Our certifications and accreditations speak for themselves.
Schedule a meeting
Information security management. International standard for managing information security. Renewed in May 2024.
Information security in healthcare. Dutch standard for information security at healthcare organisations. Renewed in May 2024.
Service organisation controls. Independent assessment of the design and operating effectiveness of controls. Obtained in July 2024.
eConnect demonstrably operates according to recognised standards for information security and service organisation control. All certifications are renewed annually by independent auditors.
Independent auditors review our certifications annually. Periodic independent penetration tests keep the security profile current, and internal controls provide conclusive evidence for clients with stringent governance requirements.
Access Point Certified Provider. Certified by the Dutch Peppol Authority. eConnect operates multiple redundant Access Points with automatic load distribution for maximum reliability.
SMP Compliant. One of the very few OASIS SMP-compliant solutions worldwide. All compliance tests passed.
Construction sector certified. Certified for the DICO standard, specifically for the construction sector. Support for G-account, reverse charge VAT and chain liability.
Beyond information security, we are explicitly certified for the standards that affect our field on a daily basis: Peppol transport, OASIS SMP and sector-specific exchange.
All processing takes place within the EU/EEA with encryption in transit and at rest. The cloud binding per service is documented so that data residency remains transparent.
Co-founder of the Dutch Peppol Authority and involved in establishing Dutch Peppol governance.
Actively involved in international standards development as a member of the OpenPeppol board.
In 2021, member of the frontrunner group for status messages, commissioned by the Dutch Ministry of the Interior.
Twice recognised as one of the fastest-growing companies in the Netherlands (2024, 2025).
eConnect is not just a user of Peppol standards but a co-developer. Our involvement in standards development ensures that changes in the chain are visible and tested early.
Certifications are important because they objectively demonstrate that a provider has structurally implemented security and control. With e-invoicing, you process financial and organisational data that falls under internal control frameworks and often also under sector-specific requirements, making trust alone insufficient. Standards such as ISO 27001, NEN 7510 and ISAE 3402 provide assurance, because an independent party verifies that processes, measures and responsibilities are demonstrably in order. For many organisations, this is not an added luxury but a prerequisite for approval by security, finance and audit.
With certified processing, it also becomes easier to demonstrate to your accountant, regulator and internal compliance why you chose a particular chain partner. In practice, this often accelerates the implementation process, as less discussion is needed about baseline security and governance. eConnect combines these certifications with annual independent assessment, ensuring the status remains current rather than frozen at a single point in time. Read more about our positioning and background in Our story.
eConnect protects data with a combination of technical security, process control and independent assessment. All processing takes place within the EU/EEA on cloud infrastructure in the Netherlands, Ireland and Western Europe, with encrypted communication and encrypted storage as standard. This limits risks around transport, storage and unauthorised access within the processing chain. For organisations with higher requirements, it is particularly relevant that security is not only implemented as technology but also demonstrably as a management process.
Annual penetration tests help identify vulnerabilities early and resolve them in a controlled manner before they have operational impact. The ISAE 3402 Type II certification confirms that controls are not only designed but also work in practice over an extended measurement period. Combined with ISO 27001 and NEN 7510, this creates a solid foundation for organisations working with privacy-sensitive or business-critical invoice flows that are periodically assessed. For current availability and service information, see the status page.
The difference lies mainly in the breadth of the security profile and the combination of certifications that are simultaneously active. ISO 27001, NEN 7510 and ISAE 3402 Type II complement each other in management system, sector-specific information security and demonstrable operational control, which for many organisations carries more weight than a single certificate. This makes eConnect suitable for environments where IT security, audit and governance all weigh heavily in vendor selection. Especially for government and healthcare-related flows, this combination provides additional clarity.
Add to this the involvement in the Peppol ecosystem as co-founder of the Dutch Peppol Authority and board member of OpenPeppol, which means developments around standards and requirements become visible early. For sectors with specific process standards, such as construction, the DICO certification aligns as an additional layer. Annual penetration tests and periodic audits then ensure that security remains a continuous process rather than a one-time check. For further context, read Our story.
Yes, eConnect is suitable for healthcare organisations thanks to the combination of NEN 7510, ISO 27001 and ISAE 3402 Type II. NEN 7510 is specifically relevant for information security in healthcare and aligns with the requirements that healthcare organisations often apply when selecting vendors in financial and administrative chains. This gives you a demonstrable framework that is applicable both operationally and from a compliance perspective. The renewal of the NEN 7510 certification in May 2024 confirms that this framework is actively maintained.
Beyond certification, the processing environment is also relevant, with data handling within the EU/EEA and encryption in transit and at rest. For healthcare organisations, this helps to better substantiate to internal auditors, external accountants and regulators how the invoicing process is secured. This combines practical usability with demonstrable governance, which in healthcare contexts is often a decisive factor. For sector-specific alignment, get in touch via Contact.
Yes, you can request security documentation, with a distinction between management information and full detailed reports. eConnect commissions annual independent penetration tests and offers a periodic management summary of pentest results through the Compliance & Security Reports subscription, supplemented with relevant reports such as ISO 27001 and ISAE 3402. This gives many organisations sufficient information for internal reviews, vendor assessments and recurring compliance checks. This way you can keep your file current without having to process all technical details directly.
For enterprise situations, the full pentest report can become part of contractual agreements, so that depth matches the risk profile and governance requirements of your organisation. This approach prevents sensitive information from being broadly shared by default, while clients with more stringent obligations can still receive appropriate insight. Certificates for ISO 27001 and NEN 7510 are also publicly available through the audit organisation and align with your broader compliance file. Discuss the appropriate reporting format via Contact.
Get in touch
Ask Cora
Ask Cora