Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DPO / RSSI / legal counsel before reliance. Citations to ANSSI / CNIL / EU regulations may lag the current text — verify against the source.
You are helping an enterprise architect generate a SecNumCloud 3.2 Compliance Assessment for cloud service procurement in the French public sector and regulated private sector. SecNumCloud is ANSSI's cloud security qualification scheme — the primary trust framework for sensitive data hosting in France.
User Input
$ARGUMENTS
Instructions
Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
Step 0: Read existing artifacts from the project context
MANDATORY (warn if missing):
REQ (Requirements) — Extract: data sensitivity levels, data classification, hosting requirements, security NFRs (NFR-SEC-xxx), integration requirements (INT-xxx), any SecNumCloud or sovereignty references
If missing: warn that SecNumCloud scoping requires defined requirements, especially data classification
SECD (Secure by Design) — Extract: security controls relevant to cloud hosting
MARPUB (Public Procurement) — Extract: any procurement constraints already documented
Step 0b: Read external documents and policies
Read any external documents in external/ — extract OIV/OSE designation letters, ANSSI correspondence, existing SecNumCloud assessments, cloud provider technical documentation
Read any global policies in 000-global/policies/ — extract cloud strategy, data classification policy, sovereignty requirements
If no external cloud/security docs exist, note: "No external cloud documentation found — assessment will be based on requirements and user input."
Step 1: Identify or Create Project
Identify the target project from the hook context. If the user specifies a project that doesn't exist yet:
Use Glob to list projects/*/ directories and find the highest NNN-* number
Calculate the next number (zero-padded to 3 digits)
Slugify the project name (lowercase, hyphens)
Use the Write tool to create projects/{NNN}-{slug}/README.md with project name, ID, and date
Set PROJECT_ID = the 3-digit number, PROJECT_PATH = the new directory path
Step 2: Read Source Artifacts
Read all documents from Step 0. Extract and note key data classification levels, OIV/OSE status, and any existing provider preferences for use in the assessment.
Step 3: SecNumCloud Template Reading
Read the template (with user override support):
First, check if .arckit/templates-custom/fr-secnumcloud-template.md exists in the project root
If found: Read the user's customized template
If not found: Read .arckit/templates/fr-secnumcloud-template.md
Step 4: Entity and Sensitivity Scoping
Before generating the assessment, determine:
Data sensitivity classification: Based on requirements and user input, classify as:
Non-sensitive (standard government data) → Standard commercial cloud may be acceptable
Sensitive (personal data, health data, administrative data) → SecNumCloud recommended
OSE: obligations under NIS directive transposition
Applicable regulatory framework: From requirements or user input, determine if any of the following apply: HDS (health data), DORA (financial sector), IGI 1300 (classified information), RGPD (personal data)
Show a brief scoping summary before generating the full document.
Step 5: Generate SecNumCloud Assessment
CRITICAL: Use the Write tool to create the assessment document.
Detect version: Check for existing ARC-{PROJECT_ID}-SECNUM-v*.md files:
No existing file → VERSION="1.0"
Existing file → compare scope; minor increment (1.0 → 1.1) if refreshed, major (1.0 → 2.0) if scope changed
Auto-populate Document Control:
Document ID: ARC-{PROJECT_ID}-SECNUM-v{VERSION}
Status: DRAFT
Created Date: {current_date}
Next Review Date: {current_date + 12 months}
Classification: OFFICIAL-SENSITIVE (minimum for cloud assessments)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ SecNumCloud Assessment Generated
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📄 Document: projects/{project_id}/ARC-{PROJECT_ID}-SECNUM-v{VERSION}.md
📋 Document ID: {document_id}
📅 Assessment Date: {date}
🔒 Classification: OFFICIAL-SENSITIVE
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📊 Scoping Summary
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Data Sensitivity: {classification}
OIV/OSE Designation: {Yes / No}
SecNumCloud Required: {Yes / Recommended / Not required}
HDS Required: {Yes / No}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🏗️ Provider Matrix Summary
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
{Summary table of provider qualification status}
⚠️ Extraterritorial Risk: {Summary of Cloud Act / FISA-702 exposure}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ Recommended Provider(s): {Name(s) with brief rationale}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Risks identified: {N} ({N} high, {N} medium)
Next steps:
1. {If OIV/OSE: Run $arckit-eu-nis2 for NIS2 obligation mapping}
2. Run $arckit-fr-marche-public for procurement documentation
3. {If health data: verify HDS certification of shortlisted providers}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Important Notes
Qualification vs Visa: A SecNumCloud Visa (provisional) does NOT confer the same assurance level as a full Qualification. Always distinguish in procurement documents.
FISA-702 residual risk: ANSSI's position is that US-lineage providers carry residual FISA-702 risk even after SecNumCloud qualification. This must be explicitly acknowledged and risk-accepted at the appropriate authority level.
Qualification status changes: SecNumCloud qualifications are maintained only as long as providers continue to meet requirements. Include a contractual clause requiring maintained qualification throughout the contract period.
Use Write Tool: SecNumCloud assessments are detailed technical documents. Always use the Write tool.
Note for reviewers: SecNumCloud is France's national cloud security qualification scheme, administered by ANSSI. It is the French equivalent of — and more stringent than — the EU's EUCS (European Cybersecurity Certification Scheme for Cloud Services). SecNumCloud 3.2 explicitly prohibits extraterritorial law exposure (US CLOUD Act, China MLSA), making it the required scheme for French government sensitive data and OIV systems. A key distinction: SecNumCloud visa ≠ SecNumCloud qualification — some providers hold a visa (provisional) rather than full qualification; only full qualification satisfies OIV/OSE and ministerial requirements.
Success Criteria
✅ Assessment document created at projects/{project_id}/ARC-{PROJECT_ID}-SECNUM-v{VERSION}.md
✅ Data sensitivity classification determined from requirements
✅ OIV/OSE status assessed
✅ All six candidate providers assessed (S3NS, Outscale, OVHcloud, Bleu, NumSpot, Cloud Temple)
✅ Extraterritorial legal risk (Cloud Act, FISA-702) assessed per provider
✅ Architecture pattern recommended based on sensitivity
✅ UGAP catalogue guidance included
✅ Residual risk register populated
✅ Decision matrix with recommendation provided
✅ Document classified OFFICIAL-SENSITIVE
Example Usage
$arckit-fr-secnumcloud Assess SecNumCloud compliance for a health data platform at a French regional hospital group (CHR), handling données de santé, potential OSE designation
$arckit-fr-secnumcloud Cloud hosting assessment for 001, ministry platform handling personal and financial data, no OIV designation
$arckit-fr-secnumcloud Evaluate sovereign cloud options for a French local authority (collectivité territoriale) digital services platform, mixed-sensitivity data
Suggested Next Steps
After completing this command, consider running:
$arckit-fr-marche-public -- Generate procurement documentation once SecNumCloud requirements are defined (when Cloud provider shortlist and qualification requirements identified)
$arckit-eu-nis2 -- Map OIV/OSE obligations to NIS2 requirements (when Entity has OIV or OSE designation)
$arckit-risk -- Integrate SecNumCloud and extraterritorial risks into the risk register