
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

The Dutch government published a draft architecture (version 0.9) for a centrally built sovereign cloud service in late August, setting out the technical blueprint for the most ambitious public sector IT infrastructure project the country has undertaken in years.
Summary
After evaluating four scenarios in a study by Gartner, the government chose the most far-reaching option: building a new, centrally managed cloud from scratch rather than federating existing government platforms or extending arrangements with commercial hyperscale providers. The choice marks a shift from years of incremental cloud adoption that left government IT operations spread across platforms controlled by American technology companies. Ron Kolkman, CIO at Rijkswaterstaat and chair of the Cloud Acceleration Team behind the design, made the case for urgency on the Dutch government’s digital programme website .
“Cloud is no longer a niche topic,” he stated. “It has become the backbone of almost everything we do.” That dependency, he argued, has become a strategic vulnerability. “When major providers decide to change or shut down a service, the consequences can be enormous.” Software sovereign, hardware not The design adopts the European SEAL framework , which classifies digital sovereignty across five levels, from 0 (no control) to 4 (full sovereign control over software, hardware and operations).
For software, the Netherlands targets SEAL-4: complete ownership of the code running government workloads, with no dependency on proprietary components or foreign licensing conditions. For hardware, the design sets SEAL-3 as the practical maximum and states this without hedging: SEAL-4 for the hardware stack is currently not achievable “due to the absence of European manufacturers of CPUs, GPUs and ASICs”. In practice, SEAL-3 means the government can determine where hardware is located and who operates it, but cannot guarantee that the processors themselves are free from firmware or management engines controlled by non-European entities.
The design treats this gap not as a temporary shortcoming but as a structural reality of European industry, while noting the ambition to push hardware sovereignty as high as possible within that constraint. The sovereign cloud centres on a container platform compliant with the Haven standard used across Dutch government IT, running Kubernetes directly on physical servers without an intermediate virtualisation layer. The architecture is designed to scale to 50,000 physical servers.
All software must be Open Source Initiative (OSI)-approved, a stricter requirement than merely being OSI-compatible. The design explicitly prioritises European open source projects, singling out the NeoNephos initiative within the Linux Foundation Europe ecosystem. Development follows a phased approach.
The first phase delivers infrastructure as a service for containers, with support for conventional virtual machines where needed. Subsequent phases add platform services and eventually software as a service. A proof of concept is running in parallel with the design process, testing architectural choices in practice.
“Sovereignty means taking ownership,” Kolkman stated on the programme website. “It means not being entirely at the mercy of a provider’s whims or geopolitical shifts.” The architecture allows government organisations at every level, from municipalities to national ministries, to use the cloud according to their data classification, with the most sensitive workloads running in the most tightly controlled environments. The design describes a three-part financing model: central funding for fixed infrastructure costs, variable charges based on actual consumption, and a structural innovation budget.
It does not specify amounts for any of the three. Sector felt bypassed The design landed in an industry that was already frustrated. When the government established a framework agreement with StackIT, the cloud arm of Germany’s Schwarz Group, in April, the Dutch Cloud Community (DCC) called the decision a missed opportunity .
In May, the trade association representing domestic cloud providers said contact with the government had stalled in an exploratory phase, and that Dutch companies meeting sovereignty requirements had been prepared to engage but were never given the chance to compete. The DCC published a position paper in June calling for a national framework agreement that would include multiple Dutch and European providers instead of routing work through a single foreign platform. It recommended splitting large contracts into smaller components so that smaller firms could compete.
It estimated that a realistic path to digital autonomy would require three to five years of parallel system operation, with additional investment before savings materialise. The organisation urged the government to communicate honestly with parliament about transitional costs and timelines, warning that a successful transition “cannot be achieved within months and demands political continuity”. The architecture describes procurement processes that will draw on commercial expertise, but the central platform remains a government-built and government-controlled asset.
For Dutch cloud providers that developed sovereign offerings in anticipation of this moment, the question is whether their expertise translates into contracts or consultations. Open source, open risk Building the entire stack on open source software eliminates one form of supplier dependency but introduces another. The design acknowledges that working with its chosen building blocks requires substantial investment in expertise.
Bert Hubert, a former member of the Dutch Cyber Security Council, argued on his blog that European organisations consistently underestimate what maintaining open source infrastructure at government scale demands. The challenge is not in finding suitable code, but making sure the communities behind critical components will keep delivering security patches and updates with the reliability that continuous government operations require. As Dutch cloud pioneers have found , European providers excel at basic infrastructure but struggle to match the integrated service depth of American hyperscalers.
Hubert described the gap bluntly : European providers sell “beautiful wood”, he wrote, while customers need finished furniture. The design mitigates this risk by anchoring its stack to established open source projects with formal community governance, which offer continuity guarantees that single-supplier dependencies do not. A proof of concept is already running in parallel with the design process, but the budget commitments to move beyond it are not in the document.
Kolkman is unequivocal about the urgency: “We must act now.” Read more about Dutch digital independence Dutch politicians raise concerns over Big Tech reliance . The Netherlands starts building its own AI language model . Dutch universities have found themselves in the grip of American tech giants .
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment — not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.