// analysis
Your identity in your phone, 3/8: sovereignty under contract

France Identité’s updated programme cost is €107.4m. Seven frameworks cover its software core. Who controls code, keys, recovery and liability?
France Identité is a State application. Its servers are said to run on the French Interior Ministry cloud. The electronic seal on its credentials relies on the ministry’s digital directorate and on keys protected in ANSSI-qualified equipment. Yet its software core, expertise, security, mobile apps, backend and interoperability environments are also divided among seven framework contracts.
Multiple suppliers are not an anomaly. The structure can reduce concentration and provide scarce skills. The sovereignty question begins elsewhere: can the State understand, audit, build, operate, repair and replace each critical component without remaining dependent on its current contractor?
The question becomes financial when the identity layer gates access to training, a grant, a corporate signature or a contractual transaction. A technical failure can then become a delay, a missed deadline or an economic loss. Who restores the service, and who compensates the user?
This is part three of Your identity in your phone. Part one followed France Identité data and logs. Part two measured the cost of proceeding without a mobile digital identity.
Version française : L’identité souveraine sous contrat.
Key points
- A French Senate budget report puts the updated total cost of the France Identité programme at €107.4 million. This covers the programme as a whole and is not a single app-development invoice.
- An EU procurement notice published in January 2025 sets a cumulative maximum value of €44.7 million for seven framework contracts covering the development, operation and security of SGIN.
- The €44.7 million consists of contractual ceilings, with no published minimum. It does not show orders placed, invoices paid or work accepted.
- French public-procurement essential data records seven awardees notified on 7 May 2025: Eurogroup Consulting, Cabinet Louis Reynaud, Stelau Conseil, Sopra Steria, BAM, IN Smart Identity France and Docaposte BPO.
- The EU notice states 24 months plus two 12-month renewals, for a 48-month maximum. Public-procurement data pages display six years. The signed contracts are needed to resolve this documentary discrepancy.
- The Senate places the outsourcing rate for France Titres projects as a whole between 78% and 95%, compared with a 60% ceiling recommended by DINUM. This is not a France Identité-specific rate.
- France Titres says hosting is on the ministry’s cloud PI. Its signature policy assigns the State seal to DNUM through SIGNHOR, with signing keys protected in ANSSI-qualified HSMs.
- Mobile versions certified in 2023 identify Atos France as developer. The 2025 mobile lot is awarded to BAM. Public records do not describe the handover of code, builds and incident procedures.
- iDAKTO says it designed the ID-card reading SDK and a backend management system. The 2025 server lot is awarded to IN Smart Identity France. These facts do not establish a complete replacement or the precise coexistence of components.
- iDAKTO announced its acquisition of Stelau in June 2026. Stelau holds the information-system expertise lot. This proves no conflict, but warrants scrutiny of recusals, team separation and change-of-control procedures.
- The mobile source code is still described as due to be published soon. The future EUDI Wallet is subject to an EU open-source licensing requirement for application components, with limited exceptions.
- France Identité’s terms strongly limit stated liability for interruptions and indirect financial loss, while also saying France Identité remains responsible to users for subcontracted services. The exact legal effect requires specialist analysis.
Two financial perimeters
The first figure comes from the French Senate’s 2026 budget report on the territorial and general administration of the State. It says the updated total cost of the France Identité programme is €107.4 million, mainly in non-payroll expenditure, and identifies €16.22 million in 2026 payment appropriations. The figures appear in the section on France Titres.
The total is not the price of a mobile app. It covers the programme over time, including infrastructure, services, operation, upgrades and other expenditure assigned to the project under the budget methodology.
The second figure comes from procurement. EU notice 58709-2025 covers development and secure operational maintenance of the Digital Identity Guarantee Service, SGIN. It divides the work into seven single-award lots and sets a total maximum value of €44.7 million.
The key word is maximum.
