2026-07-10

Added · Updated

The Path to Digital Autonomy - More Control Over Digital Dependencies

ACM, AFM, AP, DNB, and RDI jointly issue a position paper urging coordinated action to reduce strategic dependencies on non-European IT providers and enhance the resilience of European digital infrastructure. The regulators recommend that governments act as launching customers for European services, integrate digital autonomy into procurement criteria, and establish legal requirements for European fallbacks in vital processes. Organizations are advised to mitigate vendor lock-in through open standards, interoperability, and joint sectoral purchasing to foster a competitive and sovereign European digital ecosystem.

Autoriteit Financiele Markten logo

Netherlands

Autoriteit Financiele Markten

Click to view thumbnail

The Path to Digital Autonomy

More Control Over Digital Dependencies

ACM | AFM | AP | DNB | RDI

Table of Contents

  • Key Messages and Recommendations 3
  • Key Messages 3
  • Recommendations 3
  • Introduction 5
  • Digital Autonomy 7
    • Digital Autonomy Requires Freedom of Choice 7
    • Digital Autonomy Requires Conscious Trade-offs 7
  • The Path to Digital Autonomy 9
    • Governments as Launching Customers 9
    • Cooperation is Necessary and Possible 9
    • Secure Switching Options 10
    • Incorporate Digital Autonomy into Tendering and Procurement 11
    • Strengthen Knowledge and Awareness 11
  • Strengthening Policy and Legislation 12
  • The Role of ACM, AFM, AP, DNB, and RDI 14

Key Messages and Recommendations

Key Messages

  • Strengthening digital autonomy requires not only action by individual companies and institutions using IT services, but also coordinated and collective action to enable this complex transition.
  • Digital autonomy is about freedom of choice and self-determination for companies and institutions using IT services, with the aim of strengthening the resilience of business processes. Organizations must be able to move when circumstances require it.
  • Digital autonomy also requires conscious trade-offs between autonomy, costs, and functionality: not every process requires the same level of autonomy. For vital processes, it is important to take additional safeguards, and the minimum availability of a European fallback should be a basic requirement.
  • The government can play an important role by acting as a launching customer for European digital services based on open standards and by cooperating and bundling demand.
  • Incorporating digital autonomy into tenders is well possible within existing tendering rules, for example by setting requirements for compliance with specific standards and by translating digital autonomy into concrete, verifiable requirements and award criteria that protect against unwanted dependencies and exposure to non-European legal obligations.
  • We also call on companies and institutions to jointly promote digital autonomy, for example by acting as launching customers for sector-specific IT services within sectoral partnerships. There is ample room for this within the framework of the Competition Act.
  • Furthermore, it is important that companies and institutions increase optionality and portability in their IT architecture and limit vendor lock-in as much as possible, for example via containerization, open source software, and open standards. IT suppliers should design their products and services in such a way that they support switching options and facilitate integration with other (European) solutions.

Recommendations

We call on all organizations to explicitly include digital autonomy as a quality criterion in tendering, procurement, and re-contracting processes for IT services. We advise using concrete decision frameworks in which it is determined for each type of process which level of digital autonomy is appropriate and how autonomy relates to other objectives such as costs and functionality. The autonomy criterion must be translated into verifiable requirements in tender documents and contracts, such as requirements regarding data location, the use of open standards, interoperability, good exit options, and limiting vendor lock-in. Governments, companies, and institutions can make use of the EU Data Act, which obliges cloud providers to facilitate data portability and interoperability. Furthermore, it is important to create a level playing field by basing procurement processes and tenders primarily on functional needs rather than product-specific requirements. Investing in own knowledge and personnel prevents crucial expertise from lying entirely with suppliers and enables stronger client leadership and management. Existing legislation offers ample space to pay attention to digital autonomy. We invite organizations to early consultation and dialogue, for example in case of doubts about the interpretation of legislation.

Policy Makers and Legislators

  • Let the government act as a launching customer by stipulating that a certain part of cloud demand must meet the highest sovereignty requirements.
  • Include legal requirements regarding the minimum availability of a European fallback for vital processes.
  • Strengthen the investment and establishment climate for European IT providers, inter alia by improving access to capital, reducing fragmentation of the internal market, and directing scarce space for data centers towards projects that contribute to European competitiveness, autonomy, and resilience.
  • Secure an effective investment screening system to protect vital sectors from acquisitions that could pose risks.

Governments as Purchasers of IT Services

  • Use the space within the Tendering Act to translate digital autonomy into concrete, verifiable requirements and award criteria. Make explicit use of the possibilities to give preference to solutions that meet the highest sovereignty requirements.
  • Purchase jointly, for example through purchasing collectives and joint framework agreements.

