Regulation

PKIoverheid certificates for SBR filing: what is required

Filing via SBR requires a PKIoverheid services certificate alongside the software. Which type it is, who needs one and where it is requested.

For controllers and reporting teams filing via SBR for the first time who still have the certificate to arrange

Reporting software alone does not get financial statements to the Dutch Chamber of Commerce. Sending the filing also requires a digital certificate. The KvK states it plainly: besides the software, a PKIoverheid certificate is needed to send the financial statements (opens in a new tab). It is the step teams filing digitally for the first time most often miss, because it sits outside the reporting software and has a request process of its own.

Who needs a certificate

The requirement applies to legal entities in the medium-sized and large size classes. Micro and small entities file via SBR without a certificate of their own. Anyone still establishing which class applies will find the criteria in filing annual accounts with the KvK: the first mandatory filings.

Which certificate it is

Connecting to Digipoort, the channel SBR filings travel through, requires a PKIoverheid services certificate at the highest assurance level (opens in a new tab). The certificate identifies the sending system, not a person. It is therefore neither an eHerkenning means nor a personal signature, and it is not interchangeable with certificates already in use for other government services.

A services certificate is valid for three years and must be requested again after that. An expired certificate blocks the filing, including in the middle of a reporting cycle.

Where it is requested

PKIoverheid certificates are not issued by Logius itself. Accredited trust service providers do that; the current list is available at Logius, under requesting a PKIoverheid certificate (opens in a new tab).

The cost sits with the filing party. The KvK names both the software package and the certificate as the filer’s own expense, and points to the software supplier for the practical side.

Two routes to a valid filing

Own certificate. The legal entity requests a services certificate itself and the reporting software sends through it. This is the route for organisations that want the filing entirely in their own hands, and for groups already managing a certificate for other reasons.

Filing through the supplier. The filing travels through the certificate of the party supplying the software, and the legal entity requests nothing. That removes a request process from the schedule, which counts when the first mandatory filing falls in the same cycle.

Which route fits depends on how many entities file and on what is already in place. An organisation that already sends tax returns via SBR may hold a suitable certificate already. That is the first thing to check, before starting a new request.

What to do now

  • Establish which size class the legal entity falls into, and whether the certificate requirement therefore applies.
  • Check whether a PKIoverheid services certificate is already in use within the organisation, and how long it remains valid.
  • Choose a route before the reporting cycle starts, not during the closing weeks.
  • Put the certificate’s expiry date in the reporting calendar, not only in the administrator’s.

How Taxxor does this

Taxxor supports both routes. Customers managing a services certificate themselves send through it from Taxxor Disclosure Manager to Digipoort. Customers who would rather not set that up have the filing travel through Taxxor’s certificate. Which route applies is a configuration choice, not a property of the platform. Either way the filing leaves the platform as a validated package, checked against the taxonomy that applies. Which format belongs to which obligation is covered in XBRL, iXBRL or SBR Report Package: which do you choose when?.