A letter, not a law, but a real commitment
On July 2, 2026, State Secretary Eric van der Burg (Kingdom Relations and Decisive Government) told the Tweede Kamer that the cabinet will build a sovereign government cloud — infrastructure hosted on data centers the Dutch state itself owns, controls physical access to, and can operate without a foreign vendor's cooperation. A Proof of Concept is already running at Digilab, the government's internal innovation facility; if it succeeds, the first live applications move onto the sovereign cloud before the end of 2026, with formal migrations of existing government workloads beginning in 2027. A day later, a companion letter from State Secretary Willemijn Aerdts formalized the revised National Cloud Policy 2026, which is headed to the Standing Committee for Digital Affairs for discussion on September 2, 2026.
The trigger is a number the government cites directly: non-European providers — in practice, AWS, Microsoft Azure and Google Cloud — control roughly 70% of the European cloud market. For a government ministry, that concentration is not an abstract competition-policy concern. It means email, case files, and citizen-record systems can, in principle, be reached by a US court order, a licensing dispute, or a change in Washington's export-control posture — regardless of where the servers physically sit.
The case for going sovereign, stated fairly
The strongest version of the government's argument does not rest on anti-American sentiment; it rests on continuity of the state. A ministry that cannot guarantee uninterrupted access to its own tax records, benefits systems, or court filings during a geopolitical dispute has a genuine operational vulnerability, not a hypothetical one. The revised cloud policy reflects that reasoning concretely: it bars master data registries — citizen and property records — and email/document management from public cloud entirely, and requires ministries to write exit plans for any cloud service they do use, so a provider failure or sanction doesn't strand a government function mid-migration.
There is also a coherence argument. The Hague isn't improvising a homegrown standard from scratch — the design targets SEAL-4, the top tier of the European Commission's Cloud Sovereignty Framework, published June 1, 2026, which already scored providers for a €180 million EU institutional cloud contract. Building toward an EU-wide benchmark, rather than a purely national one, at least keeps the door open to interoperability with other member states doing the same thing. And before committing, the ministry consulted 69 Dutch market parties and concluded the country has the technical bench strength to execute — a due-diligence step regulators in other domestic-cloud pushes (India's telecom localization rules, for instance) have sometimes skipped.
Why the trade-off still cuts against this design
Set against that, the risks are structural, not incidental. Building a state-operated cloud from the ground up — the cabinet explicitly chose the most ambitious option after a Gartner-informed review, rejecting the cheaper route of retrofitting existing infrastructure — commits the Dutch taxpayer to competing, on cost and reliability, with companies that have spent two decades and hundreds of billions of dollars solving exactly this engineering problem. Van der Burg's own letter flags the real constraint: this only works if ministries actually adopt the platform and budgets are reallocated up front; underfund it, and the timeline — already stretching to 2027 for real migrations, with a four-year compliance runway in the broader cloud policy — extends further while agencies keep paying for both the legacy cloud contract and the sovereign build.
There's also a sovereignty paradox critics have already raised in Dutch trade press: a data center on Dutch soil running on Broadcom, Nvidia, or VMware components sourced from outside the EU is not fully sovereign in any meaningful sense — it just relocates the dependency from the software layer to the hardware layer. The government's own container-platform design, built to the open-source Haven standard specifically to reduce vendor lock-in, is an attempt to answer that critique, but it doesn't eliminate the underlying reliance on non-EU chip and component supply chains.
The proportionate path, and where this policy sits on it
A narrower, better-targeted policy would draw the line at true state-continuity functions — the master-data and identity systems the revised cloud policy already isolates — rather than aiming, longer-term, at a general-purpose government cloud meant to substitute for commercial hyperscalers across the board. The Aerdts letter's risk-tiered approach (geopolitical risk assessments, non-EU-law restrictions for critical entities, mandatory exit plans) is the proportionate core of this reform; the sovereign-cloud infrastructure project is the expensive, unproven layer stacked on top of it. The Netherlands should keep funding the former regardless of outcome. The latter deserves real parliamentary scrutiny of cost and delivery risk before the 2027 migration commitments harden — scrutiny that should intensify, not soften, once the Proof of Concept results land at Digilab later this year.