TechnologyFlanders
Cybersecurity setback

Can Antwerp recover the time lost after cancelling its €100 million cyber contract?

Antwerp has terminated its six-year cybersecurity agreement with Eviden, a contract valued at more than €100 million, after concluding that the French-owned IT provider was not delivering the promised work.

Belgium Impulse Editorial·27 August 2026·4 min read·
Well established· 1 primary source + 4 official documents + 1 independent reporting source

In 30 seconds

  • Antwerp formally terminated the Eviden agreement on 3 December 2025.
  • Atos Benelux valued Eviden's portion of the programme at more than €100 million.
  • The wider Project Versterking cybersecurity budget totalled €219 million.
  • Antwerp is claiming more than €3.8 million in damages; Eviden has counterclaimed.

Antwerp has cancelled a six-year cybersecurity contract worth more than €100 million with Eviden and is now looking for another private partner to help protect city services, the OCMW social-welfare administration and local police systems. The city formally terminated the agreement on 3 December 2025, but the scale of the dispute and earlier internal warnings were detailed in reporting published in August 2026 by Het Nieuwsblad and Gazet van Antwerpen. A court case is under way: Antwerp wants its paid invoices returned and is claiming more than €3.8 million in damages, while Eviden has filed a counterclaim.

For people who depend on Antwerp’s digital services, this is more than a procurement quarrel. The contract formed a central part of Project Versterking, the city’s €219 million programme to rebuild its cyber defences after the December 2022 attack that disrupted permits, swimming pools, waste-access cards and other public services for months. According to Het Nieuwsblad, Eviden was expected to help secure and maintain about 60% of the city’s applications. Digitalisation alderman and Digipolis chairman Ken Casier, of the N-VA, acknowledged that “we have certainly lost time”, although he said an interim assessment showed that the city remained on course for critical work.

The break followed months of escalation. Antwerp concluded in October 2025 that Eviden was failing to provide what its offer had promised despite repeated attempts to correct the programme, according to Belga reporting carried by Het Nieuwsblad. The city ended the relationship in December. Eviden, a subsidiary of France’s Atos group, maintains that it fulfilled its contractual obligations and says there was no factual or rational basis for cancelling the agreement. It has declined detailed public comment while litigation continues.

Documents reported by Gazet van Antwerpen add an uncomfortable layer. Antwerp’s Data Protection Officer had already described elements of the planned reinforcement operation as problematic in its 2024 annual report, before Eviden began work. The watchdog reportedly identified insufficient communication and control by city services and missing data-processing agreements between Atos Eviden and participating entities. A later multi-year plan for Antwerp’s municipal education network said missed objectives and deadlines were obstructing the city’s 2025-2031 cyber strategy.

Those findings support two competing readings. Casier’s position is that ending a contract that was not producing the required result protects the city and that the most critical systems can still meet Antwerp’s April 2027 target. Eviden’s position is that it performed correctly and that the cancellation lacks proper grounds. The court, rather than either party’s public account, will have to determine contractual responsibility and any financial settlement.

The European context matters, but it does not turn this municipal dispute into an EU case. Belgium transposed the NIS2 Directive in 2024, strengthening risk-management, incident-reporting and oversight duties for covered organisations. The Centre for Cybersecurity Belgium stresses that local authorities are not automatically subject to NIS2 merely because they are municipalities, although they can fall within the law through particular essential services, their size or formal designation. Antwerp’s April 2027 deadline therefore appears to be an operational target connected to its own compliance programme, not the general EU transposition deadline.

Still, Antwerp’s difficulties illustrate the wider problem Brussels and other European capitals are trying to solve: cyber resilience depends not only on buying technology but also on managing suppliers, contracts, data-processing responsibilities and institutional oversight. The EU Agency for Cybersecurity reported in 2025 that public administration was the Union’s most frequently targeted sector in its latest threat data and remained in a cybersecurity “risk zone”. EU institutions consequently emphasise supply-chain security and cybersecurity requirements in public procurement.

Antwerp must now decide which responsibilities remain with Digipolis and which will be offered to a replacement supplier, possibly under a narrower contract. The city has not disclosed how much it paid Eviden, when a successor will be appointed or what interim measures cover unfinished work. Those unanswered questions—and the court’s eventual assessment of the rival claims—will determine whether this episode becomes a contained contracting failure or another costly delay in repairing the weaknesses exposed in 2022.

Context & what happens next

What to do

Residents do not need to take a specific action because of the cancellation. They should continue using official Antwerp channels, follow normal cyber-hygiene guidance and remain alert to phishing messages exploiting concern about city services.

Impact

Regional — The immediate impact falls on Antwerp's municipal administration, OCMW, local police, education network and other organisations supported by Digipolis. The case may also prompt Flemish authorities to examine how large cybersecurity assignments are awarded through regional framework contracts.

Evidence
Well established · 1 primary source + 4 official documents + 1 independent reporting source
Explore evidence
Het Nieuwsblad — Stad Antwerpen zegt megacontract voor cyberbeveiliging van 100 miljoen euro op
Published:
21 Aug 2026, 02:00
Retrieved by ODIN:
23 Aug 2026
Read original
Het Nieuwsblad/Belga — Antwerpen verbreekt cyberbeveiligingscontract van meer dan 100 miljoen euro
Published:
1 Aug 2026, 02:00
Retrieved by ODIN:
23 Aug 2026
Read original
Centre for Cybersecurity Belgium — NIS2 FAQ for the public sector
Published:
1 Feb 2025, 01:00
Retrieved by ODIN:
23 Aug 2026
Read original
Centre for Cybersecurity Belgium — NIS2
Publication date unavailable
Retrieved by ODIN:
23 Aug 2026
Read original
ENISA — Public administration increasingly targeted by DDoS attacks
Published:
6 Nov 2025, 01:00
Retrieved by ODIN:
23 Aug 2026
Read original
European Commission — NIS2 Directive: securing network and information systems
Publication date unavailable
Retrieved by ODIN:
23 Aug 2026
Read original

Continue reading

Powered by ODIN™An Ordinis creation · © 2026 Ordinis

This story was assembled from verified evidence, with its sources and reasoning recorded as it was written.

methodology.