Each lot is a call-off framework with no published minimum. Adding the ceilings measures the maximum contractual envelope. It does not establish:
Orders actually placed
Amounts invoiced
Amounts paid
Work accepted
Penalties imposed
Ceiling still available
A headline saying that the State has already paid €44.7 million to seven companies would be false.
Seven functions, seven awardees
The procurement notice defines functions and ceilings. Awardees and the notification date are recorded in France’s public-procurement essential data, as republished in buyer and contract pages. That open data establishes award records. It does not replace the signed contract, call-off orders or execution documents.
↔ Scroll the table to read it on mobile.
| Lot | Function | Recorded awardee | Ceiling |
|---|---|---|---|
| 1 | Service coordination | Eurogroup Consulting France | €4.3m |
| 2 | International work, standards and State policies | Cabinet Louis Reynaud / CLR Labs | €3.9m |
| 3 | Information-system expertise | Stelau Conseil | €5.1m |
| 4 | Information-system security | Sopra Steria Group | €5.4m |
| 5 | Mobile-app development and maintenance | BAM | €7.2m |
| 6 | Server-app development and maintenance | IN Smart Identity France | €10.4m |
| 7 | Multi-party test and interoperability environments | Docaposte BPO | €8.4m |
All seven contracts are recorded as notified on 7 May 2025. The France Titres page on Pappers lists the lots and awardees. A Macellum page for lot 1 explicitly identifies the Ministry of Economy’s essential procurement data as its source.
Splitting the work offers an obvious benefit. No supplier automatically receives the whole chain. The notice also contains award incompatibilities. The coordination contractor cannot accumulate every other lot. Standards and security lots are incompatible with several implementation lots. The expertise lot cannot be combined with coordination.
Those clauses show that France Titres anticipated some concentration and role-confusion risk.
They do not answer the operational question. An incident may cross several lots: a mobile update calls a backend, invokes a signing service, produces logs, relies on a test environment and requires security teams to qualify it. Every supplier may meet its narrow obligation while the full chain remains unavailable.
Sovereignty then depends on the actor able to arbitrate between lots and take technical control when their diagnoses diverge.
Four years in the notice, six years in the data
The EU notice states an initial 24-month term and two 12-month renewals. The stated maximum is therefore 48 months.
The official DECP records filtered for SGIN nevertheless display 72 months for all seven contracts notified in May 2025.
The difference does not prove an irregularity. Possible explanations include:
- a metadata error or misinterpretation;
- a distinction between framework duration and execution period;
- inclusion of similar follow-on services;
- a later contractual modification;
- an error in the public-data publication chain.
The signed documents must decide the issue. Each lot requires its engagement act, administrative terms, amendments and legally applicable end date.
The discrepancy is informative in itself. A citizen can learn the awardee and ceiling. The published data still do not allow a confident conclusion about the term for which the State is legally committed.
The Senate documents a wider dependency
The Senate report does not give an outsourcing rate for France Identité alone. It covers France Titres projects as a whole.
It places their outsourcing rate between 78% and 95%, compared with a 60% maximum recommended by DINUM. The report warns of loss of sovereignty, skills and operational control. It also identifies financial risk, saying outsourcing costs 20% more according to DTNUM and up to 100% more according to France Titres than the compared internal cost. It estimates that bringing 50 full-time equivalents back in-house over five years could save about €5 million. The report publishes the estimates and their context.
Two safeguards are necessary.
First, the rate does not mean that 78% to 95% of France Identité code is written outside the State. France Titres also manages identity documents, vehicle registrations, driving licences and user assistance.
Second, the 20% to 100% cost premium is an administrative estimate reported by the Senate, not a detailed cost ledger for every France Identité contract.
The signal remains strong. Parliamentary scrutiny describes the operator of a sovereign identity system as structurally outsourcing far above the recommended reference.
The question is no longer merely how many suppliers exist. It is how many public employees can take over their work.
