Agreements Act limits GSA Schedule products, including software licences, to the US and designated countries. India and China are not designated.
Accessibility. ICT must meet Section 508, which incorporates WCAG 2.0 AA. Vendors supply an accessibility conformance report.
Marketplace. The GSA Multiple Award Schedule IT category covers cloud, IT professional services, cybersecurity and software licences.
United Kingdom
- G-Cloud 15 is the main route for cloud. It’s an open framework from August 2026, reopening at 18 and 36 months. DOS7 and Technology Services 4 cover digital and IT services.
- Cyber Essentials is required for central-government and NHS contracts handling personal or government data, at any value (PPN 014). Cyber Essentials Plus, which adds hands-on testing, is often required for higher-risk work.
- The NCSC’s 14 Cloud Security Principles are the assurance language for G-Cloud. They’re a self-assessment, not a certificate.
- No data-localisation rule applies to OFFICIAL data. UK GDPR and the Data (Use and Access) Act 2025 govern data protection, with new transfer rules from February 2026.
- Exclusions: suppliers on the national-security debarment list are excluded under the Procurement Act 2023.
European Union, France and Germany
EU-wide:
- NIS2 brings public administrations and digital providers (cloud, data centres, managed services) into its scope, and makes supply-chain security an obligation, so security clauses flow down to suppliers.
- The EU cloud certification scheme (EUCS) is still not adopted after years of debate over sovereignty requirements.
- Proposals, not yet law:
- A January 2026 package revising the Cybersecurity Act and NIS2 would let the EU restrict high-risk suppliers.
- The proposed Cloud and AI Development Act (June 2026) would create public-sector cloud sovereignty levels, with stricter levels for critical sectors.
- Data transfers to the US rely on the EU–US Data Privacy Framework. The EU General Court upheld it in September 2025, and an appeal is pending at the Court of Justice.
France.
- SecNumCloud, qualified by the national cybersecurity agency ANSSI and including immunity from non-EU law, is required for sensitive State data.
- It became legally binding through the SREN law and Decree 2026-272 (April 2026).
- Marketplaces: UGAP (the central purchasing body) and PLACE.
Germany.
- BSI C5 is an auditor attestation, not a certificate, expected for federal and health-sector cloud.
- C5:2026 was published in April 2026 and applies to audits from 1 June 2027.
- C3A, the 2026 sovereignty criteria, are a procurement tool without legal force.
Canada
- Data residency: Protected B, Protected C and classified government data must stay in Canada.
- Assessment: cloud providers are assessed by the Canadian Centre for Cyber Security, including a supply-chain integrity review, and buying runs through Shared Services Canada cloud framework agreements.
- Sovereign cloud: in 2026, Shared Services Canada launched a sovereign Canadian cloud procurement favouring Canadian-owned providers.
- Buy Canadian rules also apply to large ICT procurements.
- Bans: Huawei and ZTE are excluded from 5G, and TikTok, WeChat and Kaspersky are barred from government devices.
Australia
- IRAP: cloud services are assessed by assessors endorsed by the Australian Signals Directorate, against the Information Security Manual, up to PROTECTED.
- Hosting Certification Framework: providers hosting sensitive or whole-of-government data need a certification level (Strategic or Assured), covering ownership, control and supply chain.
- Essential Eight: Commonwealth entities must reach maturity level 2, so their suppliers face matching expectations.
- Bans: Kaspersky was removed from Commonwealth systems in 2025, and DeepSeek banned.
- Marketplace: most ICT buying runs through BuyICT.
Japan
- ISMAP: government bodies in principle buy cloud only from the ISMAP list, which requires a third-party audit against around 1,000 controls. ISMAP-LIU is a lighter track for low-risk SaaS. Preparation typically takes many months.
- Government Cloud: the platforms are AWS, Google Cloud, Azure, Oracle and, since March 2026, Sakura Cloud, the first Japanese provider to meet all requirements.
South Korea
- CSAP (cloud security assurance) has High, Medium and Low tiers. The Low tier has allowed logical separation since 2023, opening it to global providers.
- Announced in April 2026: public cloud checks will move to a single verification by the National Intelligence Service under a new framework (N2SF), grading data as classified, sensitive or open. It’s planned to take full effect in the second half of 2027, and existing CSAP certificates stay valid.
Singapore
- IM8: agencies follow the government ICT policy IM8, which reaches vendors through contract terms.
- GCC 2.0: most government systems run on Government on Commercial Cloud, which wraps AWS, Azure and Google Cloud.
- MTCS: the Multi-Tier Cloud Security standard (SS 584) is commonly expected.
- Cyber Trust marks: since April 2025, they cover cloud and AI, and vendors with sensitive access may be asked to hold them.
India
- MeitY empanelment: government cloud services must be empanelled by MeitY after an STQC audit, with data hosted in India and an undertaking that no foreign law applies to the service.
- CERT-In rules: report cyber incidents within 6 hours, and keep logs for 180 days within Indian jurisdiction.
- Land-border rule: bidders from countries sharing a land border with India must register with a government committee.
