Cloud exit scanCLOUD Act exposureExit plan per application

Sovereignty assessment: know where your cloud dependencies are

The sovereignty assessment is the cloud exit scan with which every sovereignty strategy begins. We inventory all cloud and SaaS dependencies within your organisation, determine the exposure under the US CLOUD Act for each system, and deliver a report with risk classification, an exit plan per application and a migration roadmap. Appfront carries out the scan at application and data level; alternatives for the infrastructure we map out together with specialist Dutch partners.

What is a sovereignty assessment?

A sovereignty assessment is a structured scan of all cloud and SaaS dependencies in your organisation: hyperscalers such as AWS, Azure and Google Cloud, American SaaS services and the data flows between them. For each system we determine the exposure under the US CLOUD Act, the law that can compel American companies to disclose data, even when it is physically held in a European data centre. That exposure is often deeper than expected: not only in where you host, but also in the SaaS tools and underlying services your applications rely on.

Moreover, the question is no longer optional. The revised Dutch central government cloud policy of 3 July 2026 requires storage and processing within the EEA for central government, mandates a prior risk assessment and an annual exit plan for each public cloud service. Financial institutions must, under DORA, applicable since 17 January 2025, have exit strategies for critical ICT services. And with the Cybersecurity Act, the Dutch implementation of NIS2 that enters into force on 15 August 2026, risk management across the entire digital supply chain is added. The assessment delivers exactly the substantiation these rules require: a dependency map, a risk classification and a concrete exit plan per application.

How we approach this

1
Discovery
We map out all cloud and SaaS dependencies: hyperscalers, US SaaS, underlying services, integrations and the data flows between them, down to application and data level.
2
Exposure and classification
For each system we determine the CLOUD Act exposure and classify the risk: how sensitive the data is, which legal requirements apply and how replaceable the service is.
3
Exit plan per application
For every application we work out a realistic exit scenario: moving to a European alternative, rebuilding, or documented acceptance. Factual and actionable, not a paper exercise.
4
Report and roadmap
You receive a report with a dependency map, priorities and a migration roadmap. If you want to go further, we offer cloud migration support from planning through to execution.

What we build and manage

Dependency map
A complete overview of all cloud and SaaS services, per application and per data flow, including the suppliers behind your suppliers.
CLOUD Act exposure per system
For each system, we show whether it falls under US jurisdiction, directly or via underlying services, and what that means for your data.
Risk classification
Prioritisation based on data sensitivity, legal requirements and replaceability, so you know what needs attention first and what can wait.
Exit plan per application
Mandatory annually for central government since the revised government cloud policy, and under DORA for financial institutions. We make it concrete rather than a box-ticking exercise.
Migration roadmap
An actionable sequence: which application goes first, which European alternative fits, and which dependencies need to be untangled first.
Compliance review
We test the findings against the GDPR, NIS2 and the Cyberbeveiligingswet, DORA, BIO and NEN 7510, depending on your sector.

For whom

Central government and public sector

The revised government cloud policy requires a risk assessment and an annual exit plan, advises against public cloud for email and document management, and excludes state secrets and basic registries from it. The assessment delivers that risk assessment and the exit plans, aligned with the BIO.

Financial sector

Since 17 January 2025, DORA has required exit strategies for critical ICT third-party service providers. We map, system by system, where you depend on third parties and what an exit looks like in practice.

Healthcare

Organisations processing medical data fall under NEN 7510 and the GDPR. We classify which data is stored where, which suppliers have access to it, and where jurisdiction becomes a problem.

NIS2 sectors

From 15 August 2026, the Cyberbeveiligingswet sets requirements for risk management across the digital supply chain. The dependency map shows where that chain is vulnerable and where you need to adjust.

Technology and approach

A good assessment is more than a questionnaire. We analyse the actual architecture: which services your applications call, where data is stored and processed, and which suppliers sit behind them through subcontractors. Because we build and migrate software ourselves, we also assess what an exit costs technically: which code is tied to proprietary cloud services and what is needed to make it portable. On the infrastructure side, we look at EU-based alternatives; you can find an overview of providers in our guide to the best sovereign cloud providers in the Netherlands.

Application and data inventory
Data flow mapping
CLOUD Act review
Risk classification
Exit plan per application
Migration roadmap
EU-based alternatives
Open standards

Why Appfront

Appfront is an independent software and app agency. We do not sell hosting or data centre services, so the outcome of the assessment is not driven by a platform of our own. We scan at the level where the real dependencies lie: the applications and the data. And because we build and migrate ourselves, it doesn't stop at a report: the same people who run the scan can then carry out the rebuild or move.

  • Independent of hosting parties and hyperscalers
  • Scanning at application and data level, not just an infrastructure checklist
  • Exit plan per application that meets government cloud policy and DORA requirements
  • Infrastructure alternatives mapped together with Dutch infrastructure partners

Related services

After the assessment, you can move straight on: see cloud migration guidance for the journey from plan to execution, migrating applications to a sovereign cloud for the move itself, and getting a sovereign cloud built for new builds on EU infrastructure. Looking for a provider? Read our guide to the best sovereign cloud providers in the Netherlands.

Frequently Asked Questions

What is a sovereignty assessment?
A sovereignty assessment is a structured scan of all your cloud and SaaS dependencies. We map which systems run on American hyperscalers or American SaaS services, where your data flows, and which systems fall under the US CLOUD Act. The result is a report with a dependency map, a risk classification and an exit plan for each application.
Is an exit plan mandatory?
For central government, yes: the revised Dutch government cloud policy of 3 July 2026 requires a prior risk assessment and an annually updated exit plan for public cloud services. Financial institutions must have exit strategies for critical ICT services under DORA, applicable since 17 January 2025. For other organisations it is not mandatory, but it is the logical foundation of any cloud strategy.
What exactly does CLOUD Act exposure mean?
The US CLOUD Act can compel American companies to hand over data to American authorities, even when that data is physically located in a European data centre. Exposure therefore arises not only from hosting directly with a hyperscaler, but also through SaaS services and underlying infrastructure of American providers. In the assessment, we make that exposure visible for each system.
Does Appfront also carry out the migration itself?
Yes, at the application and data level. We move or rebuild applications so they run on EU-sovereign infrastructure. For data centre, IaaS and colocation questions, we work with specialised Dutch infrastructure partners; we map those alternatives during the assessment.
What do we concretely receive?
A report with a complete dependency map, the CLOUD Act exposure per system, a risk classification, an exit plan per application and a migration roadmap with priorities. This lets you make a well-founded decision about what to tackle first and what can wait.
Do we then have to move all our systems straight away?
No. The assessment is precisely meant to help you choose on the basis of risk. Some workloads can perfectly well stay where they are, while others call for a European alternative or an adapted architecture. The risk classification shows where the real dependencies lie, so you invest where it matters.

Getting started with a sovereignty assessment

Would you like to know where your cloud dependencies lie and what an exit per application would involve? We are happy to carry out the scan for you and think independently with you about the next steps.

Edit content