Certificate/Licence number |
Standard/Scheme number or name |
Start Date (YYYY-MM-DD) |
Expiry Date (YYYY-MM-DD) |
ETS 012
|
ETSI EN 319 411-1 |
2010-08-12 |
2025-08-11 |
Scope
On the request of Identiteit & Diensten B.V. (hereafter referred to as: Identiteit & Diensten), the certification audit was performed by BSI Group The Netherlands B.V. (John M. Keynesplein 9, 1066 EP Amsterdam, The Netherlands).
The audit covered applicable requirements taken from the audit criteria listed below under “audit information” and are outlined in Identiteit & Diensten’s Overview of Applicability, dated 13 May 2024.
The scope of the assessment comprised the provision of the following Trust Service Provider component services to the Ministerie van Binnenlandse Zaken en Koninkrijksrelaties, with regard to the Country Signing Certification Authority (CSCA) for the Dutch e-Passport:
- Certificate Generation Service (generating keys and certificates by means of Identiteit & Diensten facilitated key ceremonies) (c)
- Registration Service (registration of users, i.e. devices / Document Signers for identity documents and resident permits of the Kingdom of The Netherlands (c)
- Revocation Management Service (registering, initiating and executing certificate revocations) (c)
- Certificate Status Service (generating certificate status information) (c)
- Subject Device Provision Service (i.e. managing secure devices for storage of key material for Document Signers) (c)
The Dissemination Service (publication of information) has been excluded from the scope of this audit, as this is not performed by Identiteit & Diensten.
The services provided to the Ministerie van Binnenlandse Zaken en Koninkrijksrelaties are related to generating Document Signer certificates and managing the Root Certificate for the Country Signing Certificate Authority (CSCA) for travel documents of the Kingdom of The Netherlands (passport and ID-card including eMRTD), including Document Signer certificates for the resident permit ID-cards of the department Immigratie- en naturalisatiedienst of the Ministerie van Justitie en Veiligheid.
The TSP component services are performed, partly (p) or completely (c) under the responsibility of the ministerie van Binnenlandse Zaken en Koninkrijksrelaties.
These TSP component services are being processed for:
- Issuance of public key certificates (non-qualified trust service), in accordance with the policy: NCP+.
Our certification audit was performed in May 2024. The result of the audit is that we conclude, based on the objective evidence collected during the certification audit, the areas assessed during the audit were generally found to be effective, based on the applicable requirements outlined in the Overview of Applicability, dated 13 May 2024.
Audit information
Audit criteria:
- ETSI EN 319 401 v2.3.1 (2021-05) General Policy Requirements for Trust Service Providers;
- ETSI EN 319 411-1 v1.4.1 (2023-10) Electronic Signatures and Infrastructures (ESI) - Policy and security requirements for Trust Service Providers issuing certificates - Part 1: General requirements, for the policies: NCP+.
Audit performed:
May 2024
Certificate/Licence number |
Standard/Scheme number or name |
Start Date (YYYY-MM-DD) |
Expiry Date (YYYY-MM-DD) |
ETS 014
|
ETSI EN 319 411-2 |
2012-02-20 |
2026-02-18 |
Scope
On the request of Identiteit & Diensten B.V. (hereafter referred to as: ID&D), the annual certification audit on all areas and processes was performed by BSI Group The Netherlands B.V. (John M. Keynesplein 9, 1066 EP Amsterdam, The Netherlands).
The full audit covered all applicable requirements from the audit criteria listed below (see “Audit Information”) and are defined in ID&D’s Statement of Applicability, dated 1 November 2023 and the Overview of Applicability, v1.3. The audit was planned and performed according to the requirements in the ETSI EN 319 403-1 certification scheme.
