RCDevs Security on UGAP: European Cybersecurity Built for Control, Sovereignty & Choice
RCDevs Security on UGAP: European Cybersecurity Built for Control, Sovereignty & Choice
European governments and public institutions are reconsidering the technologies on which their essential services depend.
Cybersecurity is no longer just about stopping attacks. Governments must also consider where their data is stored, who operates the underlying infrastructure, which jurisdictions may apply, and whether critical services can continue operating independently of a single foreign technology provider.
This is driving greater interest in Linux, open-source technologies, and sovereign European solutions. Public institutions increasingly want infrastructure they can control, operate, and adapt without being locked into a single proprietary ecosystem.
RCDevs Security’s availability through the UGAP multi-vendor catalog gives French public-sector organizations a more direct path to European identity and access security.

RCDevs Security Is Available Through UGAP
UGAP, the Union des groupements d’achats publics, is a central public purchasing organization serving the French public sector.
RCDevs Security has been referenced in the UGAP catalog since May 2024. This listing helps eligible public organizations simplify the procurement of cybersecurity technologies, including identity and access management, multifactor authentication, public key infrastructure, and secure access solutions.
Solutions available through the catalog include:
- Multifactor authentication for VPN and SSL VPN access
- MFA for Windows login, offline login, and Remote Desktop Services
- Authentication for cloud applications using SAML, OpenID Connect, and OAuth
- Identity federation and single sign-on
- Public key infrastructure
- Network access control
- Conditional access and Zero Trust capabilities
- Centralized SSH key management
- Comprehensive Linux access management
- Mobile authentication and push notifications
- Passwordless authentication through smartcards
- Secure access for legacy applications
- And much more
For public administrations, this means access to a broad identity security platform through an established procurement channel, not simply another isolated authentication product.
European Governments Want Greater Digital Sovereignty
Across Europe, public authorities are reassessing their dependence on a small number of large, non-European technology providers.
Governments are exploring Linux, open-source office suites, sovereign cloud services, European collaboration platforms, and locally controlled infrastructure. These initiatives are not necessarily about rejecting every proprietary or non-European technology.
They are about preserving choice.
A sovereign technology strategy allows an organization to decide where its systems run, where its data is stored, who can access it, and how critical services will continue operating during regulatory, commercial, or geopolitical disruption.
Linux and open-source technologies can support this strategy by providing:
- Greater control over infrastructure
- Better transparency
- More deployment flexibility
- Reduced dependence on a single vendor
- Improved interoperability
- Greater freedom to choose hosting and support providers
- More control over upgrades and product roadmaps
- The ability to operate critical systems on internally managed infrastructure
However, moving to Linux or open-source infrastructure is only part of the journey. Every operating system, application, server, network device, and remote access service still requires strong identity protection.
That is where RCDevs provides an essential security layer.

OpenOTP Is Not Open Source & That Can Be an Advantage
OpenOTP is not an open-source product. It is a commercially developed and supported identity security platform.
However, RCDevs does not use that commercial model to force customers into a closed ecosystem.
OpenOTP is designed to work with open standards, widely adopted authentication protocols, modern applications, existing enterprise infrastructure, and legacy systems. This gives organizations the accountability and support of a commercial security product without requiring them to replace their entire technology environment.
The distinction is important.
A product does not need to be open source to support technological sovereignty. It needs to give customers control over deployment, data, infrastructure, integrations, and long-term technology choices.
OpenOTP can integrate with technologies and standards such as:
- RADIUS
- LDAP and Active Directory
- SAML
- OpenID Connect
- OAuth
- FIDO and FIDO2
- WebAuthn
- TOTP and HOTP
- Push authentication
- X.509 certificates
- Public key infrastructure
- PAM-based Linux and Unix authentication
- SSH
- VPN and network access systems
- Windows login and Remote Desktop Services
- Modern web applications
- Legacy applications and infrastructure
This broad compatibility allows public organizations to protect heterogeneous environments from a centralized platform.
A government agency may operate Linux servers, Windows workstations, VPN appliances, older internal applications, cloud services, network equipment, and custom-developed software at the same time. OpenOTP can help apply consistent authentication policies across all of them.
