<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darya Khendrik, Author at Clever Cloud</title>
	<atom:link href="https://www.clever.cloud/blog/author/darya-khendrik/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>From Code to Product</description>
	<lastBuildDate>Wed, 26 Aug 2026 14:03:23 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cdn.clever-cloud.com/uploads/2023/03/cropped-cropped-favicon-32x32.png</url>
	<title>Darya Khendrik, Author at Clever Cloud</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The audit as a weapon: compliance, another battlefield of economic warfare</title>
		<link>https://www.clever.cloud/blog/company/2026/08/26/compliance-economic-warfare-audit/</link>
		
		<dc:creator><![CDATA[Darya Khendrik]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 14:03:22 +0000</pubDate>
				<category><![CDATA[Company]]></category>
		<category><![CDATA[compliance]]></category>
		<guid isPermaLink="false">https://www.clever.cloud/?p=25356</guid>

					<description><![CDATA[<p><img width="2499" height="1109" src="https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="2026.08.26 Clever Cloud Bannière Blog Audit Comme Arme EN" decoding="async" fetchpriority="high" srcset="https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en.png 2499w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-300x133.png 300w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-1024x454.png 1024w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-768x341.png 768w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-1536x682.png 1536w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-2048x909.png 2048w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-1368x607.png 1368w" sizes="(max-width: 2499px) 100vw, 2499px" /></p><!-- wp:paragraph -->
<p>The story is that of a French company engaged in a commercial dispute with a local competitor, abroad. The authorities of the country decide to launch an audit and the company, anxious to be beyond reproach, agrees to hand over financial data as well as information on its manufacturing processes.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The result: the company is hit with a surcharge all the same, then loses the majority of its customers to the competitor that had reported it. In the meantime, it has handed over valuable economic information which, for its part, can never be taken back.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>This case led me to consider a dimension of compliance that we do not discuss enough for my liking. We generally regard it as a way of reducing risk, protecting the company and establishing trust.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>But what happens when the tools of <a href="https://www.clever.cloud/compliance/">compliance</a> (the audit, the inspection, the certification) stop being safeguards and become weapons of economic warfare?</strong></p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Behind the procedure, the balance of power</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>An audit appears neutral to us because its vocabulary is. We speak of frameworks, of evidence, of non-conformities, of corrective actions. Everything seems to belong to an objective method whose conclusion would follow naturally from the facts observed.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Yet a control procedure never takes place outside the political and economic context in which it was decided.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The DGSI says so bluntly: these audits, "generally requested by government authorities as part of regulatory procedures, may also result from requests by competing companies".</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>What I take from this: the official procedure can be diverted in order to capture know-how, to slow a rival down, or to force it to expose itself.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Since it is the authority that audits, and that determines the information it wishes to obtain, the power sits on the other side and the balance of forces is uneven.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The two other examples reported by the DGSI illustrate precisely this risk: an audit tied to an export licence drags the timescales out to the point of leaving a factory facing a supply shortage, and in the other case, a compliance inspection results in modification requirements heavy enough to destabilise the company concerned.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The information that an audit makes it possible to obtain is considerable: the complete supply chain, the detail of industrial processes, the identity of those who hold the know-how, the architecture of a system, sometimes access to source code.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>In this way, delaying a licence, suspending a delivery, drawing on the processes, taking the market, imposing costly modifications all become a reality within the economic and industrial balance of power.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>In each of these situations, the company's cooperation is not enough to protect it. This obviously does not mean that every audit should be refused, or every certification suspected of being a hostile manoeuvre. It simply means that a technical tool can also carry a political function, and that it would be unwise to forget it.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">The concrete cases</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Without dwelling on the well-known examples of <a href="https://www.jailu.com/le-piege-americain/9782290217221">Alstom</a> or <a href="https://www.lemonde.fr/les-decodeurs/article/2014/05/30/bnp-pour-tout-comprendre-a-l-amende-record-brandie-par-les-etats-unis_4429206_4355770.html">BNP Paribas</a>, concerning foreign interference that goes even further than simple audit procedures, there are a good number of concrete cases worth knowing.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><a href="https://www.cac.gov.cn/2023-05/21/c_1686348043518073.htm">The Micron affair</a>, in China, is probably the clearest example of this shift.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>In March 2023, the Cyberspace Administration of China opened a cybersecurity review into the products of the American memory manufacturer. Two months later, it announced that these products presented serious problems liable to threaten the supply chain of the country's critical infrastructure. The operators concerned were therefore ordered to stop buying them.