Companies and Institutions

  • Work sector-wide to jointly set requirements for IT providers and invest in European alternatives. There is ample room for this within the framework of the Competition Act.
  • Realize switching options by developing and testing exit and transition plans, limiting vendor lock-in, and reducing short-term risks via multi-vendor strategies and the use of open standards and interoperability as an explicit design principle in the IT architecture.
  • When deciding to procure additional cloud services, explicitly weigh the risk of vendor lock-in.
  • Take short-term steps to limit risks, including taking control of encryption keys in-house and ensuring EU-based fallbacks for data and critical software.

IT Suppliers

  • Cooperate with other suppliers and parties in the ecosystem to develop scalable European cloud and IT services, so that alternatives can emerge for dominant non-European providers. There is room for this within the Competition Act.
  • Develop services that explicitly address public and private requirements regarding digital autonomy, such as interoperability, open source solutions, open standards, and data portability.
  • Design products and services in such a way that they support switching options, limit vendor lock-in, and facilitate integration with other (European) solutions.

Introduction

ACM, AFM, AP, DNB, and RDI present this position paper jointly to contribute to the transition towards greater digital autonomy and the reduction of dependencies on dominant non-European IT suppliers, thereby increasing the resilience, continuity, and security of business processes. The digital infrastructure of the Netherlands and Europe relies heavily on a limited number (mostly non-European) technology companies for cloud services, software, and hardware. This brings concentration and systemic risks, especially in the current geopolitical climate. There are also risks for the economic development of Europe. Various scenarios can occur; for example, service provision could suddenly disappear due to a malfunction, cyber incident, or political pressure from third countries, or third countries could demand access to data, for example through legislation such as the US Cloud Act. Furthermore, vendor lock-in makes switching and risk diversification difficult and costly, weakening the bargaining position and potentially causing prices to rise. For governments, financial institutions, and other vital organizations, digital dependency thus directly affects the security and continuity of service provision. For the economy, dependencies threaten earning capacity in the long term.

Making the Dutch economy more resilient by strengthening digital autonomy is now a widely supported goal. Digital autonomy is explicitly included in the coalition agreement as a leading principle for government policy. The Dutch Digitalization Strategy and the vision 'Digital Autonomy and Sovereignty of the Government' also emphasize the importance of control, freedom of choice, and switching options in the digital domain. Nevertheless, the regulators observe that dependencies continue to increase in practice. The Dutch situation is illustrative of the broader European development, while effective solution directions must largely be realized at the European level. Digital autonomy requires a better balance in dependencies compared to regions outside Europe. This requires not only reducing risks, but also actively strengthening the European digital ecosystem, inter alia by further developing strategic capacities, increasing diversity in the offer of IT services, better bundling the demand power of organizations, and stimulating cooperation.

For each regulator, this issue is of great importance from their own mandate. The Authority for Consumers & Markets (ACM) signals that vendor lock-in with large technology suppliers leads to a limitation of the offer and thus to obstacles for good market functioning.¹ The National Inspectorate for Digital Infrastructure (RDI) sees, as a supervisor based on the Telecommunications Act, NIS2, EIDAS, and CSA, that the digital resilience of the Netherlands depends on a limited set of companies, which entails systemic risks.² The Authority for the Financial Markets (AFM) and De Nederlandsche Bank (DNB) supervise the controlled and proper management of financial enterprises and, more specifically, their digital resilience as laid down in the Digital Operational Resilience Act (DORA), and signal that increasing dependence on a limited number (mostly non-European) technology providers leads to concentration and systemic risks, which can endanger the stability of the system and the interests of consumers.³ Digital dependency also carries the risk that personal data in vital processes are unavailable on a large scale for a long time or are compromised. Under the GDPR, governments and companies must take measures against this. The AP finds it of great importance that these vital processes are better protected.⁴

It is particularly important that companies and institutions spread their risks and do not put all their eggs in one basket when it comes to digital infrastructure and service provision. At present, Europe depends on critical infrastructure from various regions outside Europe regarding, for example, cloud services, security, and data centers. The recommendations in this position paper are therefore not directed against a specific jurisdiction or region that offers these services or infrastructure. Nor does the position paper contain new rules or obligations for companies and institutions under our supervision. However, Europe is lagging behind in digital innovation, and therefore, for both strategic and economic reasons, it is important that Europe makes up ground in this area; an ambition that is also central in the recently presented Tech Sovereignty Package of the European Commission, which aims to structurally strengthen European digital capacity and reduce strategic dependencies.


Digital Autonomy

Digital Autonomy Requires Freedom of Choice

Digital autonomy means that governments and organizations are able to make their own choices regarding their IT and actually have control over it. We emphatically do not mean by this that all technology must be developed in-house or that full technological independence is pursued. Central to this is the limitation of unwanted strategic dependencies and having freedom of choice when switching between suppliers. It also means having options when unfavorable scenarios occur.

