DNS Belgium

Belgium · www.dnsbelgium.be · 24 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 24 sub-vendors.

Insights

Last updated 2026-08-03 · revision 7

24 direct vendors, 277 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

DNS Belgium exhibits a medium level of migration readiness, driven by ongoing modernization and strategic vendor management, but constrained by significant regulatory requirements. Strengths include their proactive internal capability to undertake complex migrations, as demonstrated by the ongoing shift from Oracle to PostgreSQL, and their experience with cloud environments through current AWS usage. The strategic decision to plan a migration away from AWS indicates a willingness to address potential vendor lock-in and pursue infrastructure flexibility. Financial stability provides the necessary resources for such projects, and the use of open-source infrastructure offers greater flexibility. However, significant challenges exist due to strict EU data residency requirements under GDPR and NIS2, which mandate that critical data and infrastructure remain within EU/Belgian jurisdiction, severely limiting choices for cloud providers and regions. There is no explicit mention of cloud-native architectures like containerization or microservices, suggesting their current cloud adoption might not be fully optimized for agile migration. The overall vendor landscape is somewhat unclear due to contradictory data ('Total Vendors: 0' vs. explicit vendors and diverse countries), which could introduce unforeseen complexities during large-scale migrations.

Compliance

7 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

DNS Belgium is headquartered in Belgium (EU) and processes significant volumes of personal data — including domain name registrant data (names, addresses, contact details) for over 1.7 million .be, .brussels, and .vlaanderen domain holders, as well as employee and supplier data. GDPR is unambiguously applicable. The risk level is assessed as Medium rather than High because: (1) DNS Belgium has demonstrated a mature compliance posture through ISO 27001 certification and a published privacy statement; (2) it operates in a regulated digital infrastructure sector with strong institutional awareness of data protection; (3) however, as a ccTLD registry it handles large-scale personal data of registrants across Belgium and potentially internationally, creating inherent exposure. The Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données) is the competent supervisory authority. No public record of GDPR enforcement action against DNS Belgium was found, but full compliance status cannot be confirmed without access to internal DPO records or audit reports.

Evidence: https://www.dnsbelgium.be/en/privacy-statement, https://www.dnsbelgium.be/en/iso-27001-certification, https://www.dnsbelgium.be/en

Belgian Law on Electronic Communications — Assessment Required

The Belgian Law on Electronic Communications (implementing the EU Electronic Communications Code) governs electronic communications networks and services in Belgium. DNS Belgium, as the national ccTLD registry, operates under a specific legal framework established by Belgian law (Royal Decree of 25 October 2002 and subsequent legislation). The risk level is Medium because: (1) DNS Belgium's operations are directly regulated by Belgian telecommunications and internet governance law; (2) the BIPT (Belgian Institute for Postal Services and Telecommunications) has oversight over certain aspects of DNS Belgium's operations; (3) compliance with domain registration rules, WHOIS data accuracy, and abuse handling are legally mandated. Assessment Required to confirm current compliance status with all applicable provisions.

Evidence: https://www.dnsbelgium.be/en/news/illegal-e-cigarette-and-alcohol-sales-taken-offline-faster-thanks-collaboration-fps-health, https://www.dnsbelgium.be/en/news/dns-belgium-swaps-oracle-open-source-alternative-postgresql, https://www.dnsbelgium.be/en/secure/safebrowsing

ISO 27001 (source) — Compliant

DNS Belgium has maintained ISO 27001 certification continuously since July 2016, with successful recertifications in 2019, 2022, and again in 2025/2026 by accredited auditing body Amtivo. The risk level is Low because: (1) active certification is publicly confirmed with a downloadable certificate; (2) the ISMS is described as process-based with continuous improvement cycles; (3) a dedicated CISO (Kristof Tuyteleers) oversees the programme; (4) the General Manager has publicly committed to security as a top priority; (5) the certification scope covers data security risks within the organisation. The most recent recertification audit in 2025/2026 confirms ongoing compliance. Risk of non-compliance is low given the demonstrated institutional commitment and audit history.

Evidence: https://www.dnsbelgium.be/en/iso-27001-certification, https://assets.dnsbelgium.be/attachment/DNSBelgium_ISO27001_CERT2.3.pdf, https://www.dnsbelgium.be/en

Financials

Three-year financials

Financial Resilience Score: 7/10

DNS Belgium demonstrates solid financial resilience despite three consecutive years of net losses (2023-2025). As the monopoly registry for .be, .brussels, and .vlaanderen domains, it enjoys a quasi-utility revenue base with highly recurring subscription-like income (renewals comprise ~83% of registration-fee income). The company has no interest-bearing debt visible on its balance sheet, owns its office building outright, and maintains a low-risk operational profile with ISO 27001 certification and strong governance as a Belgian vzw. However, resilience has been eroded by deliberate strategic choices: management held prices constant for nine years (2016-2024) to return reserves to stakeholders, resulting in equity declining from €3.13M (end-2022) to €1.00M (end-2025), a -68% cumulative decline. Cash has also dropped from ~€7.97M (2022) to ~€3.89M (2025), partly due to the office building purchase and capex. The 2025 price increase demonstrated significant pricing power, lifting registration-fee income by +17.8% and validating the ability to restore profitability. Cost inflation (personnel costs +42% over four years) has structurally outpaced revenue growth, requiring ongoing pricing discipline. The company remains small-scale (~40 FTE, <€10M revenue) with concentration in a single product and geography, but its defensible market position and demonstrated ability to reprice provide a solid foundation.

Key strengths: Monopoly-like position as sole registry for .be, .brussels, .vlaanderen, Highly recurring revenues with ~83% from renewals, No interest-bearing debt; owns office building outright, Demonstrated pricing power (2025 price hike lifted revenue +17.8%), Strong governance and ISO 27001 certification, Reserves built during 2015-2022 absorbed three years of deliberate losses

Risk factors: Equity eroded -68% since 2022 due to three consecutive loss years, Cost inflation (personnel +42% over 4 years) outpacing revenue growth, Structural decline in ccTLD demand from social media, AI website builders, gTLD competition, High concentration: single product (domain registration) and single geography (Belgium), Small scale with ~40 FTE creates key-person risk, Technology transition risk: AWS-to-European provider migration (2026) and Oracle-to-PostgreSQL migration, Cash reserves declined from €7.97M (2022) to €3.89M (2025)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report