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The regulator did not publish technical details precise enough to allow any assessment of the nature of the vulnerabilities found.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The decision also came amid strong tensions surrounding semiconductors, at a time when the United States had already tightened its restrictions on the export of advanced technologies to China.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>It is hardly surprising, then, that it was widely interpreted as a retaliatory measure, even though the reason officially given remains that of cybersecurity. Here, a genuine security concern serves a broader economic strategy: the decision put at stake half of Micron's Chinese market, or around 12.5% of its worldwide revenue.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>China had already raised concerns in 2015, when it sought to impose highly intrusive control rules on service providers in the banking sector, rules that amounted to leaving all know-how at the point of entry. <a href="https://www.usito.org/news/cbrc-secure-controllable-guidelines-officially-suspended">The initiative was suspended</a> that same year following significant diplomatic pressure.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>A quick detour to our British neighbours brings us to the case of Huawei.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>From 2010, the Chinese company submitted to British scrutiny for close to a decade. GCHQ (Government Communications Headquarters) and then the NCSC (National Cyber Security Center) <a href="https://www.ncsc.gov.uk/guidance/ncsc-advice-on-the-use-of-equipment-from-high-risk-vendors-in-uk-telecoms-networks">examined</a> the company's equipment, its source code and its engineering practices. In July 2020, the British services <a href="https://www.ncsc.gov.uk/report/summary-of-ncsc-analysis-of-us-may-2020-sanction">were not convinced</a> and, under American pressure, Huawei was removed from the British 5G network.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">The tools France has built</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>France is not defenceless, it holds several defensive regulatory instruments:</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>The blocking statute of 1968</strong>, for a long time almost never applied, was reformed in 2022 (decree no. 2022-207). It prohibits the disclosure to a foreign authority of sensitive information of an economic, commercial, industrial, financial or technical nature that touches on the essential interests of France. Since April 2022, a single point of contact, the SISSE (the strategic information and economic security service, attached to the DGE), issues an opinion within one month setting out what may or may not be disclosed (sources: economie.gouv.fr, DGE, DGSI).</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>To this judicial shield an infrastructure shield has been added. <strong>The cloud at the centre policy</strong>, set out by circular in 2021 and updated in 2023, requires public administrations to host their digital projects on the state's internal clouds or on qualified commercial offerings.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>For data of particular sensitivity, the offering chosen must hold the <a href="https://www.clever.cloud/secnumcloud-trusted-cloud/">SecNumCloud qualification</a>, or an equivalent European qualification, and must be immune to any unauthorised access by the public authorities of third states.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>This qualification goes beyond technical measures, covering the legal control of the company, its personnel, the location of its activities and the legislation to which the service may be subject.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>SecNumCloud constitutes, in this sense, a defensive instrument. It allows the state to define the conditions under which certain sensitive data may be entrusted to a provider, rather than accepting that the market or foreign powers alone determine the level of risk we ought to tolerate.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>France then argued for the introduction of comparable criteria into the <strong>European cloud services certification scheme, EUCS</strong>, particularly at its highest level. These sovereignty criteria have never commanded consensus among member states. The scheme has been pending ever since.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Several member states and organisations representing European and foreign industrial interests opposed these criteria, which they considered protectionist and alien to a certification that was supposed to remain purely technical. Conversely, several European companies called for them to be retained, precisely because they held that the security of a cloud could not be separated from the law to which it is exposed.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The United States, for its part, does not hesitate: its FedRAMP programme has for years made access to the federal market for cloud services conditional on a certification that it controls.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>This debate says a great deal about our collective difficulty. At the very moment when we were seeking to define the conditions of trust applicable to our own market, we hesitated to accept that a certification might also express a sovereignty choice. To return to the image of the weapon, we began by blunting it ourselves. The reality is that we have not managed to equip ourselves with the safeguards needed in the face of the compliance instruments of non-European countries.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Their function is defensive, they are ramparts. Unlike the FCPA and OFAC, which are instruments of projection: they go and find the foreign company on its own ground.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">From compliance endured to reciprocity</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Two thousand four hundred years ago, Thucydides staged the Melian dialogue. Athens wants to subjugate the small island of Melos, which appeals to law and justice. The Athenians' reply has remained famous: "the strong do what they can and the weak suffer what they must".