Digital autonomy requires fundamental thinking about the design of the IT architecture. Freedom of choice only arises when the IT architecture is designed openly, based on open standards and interoperable solutions, where governments and organizations are not tied to one supplier. Currently, however, dominant cloud solutions from (non-European) hyperscalers lead to strong dependencies and vendor lock-in.

Digital autonomy also has a link with legal sovereignty in the current geopolitical context. Dependence on non-European IT service providers can lead to organizations dealing with foreign legislation, which can limit their own control over data and digital processes. As long as there are not yet sufficient full-fledged alternatives available in Europe, scenarios are conceivable where state actors use dependence on non-European service providers as a means of power. To increase resilience against such scenarios, strengthening the European offer of IT services is important. In this context, the concept of legal sovereignty is relevant, which means that certain legal risks must be prevented, such as data being unilaterally demanded by non-European governments.

Digital Autonomy Requires Conscious Trade-offs

Digital autonomy is not an absolute goal, but a matter of conscious and proportional trade-offs. Not every application requires the same level of autonomy or sovereignty. Therefore, it is necessary to distinguish between different categories of processes and services, and to explicitly determine for each category which level of autonomy and control is necessary. This distinction is already found in legislation. In the financial sector, DORA imposes requirements for 'critical and important' functions⁵, while in a number of other sectors, the NIS2 Directive imposes rules for 'essential and important' entities⁶ and their services. Some of these functions and entities can also be classified as 'vital', namely when failure, disruption, or manipulation can lead to serious social disruption, serious economic damage, or – in the extreme case – a threat to national security. In the financial sector, this concerns, for example, payment and securities transactions and balance management by banks.⁷

For vital processes, it is important to take additional safeguards to limit dependencies and concentration risks. It is crucial to prevent service provision from disappearing due to a malfunction, cyber incident, or political pressure from third countries, or for third countries to demand access to data. If national security is at stake, legislation also provides the possibility to exclude service providers from a tender based on sovereignty risks.

For vital processes, due to geopolitical risks, the minimum availability of a European fallback should be a basic requirement to ensure continuity. We ask European legislators to include this as a legal requirement. As long as dependence on non-European suppliers persists in the short term, it is also important for organizations in these sectors to take measures that mitigate acute risks. For example, managing encryption keys in-house increases control over data and limits the risk of unwanted access to data by third parties. Independent backups, preferably on-premise or within the EU, ensure recovery options in case of failure or incidents in the primary cloud environment.

For all critical, important, and essential functions and services, the risks of dependencies on IT service providers must be managed. Specifically for the financial sector, it applies that under the DORA regulation, providers of IT support for critical and important functions and the financial institutions themselves must comply with requirements regarding, inter alia, information security, business continuity plans, and exit strategies. The ECB Guide on outsourcing cloud services to cloud service providers aims to provide further clarity on the expectations under DORA and gives 'best practices' for meeting the various requirements.⁸ In addition to the sector-specific framework for the financial sector, it applies to other sectors that under the NIS2 Directive⁹ essential and important entities and the essential services they provide must meet increased cyber resilience and duty of care requirements, including regarding supply chain security and dependencies on IT service providers. In a recently published opinion¹⁰, the RDI has already indicated that companies and institutions must gain more control over their dependencies.

For non-vital processes, strengthening digital autonomy can also be shaped within the offer of non-European suppliers, provided a conscious trade-off is made in which the risks are carefully mapped. Optionality, portability, and preventing lock-in are important here. This requires a better offer of IT services, open standards, and interoperability. Furthermore, organizations managing non-vital processes can take technical measures to reduce the main risks, such as managing encryption keys in-house and ensuring independent fallbacks.


The Path to Digital Autonomy

The path to digital autonomy requires joint efforts from multiple parties. Reducing digital dependencies and increasing freedom of choice is not a task that can be realized by individual organizations or the market alone. Governments, policy makers, and legislators play a decisive role by providing direction through policy, procurement, and regulation. Companies and vital organizations make the concrete choices in their IT strategy. IT suppliers influence whether switching is actually possible through their design choices and the degree of interoperability. Regulators contribute by providing space and clarity within existing frameworks and by removing obstacles to cooperation and switching. In this chapter, we elaborate on the steps needed to arrive at a more autonomous and resilient IT infrastructure along these tracks.

Governments as Launching Customers

A coordinated approach under the leadership of European governments is necessary. Organizations that switch first to a European provider incur extra costs and run risks. This creates a situation where market forces and competition do not sufficiently lead to the development of alternatives. Without coordination, necessary steps towards digital autonomy remain undone. European alternatives can only grow when European public organizations commit as purchasers for a longer period. Through their scale and continuity, governments can offer demand certainty, thereby stimulating market development and creating a more integrated offer. It is important to work systematically towards a visible success within the government. By bundling knowledge and expertise and focusing on a successful switch at one or several organizations, a concrete and replicable example can be set. The lessons learned can then be used to accelerate the transition to a more autonomous IT stack.