The State retains critical layers
The chain is not wholly outsourced.
France Titres says France Identité servers are hosted on the Interior Ministry’s cloud PI, in sovereign data centres and strictly segmented from other ministry applications. The same page cites mobile and backend audits, bug bounties and forthcoming publication of the mobile source code. These statements appear on the France Identité security page.
The published signature policy describes another State-controlled layer. The Interior Ministry’s secretariat-general is the signer of identity credentials. DNUM provides SIGNHOR. SGIN is the only service authorised to request the seal under this policy. Keys are protected in ANSSI-qualified hardware security modules, and the ministry provides timestamping. The policy sets out the actors and process.
A first boundary can therefore be drawn:
Server hosting
→ Interior Ministry cloud PI
Electronic seal and timestamp
→ DNUM / SIGNHOR / ministry
Signing keys
→ ANSSI-qualified HSMs
Coordination, expertise, security,
apps, backend and testing
→ SGIN framework contracts
This prevents a simplistic account. Awarded suppliers do not necessarily hold identity data, signing keys and hosting. Conversely, owning infrastructure does not prove that the State can independently operate the applications running on it.
A public server can depend on a deployment only the supplier knows how to produce. A State-held key can be unusable when the service preparing the signing request is down. Intellectual-property rights can belong to ANTS while repositories, build pipelines, publishing accounts and daily expertise remain distributed.
Sovereignty is tested when the supplier changes
The service terms state that intellectual-property rights connected to SGIN and the France Identité application remain the property of ANTS. This is a significant safeguard. The clause appears in the current terms.
Legal ownership does not answer every operational question.
Taking over an application requires at least:
Complete source and history
Dependency and licence inventory
Build scripts
Test pipeline
Deployment images
Technical accounts
Required certificates and secrets
Architecture documentation
Incident procedures
Skills to understand the whole system
The sovereignty test can be expressed as eight verbs:
Know
Decide
Audit
Build
Operate
Repair
Replace
Answer financially
A contract that is reversible on paper is not a tested handover. Delivered documentation is not necessarily current. Repository access does not guarantee that the State can reproduce the binary installed on millions of phones.
The decisive evidence would be an exercise in which a different team takes over the source, rebuilds the app, deploys a clean backend and restores the service within the contractual target. No public result of such a test was found in the reviewed records.
From Atos to BAM: code handover should leave evidence
Official 2023 CSPN certification reports identify Atos France as developer of France Identité Android 1.2.4 and iOS 1.2.3. The Interior Ministry was the sponsor and AMOSSYS the evaluation centre. The certificates covered mobile components involved in using the app as a high-assurance electronic identification means. They did not indiscriminately certify the backend and every operational process. The Android report and iOS report are published by ANSSI.
The mobile lot notified in May 2025 is awarded to BAM.
These facts establish a supplier transition. They do not reveal:
- whether Atos still maintains a component;
- whether BAM received the entire source tree;
- which release was the first under its responsibility;
- who controls the build pipeline;
- who owns Apple Developer and Google Play Console accounts;
- whether a new evaluation followed the change;
- whether France Titres tested rebuilding without the historical team.
Changing supplier is not a problem. It is the moment when reversibility can be demonstrated.
Expected evidence is standard: a handover report, dependency inventory, repository transfer, open-ticket list, known vulnerabilities, licences, deployment procedures and validation of the first inherited release.
The claimed backend and the awarded backend
iDAKTO describes itself as a technology partner to France Identité. Its case study says the company designed the ID-card reading SDK and backend management system, and describes the wallet as using its technology. This is the supplier’s own account, not an independently verified contract map.
The 2025 lot 6 for server-app development and maintenance is awarded to IN Smart Identity France.
Several architectures are possible:
- iDAKTO still supplies a component integrated by the lot 6 contractor;
- iDAKTO acts as a subcontractor;
- a legacy backend coexists with a newer layer;
- components were transferred or rewritten;
- the case study mainly describes an earlier phase.