</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The idea is not to devalue the usefulness of compliance and of law, nor to call open markets into question. It is to recall that being in order does not guarantee being protected. Law does not defend itself: it only truly protects where a public authority is prepared to enforce it.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>For as long as the asymmetry in means of pressure exists, the most aggressive actor will keep its advantage. If access to a foreign market entails handing over source code or opening up one's factories, we must be able to demand comparable guarantees.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>It is time to add a principle that the European Union and its member states have recently begun to establish, but still hesitate to assume fully: reciprocity in their regulatory framework, faced with the offensive legal instruments of third countries.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>— Darya KHENDRIK, Compliance Manager at Clever Cloud, IMS lead (Integrated Management System) and DPO</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"25px"} -->
<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:html -->
<hr style="border: 0; border-top: 1px solid #ddd; margin: 24px 0;">
<!-- /wp:html -->

<!-- wp:spacer {"height":"25px"} -->
<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Sources</h2>
<!-- /wp:heading -->

<!-- wp:list -->
<ul class="wp-block-list"><!-- wp:list-item -->
<li><a href="https://www.dgsi.interieur.gouv.fr/dgsi-a-vos-cotes/contre-espionnage/conseils-aux-entreprises-flash-ingerence/audits-etrangers-vecteurs-de-destabilisation-et-dingerence-pour-entites-strategiques-francaises">DGSI, Foreign audits as vectors of destabilisation and interference for French strategic entities</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="http://www.cac.gov.cn/2023-05/21/c_1686348043518073.htm">Cyberspace Administration of China, Micron decision of 21 May 2023</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.usito.org/news/cbrc-secure-controllable-guidelines-officially-suspended">USITO, suspension of the Chinese banking "secure and controllable" guidelines</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.ncsc.gov.uk/report/summary-of-ncsc-analysis-of-us-may-2020-sanction">NCSC, summary of analysis of the US May 2020 sanctions concerning Huawei</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.ncsc.gov.uk/guidance/ncsc-advice-on-the-use-of-equipment-from-high-risk-vendors-in-uk-telecoms-networks">NCSC, advice on high-risk vendors</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://cyber.gouv.fr/sites/default/files/document/secnumcloud-referentiel-exigences-v3.2.pdf">ANSSI, SecNumCloud framework of requirements v3.2</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.itic.org/news-events/news-releases/iti-urges-eu-lawmakers-to-drop-sovereignty-requirements-in-final-eucs">ITI, position of 11 April 2024 on removing the sovereignty criteria from the EUCS</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/getting-started/">FedRAMP, conditions of access for cloud services to the federal market</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://eur-lex.europa.eu/legal-content/EN/LSU/?uri=CELEX:32022R1031">EUR-Lex, International Procurement Instrument, Regulation 2022/1031</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://eur-lex.europa.eu/eli/reg/2022/2560/oj">EUR-Lex, Foreign Subsidies Regulation 2022/2560</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://eur-lex.europa.eu/eli/reg/2023/2675/oj">EUR-Lex, Anti-Coercion Instrument, Regulation 2023/2675</a></li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->]]></description>
										<content:encoded><![CDATA[<p><img width="2499" height="1109" src="https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="2026.08.26 Clever Cloud Bannière Blog Audit Comme Arme EN" decoding="async" srcset="https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en.png 2499w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-300x133.png 300w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-1024x454.png 1024w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-768x341.png 768w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-1536x682.png 1536w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-2048x909.png 2048w, https://cdn.clever-cloud.com/uploads/2026/08/2026-08-26-clever-cloud-banniere-blog-audit-comme-arme-en-1368x607.png 1368w" sizes="(max-width: 2499px) 100vw, 2499px" /></p><!-- wp:paragraph -->
<p>The story is that of a French company engaged in a commercial dispute with a local competitor, abroad. The authorities of the country decide to launch an audit and the company, anxious to be beyond reproach, agrees to hand over financial data as well as information on its manufacturing processes.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The result: the company is hit with a surcharge all the same, then loses the majority of its customers to the competitor that had reported it. In the meantime, it has handed over valuable economic information which, for its part, can never be taken back.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>This case led me to consider a dimension of compliance that we do not discuss enough for my liking. We generally regard it as a way of reducing risk, protecting the company and establishing trust.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>But what happens when the tools of <a href="https://www.clever.cloud/compliance/">compliance</a> (the audit, the inspection, the certification) stop being safeguards and become weapons of economic warfare?</strong></p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Behind the procedure, the balance of power</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>An audit appears neutral to us because its vocabulary is. We speak of frameworks, of evidence, of non-conformities, of corrective actions. Everything seems to belong to an objective method whose conclusion would follow naturally from the facts observed.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Yet a control procedure never takes place outside the political and economic context in which it was decided.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The DGSI says so bluntly: these audits, "generally requested by government authorities as part of regulatory procedures, may also result from requests by competing companies".