National Government Cloud PolicyBIO and NIS2EEA data location

Sovereign cloud for government

The revised Government-wide Cloud Policy of 3 July 2026 sets clear requirements: storage and processing within the EEA, a mandatory risk assessment for each cloud service, and an exit plan updated annually. Appfront builds and migrates government applications, citizen portals and integrations so that they meet those requirements. We develop the software ourselves; for the underlying infrastructure, we work with specialist Dutch partners.

What is a sovereign cloud for government?

A sovereign cloud is cloud infrastructure that falls entirely under European law and European ownership. For government, this distinction is essential: a US provider falls under the US CLOUD Act, even if the servers are located in the EU, because the parent company can be compelled to hand over data. Anyone processing citizen data wants to rule out that dependency and demonstrably remain under EU jurisdiction.

The revised Central Government Cloud Policy of 3 July 2026 makes this concrete. Storage and processing must take place within the EEA, a risk assessment is mandatory for every cloud service, and an exit plan that is updated annually must be in place. Email and document management in the public cloud are discouraged, and state secret information and basic registries do not belong in the public cloud. In addition, the BIO applies as the baseline for information security in government, along with the NIS2 Directive, which takes effect on 15 August 2026 through the Dutch Cybersecurity Act.

Appfront helps government organisations work within those frameworks without grinding to a halt. We build new applications that are set up as sovereign from the very first architecture sketch, and migrate existing systems away from environments that no longer fit policy. For how such an environment is technically set up, see our page on building a sovereign cloud.

How we approach this

1
Inventory and risk assessment
We map out applications, data flows and integrations, and carry out the risk assessment for each cloud service that the revised Dutch government cloud policy requires: which data is sensitive and which requirements apply.
2
Architecture and partner selection
We design an architecture on infrastructure within the EEA and select, together with you, a suitable Dutch infrastructure partner, independently and based on your requirements.
3
Build or migrate
We build the application or move the existing system, using common ground principles and open source where appropriate, with attention to integrations and portability.
4
Operations and exit planning
After delivery we take care of monitoring, maintenance and further development, and provide the technical basis for the exit plan that must be updated annually.

What we build and manage

Government applications
Custom applications for core processes and back-office operations, designed from the architecture up for sovereign infrastructure and the BIO.
Citizen portals
Portals through which residents arrange their affairs, submit applications and view their data, with accessibility and privacy as starting points.
Migration out of the public cloud
Existing applications and workloads move to infrastructure within the EEA, without loss of functionality or integrations.
Integrations
Secure integrations with base registries, national facilities and your existing line-of-business applications, via open standards and APIs.
Common ground and open source
Where appropriate, we align with common ground principles and open source components, so that solutions can be reused across government bodies.
Operations and ongoing development
Ongoing maintenance, security updates and monitoring, plus the documentation you need for risk assessment and the exit plan.

For whom

Municipalities

Municipalities that want to set up line-of-business applications, portals or integrations sovereignly. For custom work in the municipal domain, we have a separate page on custom software development for municipalities.

Implementing bodies and independent administrative authorities

Organisations that process large volumes of citizen data and need to be able to justify their cloud choices with a risk assessment and exit plan.

Central government and provinces

Parts of central government and provinces that fall under the revised Central Government Cloud Policy or wish to align with it.

Municipal health services (GGDs) and joint arrangements

Collaborative bodies that process sensitive resident data and need a single sovereign environment for multiple participants.

Technology and approach

We build with open, portable technology so that your applications are not tied to a single supplier and an exit plan is not just paperwork. Containers, infrastructure as code and open standards make it possible to move between sovereign environments. The infrastructure itself runs with specialised Dutch partners; we handle the architecture, the build and application management.

Infrastructure within the EEA
Dutch infrastructure partners
Kubernetes / containers
Common ground principles
Open source and open standards
Infrastructure as Code
Encryption in transit and at rest
Logging and monitoring

Why Appfront

Appfront is an independent software and app development agency. We do not sell hosting or data centre capacity ourselves, so our advice on infrastructure and architecture is not coloured by a platform of our own. We combine building government applications with the expertise to set them up sovereignly: from the risk assessment at the start to the exit plan that must be updated every year.

For government organisations, that combination is the difference between policy on paper and policy in practice. A risk assessment is only useful when the architecture is built to support it, and an exit plan only has value when the applications are genuinely built to be portable. Because we handle both the software and the migration, we can make those requirements work technically rather than merely describing them. That also keeps you prepared for the Cybersecurity Act, which brings the NIS2 Directive into force in the Netherlands on 15 August 2026.

  • Independent of hyperscalers and hosting providers
  • Build and migration in-house, infrastructure via Dutch partners
  • Common ground and open source where appropriate
  • Architecture aligned with the BIO, the Government Cloud Policy and NIS2

Frequently Asked Questions

What does the revised Government-wide Cloud Policy mean for government organisations?
The revised policy of 3 July 2026 requires that storage and processing take place within the EEA, that a risk assessment is carried out for each cloud service, and that an exit plan is in place and updated annually. In addition, email and document management in the public cloud are discouraged, and state secrets and base registries do not belong in the public cloud.
Does this policy also apply to municipalities and provinces?
The Dutch government-wide cloud policy formally applies to central government. Municipalities, provinces and implementing organisations use it in practice as a guideline and are also subject to the BIO (Baseline Information Security for Government), which sets requirements for information security in government. We design architectures so that they can meet both frameworks.
Does Appfront itself provide the sovereign infrastructure?
No. Appfront is a software and app development agency. We build and migrate the applications and handle the architecture; for data centres and infrastructure we work with specialised Dutch partners who fall under Dutch and European jurisdiction.
Can you migrate existing government applications?
Yes. We start with an inventory of applications, data flows and integrations, carry out a risk assessment for each component and draw up a migration plan. We then move the applications step by step to sovereign infrastructure, including integrations with national facilities.
How do you handle base registries and sensitive data?
Under the revised Dutch government cloud policy, base registries and state secret information do not belong in the public cloud. We design architectures in which that data stays on private or sovereign infrastructure, while portals and integrations communicate with it in a secure and controllable way.
Do you work with common ground and open source?
Yes, where appropriate. We align with common ground principles and use open source components and open standards, so that solutions remain reusable and portable and are not tied to a single supplier.

Getting started with sovereign cloud for government

Would you like to know what the revised Government Cloud Policy means for your application landscape, or discuss a specific migration or new build? We are happy to advise you independently on the approach.

Edit content