Government Common Ground BIO-compliant

Custom government software and apps

The Dutch government faces a far-reaching digital transformation. Citizens expect the same user experience as with commercial apps, while the requirements for security, accessibility and interoperability are stricter than ever. We build government software that combines both worlds: intuitive for the user, compliant under the bonnet.

Digital services citizens deserve

Government organisations face unique challenges: high availability requirements, strict security standards and a diverse public with varying digital skills. Our approach rests on three pillars that form the core of successful government software.

Citizen-centred design

Every application starts with the end user. Whether it is a resident reporting a move, an entrepreneur applying for a permit or a professional wanting access to a file, the interface must be clear and accessible. We design to WCAG 2.1 AA, test with screen readers and validate with real users so that no one is left out.

  • Inclusive design for all digital skill levels
  • WCAG 2.1 AA compliance as a hard requirement
  • User research with representative target groups
  • Multilingual interfaces where needed

Process automation

Government processes are often complex, involving multiple departments, statutory deadlines and supporting evidence. We digitise these processes end to end, from intake and status notifications to automated decisions. This shortens lead times, reduces manual errors and frees up staff for work that requires human contact.

  • Case-based working in line with the GEMMA architecture
  • Automated status updates for applicants
  • Digital signatures and document generation
  • Statutory deadline monitoring with escalations

Transparency and open data

Democratic oversight requires transparency. We build dashboards and portals that actively make public sector information available to citizens, councillors and journalists. From budget visualisations and governance documents to open data APIs that enable reuse by third parties, all in line with the Open Government Act (Woo) and the Dutch open data policy.

  • Open data portals compliant with the DCAT standard
  • Council information systems with search functionality
  • Budget and accountability dashboards
  • APIs for reuse by third parties

Solutions for the public sector

From front-office citizen portals to back-office process applications, we build government software that fits the existing information management landscape and meets the requirements of the Forum Standaardisatie list.

Citizen portals and MijnOmgeving

Personal environments where residents handle their affairs with the government. Submit applications, upload documents, track status and receive messages. Integrated with DigiD for authentication and with the case management system for real-time status information. Responsive design for use on any device, with notifications by email or via the Berichtenbox.

Case-based working

Applications that support the full case process in line with the GEMMA case type catalogue. From registration and routing through to handling and archiving. With built-in deadline monitoring, document management and connection to the Digital Infrastructure (Digitaal Stelsel). Suitable for both simple notifications and complex permit procedures involving multiple advisory bodies.

Participation platforms

Digital platforms for citizen participation and consultation. From e-democracy tools for citizen initiatives to interactive maps for area development. With functionality for voting, commenting, visualising plans and feeding participation results back to the municipal council. Accessible to all age groups and levels of digital skill.

Open data dashboards

Interactive visualisations of government data for residents, councillors and policymakers. Energy use, air quality, housing development, safety: complex datasets translated into clear charts and maps. With export options, API access and automatic updates from source systems. Built on open standards so the data can be reused.

Permits and reports

Digital application processes that complement the Omgevingsloket (national environmental permit portal) with municipality-specific permit types. Smart forms that show the right fields based on answers, validate documents and automatically route to the responsible case handler. With integrations to the Chamber of Commerce register, BAG and the Land Registry for automatic data enrichment.

Internal work processes

Custom software for civil servants that doesn't fit off-the-shelf packages. From grant management systems and enforcement applications to WMO allocation systems and event permits. Designed around the user's workflow, not around the limitations of a generic package. With dashboards for management information and control indicators.

If your app captures information that will later count as an archival record, the new Archiving Act sets requirements for it. For what this means for an inspector or field officer, see the app for archival records from the field.

Expertise at every level of government

Each tier of government has its own statutory duties, its own information systems and its own architecture principles. We understand these differences and tailor our approach to the specific context of your organisation.

Municipalities

Municipal software

Municipalities are citizens' first point of contact. This is where citizen services, permits, WMO, youth care and the social domain come together. We build applications that align with the Municipal Data Model (RSGB/RGBZ) and integrate with common case management systems. From a municipal app for residents to back-office tools for case management.

