PKIoverheid
PKIoverheid is the Dutch government PKI (Logius, PvE), used for Digikoppeling, DigiD authentication, and qualified digital signatures and seals.
PKIoverheid is the Dutch government's PKI hierarchy, used for certificates that require trust anchored specifically in the Dutch state rather than a generic commercial root. It is governed by the Policy Authority PKIoverheid, managed by Logius, under a Programme of Requirements (PvE) that participating certificate authorities must follow. Its ultimate root is Staat der Nederlanden, and certificate authorities operate beneath this root under domains for specific purposes, including Burger, Organisatie, Autonome Apparaten, and Private Services. The Private Services domain uses its own Staat der Nederlanden Private Root CA rather than chaining to the public Staat der Nederlanden root, and is intended for closed, non-public environments rather than publicly trusted websites. Logius stopped issuing publicly trusted server certificates for websites on 4 December 2022, after the EV Root CA it relied on for that purpose expired and was not replaced; organisations that need browser-trusted TLS must use a commercial certificate instead. A new generation of PKIoverheid certificates based on G4 roots began rolling out on 28 November 2024, with each G4 certificate issued for a single purpose only; the older G3(+) and G1 Private roots remain valid until November 2028 at the latest.
Cleverbase operates as a certificate authority beneath the PKIoverheid hierarchy, issuing certificates within its rules and audit regime. This sits alongside Cleverbase's role as a QTSP under eIDAS, giving organisations access to both government-anchored and EU-wide trust frameworks depending on what a given use case requires.