The acquisition of Solvinity for Logius services (position)
This document describes the acquisition of Solvinity by Kyndryl and the significance for Logius’ services. The focus is on DigiD, but the message box is also discussed, because it facilitates a lot of communication between citizens and government. You can get this document as a PDF file here.
Executive summary
This position paper describes how the proposed acquisition of Solvinity by Kyndryl will materially change the strategic position of vital Dutch digital government facilities, despite the fact that operational services will remain intact in the short term. Since 2020, Solvinity has supplied the infrastructure and hardware platform under the direction of Logius for core facilities such as DigiD, MijnOverheid (including the Message Box) and Digipoort. Responsibility for policy, architecture and services lies entirely with the government, but technical continuity depends on a private infrastructure supplier.
The acquisition shifts ownership and ultimate control of this supplier to a non-EU party, which, according to the European Cloud Sovereignty Framework, leads to a decrease in the sovereignty level from approximately SEAL-3 (digital resilience under EU control) to SEAL-1 (Formal legal sovereignty)!
The paper explicitly places this shift in a changed geopolitical climate, in which American legislation, sanctions regimes and political pressure can demonstrably have an impact on digital services, even with strict contractual agreements and data location within Europe. Based on classic information security principles (availability, integrity and confidentiality), the paper identifies high strategic sovereignty risks, medium-term autonomy risks and concrete implementation risks, and makes it clear that this is not a technical but a fundamental political issue. The core message is that the government must now explicitly choose which risks it is willing to bear for vital digital facilities and the associated costs, and that postponement or implicit acceptance amounts to a political decision without explicit accountability.
Logius and Solvinity
In 2020, Solvinity was commissioned by Logius to supply the underlying infrastructure and hardware platform for a number of government-wide digital facilities. This concerns data center capacity, servers, storage, network and security facilities. Solvinity provides this infrastructure. Control over and responsibility for the public digital services lies with Logius.
Logius determines the architecture, security requirements, governance and use of the systems, and as an implementation organization it is responsible for the operation of DigiD, among other things. DigiD itself, the application, data processing and policy management, is and will remain fully owned by the Dutch government. DigiD is the key to all government services and related services, such as access to information in healthcare.
In 2025 it was announced that Solvinity will be acquired by Kyndryl. Kyndryl is a major American IT services company that manages infrastructure for governments and large companies worldwide, and was spun off from IBM in 2021. The company does not supply consumer products, but focuses on keeping vital IT systems running technically. The acquisition will not automatically change the day-to-day technical services, but will place ownership and ultimate control over the infrastructure supplier in American hands. A new administrative and strategic context is emerging around a platform that is used for essential public facilities.
In addition to DigiD, other core facilities of Logius also use this infrastructure, including MijnOverheid (including the Message Box for government-citizen communication), Digipoort (message traffic between government and companies), Authorizations and facilities within the OIN system for organizational identification. For PKIoverheid, the PKIoverheid agreement system manages, directs and supervises the certificate service providers within the system.” The Solvinity platform does not run a separate application, but a coherent set of digital government services, for which the government is policy-wise responsible, while technical continuity depends on a private infrastructure supplier.
European framework to provide insight into sovereignty
The European Commission’s Cloud Sovereignty Framework is an assessment framework that has been developed to provide insight and comparison to the extent to which digital services, in particular cloud and platform services, actually fall under European control, legislation and control. The framework is expressly intended for situations in which ownership, control and jurisdiction may diverge, such as in acquisitions by non-EU parties. Within this framework, the SEAL levels (Sovereignty Effective Assurance Levels) introduce an ascending scale (SEAL-0 to SEAL-4) that indicates how strongly European digital sovereignty is guaranteed: from no meaningful sovereignty (SEAL-0) to full digital sovereignty under exclusive EU law and EU control (SEAL-4). In the context of a takeover, the SEAL levels offer a concrete instrument to assess whether an organization can still meet European requirements regarding jurisdiction, data access, continuity and strategic autonomy after the takeover, regardless of formal contracts or good intentions. The framework helps administrators and governments to discuss actual control instead of purely legal structures.
| SEAL level | Name | Core meaning |
|---|---|---|
| SEAL-0 | No digital sovereignty | The service or technology is entirely under non-EU control and non-EU jurisdiction. European legislation does not provide effective protection or enforceability in practice. |
| SEAL-1 | Formal legal sovereignty | EU law formally applies, but in practice it can be undermined by non-EU ownership, foreign law or extraterritorial powers. |
| SEAL-2 | Data sovereignty | Data is subject to EU law and can be technically protected, but there are still significant dependencies on non-EU parties (e.g. management, updates or key materials). |
| SEAL-3 | Digital resilience | EU law is effectively enforceable and the service is largely under EU control, with limited and manageable non-EU dependencies. |
| SEAL-4 | Full digital sovereignty | Full European control: ownership, governance, technology, data and operational management are governed exclusively by EU law and EU jurisdiction, without critical non-EU dependencies. |
In takeovers you often see organizations move down a SEAL level, even if contracts remain formally intact. For critical government tasks, SEAL-3 or SEAL-4 is generally considered the lower limit. The infrastructure for DigiD would move from SEAL-3 (digital resilience under EU control) towards SEAL-1 (Formal legal sovereignty) through the takeover of the infrastructure supplier by a non-EU party. This is a major impact.