  • Integration with case management systems (OpenZaak, Rx.Mission)
  • BRP queries via the Haal Centraal API
  • Alignment with the Municipal Data Model
  • Social domain applications
Provinces

Provincial applications

Provinces operate at the intersection of spatial planning, mobility, nature and the economy. We develop applications for permit processing, supervision and enforcement (VTH), subsidy management and spatial planning. With GIS integration for map-based workflows and connections to PDOK and the National Environmental Permit Portal (Landelijke Voorziening Omgevingsloket).

  • GIS integration and map-based workflows
  • VTH process support
  • Grant application and accountability
  • Inter-provincial data exchange
National Government

National government applications

National government applications demand scalability for millions of users, high availability and stringent security requirements. We build in line with the NORA architecture principles and connect to the Generic Digital Infrastructure (GDI). From internal knowledge systems and policy information tools to public services accessed via DigiD or eHerkenning.

  • NORA-compliant architecture
  • Scalability for millions of transactions
  • Alignment with GDI facilities
  • High availability with multi-zone deployment
Water Boards

Water board software

Water boards manage critical infrastructure: dykes, pumping stations, wastewater treatment plants and the water system. We develop applications for asset management, emergency response and water quality monitoring. With IoT integration for field sensors and predictive maintenance models that optimise upkeep based on live measurement data.

  • IoT integration for water levels and pumping stations
  • Asset management and maintenance planning
  • Emergency management and control room tools
  • Water quality monitoring and reporting

Compliance and security as a foundation

Government software operates in one of the most regulated environments in the Netherlands. From the Baseline Information Security for Government (BIO) to the Digital Government Act (Wet digitale overheid), we know the landscape and build systems that meet every requirement without compromising ease of use.

Security

BIO and ISO 27001

The Baseline Information Security for Government (BIO) is the mandatory standard for all government organisations. Our development method follows security-by-design: threat analysis in the design phase, secure coding practices, dependency scanning, and penetration testing before production. We deliver a security file that aligns with your ISMS.

  • Security-by-design in every sprint
  • Penetration testing and vulnerability scanning
  • Encryption in transit (TLS 1.3) and at rest
  • SIEM integration for security monitoring
Accessibility

WCAG 2.1 and EN 301 549

The Temporary Digital Accessibility Decision (Tijdelijk besluit digitale toegankelijkheid) requires government bodies to comply with WCAG 2.1 at level AA. We build accessibility in from the first wireframe: semantic HTML, ARIA labels, focus management, colour contrast and testing with assistive technology. On delivery you receive an accessibility statement following the DigiToegankelijk model.

  • Semantic HTML5 and ARIA attributes
  • Automated and manual a11y testing
  • Fully supported keyboard-only navigation
  • Accessibility statement on delivery
Standards

Forum for Standardisation

The 'apply or explain' list from Forum Standaardisatie contains dozens of mandatory open standards, from Digikoppeling for message traffic and OWMS for metadata to StUF and the API Design Rules, and the NL GOV Assurance Profile for OAuth. We know these standards and apply them wherever the list requires, so your systems stay interoperable with the rest of government.

  • API Design Rules (ADR) compliant
  • Digikoppeling for MSB traffic
  • OWMS metadata on all content
  • NL GOV Assurance Profile (OAuth/OIDC)

Our process for government projects

Government projects call for a structured approach with clear decision points, but also for flexibility. We combine the governance that a public client needs with the speed of agile development.

1

Discovery and architecture

We start by mapping out stakeholders, existing systems, legal frameworks and user needs. This results in an architecture outline aligned with NORA/GEMMA, a prioritised backlog and a realistic project plan that includes compliance milestones. Duration: four to six weeks.

2

MVP and validation

We build a minimum viable product covering the core flow in two-week sprints. Interim demos with users and the client give you direct feedback. We integrate with authentication (DigiD/eHerkenning) and source systems early, so integration problems surface at the start.

3

Audit and acceptance

Before going live, the application goes through a DigiD assessment (where applicable), a penetration test, a WCAG audit and a performance test. We guide the acceptance process and deliver the necessary documentation: DPIA, security file and accessibility statement. We only go live after formal acceptance.

4

Operations and ongoing development

After go-live, we monitor performance, availability and security. Patches and updates are applied within SLA timeframes. Functional development follows fixed sprint rhythms. Knowledge transfer to your own team is a standard part of our offering, so you are never entirely dependent on us.

