The Netherlands builds sovereign cloud to cut reliance on big tech
The Hague, Sunday 27 September 2026
The Dutch government is actively developing a sovereign digital infrastructure, testing open-source alternatives to major software providers to secure national data and boost European technological autonomy.
Redefining Sovereignty in the Cloud Era
The Nederlandse Digitaliseringsstrategie (NDS) has integrated cloud infrastructure, digital resilience, and purchasing power into a unified, government-wide programme to systematically address foreign technological dependencies [1]. This strategic shift responds directly to critical administrative vulnerabilities; in 2025, the Dutch Court of Audit (Algemene Rekenkamer) reported that the central government lacked sufficient oversight over its cloud usage, revealing that out of 126 major public cloud services evaluated, 84—representing 66.667 per cent—had been implemented without any prior risk assessment [2]. The Dutch government’s 2025 vision explicitly distinguishes “digital autonomy” (the capacity to choose, change, and act) from “digital sovereignty” (strict legal and administrative control over systems and data), rejecting the unrealistic objective of total technological isolation in favour of maintaining sufficient freedom to switch suppliers or operating models [1].
A Strategic Shift in Procurement and Policy
To operationalise this vision, a revised central-government cloud policy came into effect on 3 July 2026, mandating exit plans for public-cloud services, assessing geopolitical risks, and strictly prohibiting the hosting of basic register source data within public clouds [1]. This aligns with broader European initiatives, including the European Commission’s Cloud Sovereignty Framework published on 1 June 2026, which establishes rigorous criteria for legal independence, technological autonomy, and supply chain security [2]. In tandem, the Dutch government has leveraged its collective purchasing power through frameworks like the April 2026 STACKIT agreement, which guarantees European Economic Area (EEA) data residency and audit rights without imposing minimum-spend commitments [1], alongside a formalised framework agreement with European cybersecurity provider ESET on 14 July 2026 to mitigate reliance on non-European entities [2].
Deconstructing the Technical Execution Stack
Moving beyond superficial desktop operating system migrations, the Dutch government is addressing deep-seated dependency structures using a formal technical framework represented by a directed dependency graph [1]. Under this model, a strategic dependency is identified if a component belongs to every feasible implementation path and cannot be substituted within a maximum tolerable disruption time [1]. To test these dependencies, a municipal pilot involving Amsterdam, Ede, ’s-Hertogenbosch, and Zaanstad is actively testing the DAWO endpoint management system and MijnBureau collaboration suite through 31 December 2026 [1]. As of September 2026, the DAWO fleet manager, Sextant—which utilises NixOS with layered flake definitions for enhanced configuration observability—remains in Beta while undergoing deployment validation to resolve tool mismatches with endpoint-security products [1].
Securing Infrastructure and Legacy Systems
On 31 August 2026, the Netherlands published a design for a sovereign-cloud Proof of Concept (PoC) utilising open-source government-wide IaaS and the “Haven” container platform standard, though critical details regarding governance, financing, and procurement remain deferred [1]. This push for infrastructural control is mirrored in the legacy modernisation of the Belastingdienst (Dutch Tax Authority), which in June 2026 insourced its VAT-system infrastructure hosting and established strict controls over its supplier’s software-update channels [1]. Furthermore, the state has actively protected its critical assets; in May 2026, the government blocked Kyndryl’s proposed acquisition of cloud provider Solvinity on national security grounds, subsequently launching a procurement process for the platform hosting Logius and DigiD under the Defence and Security Procurement Act [1].
Countering AI-Driven Threats at Machine Speed
The urgency of establishing secure, sovereign platforms is underscored by a rapidly escalating cyber threat landscape dominated by autonomous artificial intelligence [3]. In July 2026, security researchers documented the first fully autonomous ransomware attack, which corrected its own execution failures and compromised credentials in just 31 seconds, followed closely by a massive automated attack targeting the infrastructure of AI platform Hugging Face [3]. In response to warnings from the Cyber Security Raad that AI-driven attacks are becoming faster and less detectable [3], a coalition of twelve Dutch organisations presented the “Samen sneller dan de dreiging” manifesto on 24 September 2026 to Willemijn Aerdts, the State Secretary for Digital Economy and Sovereignty, launching the Prometheus initiative to automate software vulnerability detection and remediation [3][4].
Knowledge and Collaboration as Sovereign Foundations
Evolving these systems requires a fundamental shift towards domestic expertise and research, as highlighted by the ICT Research Platform Netherlands (IPN) in its September 2026 report, which argues that true digital sovereignty is impossible without independent informatics knowledge to design, evaluate, and replace technological alternatives [5]. This view is shared across European borders, where France, Italy, Germany, and the Netherlands established the European Digital Infrastructure Consortium for Digital Commons (DC-EDIC) in October 2025 to scale open-source digital commons [1]. As other nations like Switzerland launch sovereign workplace programmes targeting thousands of employees by late 2027 [1], the Dutch strategy demonstrates that achieving true digital autonomy requires a continuous, verifiable chain of trust spanning from local source code repositories to sovereign cloud hosting [1][2].