Europe’s First Fully Independent Cybersecurity Service Launches in The Hague
The Hague, Tuesday 6 October 2026
Launched at the ONE Conference, Merlon’s new cybersecurity service offers European critical infrastructure complete independence from foreign data laws like the US CLOUD Act.
A New Standard for European Data Sovereignty
On Tuesday, 6 October 2026, the European cybersecurity landscape marked a significant milestone at the ONE Conference in The Hague [1][2]. Cybersecurity firm Merlon officially went live, launching the first 100% European sovereign cybersecurity stack and service [1][2]. Unlike many contemporary cybersecurity providers that claim sovereignty simply by hosting data within European data centres, Merlon’s offering ensures that ownership, control, and legal jurisdiction remain entirely within European borders [1][2]. This launch directly addresses the operational risks faced by European ministries, intelligence services, and critical infrastructure operators in an increasingly tense geopolitical climate [1][2].
Evading the Reach of Foreign Jurisdictions
To establish a verifiable benchmark for sovereignty, Merlon developed its technology stack in accordance with the European Commission’s Cloud Sovereignty Framework [1][2]. This framework measures data sovereignty using Sovereignty Effectiveness Assurance Levels (SEAL), ranging from SEAL-0 (indicating no sovereignty) to SEAL-4, which represents a completely European supply chain spanning from semiconductor chips to software applications [1][2]. While storing data within the European Union and complying with regional legislation satisfies only the baseline SEAL-2 level, Merlon’s stack is designed to meet a much higher standard [1][2][alert! ‘The source text contains an unpopulated placeholder “[SEAL-niveau]” for Merlon’s specific SEAL level compliance’]. Through this rigorous framework, Merlon provides continuous detection, analysis, and response services, keeping operational control firmly in European hands [1][2].
Securing Critical Infrastructure
This level of strict sovereignty is becoming essential due to the extraterritorial reach of foreign legislation, such as the United States CLOUD Act [1][2][GPT]. Under such laws, foreign governments can compel technology companies to grant access to stored data if the parent company or its investors are based outside of Europe, regardless of where the servers are physically located [1][2]. Earth Grob, the Chief Executive Officer of Merlon, emphasised the shifting reality, stating that geopolitical dependencies are becoming more visible and the threat landscape is growing heavier [1][2]. Grob noted that while organisations must choose how to respond, Merlon offers a clear, unambiguous answer for those wanting to know who ultimately controls their security: Europe [1][2]. The service is specifically tailored for high-risk sectors, including defence, national governments, European institutions, and vital infrastructure operators in energy, mobility, ports, and telecommunications [1][2].
Modernising Legacy Digital Foundations
The push for digital independence and modernisation is not limited to cybersecurity; it is also reshaping how legacy organisations manage their digital platforms [GPT]. Also on Tuesday, 6 October 2026, Nevi, the Dutch association for purchasing and supply management, completed the migration of its primary platform, Nevi.nl, to “Xperience by Kentico” [4][GPT]. Executed in partnership with Aviva Solutions, this migration represents a shift away from Kentico 13 towards an “evergreen” platform model [4]. This modern framework eliminates the need for future large-scale technical migrations by allowing continuous, incremental updates [4]. For Nevi, the upgrade involved a comprehensive overhaul of its digital workflows, including content classification, email construction, audience segmentation, and system integrations [4]. Roel Vanhooydonck, Digital Marketeer at Nevi, explained that the goal was to build an environment where content, data, and email marketing converge, allowing the organization to adapt its digital services dynamically over the next five years [4].
Scaling Data and AI Across Borders
As organisations modernise their software foundations, the demand for advanced data analytics and artificial intelligence is driving rapid business expansion across the Benelux region [GPT]. Earlier, on 6 September 2026, the Belgian data and AI consultancy Element61 announced its expansion into the Dutch market with a new office in Utrecht [3]. Led by partners Maarten Molenaars, Reinier Plantinga, Bart Van Der Vurst, and Managing Partner Steven Decerf, the firm is targeting large enterprises with annual revenues of €250 million or more [3]. Element61 reported a total revenue of €27 million in 2025, having maintained an average annual organic growth rate of 25% since 2020 [3]. The company aims to nearly double its business to reach €50 million in revenue within the next three years [3], representing a targeted growth of 85.185% through organic expansion and strategic acquisitions [3]. To support this rapid scaling, Element61 relies on proprietary technology, notably an “agentic colleague” named “Ralph”, designed to automate data engineering, monitor pipelines, and accelerate migrations from legacy systems [3].