
For European institutions and international organisations, digital sovereignty raises practical questions. Who controls the technology behind critical services? How easily can an organisation change providers? And what expertise is needed to maintain that freedom of choice?
Cybersecurity is an important part of this discussion. Our sister company ACEN is developing Open Source Cybersecurity-as-a-Service (OCaaS): a platform designed to make open-source security technology accessible to organisations without requiring them to build a fully specialised team and infrastructure themselves.
Open-source technology can give organisations more flexibility in how they build and evolve their security environment. However, selecting tools is only part of the work. Those tools also need to be integrated, maintained and operated by people with the right expertise.
ACEN’s OCaaS initiative aims to address this challenge by bringing together identity and access management, monitoring, detection and vulnerability management in a platform built on open-source technology and operationally managed by ACEN.
The intended model gives organisations greater control over their technology choices and the flexibility to adapt their security environment as their needs evolve, while ACEN provides the operational expertise needed to keep the platform secure and up to date.
At Cronos Europa, we see this development as a useful contribution to the discussion about how European institutions and international organisations can strengthen control over their digital environments.
For organisations considering this approach, several questions deserve attention:
Technology choice: Can individual components be adapted or replaced as requirements evolve?
Data governance: Where is security data processed, who can access it, and under which arrangements?
Operational responsibility: How are responsibilities divided between the organisation and its service provider?
Continuity: How can expertise, configurations and data be transferred if the operating model changes?
Open-source technology can support these objectives, but it requires more than the technology alone. Clear governance, appropriate architecture and reliable operational support are equally important aspects to keep in mind. That's where a managed approach adds value: it helps ensure all of these elements work well together.
ACEN is investing approximately €1 million in the platform’s initial foundations, including €180,000 in support from VLAIO, the Flanders Innovation & Entrepreneurship Agency.
OCaaS is currently under development, with the first pilot projects planned for 2027. ACEN intends to start in the Benelux, followed by expansion into Germany, Austria and Switzerland, with a longer-term ambition to scale across Europe.
For Cronos Europa, the initiative offers a concrete starting point for conversations about open-source cybersecurity and the operational choices behind digital sovereignty. As the platform develops, its relevance for institutional environments will depend on how its capabilities align with each organisation’s security, governance and operational requirements.
Looking for more control and flexibility in your cybersecurity approach? Let’s discuss what this could look like for your organisation.
This article draws on ACEN’s announcement of its OCaaS initiative.