Skip to main content
12/18/2025GovernmentHealth CareMunicipalitiesSovereignty

DigiD Acquisition Highlights Urgency of Supplier Risk Management

The questions and concerns in the House of Representatives regarding the American acquisition of Solvinity, a supplier providing services related to DigiD, make one thing very clear… Read more

Explore healthcare cyber intelligence in the live cyber intelligence feed.

Explore

Related signal context

Open the classified signal themes connected to this analysis.

The questions and concerns in the House of Representatives regarding the American acquisition of Solvinity, a supplier providing services related to DigiD, make one thing very clear: our digital supply chains are vulnerable when changes occur out of our sight. An acquisition is one such change. Today you have agreements, tomorrow there's a new owner, a different governance structure, and potentially a different legal context. Then, critical management questions quickly arise: who can access the data, which legislation applies, who bears responsibility, and what happens if the service changes or temporarily fails?

For organizations relying on cloud and IT services, this is not a “government-only” issue. It's a recognizable scenario that can happen in any sector: healthcare, industry, finance, retail, logistics. Precisely for this reason, mature supplier risk management is no longer a nice-to-have but a prerequisite for continuity, especially now that NIS2 makes supply chain responsibility more explicit.

Why This Case Is So Sensitive

Solvinity provides services for DigiD and other government systems. When a party with a role in such a critical digital supply chain is acquired by a foreign company, more than just a shareholder register shifts. In practice, new risks can arise, for example, because:

  • Jurisdiction changes: a different “home base” can create different legal possibilities regarding access, oversight, or data claims.
  • Security and governance are reconfigured: processes, priorities, and responsibilities can change, even if the contract remains the same.
  • Continuity and dependency feel different: strategic choices (investments, consolidation, relocation of services) can affect delivery assurance.

The core issue is not that a foreign owner is inherently “wrong.” The core issue is that ownership changes can alter the risk profile, often faster than your organization is accustomed to assessing.

A Wake-Up Call for Entrepreneurs and CISOs

The digital landscape of organizations has been growing rapidly for years: cloud platforms, SaaS, invoicing and HR systems, data integrations, AI tools. What was once a manageable list of suppliers has now become an ecosystem with dozens, sometimes hundreds, of parties—direct and indirect. With this growth, the chance also increases that you are dependent on a supplier you haven't even labeled as “critical,” while an outage would directly impact business operations or customer processes.

That's why this topic is increasingly moving to the executive boardroom. Not only because of incidents, but also due to questions surrounding digital sovereignty, exit possibilities, and “what if” scenarios. Those who only look at individual puzzle pieces, such as contracts, certificates, an audit report, or a periodic scan, often miss the complete picture: which parties are interconnected, where are the concentration risks, and which change in the supply chain will affect you first?

What NIS2 Requires from Supply Chain Risk Management

In practice, NIS2 doesn't demand more paperwork, but demonstrable control over risks within and through your supply chain. This means, among other things, that you:

  • identifies critical suppliers and dependencies (who is essential and why),
  • implements appropriate security requirements (not only internally, but also towards supply chain partners),
  • structurally organizes supplier risk management (roles, processes, decision-making),
  • and picks up changes and signals faster, such as incidents, deteriorating cyber hygiene, or ownership changes.

The main lesson from the DigiD case is how unexpectedly such changes can occur and how quickly the impact becomes managerially and operationally relevant.

Real-World Scenario: Your Supplier Is Sold “Overnight”

Imagine: one of your critical IT suppliers, for example, your managed service provider, your identity platform, or your core SaaS, is suddenly acquired by a foreign party. Within hours, risks can increase or at least need to be re-evaluated. Consider: data that may fall under different legislation, security agreements that are reinterpreted, and uncertainty about governance or continuity if reorganizations or strategic changes follow.

Without active supplier risk management, you often only hear about this when the news reports it, or if someone internally happens to see a press release. Then you are reactive, and that's exactly where you don't want to be. An effective approach means quickly picking up signals, immediately understanding the potential impact, and having clear reports for management, security, and compliance. Not to panic, but to calmly and factually decide: should we re-contract, impose additional requirements, implement extra monitoring, or activate an exit route?

How RiskStudio Can Support This

1) Overview of your digital ecosystem
RiskStudio helps organizations visualize the entire digital ecosystem: companies, products, dependencies, and also the “shadow layer” behind suppliers. This clarifies who truly can access data and systems, which technology and cloud providers are behind a service, and how dependencies run through your organization. Ownership structures and jurisdiction also become transparent: which laws and regulations might be relevant and which parent companies play a role. So you don't just see individual suppliers, but the whole picture—and that is precisely what is needed to properly understand supply chain risks.

2) Earlier informed about incidents and signals
RiskStudio links cyber intelligence to your supplier landscape. Alerts about data breaches, vulnerabilities, or deteriorating security signals are linked to the relevant organizations, so you immediately see: which supplier is involved here, and where could it affect you? This allows you to prioritize: intervene first where it truly matters. This shifts your stance from “reacting when things go wrong” to “seeing early and acting decisively”—especially important during incidents and changes like acquisitions.

3) Risk-based collaboration towards NIS2, DORA, and ISO 27001
Legislation and standards require a structured, risk-based approach. RiskStudio supports this with risk profiles per supplier, reports for management, auditors, and compliance, and collaboration between departments. Teams can share dependencies, report signals, and use the same facts. This makes supplier risk something you manage together, instead of a topic that only resides with security or procurement and primarily relies on “awareness.”

Conclusion

The DigiD/Solvinity case demonstrates how quickly supply chain risks can arise when ownership and context change. Without an overview and timely signaling, steering is difficult: you discover changes too late, miss impact analysis, and lose valuable time in decision-making. With an approach that combines supply chain overview with continuous intelligence, you can act more calmly and quickly—and work towards NIS2 with greater confidence.

Practical tip: start small but effectively. Take your top 20 most critical suppliers and map out their digital footprint, key dependencies, and ownership structure for each. Build from there, so that the next “overnight change” is no longer a surprise, but a scenario you control.

FAQ

Questions about this analysis

What does this article explain?

The questions and concerns in the House of Representatives regarding the American acquisition of Solvinity, a supplier providing services related to DigiD, make one thing very clear… Read more

How is this analysis connected to current intelligence?

Related signal context is selected from current published reporting using the article subject, content and topic tags.

Where can I find related analysis?

Follow the article tags or return to the analysis archive to browse other reporting on connected subjects.