Integrations with the government landscape

Dutch government organisations work with an extensive landscape of base registers, authentication services and sector systems. We have experience with the common integrations and know the specific protocols and agreements that go with them. Our API integration expertise ensures reliable connections.

DigiD

SAML 2.0 authentication for citizens at assurance level Basic, Substantial or High. Includes app authentication and DigiD Machtigen (proxy authorisation).

eHerkenning

Business authentication via the eHerkenning network. Assurance levels EH2 to EH4 for businesses and institutions that use government services.

BRP (Haal Centraal)

Retrieve personal data via the modern Haal Centraal BRP API. A RESTful JSON interface that replaces the classic StUF query.

BAG

Basic Registry of Addresses and Buildings for address validation, location data and building characteristics. Essential for form validation and GIS applications.

BRK (Kadaster)

Basic Registry of Land Registry (Kadaster) for parcel data, ownership information and mortgage data. Relevant for permits and spatial planning processes.

Trade Register (KVK)

Retrieve company data for automatic form completion, verification of authority to represent, and authorisation checks.

Haal Centraal APIs

The complete Haal Centraal ecosystem: BRP Persons, BRK Cadastral Real Estate, BAG Current Queries and WOZ property valuations via RESTful APIs.

Digikoppeling

MSB messages via ebMS or WUS for machine-to-machine communication within government. Includes MSB gateway integration for reliable asynchronous message exchange.

We also integrate with common case management systems (OpenZaak, Rx.Mission, Decos JOIN), DMS solutions, GIS systems (QGIS, ArcGIS, PDOK services) and financial systems. Our API-first architecture makes it easy to add new integrations as your systems landscape evolves.

Frequently Asked Questions

Does your software meet BIO standards? +

Yes. We develop in line with the Baseline Information Security for Government (BIO) and apply the mandatory security measures from the ISO 27001/27002 standards on which it is based. This includes data encryption in transit and at rest, role-based access control, logging and audit trails, and regular penetration testing. Our development processes are built around security by design, so BIO compliance is not an afterthought but an integral part of the architecture.

How do you integrate with DigiD and eHerkenning? +

We connect via the standard SAML 2.0 protocols that Logius prescribes for DigiD, and via the eHerkenning network for business authentication. The integration runs through a certified broker, and we implement all mandatory security levels (substantial or high assurance level). Our applications go through the DigiD assessment process, including the mandatory ICT security assessment, before they go into production.

How much does a custom municipality app cost? +

The cost depends on the scope and complexity of the project. Factors that determine the investment include the number of source systems to integrate (BRP, case management system, DMS), the required authentication levels, WCAG accessibility requirements, and the size of the user group. We take a modular approach, so you can start with a basic version and expand step by step. Get in touch for a no-obligation conversation about your situation.

How do you ensure WCAG accessibility? +

We design and build to WCAG 2.1 Level AA, the legal requirement for government websites and apps under the Dutch Temporary Decision on Digital Accessibility of Government. This covers semantic HTML, keyboard navigation, sufficient colour contrast, screen reader compatibility and captions for media. We test with automated tools (axe, Lighthouse) and carry out manual checks with assistive technologies. Upon delivery, we provide an accessibility statement.

Can you work with the Common Ground architecture? +

Yes. We build applications according to the five-layer Common Ground architecture: interaction, process, integration, services and data. This means data stays at the source and is made available through standardised APIs (in line with the Dutch government's API Design Rules). We work with components from the Common Ground component catalogue wherever possible, and develop new components that can be reused by other government organisations.

How long does a government project typically take? +

Een typisch overheidsproject doorloopt meerdere fasen: discovery en architectuur (4-6 weken), MVP-ontwikkeling (8-14 weken), en iteratieve doorontwikkeling. De totale doorlooptijd tot eerste productierelease ligt meestal tussen drie en zes maanden, afhankelijk van de complexiteit van integraties en het interne goedkeuringsproces. Wij werken agile in sprints van twee weken met tussentijdse demonstraties, zodat u continu zicht hebt op voortgang en kunt bijsturen.

Ready to improve your digital services?

Whether you want to modernise a citizen portal, digitise an internal work process or realise your Common Ground ambitions, we are happy to think along with you. In a no-obligation conversation, we will explore the possibilities, discuss your architecture landscape and sketch out an initial approach.

BIO-compliant development WCAG 2.1 AA guaranteed Common Ground experience Agile way of working

Edit content