SSC-Campus
Netherlands · www.logius.nl · 9 vendors
Logius is the digital government service of the Netherlands Ministry of the Interior and Kingdom Relations. It develops and maintains government-wide ICT solutions and common standards. These services simplify communication and digital transactions between authorities, citizens, and businesses in the Netherlands.
Resilience scores
- Digital Sovereignty: 67
- Digital Resilience: 8
- Financial Resilience: 9
Technology vendors
- Drupal — Technology — Belgium
- Oracle Corporation — Technology — United States
- Piwik PRO — Media & Marketing — Poland
- and 6 more
Services catalogue
1 service in catalogue across 1 category; runs on 9 sub-vendors.
- DNS Hosting
Insights
Last updated 2026-05-02 · revision 2
9 direct vendors, 102 subvendors
Direct vendors by controlling owner country (sample)
- United States: 3
- Belgium: 1
- Poland: 1
Subvendors by controlling owner country (sample)
- Australia: 2
- Russia: 1
- France: 3
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
SSC-Campus exhibits exceptionally high migration readiness, largely due to its advanced and cloud-native technology architecture. The company's internal tech stack is highly modern, featuring Kubernetes, Docker, cloud-agnostic/multi-cloud infrastructure, extensive use of open-source components, and a mature DevOps toolchain with CI/CD pipelines. The 'Standaard Platform' is a dedicated, cloud-native, Kubernetes-based platform, which positions them as already having embraced or completed significant aspects of a cloud migration. Their adoption of modern API standards (REST, OAuth 2.0, CloudEvents) facilitates integration and portability. While the 'XML / SOAP (Digikoppeling messaging)' is mentioned, it's part of an interoperability framework and doesn't negate the overall cloud-native posture. The primary challenges for migration readiness stem from external factors and data gaps. Data residency requirements are not specified but are highly likely to be strict given their role as a Dutch government entity handling sensitive citizen data, which could complicate multi-cloud deployments outside the Netherlands/EU. Financial stability data (revenue, growth) is also missing, making it impossible to assess the financial capacity to fund large-scale migrations. The 'Total Vendors: 0' entry is ambiguous, but if there are vendors for 10 services, the 'Vendor Lock-in Risk' is 'Unknown'. However, the cloud-agnostic approach of their 'Standaard Platform' suggests a proactive strategy to minimize vendor lock-in at the infrastructure level.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
As a Dutch government organization processing extensive personal data (DigiD, MijnOverheid, eHerkenning), GDPR compliance is critical. Non-compliance would result in severe regulatory sanctions, loss of public trust, and potential legal action. The organization handles millions of citizens' authentication data, making data protection paramount. High enforcement likelihood given the public sector nature and visibility.
Evidence: https://www.logius.nl/over-ons/privacy, https://www.logius.nl/privacyverklaring
SOC 2 (source) — Assessment Required
While not legally required, SOC2 compliance would be valuable for a critical infrastructure provider handling sensitive government data. Risk is moderate as it affects vendor relationships and trust, but non-compliance doesn't carry legal penalties. However, given their role in critical infrastructure, security frameworks are essential.
Evidence: https://www.logius.nl/over-ons/veiligheid
ISO 27001 (source) — Assessment Required
For a critical government infrastructure provider, ISO 27001 certification would be highly valuable and potentially required by government security standards. Risk is moderate as it affects security posture and compliance with government requirements, though specific legal penalties may not apply. However, government entities often have mandatory security framework requirements.
Evidence: https://www.logius.nl/over-ons/veiligheid
Financials
Three-year financials
- 2024:
- 2023: revenue €400M, equity €17.5M
- 2022: revenue €365M, equity €17.5M
Financial Resilience Score: 9/10
Logius is a statutory government agency (agentschap) of the Dutch Ministry of the Interior and Kingdom Relations (BZK), operating under a cost-recovery baten-lasten model. Its funding is secured through multi-year budget allocations and service-level agreements with other government bodies, meaning there is effectively zero revenue risk from market competition. The organisation operates critical, non-substitutable national digital infrastructure including DigiD (serving ~17 million Dutch citizens), MijnOverheid, Digipoort, and PKIoverheid, making it structurally indispensable to the Dutch public sector. The agency's financial resilience is essentially as strong as the Dutch sovereign state itself. It is required to operate near break-even, with any surplus returned to the ministry or held in a capped equity buffer (eigen vermogen, limited to ~5% of total lasten). This model eliminates commercial financial risk, though it also means there is no profit generation or shareholder return. Recent years have shown modest positive saldi, consistent with the agency model, and no significant operating losses have been reported. Growth drivers are robust: the Dutch government's NL DIGIbeter digitalisation strategy ensures continued demand expansion, and usage metrics confirm this trajectory — DigiD reached a record 350 logins per second in the 2024 tax season, up from 250 the prior year, with 9 million ID-check users and 342 municipalities onboarded to Berichten over uw Buurt. Service availability metrics are strong, with Digipoort and Diginetwerk achieving near-100% uptime and DigiD/MijnOverheid exceeding 99%. Key risks include infrastructure modernisation complexity (the ICT advisory board flagged the original migration plan as infeasible in 2023), cybersecurity exposure as a high-value national target, talent competition from the private sector, dependency on key external suppliers (notably Solvinity), and evolving EU regulatory compliance obligations under eIDAS 2.0, NIS2, and GDPR. These risks are real but manageable given the sovereign backing and mandatory mandate.
Key strengths: Sovereign mandate with guaranteed multi-year funding from Ministry of BZK, Operator of critical, non-substitutable national digital infrastructure (DigiD, MijnOverheid, Digipoort, PKIoverheid), Cost-recovery baten-lasten model eliminates commercial revenue risk, Growing demand driven by Dutch government NL DIGIbeter digitalisation strategy, Record DigiD usage (350 logins/sec in 2024 tax season; 9 million ID-check users), Near-100% service availability across core infrastructure platforms, Expanding service portfolio with successful new launches in 2023–2024, Financial resilience effectively backed by Dutch sovereign credit
Risk factors: Infrastructure modernisation risk: ICT advisory board (Adviescollege ICT-toetsing) assessed original migration plan as infeasible in 2023; revised strategy carries cost overrun and continuity risk, Cybersecurity exposure: high-value target for cyberattacks as operator of national digital identity infrastructure, Budget dependency on political and parliamentary decisions; austerity or reprioritisation could constrain investment, Systemic concentration risk: entire Dutch public sector depends on Logius infrastructure; prolonged outage has nationwide impact, Talent and capacity constraints: competition with private sector for skilled IT professionals, Key supplier dependency, notably potential Solvinity takeover situation, Ongoing compliance burden from eIDAS 2.0, GDPR, NIS2, and evolving EU digital identity regulations
Revenue by geography
- Netherlands: 100%
Revenue by product/service
- Toegang (Access/Identity — DigiD, eHerkenning, PKIoverheid, BSNk PP, eIDAS): 40%
- Gegevensuitwisseling (Data Exchange — Digipoort, Digikoppeling, SBR/XBRL, e-Factureren, Peppol): 30%
- Interactie (Interaction — MijnOverheid, Berichtenbox, Berichten over uw Buurt): 18%
- Infrastructuur (Diginetwerk, Standaard Platform, Digitoegankelijk): 9%
- Publicatie/Standaarden (Stelselcatalogus, API-standaarden, BOMOS): 3%
Workforce by country
- Netherlands: 1200
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.