Certificates and supporting information for your review of Ver.iD. Our information security certificates are held by Subst.iD B.V., trading as Ver.iD.
Our certifications
CERCOMS has certified our information security management system. The scope covers software development, management and maintenance, in accordance with the relevant Statements of Applicability.
ISO/IEC 27001:2022/Amd1:2024
Current
Development, management and maintenance of software, in accordance with the Statement of Applicability dated 12 March 2026.
Information security relating to the development, management and maintenance of software, in accordance with the Statement of Applicability dated 22 January 2025.
Both PDFs contain two pages. The ISO 27001 certificate is in English; the NEN 7510 certificate is in Dutch.
These management system certificates do not establish that every product, client application or individual trust service is qualified. Always consider the certificate’s scope and the requirements of your use case.
Assessments and available information
Certificates, internal risk assessments and legal requirements answer different questions. The following information distinguishes available evidence from assessments still in progress.
DPIA: internal privacy risk assessment
The 2024 DPIA is maintained internally and reviewed annually. It assesses privacy risks in our processing. No public DPIA report is offered on this page; it is not an independent certification.
Ver.iD is assessing whether to pursue a SOC 2 examination. No Type I or Type II examination is scheduled and no SOC 2 report is available. SOC 2 produces an assurance report, not a certificate.
We are examining how our controls, contracts and evidence support the DORA requirements of financial clients. This includes incident support, continuity, supplier information and service termination. ISO 27001 and NEN 7510 provide a foundation, but not a DORA certification. Specific obligations follow from the applicable agreements.
Ver.iD is assessing whether the organisation falls within NIS2’s scope and which requirements apply. No NIS2 compliance status has been established. An ongoing assessment does not mean that all requirements have been met.
Our documentation identifies Statements of Applicability and Audit Fact Reports as available on request. Tell us what information you need for your review. You can open the certificates above directly.
Read the privacy policy for personal data processing and the service agreement for the terms of our services. The original legal texts are available in English.