Solvinity B.V.
Netherlands · owned by Kyndryl Nederland B.V. (Netherlands) · www.solvinity.com · 15 vendors
Solvinity B.V. is a Dutch Secure Managed Cloud provider that designs, builds, and manages secure and innovative IT environments for organisations handling sensitive and mission-critical data. The company offers services including IT outsourcing, managed cloud services (private, public, and hybrid), managed security services, and managed application services. It serves clients in government, financial services, and business services sectors, and is notably the platform operator behind the Dutch national identity service DigiD.
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Akamai Technologies, Inc. — Technology — United States
- Google LLC — Technology — United States
- SevenSpark — Technology — United States
- and 12 more
Insights
Last updated 2026-05-02 · revision 3
15 direct vendors, 229 subvendors
Direct vendors by controlling owner country (sample)
- Israel: 1
- Denmark: 1
- Germany: 1
Subvendors by controlling owner country (sample)
- Luxembourg: 1
- Switzerland: 1
- Denmark: 4
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Solvinity B.V. exhibits exceptionally high migration readiness, largely due to its core business model centered on managed cloud services and its highly advanced, multi-cloud internal technology stack. The company's product offerings, such as 'Managed Cloud Services', 'Microsoft Azure (Managed)', 'Amazon Web Services (Managed)', and 'Hybrid Cloud', directly reflect its expertise in cloud adoption and migration. Internally, Solvinity leverages 'VMware', 'OpenStack', 'Kubernetes', 'Microsoft Azure', and 'Amazon Web Services (AWS)', demonstrating a strong commitment to cloud-native architectures, containerization, and multi-cloud flexibility. The use of 'CI/CD' pipelines and services like 'Azure OpenAI Kickstart' further highlights their embrace of modern, agile development and deployment practices that facilitate seamless migrations. Their extensive experience and certifications in regulatory compliance (ISO 27001, SOC 2, GDPR, NEN 7510, NIS2 applicable) and data residency requirements (Netherlands/EU) are significant strengths. While these regulations introduce complexity, Solvinity's proven capability to manage them means they are well-prepared to ensure compliance throughout any migration process, rather than being hindered by it. The consistent growth history suggests financial stability to fund migration initiatives. The diversity of their technology vendors, as inferred from their 'Internal Tech Stack' (e.g., Microsoft, AWS, VMware, OpenStack), and their multi-cloud service offerings, significantly reduces vendor lock-in risks and enhances their ability to migrate workloads between different platforms. Although the 'Vendor Lock-in Risk' is explicitly stated as 'Unknown' in the provided data, their strategic adoption of multiple cloud providers and open-source technologies strongly indicates a proactive approach to minimizing such risks.
Compliance
5 in-scope frameworks identified; showing 3.
SOC 2 (source) — Compliant
Solvinity actively maintains SOC 1 & 2 compliance with annual audits covering both private cloud and Azure public cloud services. As a cloud services provider, SOC 2 compliance is essential for customer trust and contract requirements. Their proactive approach to SOC 2 compliance and dedicated compliance assurance service indicates strong controls and low risk of non-compliance.
Evidence: https://www.solvinity.com/services/soc-2-compliance-assurance/, https://www.solvinity.com/
ISAE 3000 (source) — Assessment Required
As a provider of assurance services through SOC reports and compliance services, Solvinity may need ISAE 3000 compliance for their assurance reporting activities. The risk is medium because while they provide SOC reports (which may follow ISAE 3000 standards), specific ISAE 3000 compliance status is unclear. Non-compliance could affect their ability to provide credible assurance services to customers.
Evidence: https://www.solvinity.com/services/soc-2-compliance-assurance/
NIS2 (source) — Assessment Required
Solvinity operates as a digital infrastructure and ICT service management provider in the EU with 350+ employees, clearly exceeding the 50+ employee threshold. As a managed cloud services provider offering critical IT infrastructure services to government and financial sectors, they likely qualify as an Important Entity under NIS2. Non-compliance could result in fines up to €10M or 2% of annual turnover, plus operational restrictions. Risk is medium pending formal assessment of their specific services against NIS2 criteria.
