quality & security
Quality & security

Our certifications and accreditations speak for themselves.

Schedule a meeting

ISO 27001

Information security management. International standard for managing information security. Renewed in May 2024.

NEN 7510

Information security in healthcare. Dutch standard for information security at healthcare organisations. Renewed in May 2024.

ISAE 3402 Type II

Service organisation controls. Independent assessment of the design and operating effectiveness of controls. Obtained in July 2024.

information security
Information security and control

eConnect demonstrably operates according to recognised standards for information security and service organisation control. All certifications are renewed annually by independent auditors.

audits
Continuously assessed

Independent auditors review our certifications annually. Periodic independent penetration tests keep the security profile current, and internal controls provide conclusive evidence for clients with stringent governance requirements.

Peppol Certified

Access Point Certified Provider. Certified by the Dutch Peppol Authority. eConnect operates multiple redundant Access Points with automatic load distribution for maximum reliability.

OASIS SMP

SMP Compliant. One of the very few OASIS SMP-compliant solutions worldwide. All compliance tests passed.

DICO

Construction sector certified. Certified for the DICO standard, specifically for the construction sector. Support for G-account, reverse charge VAT and chain liability.

Read more
peppol and sector
Peppol and sector standards

Beyond information security, we are explicitly certified for the standards that affect our field on a daily basis: Peppol transport, OASIS SMP and sector-specific exchange.

AspectDetailCloud hostingData centres in the Netherlands, Ireland and Western Europe (within the EU/EEA)Data residencyAll processing within the EU/EEAUptimestatus pagePSB maintenanceNo maintenance window; rolling upgrades without downtimePlatform maintenanceSaturday 02:00-08:00 (outside business hours)EncryptionTLS in transit, AES at rest
hosting
Hosting and data

All processing takes place within the EU/EEA with encryption in transit and at rest. The cloud binding per service is documented so that data residency remains transparent.

Co-founder NPa

Co-founder of the Dutch Peppol Authority and involved in establishing Dutch Peppol governance.

OpenPeppol board member

Actively involved in international standards development as a member of the OpenPeppol board.

E-return initiative

In 2021, member of the frontrunner group for status messages, commissioned by the Dutch Ministry of the Interior.

FD Gazellen

Twice recognised as one of the fastest-growing companies in the Netherlands (2024, 2025).

standards development
Standards development

eConnect is not just a user of Peppol standards but a co-developer. Our involvement in standards development ensures that changes in the chain are visible and tested early.

Frequently asked questions
Why are certifications important when choosing an e-invoicing provider?

Certifications are important because they objectively demonstrate that a provider has structurally implemented security and control. With e-invoicing, you process financial and organisational data that falls under internal control frameworks and often also under sector-specific requirements, making trust alone insufficient. Standards such as ISO 27001, NEN 7510 and ISAE 3402 provide assurance, because an independent party verifies that processes, measures and responsibilities are demonstrably in order. For many organisations, this is not an added luxury but a prerequisite for approval by security, finance and audit.

With certified processing, it also becomes easier to demonstrate to your accountant, regulator and internal compliance why you chose a particular chain partner. In practice, this often accelerates the implementation process, as less discussion is needed about baseline security and governance. eConnect combines these certifications with annual independent assessment, ensuring the status remains current rather than frozen at a single point in time. Read more about our positioning and background in Our story.

How does eConnect protect my data?

eConnect protects data with a combination of technical security, process control and independent assessment. All processing takes place within the EU/EEA on cloud infrastructure in the Netherlands, Ireland and Western Europe, with encrypted communication and encrypted storage as standard. This limits risks around transport, storage and unauthorised access within the processing chain. For organisations with higher requirements, it is particularly relevant that security is not only implemented as technology but also demonstrably as a management process.

Annual penetration tests help identify vulnerabilities early and resolve them in a controlled manner before they have operational impact. The ISAE 3402 Type II certification confirms that controls are not only designed but also work in practice over an extended measurement period. Combined with ISO 27001 and NEN 7510, this creates a solid foundation for organisations working with privacy-sensitive or business-critical invoice flows that are periodically assessed. For current availability and service information, see the status page.

What makes eConnect different from other Peppol providers in terms of security?

The difference lies mainly in the breadth of the security profile and the combination of certifications that are simultaneously active. ISO 27001, NEN 7510 and ISAE 3402 Type II complement each other in management system, sector-specific information security and demonstrable operational control, which for many organisations carries more weight than a single certificate. This makes eConnect suitable for environments where IT security, audit and governance all weigh heavily in vendor selection. Especially for government and healthcare-related flows, this combination provides additional clarity.

Add to this the involvement in the Peppol ecosystem as co-founder of the Dutch Peppol Authority and board member of OpenPeppol, which means developments around standards and requirements become visible early. For sectors with specific process standards, such as construction, the DICO certification aligns as an additional layer. Annual penetration tests and periodic audits then ensure that security remains a continuous process rather than a one-time check. For further context, read Our story.

Is eConnect suitable for healthcare organisations?

Yes, eConnect is suitable for healthcare organisations thanks to the combination of NEN 7510, ISO 27001 and ISAE 3402 Type II. NEN 7510 is specifically relevant for information security in healthcare and aligns with the requirements that healthcare organisations often apply when selecting vendors in financial and administrative chains. This gives you a demonstrable framework that is applicable both operationally and from a compliance perspective. The renewal of the NEN 7510 certification in May 2024 confirms that this framework is actively maintained.

Beyond certification, the processing environment is also relevant, with data handling within the EU/EEA and encryption in transit and at rest. For healthcare organisations, this helps to better substantiate to internal auditors, external accountants and regulators how the invoicing process is secured. This combines practical usability with demonstrable governance, which in healthcare contexts is often a decisive factor. For sector-specific alignment, get in touch via Contact.

Can I request a pentest report or security documentation?

Yes, you can request security documentation, with a distinction between management information and full detailed reports. eConnect commissions annual independent penetration tests and offers a periodic management summary of pentest results through the Compliance & Security Reports subscription, supplemented with relevant reports such as ISO 27001 and ISAE 3402. This gives many organisations sufficient information for internal reviews, vendor assessments and recurring compliance checks. This way you can keep your file current without having to process all technical details directly.

For enterprise situations, the full pentest report can become part of contractual agreements, so that depth matches the risk profile and governance requirements of your organisation. This approach prevents sensitive information from being broadly shared by default, while clients with more stringent obligations can still receive appropriate insight. Certificates for ISO 27001 and NEN 7510 are also publicly available through the audit organisation and align with your broader compliance file. Discuss the appropriate reporting format via Contact.

Want to know more about our certifications and accreditations? Get in touch.

Get in touch

Ask Cora

Ask Cora