The organization does not need to redesign its infrastructure around RCDevs. RCDevs adapts to the organization’s infrastructure.
Modern Security Without Abandoning Legacy Systems
Government IT environments are rarely built entirely from modern cloud applications.
They often include systems that have been operating for many years, specialized applications with long replacement cycles, industrial or operational technologies, and services that cannot easily be migrated.
A security platform that only supports the latest applications creates a difficult choice: replace working systems or leave them insufficiently protected.
RCDevs provides another option.
Through support for established protocols such as RADIUS, LDAP, PAM, and certificate-based authentication, OpenOTP can extend modern identity security to older infrastructure. At the same time, it supports modern standards such as SAML, OpenID Connect, OAuth, FIDO2, and WebAuthn.
This creates a bridge between legacy and modern technology.
Organizations can introduce capabilities such as multifactor authentication, passwordless access, conditional access, identity federation, and centralized auditing without requiring an immediate, large-scale infrastructure replacement.
The advantages include:
- Faster security improvements
- Lower migration risk
- Reduced disruption to public services
- Better protection for existing investments
- A gradual path toward modernization
- Consistent policies across old and new systems
- Less dependence on a single operating system or application provider
Modernization can happen according to the organization’s priorities,not according to a vendor’s commercial timetable.
Avoiding the Microsoft Ecosystem Lock-In
Microsoft provides a broad and capable technology ecosystem. For organizations that already use Microsoft 365, Azure, Entra ID, Windows, and related services, adopting additional Microsoft security products can appear to be the most convenient option.
However, convenience can gradually become dependency.
The more identity, authentication, endpoint management, collaboration, email, cloud infrastructure, and security services are concentrated within one ecosystem, the more difficult and expensive it can become to move away from it.
Organizations may find that advanced security features depend on:
- Specific Microsoft subscription levels
- Additional premium licenses
- Azure or Microsoft cloud services
- Entra ID integration
- Microsoft-managed identity infrastructure
- Windows-centered administration
- Bundled products and licensing agreements
- Continued adoption of other Microsoft services
This can create a compounding form of vendor lock-in.
A customer may initially adopt one product because it integrates easily with the technology already in place. That product then makes the next Microsoft product easier to adopt. Over time, the technical and financial cost of choosing an alternative becomes increasingly high.
The organization is no longer selecting each technology independently. It is making decisions within the boundaries of a single vendor’s ecosystem.
RCDevs takes a different approach.
OpenOTP is not tied to one productivity suite, operating system, cloud platform, directory, or device ecosystem. It can secure Microsoft technologies, but it can also secure Linux, Unix, VPNs, network equipment, cloud applications, on-premises applications, and legacy systems.
An organization can use Active Directory today, migrate some services to Linux tomorrow, introduce a different cloud provider later, and continue using the same central authentication platform.
This provides several strategic advantages:
- Freedom to use multiple operating systems
- Freedom to choose different cloud providers
- Freedom to retain on-premises infrastructure
- Freedom to replace individual applications
- Freedom to modernize gradually
- Reduced dependence on bundled licensing
- Greater negotiating power with technology vendors
- Better long-term control over the IT roadmap
RCDevs does not require customers to abandon Microsoft technology. It allows them to use Microsoft technology without making Microsoft the mandatory center of every security and identity decision.
One Security Platform for Linux, Windows, Cloud, and Legacy Technology
A sovereign infrastructure requires sovereign access controls.
RCDevs enables organizations to protect Linux, Unix, Windows, VPN, cloud, network, and legacy environments through a centralized identity and authentication architecture.
Administrators can apply consistent access policies across heterogeneous systems instead of maintaining separate authentication mechanisms for every platform.
For Linux and Unix environments, RCDevs can provide:
- Multifactor authentication for local and remote access
- Centralized authentication policies
- Secure SSH access
- SSH key lifecycle management
- Certificate-based authentication
- Conditional access rules
- Passwordless authentication
- Identity federation
- Detailed authentication logs
- Centralized auditing
- Integration through PAM and standard protocols
This allows public organizations to adopt Linux and sovereign infrastructure without sacrificing enterprise-grade identity security.
