France’s sovereign stack¶
France, and cyber capability as an attribute of sovereignty
France patches and warns without boasting, runs a well-regarded national defender in ANSSI, and keeps a careful silence wherever offence might come up. What sets it apart is a prior decision, taken before any particular operation, about who holds the capability and who is permitted to depend on whom. France has been unusually explicit in turning the refusal to depend into published doctrine.
The French form is a stack held whole. Where a small state gains reach by embedding its capability in a larger network, France builds reach the other way, by keeping the ability to act when the network is not there. Doctrine, command, intelligence, a defensive agency, an industrial base, the tooling and the legal authority to use it: France assembles every layer and insists on owning it, because a capability that has to be borrowed can be withheld. Cyber becomes, in the French account, an attribute of sovereignty rather than a service the state consumes.
The whole stack, owned¶
Read the apparatus as a stack and every principal layer is deliberately national. At the top sits published doctrine, unusual in a domain usually kept classified: France openly states an offensive military-cyber doctrine, lutte informatique offensive, naming cyber as a mode of military action it will use, and a defensive one beside it. The military cyber command that runs both was stood up in 2017. The external intelligence service carries collection and the deniable end. ANSSI defends the state and critical operators. And underneath sits a defence-industrial base the state can procure from at home. The distinctive thing is not any single layer’s quality. It is the insistence that all of them be French.
Autonomy as inheritance¶
The substrate is a strategic culture organised around acting alone. France built an independent nuclear deterrent rather than shelter under someone else’s, kept a defence-industrial base able to arm the country largely from home, and made autonomy, the freedom to decide and act without another state’s permission, the organising value of its security policy. Cyber arrived into that culture and inherited it. The question a French planner puts to a capability is less how good is it than can we use it without asking, and the second question shapes the answer to the first.
Defence kept clean¶
The most revealing French choice is a wall. When France reorganised its posture in the 2018 strategic review of cyberdefence, it separated the missions rather than fusing them: the defence of the nation’s systems kept apart from military action, from intelligence, and from judicial response, with ANSSI on the defensive side only, outside the intelligence services and with no offensive role. The contrast with the American arrangement is exact. Where the United States runs its offensive command and its signals-intelligence agency under one dual-hatted commander, France keeps the body that secures the nation’s networks structurally apart from the bodies that break into other people’s. The separation is a sovereignty statement of its own: a national defender that critical operators and allies can trust precisely because it is not also the spy. Owning the whole stack, in the French design, includes owning the boundaries inside it.
Sovereignty in the server room¶
Sovereignty does not stop at doctrine and command; France pushes it down into the infrastructure the capability runs on. ANSSI operates a qualification for trusted cloud, SecNumCloud, and its conditions reach past security into jurisdiction, ownership and operational control: a cloud that holds sensitive French data has to be shielded from non-European law and run by an entity a foreign state cannot compel. The cloud de confiance doctrine that grew up around it pushes sovereignty down into the cloud itself, not merely onto a French corporate label. Data localisation, immunity from extraterritorial law, control of who operates the machines: the logic that keeps the defender national is carried into the server room. If capability is only sovereign when the state can act without asking, the ground it runs on has to be sovereign too.
Autonomy pays for autonomy¶
Seen as effects, the posture is a loop that funds itself. A commitment to strategic autonomy drives investment in the national stack; the investment builds a capability the state can use without asking; that capability buys France freedom of action and strategic standing; and that standing renews the commitment that started it. Four edges the same direction, one reinforcing loop, marked R. Autonomy is not only a value France holds. It is a thing the value pays for and is paid back by. What hangs off it in grey is the floor the loop never owns.
The floors are foreign¶
The loop tells a clean story. What hangs off it does not close. France cannot in fact own every layer, and the cloud is where the gap is plainest. The flagship trusted-cloud ventures are built on the very foreign technology the doctrine is meant to escape: one, owned by Orange and Capgemini, runs on Microsoft’s platform under licence; another, backed by Thales, runs on Google’s. The arrangement keeps the operator French and the technology American, which is either sovereignty defended at the last defensible line or sovereignty conceded and relabelled, depending on how much weight the word is asked to bear. The dependency is architectural, not corporate: hyperscale cloud is not a thing a national champion reproduces by changing the wrapper on someone else’s platform. Below the cloud the floor is harder still: Europe makes only a small share of the world’s chips, a dependence the European Chips Act exists to reduce, so the silicon under the stack is largely imported, and the intelligence relationships that make the apparatus effective run through alliances France does not control. The dependence is real. What the loop does not offer is a path that closes it, which is why the diagram draws it in grey.
Read from the doctrine¶
The sovereign stack is visible mostly as doctrine and institutions, not as operations. France publishes what it will do and how it is arranged to do it; what it actually does offensively is as unseen as anyone’s, and by design. The visible French output is defensive: ANSSI’s technical reporting on the adversaries working against French targets, which shows the defender at work and says nothing about the attacker France also is. So a good deal of French sovereignty is read from France’s own account of itself, the doctrine taken close to its word. The word capability hides three different things: what France declares in doctrine, what its institutions have demonstrably done, and the operational capability whose existence is inferred and whose use is classified. The record shows the first, watches the second, and can only guess at the third. A state that describes its autonomy carefully is not the same as a state whose autonomy has been tested and held, and the outside record cannot tell them apart.
The sovereignty that needs a continent¶
Which leaves the awkward part of the posture, and it is the one that points past France. The autonomy is threaded through the very structures it claims to stand apart from. France shapes European cyber policy and leans on it; its deterrent lives inside an alliance; its supply chains are European and Atlantic; its trusted cloud is American underneath. The state built to act alone turns out to act alone within a network it needs and helps to run. That is less a French failure than the shape the problem takes at national scale. France’s question was always who holds the capability, and its answer, all of it, still comes up short. A union that decides no one may hold the whole asks a different question: not who holds capability, but what that refusal makes.