The file by autumn:
what a credible exit plan actually contains
You are a CIO at a French ministry. On Wednesday morning, 8 April 2026, your inbox contains a one-page directive from the Direction interministérielle du numérique signed jointly by DINUM, the DGE, ANSSI and the DAE. By autumn, you are to file a written plan reducing your ministry’s extra-European digital dependencies. Seven categories are mandatory: workstations, collaborative tools, antivirus, artificial intelligence, databases, virtualisation, network equipment. The signatures on the directive are Anne Le Hénanff’s and David Amiel’s. The deadline is non-negotiable.
What you write into that file in the next six months is not a roadmap. It is the document that will define your ministry’s IT trajectory for the next decade — and, with high probability, will be cited as either evidence or counter-evidence in every subsequent procurement debate.
The trigger sits ten months upstream. On Tuesday, 10 June 2025, Senator Dany Wattebled asked Microsoft France’s Director of Public and Legal Affairs, Anton Carniaux, one question on the record before the Commission d’enquête on public procurement costs. Could Microsoft guarantee that French citizens’ data would not be transmitted to US authorities following a US government order? Carniaux did not equivocate. “Non, je ne peux pas le garantir, mais, encore une fois, cela ne s’est encore jamais produit” — no, I cannot guarantee it, but again, this has never yet happened. The sentence circulated for ten months. The directive on your desk is what the French state did with it.
This article is the audit of what makes an exit plan credible rather than performative, the reference case the directive is built on, and the specific question your file has to answer before the methodology can run its course.
What the directive requires
Each ministry must produce a roadmap. The seven categories are non-negotiable; the timelines within each are. The aggregate target is a substantial migration of state IT infrastructure by 2030. La Suite becomes the default office stack. Tchap, Visio and FranceTransfert become the default collaboration tools.
The Caisse nationale d’Assurance maladie is already the largest visible commitment: 80,000 employees moving onto Tchap, Visio and FranceTransfert. La Suite had reached about 40,000 regular users before the directive made it the default. The first inter-state milestone after the press release is a set of Rencontres industrielles du numérique in June 2026, at which DINUM intends to formalise public-private coalitions for the transition. DINUM itself will pilot the Windows-to-Linux migration before requiring it of others.
The political framing came from Le Hénanff, in one line: “La souveraineté numérique n’est pas une option.” The administrative framing is more concrete: every ministry is now responsible for a documented plan, and the plan will be read against a known reference case.
What makes the plan credible
There is a difference between a plan that survives publication and a plan that survives the autumn budget cycle. The directive does not specify the difference. The reference case the directive is built on does.
A credible seven-category plan, in the DINUM methodology, contains five elements that distinguish it from the European public-sector migration documents of the last decade. Most ministry roadmaps that get filed without these elements will be classified, internally, as performative — and the budget cycle will reflect that classification.
Named vendor replacements per category. Not “a sovereign alternative to Microsoft 365” but “La Suite for 4,200 users by Q2 2027, with Tchap replacing internal Teams for 2,800 users by Q4 2026, hosted on internal Proxmox cluster with Outscale as failover”. Vagueness in the plan is the marker the budget reviewer reads as absence of seriousness.
Per-category timelines tied to budget lines. The plan that wins the next funding round is the one whose 2027 line item is already specified in the 2026 document. Plans that promise “phased migration over five years” without naming the phases are the ones that get cut first when the political weather changes.
A staffing model for the transition. Migrations of this scope require a dedicated team — typically 8–15 architects and engineers for a ministry of 5,000 staff — for 18 to 36 months. Plans that do not name the team get the team allocated to them post hoc, by whoever is available, which is the operational definition of how the Munich migration failed.
Explicit dependency analysis at the supply-chain layer. The seven-category list covers what runs on the workstation. The plan that survives audit covers what the workstation depends on: kernel sources, package repositories, the build pipeline, the certificate-authority chain. A plan that promises Linux desktops without specifying where the kernel ships from will be re-opened when the supply-chain question is asked publicly, which on the current trajectory will be 2027.
A rollback specification. The plan that gets approved at the political level is the one that specifies, explicitly, the conditions under which the migration would be paused or reversed. Counter-intuitively, including a rollback clause raises political support for the plan, because it signals operational seriousness rather than ideological commitment.
These five elements do not appear in the DINUM directive text. They are the difference between the plans the methodology is designed to produce and the plans that will be filed by ministries that read the directive as a press release.
The Gendarmerie precedent
The empirical reference case behind the methodology is the Gendarmerie nationale. The Gendarmerie has run roughly 100,000 machines on Linux for two decades, with reported cumulative licence-cost avoidance of around €500 million. It is the only widely-citable European public-sector Linux migration that is unambiguously a success.
What is less widely cited is the methodology that produced it. The Gendarmerie’s migration began in 2005 with a scope so narrow it would be considered timid by today’s sovereignty rhetoric: replace Microsoft Office on existing Windows desktops with OpenOffice on the same desktops. The Linux migration came later, in 2008, by which point the team had three years of organisational learning about which workflows would and would not survive a stack change. The full Ubuntu rollout took until 2013. Then the team began documenting what they had learned, which is the part DINUM is now reusing.