RCDevs also supports mixed environments. Governments do not need to migrate every system simultaneously before improving security. Existing Windows services, Linux servers, VPNs, directories, cloud applications, and legacy systems can be protected as part of the same identity strategy.
On-Premises Deployment for Maximum Control
For organizations handling sensitive, regulated, or classified information, on-premises deployment remains essential.
RCDevs solutions can be deployed entirely within the customer’s infrastructure, allowing the organization to maintain direct control over:
- Authentication data
- Identity information
- Encryption keys and certificates
- Security policies
- Audit logs
- Administrative access
- System availability
- Backup and recovery procedures
- Software update schedules
- Integration with internal infrastructure
An on-premise deployment can also support isolated, restricted, or air-gapped networks where external cloud dependencies are undesirable or prohibited.
The customer determines where the platform runs, who can administer it, how it connects to internal systems, and when changes are introduced.
Security teams can align the deployment with their own architecture, compliance requirements, operational procedures, and risk management policies.
For institutions pursuing digital sovereignty, this level of control is significant. It limits unnecessary third-party dependencies while keeping identity enforcement close to the systems being protected.
It also reduces reliance on external cloud availability. Authentication services can continue operating within the organization’s own infrastructure, according to its own continuity and disaster recovery strategy.

European-Hosted SaaS Without Giving Up Choice
Not every organization wants to operate its own authentication infrastructure.
RCDevs also provides a SaaS option hosted in European data centers. This gives customers the operational advantages of a managed service while keeping the hosting environment within Europe.
A European-hosted SaaS deployment can provide:
- Faster implementation
- Reduced infrastructure management
- Predictable maintenance
- European data residency
- Managed availability
- Access to RCDevs identity and authentication capabilities without maintaining the entire platform internally
This model is suitable for organizations that want a cloud-based service while remaining attentive to data location, jurisdiction, regulatory alignment, and European technology sovereignty.
Most importantly, the deployment model is a customer decision.
RCDevs does not force every organization into a cloud-only architecture. Customers can choose on-premises deployment when maximum infrastructure control is required or European-hosted SaaS when operational simplicity is the priority.
Organizations can select the model that matches their security requirements rather than adapting their requirements to the provider’s preferred business model.
More Control Creates the Foundation for More Security
Control alone does not guarantee security. However, it gives an organization the ability to make, enforce, and maintain its own security decisions.
Greater control means knowing where identity data resides. It means determining who can administer the infrastructure. It means choosing how authentication is performed, how encryption keys are managed, and how services continue operating during an external disruption and it also means preserving the ability to change direction.
A sovereign security strategy should allow an organization to replace an operating system, cloud provider, VPN vendor, directory, or business application without having to replace its entire identity security platform.
RCDevs supports this approach through flexible deployment, broad protocol compatibility, and centralized identity security.
Organizations can retain control while benefiting from modern capabilities such as:
- Multifactor authentication
- Passwordless access
- FIDO2 and WebAuthn
- Public key infrastructure
- Identity federation
- Single sign-on
- Zero Trust
- Conditional access
- Secure SSH management
- Centralized logging and auditing
This is particularly important for public services, where authentication infrastructure must remain secure, available, interoperable, and manageable over the long term.
A European Security Partner for Public-Sector Transformation
The inclusion of RCDevs Security in the UGAP catalog comes at a time when European administrations are placing greater emphasis on technological control, open systems, interoperability, and regional cybersecurity expertise.
RCDevs offers more than a product designed for a single operating system, directory, cloud, or use case.
It provides a European identity security platform capable of protecting Linux, Windows, cloud, network, and legacy environments through a unified architecture.
OpenOTP may not be open source, but it supports the fundamental objectives behind open and sovereign technology strategies: interoperability, portability, infrastructure control, deployment choice, and independence from a single vendor ecosystem.
Whether deployed entirely on premises or delivered as SaaS from European data centers, RCDevs enables public organizations to choose the balance of control and operational simplicity that works for them.
For governments moving toward Linux, open standards, sovereign infrastructure, and European digital services, identity must remain at the center of the strategy.
With RCDevs, organizations do not have to choose between modern security and technological independence.
They can have both.