PUT-IT-ON
Digitale EU

National cloud policy sharpens government requirements

PUT-IT-ON Newsroom
PUT-IT-ON Newsroom
·Sep 3, 2026 · 10:04·
National cloud policy sharpens government requirements

National cloud policy sharpens requirements for the government

Source: Sander Hulsman on September 2, 2026

Government opts for more control over cloud usage

The national cloud policy changes the way the Dutch government deals with cloud services. The new regulations place more emphasis on digital resilience, control over data, and reducing dependence on large cloud providers.

The Council of Ministers approved the revision of the national cloud policy on July 3, 2026. The tightening follows investigations into the existing cloud usage, changed geopolitical circumstances, and developments in the international cloud market. The government wants to maintain space for innovation, but at the same time imposes stricter conditions on the processing and storage of government information.

The new approach applies to the entire national government, with the exception of the High Colleges of State and the Ministry of Defense. Other government organizations are advised to follow the policy. For existing applications that do not yet meet the new requirements, a transition period of four years applies. This gives organizations time to carry out migrations carefully and integrate new choices within existing plans.

Tightening cloud policy directs government

An important part of the new policy is the increased focus on risks related to dependence on suppliers and foreign jurisdictions. The government aims to prevent critical digital processes from becoming too reliant on parties that are subject to legislation other than Dutch or European regulations.

Therefore, organizations must consider not only technical performance and costs when using cloud resources, but also strategic risks. Vendor dependency, continuity of service, and control over data take on a more significant role in decision-making.

Not only making appointments, but also drawing up a concrete exit plan

The requirements regarding exit strategies are also being expanded. Organizations must now not only make agreements about retrieving and deleting data but also develop a concrete exit plan. This plan must account for a planned transition and situations where a cloud service suddenly becomes unavailable. With this, the government aims to gain better insight into the consequences of disruptions and increase their own digital resilience.

Material cloud usage and associated risk analyses must be reported to the Chief Information Officer of the government. This central registration helps monitor developments and risks within the government. The ultimate responsibility for risk acceptance remains with the involved director or government official.

Exit strategy for cloud usage gains more importance

[Image: Gerd Altmann | Pixabay]

The revised policy also restricts the use of public cloud for specific applications. Public cloud solutions may only store and process data within countries of the European Economic Area. Additionally, data must be encrypted, except when it concerns public information.

For email and document management, the government is opting for a stricter approach. New processes in the public cloud are discouraged, and existing solutions will be adjusted over time. The reason for this is that large amounts of government information can collectively pose a risk, even when individual documents do not have a high classification. Moreover, email and document management is an essential part of daily operations.

The use of public cloud for special personal data is also discouraged. When organizations still choose to do so, they must implement additional techniques to mitigate privacy risks.

Public cloud gets stricter limits

For state secret information and to protect interests, public cloud is still not permitted. External suppliers must comply with the requirements of the General Security Requirements of the National Government 2026 in such situations.

At the same time, there remains space for public cloud in basic registries, for example, when scalability or performance demands it. The source data must not be managed in public cloud environments. This way, the government maintains control over the key data sources.

Important step towards a resilient and more sovereign digital government

The revision aligns with broader European developments regarding digital autonomy and cloud infrastructure. The government is also exploring the development of an overarching cloud policy for municipalities, provinces, and water boards. Through increased collaboration and standardization, the Netherlands aims to build a stronger digital foundation.

The coming years will therefore be characterized by balance. The government wants to benefit from technological innovation while simultaneously maintaining control over data, suppliers, and digital continuity. The new nationwide cloud policy constitutes an important step towards a resilient and more sovereign digital government.

#PUTITON #cyber security # Data sovereignty # Digital governance # European cloud  #Privacy

0 comments·0 shares
Only PUT-IT-ON members can comment and like.JOIN US
0 comments