</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>What I take from this: the official procedure can be diverted in order to capture know-how, to slow a rival down, or to force it to expose itself.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Since it is the authority that audits, and that determines the information it wishes to obtain, the power sits on the other side and the balance of forces is uneven.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The two other examples reported by the DGSI illustrate precisely this risk: an audit tied to an export licence drags the timescales out to the point of leaving a factory facing a supply shortage, and in the other case, a compliance inspection results in modification requirements heavy enough to destabilise the company concerned.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The information that an audit makes it possible to obtain is considerable: the complete supply chain, the detail of industrial processes, the identity of those who hold the know-how, the architecture of a system, sometimes access to source code.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>In this way, delaying a licence, suspending a delivery, drawing on the processes, taking the market, imposing costly modifications all become a reality within the economic and industrial balance of power.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>In each of these situations, the company's cooperation is not enough to protect it. This obviously does not mean that every audit should be refused, or every certification suspected of being a hostile manoeuvre. It simply means that a technical tool can also carry a political function, and that it would be unwise to forget it.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">The concrete cases</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Without dwelling on the well-known examples of <a href="https://www.jailu.com/le-piege-americain/9782290217221">Alstom</a> or <a href="https://www.lemonde.fr/les-decodeurs/article/2014/05/30/bnp-pour-tout-comprendre-a-l-amende-record-brandie-par-les-etats-unis_4429206_4355770.html">BNP Paribas</a>, concerning foreign interference that goes even further than simple audit procedures, there are a good number of concrete cases worth knowing.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><a href="https://www.cac.gov.cn/2023-05/21/c_1686348043518073.htm">The Micron affair</a>, in China, is probably the clearest example of this shift.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>In March 2023, the Cyberspace Administration of China opened a cybersecurity review into the products of the American memory manufacturer. Two months later, it announced that these products presented serious problems liable to threaten the supply chain of the country's critical infrastructure. The operators concerned were therefore ordered to stop buying them.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The regulator did not publish technical details precise enough to allow any assessment of the nature of the vulnerabilities found.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The decision also came amid strong tensions surrounding semiconductors, at a time when the United States had already tightened its restrictions on the export of advanced technologies to China.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>It is hardly surprising, then, that it was widely interpreted as a retaliatory measure, even though the reason officially given remains that of cybersecurity. Here, a genuine security concern serves a broader economic strategy: the decision put at stake half of Micron's Chinese market, or around 12.5% of its worldwide revenue.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>China had already raised concerns in 2015, when it sought to impose highly intrusive control rules on service providers in the banking sector, rules that amounted to leaving all know-how at the point of entry. <a href="https://www.usito.org/news/cbrc-secure-controllable-guidelines-officially-suspended">The initiative was suspended</a> that same year following significant diplomatic pressure.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>A quick detour to our British neighbours brings us to the case of Huawei.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>From 2010, the Chinese company submitted to British scrutiny for close to a decade. GCHQ (Government Communications Headquarters) and then the NCSC (National Cyber Security Center) <a href="https://www.ncsc.gov.uk/guidance/ncsc-advice-on-the-use-of-equipment-from-high-risk-vendors-in-uk-telecoms-networks">examined</a> the company's equipment, its source code and its engineering practices. In July 2020, the British services <a href="https://www.ncsc.gov.uk/report/summary-of-ncsc-analysis-of-us-may-2020-sanction">were not convinced</a> and, under American pressure, Huawei was removed from the British 5G network.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">The tools France has built</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>France is not defenceless, it holds several defensive regulatory instruments:</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p><strong>The blocking statute of 1968</strong>, for a long time almost never applied, was reformed in 2022 (decree no. 2022-207). It prohibits the disclosure to a foreign authority of sensitive information of an economic, commercial, industrial, financial or technical nature that touches on the essential interests of France. Since April 2022, a single point of contact, the SISSE (the strategic information and economic security service, attached to the DGE), issues an opinion within one month setting out what may or may not be disclosed (sources: economie.gouv.fr, DGE, DGSI).</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>To this judicial shield an infrastructure shield has been added. <strong>The cloud at the centre policy</strong>, set out by circular in 2021 and updated in 2023, requires public administrations to host their digital projects on the state's internal clouds or on qualified commercial offerings.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>For data of particular sensitivity, the offering chosen must hold the <a href="https://www.clever.cloud/secnumcloud-trusted-cloud/">SecNumCloud qualification</a>, or an equivalent European qualification, and must be immune to any unauthorised access by the public authorities of third states.