##Changed climate
The proposed acquisition of Solvinity takes place in a reality that has fundamentally changed over the past year since the new US administration took office. While IT tenders used to be often assessed by the IT department based on technical quality and price, a (political) administrative assessment is increasingly required with regard to the effect of the product on the strategic autonomy of the organization. Four recent developments illustrate that the self-evidence with which we trusted American service providers is under pressure.
The Precedent of ‘Shutter Control’ (Maxar). The case surrounding satellite company Maxar makes it clear that commercial supply contracts are subordinate to geopolitical interests. Despite private law agreements, the American government appeared to be able to limit or direct the supply of data to allies through Shutter Control. As happened after a conflicted conversation between the American government and the president of Ukraine over the supply of satellite images. This sets a precedent for other sectors: ownership of the infrastructure ultimately determines who operates the ‘switch’, not the paying customer.
Erosion of the legal safety net (Privacy Shield). The legal basis for data exchange is unstable. Confidence in transatlantic agreements has been damaged by the uncertainty surrounding the successors to the Privacy Shield. The political climate in the US, where supervisory bodies (such as the privacy ombudsman function) can be sidelined by executive orders such as those of the Trump administration, demonstrates the vulnerability. In practice, guarantees for the protection of data of non-Americans appear to depend on the political issues of the day in Washington. There is currently a legal battle in Europe over the validity of this safety net.
Escalation surrounding European regulations (Case X). Relations between American tech companies and the European legislature have hardened. After the introduction of the Digital Services Act (DSA) and the associated fines and warnings against platform There are open threats to withdraw services or ignore European sanctions, supported by political pressure from the US. This illustrates a new risk: American owners of critical infrastructure could use their position as leverage in broader trade conflicts between the US and the EU. Dutch government data can therefore unintentionally become part of a political power game.
The case involving the International Criminal Court revealed how geopolitical tensions translate into digital dependencies. When the United States imposed sanctions on ICC officials, this not only had an impact on diplomacy and finance, but also affected operational digital services, such as e-mail and other essential IT facilities. Suppliers with an American legal connection therefore appeared to be sensitive to political decision-making outside Europe, regardless of contractual agreements or the location of data. Digital services are part of the exercise of geopolitical power, and dependence on non-European jurisdictions can lead to actual disruptions to the continuity and autonomy of even international constitutional institutions.
In these examples we must remember that international law is currently under pressure due to a transition to a new, pluralistic world order; a world in which the old power structures are crumbling and major powers (US, China, Russia) govern on the basis of Realpolitik instead of rules and treaties.
Information security issue
The theme touches the core of information security and must be viewed from the classic security goals of availability, integrity and confidentiality (BIV). These three principles have formed the foundation of information security since the 1970s, initially in military and government contexts and later in civilian and commercial information systems. In the decades that followed, they have been explicitly laid down in international standards, audit frameworks and government policy, and have since become leading in assessing risks surrounding automation, outsourcing and chain dependencies. The application of BIV to digital government facilities such as DigiD and other Logius services is therefore not a new approach, but the continuation of a security principle that has been proven for decades in a context of increasing digitalization and complexity.
The risks within this theme always manifest themselves along these three security objectives. Availability is at risk when the continuity of the underlying infrastructure can no longer be fully enforced by the government, for example in the event of disruptions, supplier dependence or strategic decision-making outside the public sphere of influence. Integrity concerns the extent to which the government can demonstrably guarantee that systems, configurations and data are not changed undesirably, and that supervision, auditing and change management remain effective within an outsourced technical domain. Confidentiality concerns the risk that personal data and authentication data are exposed, indirectly or otherwise, to unauthorized access or legal claims outside the Dutch and European legal framework. These risks are not theoretical constructions, but classic information security issues that arise again and amplified in a modern, outsourced digital infrastructure.
The risks
The developments force a recalibration of the risk analysis surrounding Solvinity and Logius. The question is no longer just whether the services are adequate, but whether the Dutch state retains sufficient control in a scenario in which American legislation or political pressure conflicts with Dutch interests and regulations.
