Summary
The core message of the available session transcript is that Dutch strength in cryptographic research and production does not automatically translate into strategic autonomy or sufficient supply for government and industry needs. Tommy van der Vorst opened by framing cryptography as a foundational ingredient for everyday Internet services, jobs, and vital systems, while stressing the need for access to cryptography even in scenarios where the Netherlands cannot rely on current foreign sources. The session positioned a Dialogic study on strategic dependencies as the analytical basis for understanding the gap between Dutch cryptographic capability and the ability to meet demand, followed by a planned explanation from Tony van der Togt on the National Cryptography Strategy.
Guido de Moor then introduced the Dutch cryptographic ecosystem, identifying four foundations: knowledge institutions conducting fundamental cryptographic research, cryptographic producers, certification bodies and testing labs, and government stakeholders such as the Ministry of Defense and intelligence services. He noted that the Netherlands is one of the few crypto-producing nations in the UN and NATO context, with research strengths in places such as Nijmegen, Eindhoven, Delft, Maastricht, TNO, and nearby Belgian institutions. However, he also highlighted the paradox found in reports including TNO’s: the current ecosystem does not adequately meet long-term requirements of government and industry, especially for high-assurance cryptography and for maintaining long-term business cases that enable development of new technologies such as post-quantum cryptography.
The presentation then scoped the cryptographic market into three segments: high assurance, generic, and a middle segment. High assurance covers products and services used for state secrets and similar sensitive use cases, where cryptography is the main element and everything must be tested, evaluated, and certified. Generic cryptography appears in everyday applications such as phones. The middle segment, which the research deliberately emphasized, contains high-quality cryptography for wider applications just below high assurance, including departmental confidential uses. Guido explained that this middle segment matters strategically because high-assurance suppliers might scale by addressing it, but dependencies there become more complex because cryptography is embedded in broader hardware, products, and services.
The dependency framework moved from identifying import dependence, to asking whether the product safeguards Dutch or European public interests, and finally to determining whether there is a risk of supply interruption. Only when all three conditions are present does a high-risk strategic dependency exist. In the results discussed before the transcript truncates, the middle segment emerged as particularly important: dependency risks are more diffuse, products are harder to replace, and demand depends heavily on awareness and urgency among users in vital sectors. A key conclusion was that the Netherlands has excellent academic capability, but that academic strength alone does not reduce national dependency unless it is connected to demand, supply, certification, human capital, and strategic market development.
Key Topics
5 key topics from Tommy van der Vorst, Guido de Moor and Tony van der Togt at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Map cryptographic dependencies before assessing strategic risk.
- Strengthen demand signals for high-assurance Dutch cryptography.
- Use the middle segment to scale specialist suppliers.
- Invest in user-side cryptography awareness and expertise.
- Connect academic excellence to deployable certified products.
“our academic position, so based on the knowledge institutes, is actually quite excellent, but that does not automatically reduce our dependencies as a country”
Up Next

Next in agenda
Navigating the Grey Zone: Cyber Resilience and National Security in the Age of new technologies
Marc Kuipers

Also on cryptography
PQC: Who owns cryptography? When decisions outgrow IT

Also on cybersecurity
Squaring the Circle: Lawful Access to Encrypted Data while preserving Cyber Security
Otmar Lendl