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>This qualification goes beyond technical measures, covering the legal control of the company, its personnel, the location of its activities and the legislation to which the service may be subject.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>SecNumCloud constitutes, in this sense, a defensive instrument. It allows the state to define the conditions under which certain sensitive data may be entrusted to a provider, rather than accepting that the market or foreign powers alone determine the level of risk we ought to tolerate.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>France then argued for the introduction of comparable criteria into the <strong>European cloud services certification scheme, EUCS</strong>, particularly at its highest level. These sovereignty criteria have never commanded consensus among member states. The scheme has been pending ever since.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Several member states and organisations representing European and foreign industrial interests opposed these criteria, which they considered protectionist and alien to a certification that was supposed to remain purely technical. Conversely, several European companies called for them to be retained, precisely because they held that the security of a cloud could not be separated from the law to which it is exposed.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The United States, for its part, does not hesitate: its FedRAMP programme has for years made access to the federal market for cloud services conditional on a certification that it controls.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>This debate says a great deal about our collective difficulty. At the very moment when we were seeking to define the conditions of trust applicable to our own market, we hesitated to accept that a certification might also express a sovereignty choice. To return to the image of the weapon, we began by blunting it ourselves. The reality is that we have not managed to equip ourselves with the safeguards needed in the face of the compliance instruments of non-European countries.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Their function is defensive, they are ramparts. Unlike the FCPA and OFAC, which are instruments of projection: they go and find the foreign company on its own ground.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">From compliance endured to reciprocity</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Two thousand four hundred years ago, Thucydides staged the Melian dialogue. Athens wants to subjugate the small island of Melos, which appeals to law and justice. The Athenians' reply has remained famous: "the strong do what they can and the weak suffer what they must".</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The idea is not to devalue the usefulness of compliance and of law, nor to call open markets into question. It is to recall that being in order does not guarantee being protected. Law does not defend itself: it only truly protects where a public authority is prepared to enforce it.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>For as long as the asymmetry in means of pressure exists, the most aggressive actor will keep its advantage. If access to a foreign market entails handing over source code or opening up one's factories, we must be able to demand comparable guarantees.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>It is time to add a principle that the European Union and its member states have recently begun to establish, but still hesitate to assume fully: reciprocity in their regulatory framework, faced with the offensive legal instruments of third countries.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>— Darya KHENDRIK, Compliance Manager at Clever Cloud, IMS lead (Integrated Management System) and DPO</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"25px"} -->
<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:html -->
<hr style="border: 0; border-top: 1px solid #ddd; margin: 24px 0;">
<!-- /wp:html -->

<!-- wp:spacer {"height":"25px"} -->
<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Sources</h2>
<!-- /wp:heading -->

<!-- wp:list -->
<ul class="wp-block-list"><!-- wp:list-item -->
<li><a href="https://www.dgsi.interieur.gouv.fr/dgsi-a-vos-cotes/contre-espionnage/conseils-aux-entreprises-flash-ingerence/audits-etrangers-vecteurs-de-destabilisation-et-dingerence-pour-entites-strategiques-francaises">DGSI, Foreign audits as vectors of destabilisation and interference for French strategic entities</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="http://www.cac.gov.cn/2023-05/21/c_1686348043518073.htm">Cyberspace Administration of China, Micron decision of 21 May 2023</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.usito.org/news/cbrc-secure-controllable-guidelines-officially-suspended">USITO, suspension of the Chinese banking "secure and controllable" guidelines</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.ncsc.gov.uk/report/summary-of-ncsc-analysis-of-us-may-2020-sanction">NCSC, summary of analysis of the US May 2020 sanctions concerning Huawei</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.ncsc.gov.uk/guidance/ncsc-advice-on-the-use-of-equipment-from-high-risk-vendors-in-uk-telecoms-networks">NCSC, advice on high-risk vendors</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://cyber.gouv.fr/sites/default/files/document/secnumcloud-referentiel-exigences-v3.2.pdf">ANSSI, SecNumCloud framework of requirements v3.2</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.itic.org/news-events/news-releases/iti-urges-eu-lawmakers-to-drop-sovereignty-requirements-in-final-eucs">ITI, position of 11 April 2024 on removing the sovereignty criteria from the EUCS</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/getting-started/">FedRAMP, conditions of access for cloud services to the federal market</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://eur-lex.europa.eu/legal-content/EN/LSU/?uri=CELEX:32022R1031">EUR-Lex, International Procurement Instrument, Regulation 2022/1031</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://eur-lex.europa.eu/eli/reg/2022/2560/oj">EUR-Lex, Foreign Subsidies Regulation 2022/2560</a></li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><a href="https://eur-lex.europa.eu/eli/reg/2023/2675/oj">EUR-Lex, Anti-Coercion Instrument, Regulation 2023/2675</a></li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