Strategic sovereignty risks (high)
| Risk | Explanation | BIV |
|---|---|---|
| Loss of ultimate control | Infrastructure for core facilities falls under a foreign parent company | B / I / V |
| Limited policy freedom | Strategic choices are influenced by external commercial interests | B/I |
| Legal extraterritoriality | Foreign legislation can indirectly influence infrastructure and business operations | V |
| Irreversible dependence | Technical and contractual complexity makes re-insourcing very difficult in practice | B |
| Structural Negotiation Weakness | In the long term, the government will have less room for choice when it comes to contract extension B / I | |
| Dependency | Limited recoverability in the event of forced infrastructure migration: if the existing environment disappears, digital trust mechanisms cannot be immediately transferred, making the government insufficiently autonomous to quickly restore vital services. | B/I |
B= Availability, I=Integrity and V=confidentiality
Medium-term autonomy risks
| Risk | Explanation | BIV |
|---|---|---|
| Remote Governance | Decision making lies outside direct democratic control | I |
| Loss of system knowledge | Critical knowledge shifts to supplier | B/I |
| Limited strategic agility | Policy changes require the consent or cooperation of an external party. This can come into play, especially in geopolitical conflicts B | |
| Access to information or services for a foreign power | Legislation requires access to systems or information. Because the platform is managed by Solvinity, access is possible based on a warrant. This not only concerns DigiD, but also the message box. The problem is that this access is impossible or very difficult to detect. It has been known for some time that collected encrypted data is also stored for longer under the motto ‘collect now, decrypt later’. | V |
B= Availability, I=Integrity and V=confidentiality
Practical implementation risks (underlying)
| Risk | Explanation | BIV |
|---|---|---|
| Escalation outside the national sphere | Incident handling requires coordination across national borders if the incident is important enough or is of a geopolitical nature B | |
| Public trust under pressure | Explainability to citizens becomes more difficult | V |
| Fragmentation of responsibilities | Lack of clarity about who can actually intervene | I |
| Migration to another solution is time consuming | If there is insufficient preparation, migration of the solution may take additional time. Consider, for example, issuing security certificates to all users, carrying out audits to ensure security, and setting up a well-functioning management organization. | B |
B= Availability, I=Integrity and V=confidentiality
The policy options
For strategic risks surrounding DigiD, the Message Box and other Logius services, there are four classic options for action in policy and risk management. For the government, these options differ greatly in terms of reality and political significance.
The discussion is not about whether there are risks, but which risks the government is prepared to bear on a structural basis, and which risks it wants to actively avoid or manage. That is a political choice, not a technical one.
1. Avoidance – structurally removing the risk
Core: ending the dependency itself.
This is the most far-reaching option and affects fundamental choices about the design of digital government.
Possible steps:
- Ban takeover.
- Accelerated transition to the successor to DigiD (eIDAS). For example, an implementation has already been made by the Belgian company ‘itsme’, which can also work in the Netherlands.
- Repurposing the infrastructure to a fully public or state-controlled environment. That makes a step to SEAL level 4 possible.
- Splitting vital core facilities from commercial infrastructure
- Legally stipulate that certain digital facilities may only fall under national control
- Building a government-wide infrastructure facility for vital services
Political significance:
- Maximum (digital) sovereignty
- High costs and long lead time
- Forces explicit choices about what constitutes “critical infrastructure”.
2. Reduce (mitigate) – make the risk manageable
Core: accept the dependency, but clearly limit it.
Possible steps:
- Tightening contractual requirements on exit, contingency and recoverability
- Requiring technical and organizational separation (ring fencing) for vital services
- Strengthen government audit and surveillance powers
- Building parallel facilities or fallback scenarios
- Setting requirements for knowledge assurance within the government
- Drawing up an integral digital sourcing policy for what may or may not be outsourced and under what conditions. Services can be linked to the European policy that has already been developed.
Political significance:
- Less drastic, quicker to implement
- Does not completely solve structural dependency, but reduces it
- Requires permanent administrative attention
3. Transfer – transferring the risk to another party
Core: passing on the risk contractually or legally.
Relevant observation for the government: This is not a serious option for sovereignty and autonomy risks.
Why not:
- The government remains politically and socially responsible
- Continuity of facilities such as DigiD and the Message Box is not “insurable”
- Damage to reputation and trust is not transferable
Political significance:
- Important to exclude explicitly
- Prevents false security (“it is in the contract”)
4. Accept – bear the risk consciously
Core: recognizing that the risk exists and deciding to accept it.
This requires explicit political responsibility.