None can be presented as fact without the contracts and current architecture.
One nuance prevents an overly simple State-versus-private-company narrative. The national business register, as displayed by Pappers, lists Imprimerie Nationale as president of IN Smart Identity France. France’s Economy Ministry also describes IN Groupe as 100% state-owned in the release announcing completion of the IDEMIA Smart Identity acquisition. The official release is dated 1 July 2025.
The server lot is therefore held by a separate company integrated into a State-owned industrial group. This weakens any claim of complete privatisation. It does not settle operational control: source, licences, teams, secrets, subcontractors and replacement capacity still need mapping.
Stelau’s acquisition creates a separation-of-roles question
Stelau Conseil is recorded as the awardee of lot 3 for information-system expertise.
On 16 June 2026, iDAKTO announced its acquisition of Stelau. The release brings together iDAKTO’s identity platforms and Stelau’s advisory, security-assessment, compliance and cybersecurity work. The acquiring company dates and describes the transaction.
The acquisition proves no conflict of interest.
It creates governance questions:
- does lot 3 advise on components supplied or claimed by iDAKTO?
- which assignments require recusal?
- are teams, managers and tools separated?
- was France Titres notified of the change of control?
- did the contract require consent or reassessment?
- does another actor validate work when the group is involved?
The procurement notice anticipated incompatibilities between some lots. A later acquisition can alter the economic balance without changing the original awardee name in public data. Controlling such changes is part of contractual sovereignty.
Open source is still promised for later
The official security page still says that the mobile application source code will be published open source “soon”. The wording remained online on 28 August 2026.
The European framework adds a specific requirement for the future EUDI Wallet. Regulation 2024/1183 requires application software components to be licensed open source, with justified exceptions for certain specified components not installed on the device. The rule appears in Article 5a.
This does not establish that the current France Identité app already breaches the requirement. It is not yet the entire European wallet, and implementation is ongoing.
The promise should nevertheless become testable:
- publication date;
- iOS and Android scope;
- Git history;
- dependencies and submodules;
- NFC SDK;
- build instructions;
- licence;
- excluded components;
- correspondence between public source and distributed binaries.
An incomplete repository published after each release would provide limited transparency. Reproducible builds would go further by allowing a compiled binary from public source to be compared with the one distributed through app stores.
Who holds what?
L0G TOOL // WHO HOLDS WHAT?
Open a scenario. Each card separates the documented component, the possible economic consequence, the known fallback and the information still missing.
The mobile app no longer starts
Documented: lot 5 covers mobile-app development and maintenance. BAM is recorded as the awardee from May 2025. Atos France developed the versions certified in 2023.
Financial risk: inability to use FranceConnect+ or a mobile credential for urgent training, benefit or corporate filing.
Fallback: it depends on the end service. Part two found alternatives involving post, an external certificate or an in-person visit.
Unknown: contractual correction time, the State’s build capability, app-store publishing accounts and handover procedure.
The SGIN backend becomes unavailable
Documented: lot 6 covers server applications. France Identité says the servers are hosted on the Interior Ministry cloud PI.
Financial risk: authentication or credential generation may fail across several services relying on the same identity layer.
Fallback: no public matrix shows which functions remain available offline or without the backend for each connected service.
Unknown: RTO, RPO, failover tests and France Titres’ access to repositories, deployment images and recovery secrets.
The State electronic seal is unavailable
Documented: DNUM provides SIGNHOR. Keys are protected in ANSSI-qualified HSMs, and only SGIN may request the seal under this policy.
Financial risk: inability to generate signed identity evidence needed for a rental, contract or procedure.
Fallback: a recipient may accept another document, depending on its policy and the applicable law.
Unknown: signing-service redundancy, restoration time and liability when evidence arrives after a deadline.
