Sovereign cloud for government
The revised Government-wide Cloud Policy of 3 July 2026 sets clear requirements: storage and processing within the EEA, a mandatory risk assessment for each cloud service, and an exit plan updated annually. Appfront builds and migrates government applications, citizen portals and integrations so that they meet those requirements. We develop the software ourselves; for the underlying infrastructure, we work with specialist Dutch partners.
What is a sovereign cloud for government?
A sovereign cloud is cloud infrastructure that falls entirely under European law and European ownership. For government, this distinction is essential: a US provider falls under the US CLOUD Act, even if the servers are located in the EU, because the parent company can be compelled to hand over data. Anyone processing citizen data wants to rule out that dependency and demonstrably remain under EU jurisdiction.
The revised Central Government Cloud Policy of 3 July 2026 makes this concrete. Storage and processing must take place within the EEA, a risk assessment is mandatory for every cloud service, and an exit plan that is updated annually must be in place. Email and document management in the public cloud are discouraged, and state secret information and basic registries do not belong in the public cloud. In addition, the BIO applies as the baseline for information security in government, along with the NIS2 Directive, which takes effect on 15 August 2026 through the Dutch Cybersecurity Act.
Appfront helps government organisations work within those frameworks without grinding to a halt. We build new applications that are set up as sovereign from the very first architecture sketch, and migrate existing systems away from environments that no longer fit policy. For how such an environment is technically set up, see our page on building a sovereign cloud.
How we approach this
What we build and manage
For whom
Municipalities that want to set up line-of-business applications, portals or integrations sovereignly. For custom work in the municipal domain, we have a separate page on custom software development for municipalities.
Organisations that process large volumes of citizen data and need to be able to justify their cloud choices with a risk assessment and exit plan.
Parts of central government and provinces that fall under the revised Central Government Cloud Policy or wish to align with it.
Collaborative bodies that process sensitive resident data and need a single sovereign environment for multiple participants.
Technology and approach
We build with open, portable technology so that your applications are not tied to a single supplier and an exit plan is not just paperwork. Containers, infrastructure as code and open standards make it possible to move between sovereign environments. The infrastructure itself runs with specialised Dutch partners; we handle the architecture, the build and application management.
Why Appfront
Appfront is an independent software and app development agency. We do not sell hosting or data centre capacity ourselves, so our advice on infrastructure and architecture is not coloured by a platform of our own. We combine building government applications with the expertise to set them up sovereignly: from the risk assessment at the start to the exit plan that must be updated every year.
For government organisations, that combination is the difference between policy on paper and policy in practice. A risk assessment is only useful when the architecture is built to support it, and an exit plan only has value when the applications are genuinely built to be portable. Because we handle both the software and the migration, we can make those requirements work technically rather than merely describing them. That also keeps you prepared for the Cybersecurity Act, which brings the NIS2 Directive into force in the Netherlands on 15 August 2026.
- Independent of hyperscalers and hosting providers
- Build and migration in-house, infrastructure via Dutch partners
- Common ground and open source where appropriate
- Architecture aligned with the BIO, the Government Cloud Policy and NIS2
Related services
See also building a sovereign cloud and custom software development for municipalities. Looking more broadly? Read our overviews of the best sovereign cloud solutions for government and the best software vendors for government.
Frequently Asked Questions
Getting started with sovereign cloud for government
Would you like to know what the revised Government Cloud Policy means for your application landscape, or discuss a specific migration or new build? We are happy to advise you independently on the approach.