- Data protection: the Digital Personal Data Protection Act’s rules were notified in November 2025.
- Marketplace: most IT purchases run through GeM.
United Arab Emirates
- Dubai: government and semi-government bodies may use only cloud providers certified to the DESC CSP Security Standard, with annual audits and recertification every three years.
- Federal level: the Cyber Security Council’s National Cloud Security Policy (2023) sets governance and sovereignty expectations. In May 2026, the first cloud was certified for all government workloads below Secret.
Practical advice
- Pick markets by certification overlap. ISO 27001 and SOC 2 underpin most national schemes, but none transfers automatically.
- Budget time. FedRAMP, ISMAP and IRAP each take many months, and France’s SecNumCloud requires an EU-controlled operation.
- Check your supply chain against bans (Section 889, land-border rules, high-risk vendor lists) before you bid. A banned component can sink a bid.
- Partner locally where sovereignty rules bite. A local provider or reseller with the right certification is often the fastest route into France, Canada, India, Korea or the UAE.
What changed in 2025–2026
- 2025: Australia banned Kaspersky and DeepSeek on Commonwealth systems. Singapore extended its Cyber Trust marks to cloud and AI. The EU General Court upheld the Data Privacy Framework (September).
- 10 November 2025: CMMC Phase 1 began.
- January 2026: the EU proposed high-risk supplier powers.
- February 2026: FedRAMP introduced “Certified” status and certification classes. The UK’s new data transfer rules took effect.
- March 2026: Sakura Cloud joined Japan’s Government Cloud.
- April 2026:
- France’s SecNumCloud decree.
- Germany’s C5:2026.
- Korea announced the move from CSAP to N2SF.
- May 2026: the UAE certified its first sovereign cloud for government.
- June 2026: FedRAMP’s Consolidated Rules for 2026; the EU’s proposed Cloud and AI Development Act.
- Coming:
- CMMC Phase 2 (10 November 2026).
- FedRAMP’s new rules mandatory (1 January 2027).
- Korea’s N2SF (second half of 2027).
- The EU Court of Justice ruling on the Data Privacy Framework.
Questions
What is FedRAMP and what changed in 2026?
FedRAMP is the US government’s security certification for cloud services used by federal agencies; it charges no fee, though assessors and preparation cost money. In 2026 every authorisation was renamed ‘FedRAMP Certified’, Low/Moderate/High became certification classes (A to D), and the Consolidated Rules for 2026 made the automated ‘20x’ path the standard. The new rules become mandatory on 1 January 2027, and no new Rev5 certifications start after 11 June 2027.
Do foreign companies need CMMC to sell to the US Department of Defense?
Yes, if they handle federal contract information or controlled unclassified information, including as subcontractors. CMMC Level 1 is an annual self-assessment; Level 2 covers the 110 NIST SP 800-171 requirements, and from 10 November 2026 applicable contracts require third-party certification, which the rule estimates at about $104,670 over three years for a small company.
Can Chinese or Indian software vendors sell to the US government?
Equipment and services from Huawei, ZTE, Hytera, Hikvision and Dahua are banned, whether supplied or used by contractors (Section 889), as are Kaspersky and TikTok. Separately, products on the GSA Schedule must come from the US or a ‘designated country’ under the Trade Agreements Act, and neither India nor China is designated.
Which cloud certification do I need to sell to the Japanese government?
ISMAP: Japanese government bodies in principle buy cloud only from services on the ISMAP list, which requires a third-party audit against around 1,000 controls. A lighter track, ISMAP-LIU, exists for low-risk SaaS.
Does selling cloud to the Indian government require data to stay in India?
Yes. Government cloud services must be empanelled by MeitY after an STQC audit, with data hosted in India and an undertaking that no non-Indian law applies to the service. CERT-In rules also require reporting cyber incidents within 6 hours and keeping logs for 180 days within Indian jurisdiction.
Is sovereign cloud required in Europe?
Not EU-wide yet, but it’s coming. France requires SecNumCloud-qualified cloud, immune from non-EU law, for sensitive State data, made binding by decree in April 2026. The EU’s proposed Cloud and AI Development Act (June 2026) would create public-sector sovereignty levels, and the EU’s own cloud certification scheme (EUCS) is still not adopted.
Sources
- FedRAMP: 2026 timeline
- FedRAMP: Consolidated Rules for 2026 launch (25 June 2026)
- FedRAMP: Notice 0004 (FedRAMP Certified and certification classes)
- US FAR 52.204-25: prohibition on certain telecommunications and video surveillance equipment
- UK PPN 014: Cyber Essentials scheme
- UK G-Cloud 15 (Government Commercial Agency)
- Japan Digital Agency: Government Cloud
- Australia: Hosting Certification Framework
- Singapore GovTech: Government on Commercial Cloud
- AWS: Dubai DESC CSP Security Standard (explainer)
This guide explains the rules in plain English; it isn’t legal advice. Procurement rules change, and each tender document sets its own conditions — it always prevails.