Possible steps:
- Formally record what loss of sovereignty is considered acceptable
- Make transparent which dependencies exist
- Periodic reassessment of the risk (for example in case of geopolitical changes)
- Clear communication towards citizens and parliament
Political significance:
- Lowest costs in the short term
- High risk of failure in the event of incidents
- Requires explicit accountability: this risk was taken consciously
The options are summarized:
| Option | Effect on sovereignty | Political gravity |
|---|---|---|
| Avoid | Maximum control | High |
| Reduce | Limited dependency | Medium |
| Transfer | Not realistic | NOT POSSIBLE |
| Accept | Structural dependence | Politically risky |
Outstanding issues
Below is a coherent set of core issues on which clarity is required in order to conduct a substantive, politically pure debate. They have been deliberately formulated as open issues (not positions), so that MPs can use them for questions, positioning and motions. They are clustered according to sovereignty, governance, continuity and political responsibility.
1. Sovereignty and autonomy (fundamental)
- Which digital government facilities do we qualify as vital, in the sense that structural dependence on American control is considered undesirable?
- What degree of loss of autonomy is acceptable with core facilities such as DigiD and the Message Box?
- Is the current design the result of an explicit political choice, or the result of gradual outsourcing without an integral decision point?
- Where is the lower limit of digital sovereignty: when is a dependency no longer acceptable, even if the service functions technically well?
2. Ownership, control and responsibility
- How do ownership of infrastructure, control over the supplier and responsibility for public services relate to each other in crisis situations?
- Does the government have sufficient perseverance in practice to fulfill its public responsibility in the event of conflicting interests?
- Is the current governance designed for daily stability, or also for strategic stress scenarios (geopolitics, legal conflicts, escalations)?
3. Continuity and recoverability
- To what extent can the government independently and timely repair or deviate when the existing infrastructure environment is no longer available?
- What structural recovery limitations exist that cannot be resolved quickly contractually or technically?
- Have these limitations been explicitly taken into account in previous decision-making regarding outsourcing of core facilities?
- What is the socially acceptable maximum outage time of facilities such as DigiD and the Message Box in a crisis situation?
4. Legal and geopolitical context
- Which legal and geopolitical developments could limit the Dutch government’s freedom of action in the future?
- How are situations in which legal frameworks conflict with policy goals or public interests handled?
- Has a scenario analysis been made for changing geopolitical circumstances, and if so, how robust are the results?
5. Policy options and reversibility
- Which of the current choices are reversible, and which actually lead to long-term or permanent dependencies?
- Which policy options are currently still realistic within a period of 5 to 10 years?
- Which risks can be controlled with mitigation, and which will structurally persist, regardless of additional measures?
- Where is the point at which risk acceptance should be an explicit political decision rather than an implicit consequence?
6. Democratic accountability and transparency
- At what point is the House actively involved in decisions that structurally influence digital autonomy?
- How is it explained to citizens who ultimately has control over core digital government facilities?
- Is it sufficiently clear which risks are consciously taken and who is politically responsible for them?
Colophon
This paper from the LibreKAT Foundation was created with the help and support of various people and organizations: AdversIQ B.V., Anovum B.V., Jeroen Baten, BIT B.V., Van Buuren IT Security B.V., Chateau IT, Cloudaware Cybersecurity, Coderial B.V., Cynalytics B.V., DSEC Consulting B.V., Stichting DIVD, Jesse Six Dijkstra, Sebastiaan van ’t Erve, Freedom Internet, Innerheight Internet Services B.V., Mathison B.V., Stichting IP Zorg, Good Cloud B.V., Chris van ’t Hof, Koopman Digital Forensics & Consulting (KDFC), Pieter Muller, Guido de Nobel, Oosenbrug Advies, Vereniging Open Domein, OpenNovations B.V., Stichting Petities.nl, Mr. Victor de Pous, Unicorn Holding B.V., Hans de Raad, Vigilis Consultancy, Weissheid and De Winter Information Solutions.
About the LibreKAT Foundation
The LibreKAT Foundation is committed to a safer digital society. The foundation focuses on open, controllable and verifiable information security. We do this through knowledge sharing, community building and supporting open source solutions within cybersecurity. For example, we offer OpenKAT for identifying vulnerabilities, the Methodology for Information Security Research with Audit Value (MIAW), checklists for information security and we organize the Cyber Research Council to investigate complex problems and explain them clearly.
Our objective includes:
- Stimulating the development and use of open source software and hardware for secure digital infrastructures.
- Promoting transparency and reproducibility in security processes.
- Organizing and supporting research, training and activities on digital resilience.
- Connecting citizens, companies, government and social organizations to increase collective digital resilience.
The board of the Foundation consists of:
- Brenno de Winter, chairman
- Jan Klopper, secretary
- Astrid Oosenbrug, treasurer