Evidence: https://www.solvinity.com/about-solvinity/, https://www.solvinity.com/services/managed-cloud-services/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Solvinity demonstrates strong qualitative financial resilience anchored by its role as operator of mission-critical Dutch government infrastructure, most notably the DigiD national digital identity platform. Its client base includes the Ministry of Justice & Security and the Central Judicial Collection Agency, representing long-term, sticky, high-security contracts that provide highly predictable recurring revenue with low churn risk. The company's almost entirely subscription/retainer-based managed services model further reinforces revenue visibility and stability. The company's extensive certification portfolio — ISO 27001, ISO 9001:2015, ISO 14001, SOC 1 & 2, and PCI DSS — constitutes a significant barrier to entry in regulated sectors and strongly supports client retention. The announced acquisition by NYSE-listed Kyndryl (spun off from IBM in 2021) serves as an implicit validation of Solvinity's financial health and strategic value, as a sophisticated acquirer would have conducted thorough due diligence. Headcount growth from approximately 275 to 350+ employees over roughly 3–4 years implies a CAGR of 6–8%, consistent with a growing and likely profitable business. However, the pending Kyndryl acquisition introduces meaningful transition risk, including political and regulatory scrutiny in the Netherlands over data sovereignty concerns related to DigiD and potential US CLOUD Act exposure under a US-listed parent. Key client concentration in the Dutch government vertical represents a material single-sector dependency. Additionally, the complete absence of publicly disclosed financial statements prevents independent verification of revenue, profitability, or balance sheet strength, limiting external confidence in the company's financial position. Overall, the combination of a resilient recurring revenue model, mission-critical government contracts, strong compliance posture, and strategic acquirer validation supports a above-average resilience score, tempered by ownership transition uncertainty, political risk, and financial opacity.
Key strengths: Operator of DigiD — Netherlands' national digital identity platform — providing highly sticky, long-term government revenue, Recurring managed services contract model with multi-year engagements ensuring strong revenue visibility, Extensive certifications (ISO 27001, ISO 9001:2015, ISO 14001, SOC 1 & 2, PCI DSS) acting as barriers to entry and supporting client retention, Diversified blue-chip client base spanning government, financial services, and business services, Strategic acquisition by Kyndryl (NYSE: KD) implicitly validates financial soundness and strategic value, Sovereign cloud and EU data residency positioning as a structural tailwind under NIS2, DORA, and EU data sovereignty regulations, Headcount CAGR of approximately 6–8% over 3–4 years consistent with a growing, likely profitable business, Unverified industry analyst estimates place annual revenue in the range of EUR 50M–100M
Risk factors: Pending Kyndryl acquisition introduces ownership transition risk affecting client, staff, and contract stability, US parent company (Kyndryl, NYSE: KD) exposure raises concerns about US CLOUD Act data access requests, already publicly debated by Dutch politicians, Regulatory and political risk: Dutch government as major client could renegotiate or terminate contracts due to sovereignty concerns, Significant key client concentration in the Dutch government vertical — loss of DigiD or related contracts would be material, Scale constraints with ~350 employees competing against much larger global IT services firms, Complete absence of publicly disclosed financial statements prevents independent verification of revenue, profitability, or balance sheet strength, Competitive Dutch IT labour market creates persistent cost and operational risk for retaining specialised cloud and security engineers
Revenue by geography
- Netherlands: 100%
Revenue by product/service
- IT Outsourcing: 35%
- Managed Cloud Services: 30%
- Managed Security Services: 15%
- Service Integration & Management (SIAM): 10%
- Managed Application Services: 7%
- Lango Workspace: 3%
Workforce by country
- Netherlands: 350
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.