A supplier fails or changes control
Documented: the lots are separated and include award incompatibilities. iDAKTO announced its acquisition of Stelau in June 2026.
Financial risk: loss of expertise, slower fixes, transition cost or dependence on a proprietary component.
Fallback: contract terms can provide for continuity and exit. The signed agreements needed to establish whether, how and within what deadlines they apply are not available in this public record.
Unknown: change-of-control notifications, recusal rules, source-code escrow, tested reversibility and exit assistance.
An identity is wrongly revoked or rejected
Documented: France Identité can gate access to FranceConnect+ and sensitive procedures. The service terms provide support and complaint channels.
Financial risk: delayed benefit, lost training place, blocked corporate signature or missed contract.
Fallback: there is no single public appeal route for every connected service. Each operator retains its own procedures.
Unknown: correction time, retroactive preservation of rights and liability sharing among France Titres, the end service and the technical supplier.
This tool does not predict an outage. It converts a technical chain into questions of continuity, liability and financial loss.
Operational risk becomes financial risk
France Identité contains neither a bank account nor a monetary balance. The app by itself does not give the State a power to seize or freeze a citizen’s money.
Financial risk appears through functional dependency.
Part two documented services where FranceConnect+ accelerates access to training, a benefit or a corporate filing. France Identité presents certified identity as a route to Mon Compte Formation, MaPrimeRénov and INPI. When the identity layer fails, a user may be pushed to a slower path involving post, an external certificate or an in-person visit.
A common failure can therefore produce correlated blocks even when end services remain legally and technically distinct.
The scenario does not predict a nationwide outage. It imposes analytical discipline:
Failed component
→ unavailable or rejected identity
→ inaccessible economic service
→ delay or deadline
→ measurable loss
→ liability to allocate
The most important metric will not be France Identité’s availability percentage alone. Public accountability requires:
- maximum critical-incident response time;
- recovery time objective, or RTO;
- recovery point objective, or RPO;
- mean time to repair;
- number of end transactions affected;
- ability to preserve rights retroactively;
- compensation mechanism.
The terms limit stated liability
The terms promise availability “as far as possible” 24 hours a day and seven days a week. They allow testing, maintenance and emergency intervention and disclaim responsibility for resulting direct or indirect consequences.
The liability section says France Identité cannot guarantee the absence of errors. It classifies financial and commercial losses, lost customers, profit or reputation as indirect loss excluded from its stated responsibility. It also disclaims responsibility for continuity, durability, compatibility, performance and bugs. The wording is in the current terms.
The same document contains an important provision: France Identité may subcontract any part of the service, but remains solely responsible to the user, with recourse against its subcontractors.
The terms do not prove that compensation is legally impossible. Their effect depends on French administrative liability, mandatory national law, GDPR, eIDAS, negligence and the end service involved.
eIDAS already allocates liability in certain cross-border identification transactions when damage results intentionally or negligently from a breach. The new framework applies corresponding liability rules to EUDI Wallets. The consolidated text contains Article 11 and the reference in Article 5a.
The practical question remains simple:
An identity error costs someone a training place, delays a grant or blocks a company closure. Must the user act against France Titres, the end service, the authentication operator or the technical supplier?
The subcontracting clause supplies part of the answer: users should not have to identify every contractor before approaching France Identité. It still publishes no compensation table, payment deadline or single mechanism for economic losses.
The missing documents
Public material provides names, functions and ceilings. It does not measure recovery capability.
l0g seeks release, with necessary security redactions, of the following records.
For each lot
- engagement act;
- administrative terms;
- technical specification;
- amendments;
- call-off orders;
- invoices and amounts paid;
- declared subcontractors;
- acceptance records;
- penalties imposed.
For reversibility
- detailed intellectual-property clauses;
- proprietary component inventory;
- third-party licence status;
- source-code deposit or escrow;
- exit plan;
- tested handover report;
- Atos-to-BAM transition record;
- account and secret matrix;
- post-contract assistance period.