Three principles from the Gendarmerie methodology shape the April 2026 directive:
One: narrow scope before broad ambition. The Gendarmerie did not announce a sovereignty transformation. It announced a licence-cost reduction. The architectural change was the unannounced consequence of the operational change, not the other way around.
Two: working replacements before mandates. The Gendarmerie tested OpenOffice on a pilot of 5,000 users for nine months before scaling. The April 2026 directive presupposes that La Suite, Tchap and Visio are already at the working-replacement stage. The CNAM’s 80,000-user commitment is the public evidence that this presupposition is correct.
Three: institutional autonomy from political cycles. The Gendarmerie reports jointly to the Interior and Defence ministries — a structure that has historically protected it from the kind of political reversal that ended Munich’s LiMux project. The April 2026 directive does not have that structural protection. It is an administrative instrument. The political cover is the Le Hénanff signature, which is contingent on the Bayrou government, which is contingent on the 2027 presidential election.
Carniaux’s June 2025 sentence is what closed the political distance between “the Gendarmerie’s methodology is interesting” and “every ministry will file a plan that uses it”. Without an admission from Microsoft itself, on the record, in a national legislature, the operational layer of French government would not have produced a directive of this scope this quickly. The Senate moment converted an architectural argument into a political fact.
What the directive does not fix
Even on the most optimistic reading, the directive addresses one layer of the dependency. Several deeper layers remain unaddressed.
Linux on 2.5 million government desktops would close a large exposure. It would not close the upstream supply chain — the kernel, the toolchains, the package repositories — most of which are hosted on US infrastructure, primarily GitHub. It would not close the cryptographic trust chain: certificate authorities and DNS root servers remain US-dominated. It would not close the hardware layer. The CPUs are Intel or AMD silicon with US export-control exposure, on firmware that is largely closed.
The directive’s seven-category list includes network and telecoms infrastructure, which is more than previous European efforts addressed. The upstream open-source supply chain on which everything else depends is not in scope. The directive is necessary, not sufficient, for the sovereignty it is claimed to deliver — and the plans your ministry files in autumn need to acknowledge the gap explicitly, even if the corrective work is out of scope.
There is also an industrial-policy reading that has not been widely surfaced. If France succeeds at this migration, two clusters of vendors win materially: Dassault Systèmes through Outscale, which hosts Visio, and a smaller constellation of French open-source service companies — Linagora, Atos, Worteks, Mailo Pro. The directive is, in commercial terms, a domestic procurement programme worth low single-digit billions over five years. That is not necessarily a problem — but the ministry plans are also industrial-policy instruments, and the procurement officers reviewing them will be measuring vendor concentration as well as sovereignty.
What this article is not
Anyone reading this analysis as a claim that France has solved the problem has missed the point — the DINUM directive begins a six-year programme, and the autumn 2026 ministry plans are the first measurable test, not the result. The methodology is not readily transferable to other member states: the institutional autonomy of the Gendarmerie and twenty years of Linux experience exist nowhere else in the EU. Linux on the workstation is one layer — the upstream supply chain on which Linux itself depends sits outside the scope of this investigation. For readers writing their own migration file, it does not substitute for technical or contract-law advice.
The question your file has to answer
What will be read most carefully in the autumn plans is not the timeline. It is the specificity. The base rate for European public-sector Linux migrations of this scope is failure. The base rate for migrations designed with named vendors, named teams, named budgets and named rollback conditions is unknown — because no European administration has tried the combination at this scale.
The 2027 presidential election will arrive before your ministry’s plan has been fully delivered against. A different political constellation could deprioritise the directive without legally reversing it. The directive is administrative, not parliamentary. The protection your plan has against political reversal is its concreteness. A plan with budget lines, a named team and a published rollback clause is harder to deprioritise than a plan with milestones. A plan that names Outscale as Visio host, names Linagora as Tchap deployment partner, names a senior architect with 24 months of dedicated time — that plan survives a change of government. A plan that promises “phased migration toward sovereign alternatives” does not.
The question your file has to answer, between now and autumn, is whether it is a plan that survives the next political cycle, or whether it is a roadmap that survives the news cycle. The methodology DINUM gave you is good enough that the difference is yours to decide.
Until then, the line that opened the file is the line that opens it: no, I cannot guarantee it.
Sources
- DINUM (numerique.gouv.fr): Souveraineté numérique — réduction des dépendances extra-européennes (8 April 2026)
- Sénat: Commission d’enquête — audition de Microsoft France (10 June 2025)
- Ministère des Finances: Souveraineté numérique — l’État accélère la réduction de ses dépendances extra-européennes
- LeMagIT: Souveraineté numérique — les ministères sommés de réduire leurs dépendances
- Alliancy: L’État structure sa stratégie de sortie des dépendances extra-européennes
- heise: Frankreichs Plan Weg von Windows hin zu Linux (10 April 2026)
- Clubic: Microsoft face au Sénat — l’aveu qui fait vaciller la souveraineté numérique française (June 2025)
- MyHostNews: Gendarmerie — €500 million saved, 20 years of Linux
Topic overview: Digital Sovereignty in Europe Related articles: Sovereignty on Microsoft’s servers, Linux in the Public Sector