Policy & Sovereignty

The Netherlands Publishes a Cryptography Policy Framework for Central Government

February 24, 2026 — The Netherlands has published the English edition of a cryptography framework that sets out how central government organizations must develop and implement cryptographic policies, including requirements for preparing for quantum computing threats. The “Framework cryptography policy for the Central Government” is adopted by the Interdepartmental Committee on Government Operations (ICBR) and applies to all core departments of ministries and their subordinate units. The document’s colophon dates version 1.0 to 14 February 2025.

The framework establishes mandatory requirements for cryptographic key management, certificate handling, and asset inventories while explicitly addressing quantum-safe cryptography preparations. Organizations must document their current cryptographic implementations, record the quantum security level of each, and state how they apply crypto agility.

Under the new requirements, government bodies must maintain detailed inventories of all cryptographic applications, including where cryptography is applied, what algorithms and key lengths are in use, and the current quantum security level of each implementation. The framework also requires organizations to impose identical requirements on vendors executing contracts for the central government.

The document pairs the policy framework with a list of technical aspects on which each organization must decide, covering symmetric and asymmetric cryptography, hashing, certificates and quantum-safe cryptography, including hybrid constructions. Rather than prescribing algorithms itself, it points to BSI’s TR-02102 series and NIST SP 800-57, SP 800-131A and SP 800-175B as reliable sources for those choices.

The framework itself is revised every two years. Organizations must integrate cryptographic considerations into existing processes for asset management, vulnerability management, incident response, and business continuity planning. The framework applies to all unclassified information and classified information up to “Departementaal VERTROUWELIJK” (Departmental Confidential) level.

My Analysis

What strikes me immediately about this Dutch framework is how it manages to be both prescriptive and flexible. Rather than a technical specification, the Netherlands has created something more practical: a blueprint for building cryptographic governance from the ground up.

The requirement for comprehensive cryptographic inventories addresses a fundamental problem I’ve observed across organizations preparing for quantum threats. You can’t protect what you don’t know exists. By mandating detailed documentation of every cryptographic implementation, including its quantum resistance level, the Dutch government forces agencies to confront their technical debt head-on.

This inventory requirement goes beyond simple algorithm tracking. Organizations must document where cryptography lives, how it’s used, what it protects, and critically, its quantum security posture. This creates the foundation for meaningful migration planning.

The framework’s approach to vendor management particularly catches my attention. By requiring government contractors to meet identical cryptographic standards, the Netherlands effectively extends its quantum preparedness requirements throughout its supply chain. This addresses a vulnerability I’ve repeatedly highlighted: even perfectly implemented internal cryptography fails if your vendors remain quantum-vulnerable.

The document explicitly references the PQC Migration Handbook from TNO, CWI, and AIVD, which provides detailed technical guidance for quantum migration. This connection between high-level policy and practical implementation guides shows sophisticated thinking about how organizations actually accomplish cryptographic transitions.

What I find particularly clever is the framework’s integration with existing security processes. Rather than creating parallel cryptographic management structures, it requires organizations to embed cryptographic considerations into their existing asset management, change management, and incident response processes. This dramatically increases the likelihood of actual implementation.

The two-year review cycle strikes a reasonable balance. Annual reviews would create excessive overhead, while longer cycles risk missing critical developments in quantum computing progress. Given the current pace of quantum advancement and the multi-year timeline for cryptographic migrations, biennial updates make sense.

One notable aspect is the framework’s explicit focus on “crypto agility.” Organizations must implement cryptography in modular ways that facilitate rapid algorithm replacement. This addresses a core challenge in preparing for Q-Day: we need systems that can quickly swap algorithms when quantum computers achieve cryptographic relevance, whenever that occurs.

The framework’s scope limitations reveal pragmatic thinking. By excluding state secret classifications (Staatsgeheim CONFIDENTIEEL and higher), it acknowledges that these systems already operate under stringent cryptographic requirements. Attempting to harmonize these specialized systems with general government IT would add complexity without meaningful security benefits.

Personnel requirements in the framework deserve attention. Beyond technical implementation, it mandates security screening for cryptographic roles and ongoing training requirements. Human factors remain a critical weakness in cryptographic systems. The best algorithms fail when improperly implemented or managed by inadequately trained staff.

The document’s approach to certificate management reflects lessons learned from past failures like DigiNotar. By requiring detailed lifecycle management and explicit trust criteria, it addresses vulnerabilities that have plagued PKI implementations. The framework specifically addresses self-signed certificates, acknowledging their occasional necessity while requiring additional compensating controls.

I appreciate how the framework addresses archival challenges. Encrypted or signed documents must remain accessible for decades, long after the cryptographic methods used to protect them become obsolete or quantum-vulnerable. By requiring organizations to plan for long-term cryptographic material retention, it prevents future accessibility crises.

The framework positions itself as both normative and educational. While mandatory for central government organizations, it explicitly invites adoption by regional governments and private sector entities. This multiplier effect could significantly accelerate quantum preparedness across Dutch critical infrastructure.

Comparing this to international efforts, the Netherlands has struck an effective balance. It provides more concrete requirements than high-level strategies from some nations, while avoiding the paralysis that can come from overly detailed technical mandates. The framework creates structure without strangling flexibility.

For CISOs implementing this framework, the message is clear: start with the inventory. Without understanding your current cryptographic landscape, meaningful quantum preparation remains impossible. The framework provides the structure, but organizations must do the hard work of discovery and documentation.

This Dutch framework represents the kind of practical quantum preparedness guidance I’ve been advocating for. It acknowledges both the reality of the quantum threat and the complexity of cryptographic migration. By creating standardized approaches while maintaining implementation flexibility, it offers a model other nations should study carefully.

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com.