The scope of the assessment comprised the following Trust Service Provider component services provided to the Human Environment and Transport Inspectorate, an integral part of the Ministry of Infrastructure and Water Management, with regard to the Boordcomputer Taxi:
-,,Subject Device Provision Service
These TSP component services are being provided for the following qualified trust services as defined in EU Regulation 910/2014 (eIDAS):
§,,Issuance of qualified certificates for electronic signatures (qualified trust service), in accordance with the policy: QCP-n-qscd
Our annual certification audit was performed in November 2023. The result of the full audit is that we conclude, based on the objective evidence collected during the surveillance audit for the period from 1 September 2022 through 31 August 2023, the areas assessed during the audit were generally found to be effective, based on the applicable requirements defined in ID&D’s Statement of Applicability, dated 1 November 2023 and the Overview of Applicability, v1.3.
NEW-PAGEAudit information:
Audit criteria:
-,,ETSI EN 319 401 v2.3.1 (2021-05) General Policy Requirements for Trust Service Providers;
-,,ETSI EN 319 411-1 v1.3.1 (2021-05) Electronic Signatures and Infrastructures (ESI) - Policy and security requirements for Trust Service Providers issuing certificates – Part 1: General requirements
-,,ETSI EN 319 411-2 v2.4.1 (2021-11) Electronic Signatures and Infrastructures (ESI) - Policy and security requirements for Trust Service Providers issuing certificates – Part 2: Requirements for trust service providers issuing EU qualified certificates
-,,CA/Browser Forum – Network and Certificate System Security Requirements v1.7
-,,Regulation (EU) N 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC, Chapter III – Trust Services
-,,PKIoverheid - Program of Requirements v4.11, part 3 Basic Requirements, part 3 Additional Requirements and the requirements from part 3a, b and d
-,,
Audit Period of Time:
1 September 2022 – 31 August 2023
Audit performed:
November 2023
Information and Contact:
BSI Group the Netherlands B.V., John M. Keynesplein 9, 1066 EP Amsterdam, NL
Certificate/Licence number |
Standard/Scheme number or name |
Start Date (YYYY-MM-DD) |
Expiry Date (YYYY-MM-DD) |
ETS 042
|
ETSI EN 319 411-1 |
2015-02-19 |
2026-02-18 |
Scope
On the request of Identiteit & Diensten B.V. (hereafter referred to as: ID&D), the annual certification audit on all areas and processes was performed by BSI Group The Netherlands B.V. (John M. Keynesplein 9, 1066 EP Amsterdam, The Netherlands).
The full audit covered all applicable requirements from the audit criteria listed below (see “Audit Information”) and are defined in ID&D’s Statement of Applicability, dated 1 November 2023 and the Overview of Applicability, v1.3. The audit was planned and performed according to the requirements in the ETSI EN 319 403-1 certification scheme.
The scope of the assessment comprised the following Trust Service Provider component services provided to the Human Environment and Transport Inspectorate, an integral part of the Ministry of Infrastructure and Water Management, with regard to the Boordcomputer Taxi:
-,,Subject Device Provision Service
These TSP component services are being provided for the following qualified trust services as defined in EU Regulation 910/2014 (eIDAS):
§,,Issuance of public key certificates (non-qualified trust service), in accordance with the policy: NCP+;
Our annual certification audit was performed in November 2023. The result of the full audit is that we conclude, based on the objective evidence collected during the surveillance audit for the period from 1 September 2022 through 31 August 2023, the areas assessed during the audit were generally found to be effective, based on the applicable requirements defined in ID&D’s Statement of Applicability, dated 1 November 2023 and the Overview of Applicability, v1.3.
