CIO GUIDE — IDENTITY MANAGEMENT

Choosing an IAM solution commits your organisation for several years

Hosting, sovereignty, reversibility and cost model are all criteria that providers do not always highlight spontaneously. This guide brings together the questions to ask and the warning signs to identify in their answers.

A three-page document covering five assessment areas, ready to use during your consultations. Ask every provider the same questions, then compare their answers: an evasive response is already useful information.

What the guide helps you assess with every IAM provider

souveraineté

Hosting and sovereignty

Determine where your identity data is physically hosted, assess its exposure to U.S. extraterritorial laws (Cloud Act, FISA Section 702), and confirm that your directory is isolated from shared multi-tenant environments.

conformité

Compliance and regulation

Understand the actual scope of certifications (ISO 27001, HDS, SecNumCloud, SOC 2), gather the evidence required for your NIS2 compliance documentation, identify who is responsible for security patches, and how publicly disclosed vulnerabilities (CVEs) are monitored.

12

Service availability and security

Verify what a Service Level Agreement (SLA) actually covers, and review the available strong authentication methods (passkeys, WebAuthn, step-up authentication).

baopen source

Reversibility and open standards

Require the ability to recover password hashes, ensure support for open standards (OAuth 2.0, OpenID Connect, SAML v2), and verify LDAP / Active Directory federation.

bafacturation

Total cost and pricing model

Ensure pricing is transparent, clarify the notice period for price increases, and identify any potential exit fees.

Who this guide is for

CIOs and teams assessing, renewing or bringing an identity and access management solution in-house, particularly in regulated sectors subject to sovereignty and compliance requirements.

Keycloak as a Service by Clever Cloud

Managed Keycloak, hosted in France, with maintenance and vulnerability monitoring handled by our teams. Starting at €47/month.

Included in the offering: dedicated infrastructure and isolated resources, integrated monitoring (metrics and dashboards included, no paid tier), IP filtering (admin, per realm, and within the authentication flow), strong authentication (passkeys, WebAuthn, email OTP), domain-based registration filtering (whitelist/blacklist), autoscaling, open standards (OAuth 2.0, OIDC, SAML v2, SCIM in preview, LDAP/AD), realm exports (including password hashes), cluster provisioning via Terraform, and termination without penalty.

Available as an option or through a dedicated offering: availability SLA of up to 99.99%, 24/7 support and response time commitments (Premium); a SecNumCloud-qualified zone available on request through our partner Cloud Temple.

At Clever Cloud level: a French company certified to ISO 27001:2022 and HDS for all six activities (HDS hosting applies to eligible services under a specific contract). SecNumCloud certification is currently being obtained.