Sovereignty assessment: know where your cloud dependencies are
The sovereignty assessment is the cloud exit scan with which every sovereignty strategy begins. We inventory all cloud and SaaS dependencies within your organisation, determine the exposure under the US CLOUD Act for each system, and deliver a report with risk classification, an exit plan per application and a migration roadmap. Appfront carries out the scan at application and data level; alternatives for the infrastructure we map out together with specialist Dutch partners.
What is a sovereignty assessment?
A sovereignty assessment is a structured scan of all cloud and SaaS dependencies in your organisation: hyperscalers such as AWS, Azure and Google Cloud, American SaaS services and the data flows between them. For each system we determine the exposure under the US CLOUD Act, the law that can compel American companies to disclose data, even when it is physically held in a European data centre. That exposure is often deeper than expected: not only in where you host, but also in the SaaS tools and underlying services your applications rely on.
Moreover, the question is no longer optional. The revised Dutch central government cloud policy of 3 July 2026 requires storage and processing within the EEA for central government, mandates a prior risk assessment and an annual exit plan for each public cloud service. Financial institutions must, under DORA, applicable since 17 January 2025, have exit strategies for critical ICT services. And with the Cybersecurity Act, the Dutch implementation of NIS2 that enters into force on 15 August 2026, risk management across the entire digital supply chain is added. The assessment delivers exactly the substantiation these rules require: a dependency map, a risk classification and a concrete exit plan per application.
How we approach this
What we build and manage
For whom
The revised government cloud policy requires a risk assessment and an annual exit plan, advises against public cloud for email and document management, and excludes state secrets and basic registries from it. The assessment delivers that risk assessment and the exit plans, aligned with the BIO.
Since 17 January 2025, DORA has required exit strategies for critical ICT third-party service providers. We map, system by system, where you depend on third parties and what an exit looks like in practice.
Organisations processing medical data fall under NEN 7510 and the GDPR. We classify which data is stored where, which suppliers have access to it, and where jurisdiction becomes a problem.
From 15 August 2026, the Cyberbeveiligingswet sets requirements for risk management across the digital supply chain. The dependency map shows where that chain is vulnerable and where you need to adjust.
Technology and approach
A good assessment is more than a questionnaire. We analyse the actual architecture: which services your applications call, where data is stored and processed, and which suppliers sit behind them through subcontractors. Because we build and migrate software ourselves, we also assess what an exit costs technically: which code is tied to proprietary cloud services and what is needed to make it portable. On the infrastructure side, we look at EU-based alternatives; you can find an overview of providers in our guide to the best sovereign cloud providers in the Netherlands.
Why Appfront
Appfront is an independent software and app agency. We do not sell hosting or data centre services, so the outcome of the assessment is not driven by a platform of our own. We scan at the level where the real dependencies lie: the applications and the data. And because we build and migrate ourselves, it doesn't stop at a report: the same people who run the scan can then carry out the rebuild or move.
- Independent of hosting parties and hyperscalers
- Scanning at application and data level, not just an infrastructure checklist
- Exit plan per application that meets government cloud policy and DORA requirements
- Infrastructure alternatives mapped together with Dutch infrastructure partners
Related services
After the assessment, you can move straight on: see cloud migration guidance for the journey from plan to execution, migrating applications to a sovereign cloud for the move itself, and getting a sovereign cloud built for new builds on EU infrastructure. Looking for a provider? Read our guide to the best sovereign cloud providers in the Netherlands.
Frequently Asked Questions
Getting started with a sovereignty assessment
Would you like to know where your cloud dependencies lie and what an exit per application would involve? We are happy to carry out the scan for you and think independently with you about the next steps.