NEW-PAGE
Audit information:
Audit criteria:
- ETSI EN 319 401 v2.3.1 (2021-05) General Policy Requirements for Trust Service Providers;
- ETSI EN 319 411-1 v1.3.1 (2021-05) Electronic Signatures and Infrastructures (ESI) - Policy and security requirements for Trust Service Providers issuing certificates – Part 1: General requirements
- ETSI EN 319 411-2 v2.4.1 (2021-11) Electronic Signatures and Infrastructures (ESI) - Policy and security requirements for Trust Service Providers issuing certificates – Part 2: Requirements for trust service providers issuing EU qualified certificates
- CA/Browser Forum – Network and Certificate System Security Requirements v1.7
- Regulation (EU) N 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC, Chapter III – Trust Services
- PKIoverheid - Program of Requirements v4.11, part 3 Basic Requirements, part 3 Additional Requirements and the requirements from part 3a, b and d
Audit Period of Time:
1 September 2022 – 31 August 2023
Audit performed:
November 2023
Information and Contact:
BSI Group the Netherlands B.V., John M. Keynesplein 9, 1066 EP Amsterdam, NL
Certificate/Licence number |
Standard/Scheme number or name |
Start Date (YYYY-MM-DD) |
Expiry Date (YYYY-MM-DD) |
ETS 069
|
ETSI EN 319 411-1 |
2021-01-27 |
2025-01-26 |
Scope
On the request of Identiteit & Diensten B.V., the certification audit was performed by BSI Group The Netherlands B.V. (John M. Keynesplein 9, 1066 EP Amsterdam, The Netherlands).
The audit covered all applicable requirements from the audit criteria listed below and are defined in the Identiteit & Diensten Statement of Applicability, dated 30 August 2023 and the Overview of Applicability, version 1.6-RC1, dated 9 March 2022.
The scope of the assessment comprises the provision of the following Trust Service Provider component services to the ministerie van Binnenlandse Zaken en Koninkrijksrelaties, with regard to the Polymorphic eMRTD PKI for the Dutch e-Passport:
-,,Registration Service (registration of users, i.e. DVCA, IS)
-,,Certificate Generation Service (generating keys and certificates by means of facilitated key ceremonies). The Country Verifying Certification Authority (Root) is used to generate certificates for the Document Verifier Certification Authority (DVCA). The DVCA will generate Inspection system (IS) certificates)
-,,Dissemination Service (publication of information and distribution of certificates)
The Revocation Management Service, the Revocation Status Service and the Subject Device Provision Service are not applicable to this Polymorphic eMRTD PKI and are therefore excluded from the scope
The TSP component services are performed, partly or completely under the responsibility of the ministerie van Binnenlandse Zaken en Koninkrijksrelaties.
These TSP component services are being processed for:
-,,Issuance of public key certificates (non-qualified trust service), in accordance with the policy: NCP+.
The Certification Authority processes and services are documented in the following document:
-,,Certificate Practice Statement CVCA/DVCA Polymorphic eMRTD, v1.2, dated: 18 February 2022.
Our certification audit was performed in September 2023. The result of the audit is that we conclude, based on the objective evidence collected during the certification audit, the areas assessed during the audit were generally found to be effective, based on the applicable requirements defined in the Identiteit & Diensten Statement of Applicability, dated 30 August 2023 and the Overview of Applicability, version 1.6-RC1, dated 9 March 2022.
Audit criteria:
-,,ETSI EN 319 401 v2.3.1 (2021-05) General Policy Requirements for Trust Service Providers
-,,ETSI EN 319 411-1 v1.3.1 (2021-05) Electronic Signatures and Infrastructures (ESI) - Policy and security requirements for Trust Service Providers issuing certificates - Part 1: General requirements, for the policy: NCP+.
Audit performed:
September 2023
Information and Contact:
BSI Group The Netherlands B.V., John M. Keynesplein 9, 1066 EP Amsterdam, NL
Certificate/Licence number |
Standard/Scheme number or name |
Start Date (YYYY-MM-DD) |
Expiry Date (YYYY-MM-DD) |
ISC 552
|
ISO/IEC 27001:2013 |
2017-06-06 |
2025-10-31 |
Scope
The management of information security applies to the following products and services: design, develop, produce, deploy, deliver and support of identity solutions including production and printing of secure documents.
Het ontwikkelen, testen en distribueren van maatwerksoftware voor IT systemen alsmede het onderhouden van hardware en standaard- en maatwerksoftware en het verlenen van ondersteuning aan gebruikers van deze hardware en software; het ontwerpen, ontwikkelen, produceren, personaliseren en distribueren van beveiligde documenten.