Programme of Requirements (PoR)
The Programme of Requirements (PoR) sets the binding rules every provider must follow to issue certificates in the Dutch PKIoverheid hierarchy.
The Programme of Requirements (Programma van Eisen, PvE) is the binding set of documents that lays down what a party must do before it may issue certificates within the PKIoverheid hierarchy, the Dutch government's own PKI. It is maintained by the Policy Authority PKIoverheid, the body responsible for setting and enforcing PKIoverheid policy, and applies to every accredited Trust Service Provider (TSP) that operates under a PKIoverheid root, whatever the certificates are used for.
Until version v4.12, effective 15 January 2024, the Programme of Requirements was split into numbered parts, each covering a separate obligation. That version unified them into a single document, though the underlying topics still make up its main sections:
- general requirements: baseline governance, security and audit rules that apply across the whole hierarchy, including the accreditation of TSPs and the Policy Authority's ongoing oversight of them
- Certificate Policies: a Certificate Policy for authenticity, confidentiality and non-repudiation certificates for Organisation Services, alongside separate policies for other certificate domains such as personal and server certificates
- definitions and abbreviations: a shared glossary of the terms the other sections rely on
A TSP's own CP/CPS does not replace the Programme of Requirements; it implements it. The obligations of the TSPs that are part of the government PKI are specified in the Programme of Requirements' Certificate Policies section.
The Policy Authority revises the document from time to time, and each revision carries its own version number and effective date. Since the parts were unified, two further changes stand out:
- version v4.12 replaced the earlier term Certificate Service Provider (CSP) with Trust Service Provider (TSP), in line with eIDAS terminology
- version v5.4, effective 1 July 2026 and the current version, folds the former G3 TRIAL hierarchy into the main structure
Note: The Programme of Requirements only governs the PKIoverheid hierarchy. A qualified certificate anchored instead in a QTSP's own root on the EU Trusted List follows that provider's own CP/CPS, not the Programme of Requirements.