For continuity
- contractual RTO and RPO;
- business-continuity plan;
- disaster-recovery plan;
- restoration results;
- multi-supplier crisis exercises;
- fallback modes by use case;
- insurance and liability limits.
Those records need not expose vulnerabilities, secrets or administrative paths. Recovery objectives, allocation of responsibility, amounts paid and proof that a reversibility test succeeded can be published without compromising the system.
l0g methodology
This article uses five documentary layers:
- the Senate budget report for programme cost and France Titres outsourcing;
- the EU procurement notice for functions, ceilings, durations and lot incompatibilities;
- French public-procurement essential data for awardees and notification dates;
- France Identité pages and policies for hosting, signing, intellectual property and liability;
- official ANSSI certification reports and company statements to reconstruct historical suppliers and their own claims.
The method keeps five categories separate:
ESTABLISHED
Official record, law or public data
DECLARED
Statement by France Identité or a supplier
INFERRED
Logical consequence explicitly identified as l0g analysis
UNKNOWN
Information absent from reviewed records
TO BE TESTED
Recovery, reversibility or behaviour requiring evidence
The article does not turn:
- a ceiling into expenditure;
- an agency-wide outsourcing rate into a France Identité-specific rate;
- marketing into an official architecture map;
- an acquisition into a conflict of interest;
- an intellectual-property clause into proof of operational skill;
- certification of a mobile version into certification of the whole infrastructure;
- a contractual disclaimer into a final ruling on compensation rights.
Questions must now go to France Titres, DNUM, ANSSI and the awardees. Any response should be incorporated with its date, scope and supporting evidence.
Documentary sources
Institutional sources and public data:
- French Senate 2026 budget report on France Titres
- EU notice 58709-2025 for the seven SGIN framework contracts
- Official French public-procurement essential-data dataset
- France Identité security page
- France Identité signature policy
- SGIN terms of use
- ANSSI CSPN report for France Identité Android 1.2.4
- ANSSI CSPN report for France Identité iOS 1.2.3
- French Economy Ministry release on IN Groupe’s acquisition of IDEMIA Smart Identity
- Regulation (EU) 2024/1183 on the European Digital Identity Wallet
- Consolidated eIDAS Regulation as of 18 October 2024
Company statements, used only to attribute the companies’ own claims:
Evidence of operational sovereignty
France Identité combines substantial public control with an extensive contract chain.
The State says it hosts the servers. It retains the electronic seal, timestamping and signing keys. ANTS claims intellectual-property rights over the service. Lot separation limits supplier concentration.
At the same time, seven frameworks cover coordination, expertise, security, mobile apps, backend and testing. The Senate describes high outsourcing across France Titres. Supplier handovers, recovery plans, deployment accounts, tested reversibility and financial allocation of liability are not assembled in a public, verifiable record.
The evidence therefore does not establish that the State has lost control. It also does not establish that it can independently take over every component within a known time.
Real sovereignty is measured on the day a supplier stops answering.
Has the State bought skills it can take over, or a dependency it will discover only during the first major incident?
For the user, the paired question is:
When the contract chain fails and identity no longer opens access to a benefit, signature or filing, who bears the loss?
Limitations and update date
Document review closed on 28 August 2026.
l0g did not have access to signed contracts, call-off orders, source repositories, build pipelines, secrets, service dashboards or production-recovery plans. No outage, failover or reversibility test was conducted for this article. Amounts paid, effective subcontractors, RTO/RPO targets and compensation mechanisms remain to be obtained through the right of reply and documentary requests.
This analysis is not investment advice.
// cite this analysis
l0g, “Your identity in your phone, 3/8: sovereignty under contract”, l0g.fr, published August 28, 2026, updated August 28, 2026, https://l0g.fr/en/analysis/your-identity-in-your-phone-3-sovereignty-under-contract/
$ cd ../analysis