Cooperation is Necessary and Possible

Cooperation within governments and sectors offers opportunities to stand stronger together. A group of purchasers can jointly formulate requirements towards providers of cloud and software services. By bundling demand and setting joint requirements (for example, focused on autonomy, limiting vendor lock-in, increasing transparency, and ensuring continuity), more influence on the offer is created. Organizations can jointly invest in the development of existing and new (European) cloud services or infrastructure, including open source alternatives. This reduces the risks for individual organizations and accelerates the availability of alternatives.

Scale is needed to create a European offer that can compete with large players from outside Europe; bundling both demand and supply can help here. Think, for example, of agreements between financial institutions to procure cloud services from a European provider that currently lacks sufficient scale. The bundling of demand enables this provider to scale up quickly, thereby reducing costs and investing in quality and functionality. Bundling the supply can also help in obtaining the necessary scale. Agreements on bundling demand and supply can thus ultimately lead to more competition.

The regulators often see reluctance among companies to cooperate, but the Competition Act provides ample space for cooperation that does not restrict competition. Joint purchasing and the development of common standards are examples of such cooperation.

Secure Switching Options

To prevent vendor lock-in, it is essential that IT architectures are designed with switching in mind. This involves using open standards, ensuring data portability, and designing clear exit strategies. Organizations should regularly test their ability to switch providers to ensure that data can be retrieved and processes can be continued without significant disruption. Suppliers should facilitate this by providing standard interfaces and documentation.

Incorporate Digital Autonomy into Tendering and Procurement

Tendering and procurement are powerful tools to drive digital autonomy. Governments and large organizations should include criteria related to sovereignty, open standards, and interoperability in their tenders. This signals demand for European alternatives and encourages suppliers to design their products with these requirements in mind. Award criteria can favor solutions that offer better control over data and lower strategic risks.

Strengthen Knowledge and Awareness

Organizations must have the internal knowledge to manage their IT dependencies effectively. This includes understanding the technical and legal implications of different service models and providers. Investing in staff training and expertise reduces reliance on external suppliers for basic management tasks and enables better negotiation and oversight.


Strengthening Policy and Legislation

To support the transition to digital autonomy, policy and legislation must evolve. This includes updating procurement laws to allow for sovereignty criteria, strengthening data protection regulations to limit extraterritorial access, and fostering an environment where European tech companies can thrive. International cooperation is also essential to align standards and reduce regulatory fragmentation.


The Role of ACM, AFM, AP, DNB, and RDI

The five regulators play distinct but complementary roles in promoting digital autonomy:

  • ACM (Authority for Consumers & Markets): Focuses on competition and market functioning, ensuring that vendor lock-in does not hinder competition and that markets for IT services remain open and competitive.
  • AFM (Authority for the Financial Markets) & DNB (De Nederlandsche Bank): Supervise the financial sector's resilience, ensuring that financial institutions manage their IT dependencies in line with DORA and other regulatory requirements to maintain financial stability.
  • AP (Autoriteit Persoonsgegevens): Protects personal data, ensuring that digital dependencies do not compromise privacy rights and that data protection standards are maintained across borders.
  • RDI (Rijksinspectie Digitale Infrastructuur): Oversees the security and resilience of critical digital infrastructure, ensuring that essential services are protected against cyber threats and systemic risks.

Together, these regulators advocate for a coordinated approach to digital autonomy, recognizing that it is a shared responsibility involving governments, businesses, and citizens.


¹ State of the Market 2026 | ACM ² Supervision of the use of cloud services | National Inspectorate for Digital Infrastructure | RDI ³ Digital Dependency in the Financial Sector | DNB, AFMLetter to Minister EZ on Digital Sovereignty | APCritical or important functions are functions whose disruption would significantly impair the financial performance of a financial entity or the solidity or continuity of its services and activities.Essential and important entities are entities that are critical due to their sector or the type of services they provide, taking into account their size.See for a complete overview of vital processes Approach Vital | National Coordinator for Counterterrorism and Security, and for more information on vital processes in the financial sector Parliamentary Document 30821, no. 323 | Government.nl > Official Publications.ECB Guide on outsourcing cloud services to cloud service providersThe NIS2 Directive is implemented in the Netherlands in the Cybersecurity Act (Cbw), which will enter into force in 2026. ¹⁰ Supervision of the use of cloud services | RDI

Note: The document text provided ends abruptly at page 10. The above translation reflects the content available in the source text.