Service · Web development

Custom certification portal development.

A custom portal for trade associations, professional bodies, quality marks, training institutes and certification bodies that issue certificates, coordinate audits and supervise members. From application and verification to issuing with a QR code, a public register, renewals and a revocation flow — set up around the rules of your scheme, not those of a generic package.

Registration & verificationExamination & audit plannerMultiple reviewerseIDAS QESPublic registerComplaints & revocation

A certification portal is not a form tool with a PDF export.

Those who issue certificates rely on one thing above all: trust. A certificate stands or falls with the credibility of its issuer — and that credibility depends largely on the system underneath. How is it established that an applicant genuinely meets the requirements? Who assessed them, when, and on what grounds? Can a client check for themselves that a certificate is still valid tomorrow? A certification portal manages that entire chain, so the issuing organisation can focus on the substance.

That differs fundamentally from a general web application: a certification portal links the application to an exam or audit, the assessment process to multiple independent reviewers, the outcome to a legally valid issuance, and the certificate to a searchable register. The scheme you operate, whether it is professional certification, a quality mark, an educational certificate or an ISO management system, is the driving force behind the configuration.

We build custom portals for organisations for whom an off-the-shelf package is either too broad or too narrow: an industry body that issues its professional certification and wants to retain control; a quality mark that coordinates audits of its members; an education institute that handles formal diploma recognition; a certification bureau that wants to move its client portal away from an outdated Access environment. We start from the scheme and the rules of your profession, not from a feature list.

Three levels of certification portal.

The right level depends on your issuance volume, the number of assessors, the severity of compliance requirements (eIDAS, GDPR, accreditation requirements), and the extent to which the system also needs to invoice, integrate and publish. We advise on this during the initial conversation.

Compact project · fixed sprint budget

Application and issuance portal

A focused portal for a single scheme: candidates or companies register, upload supporting evidence, pay exam or audit fees and, after assessment, receive a digital certificate with a QR code. A simple assessor workspace and a simple public register. Enough to escape from Excel lists and loose PDF certificates.

ApplicationPaymentIssuance with QRPublic register
Mid-sized project · fixed sprint budget

Scheme-driven certification platform

The rules of your scheme built in: multiple certificates per person or company, exam and audit scheduling, assessment by multiple independent reviewers with conflict detection, renewal cycles with automatic reminders, a complaints and revocation workflow, and a public register on which a client can rely with a single click.

Multiple reviewersAudit plannerRenewalsRevocation workflow
Larger project · fixed sprint budget

Multi-scheme platform with deep integration

Mission-critical portal for organisations that manage multiple schemes in parallel. Separate scheme data per scheme owner, client portals in your own branding, and integrations with accounting, PSPs, e-signature providers, accreditation bodies and webhook APIs for external registers. Includes eIDAS QES, an anchored integrity hash for public verifiability and a formal handover of management to your IT team.

If you manage amusement or play equipment, each unit carries its own certificate and file. That is what the page on inspection file software for amusement equipment is about.

Multi-schemeeIDAS QESWebhook APIAnchored integrity

What a custom certification portal minimally includes.

Regardless of level, we deliver a number of core components as standalone modules, so that you can later scale from a single scheme to a platform without redrawing your architecture.

  • Scheme engine as a first-class componentWe define schemes as configuration: requirements, evidence, scoring rules, validity period and renewal conditions. A scheme administrator can adjust requirements or publish a new version without a release; every version is traceable in the audit trail. Builds on our approach to workflow software.
  • Registration with identity verificationApplicants register through a wizard tailored to the scheme. Identification via iDIN, DigiD, eHerkenning, KvK verification or passport upload with OCR checking. For educational certificates, an integration with the BRP or DUO; for professional certification, a match against earlier registrations.
  • Payment and invoicing per schemeExam fees, audit rates and renewal fees are settled via Mollie, Adyen or Buckaroo. Invoicing through integration with Exact, AFAS, e-Boekhouden or Twinfield. For member subscriptions, we integrate with your existing membership system so that a suspension automatically affects the certificate status.
  • Exam and audit plannerExam venues, examiners, auditors and candidates are mapped with capacity monitoring, conflict detection (no assessment by one's own employer), travel time optimisation and rescheduling. For digital exams, an integration with your invigilation or proctoring provider.
  • Document upload with integrity hashApplicants and auditees upload supporting evidence that lands in a case-bound document store (S3-compatible, EU-based). Each file receives an integrity hash so that it can later be proven the document has not been altered, much like our approach to case management.
  • Assessment by multiple reviewersAn asynchronous review workflow in which two or three independent assessors evaluate the same application without seeing each other's scores until they have reached their own judgement. Disputes escalate to an arbitration role or committee. The review environment shows only the relevant parts of the file to each reviewer role.
  • Issuance with eIDAS QES and QR verificationApproved applications lead to a digital certificate signed with a qualified electronic signature (QES) under eIDAS, legally equivalent to a handwritten signature. The certificate carries a QR code linking to the current status in your register; even after revocation the QR keeps working and shows that the certificate is no longer valid.
  • Renewal and continuing education cycleCertificates with a validity period are automatically flagged for renewal, with reminders ahead of expiry. Continuing education requirements, CPD points or audit cycles are configurable per scheme. A missed renewal results in a controlled expired status in the register, not a silently continuing certificate.
  • Public register with APIA searchable public register where clients and consumers can verify whether a certificate is valid, for which scheme and until when. Full-text search, filters, and an open API so that external systems (procurement platforms, training providers, marketplaces) can retrieve the current status in real time.
  • Complaints, sanctions and revocation workflowA complaints workflow in which a complainant lodges a formal report, a committee hears the case and decides, and the outcome (warning, suspension, revocation) flows automatically into the status in the public register. With logging that is demonstrably auditable for accreditation bodies.
  • Record-level audit trailWho assessed which application and when, which score, which scheme version, and which decision-maker signed off a withdrawal. Tamper-proof and time-stamped, in line with ISO 27001 and, for accredited schemes, supplementary to ISO/IEC 17024 or 17065.
  • Role and permissions model (RBAC)Access by role: applicants see only their own file, examiners only their assigned examinations, assessors only their assigned review work, the committee the decisions, and the accreditation auditor aggregates without personal data. Least privilege as the starting point; conflict-of-interest detection as a feature, not a manual check.

When a certification portal is the right choice.

For a small certification scheme issuing a handful of certificates a year, a spreadsheet and a PDF template are often still workable. We only come into the picture with one or more of the patterns below. During the intake we discuss, without obligation, whether custom development fits — or whether a lighter alternative will suffice.

Scheme discipline

Requirements are interpreted differently

You'll notice that the requirements of your scheme are interpreted differently in practice by different assessors. A scheme-driven portal enforces the same definitions and evidence requirements for every application, and every assessor works from the same rubric.

Independence

Multiple reviewers and conflict detection

For accreditation-compliant certification (ISO/IEC 17024, 17065), independent assessment by multiple reviewers with demonstrable conflict-of-interest controls is a requirement. Off-the-shelf tools rarely handle this well.

Public register

Clients must be able to verify for themselves

You want a contracting authority, training provider or consumer to be able to check for themselves whether a certificate is valid. A PDF on a personal page doesn't achieve that; a searchable register with an API and QR verification does.

Renewals

Cycle too complex for a reminder email

Continuing-education points, audit cycles and renewal requirements differ from scheme to scheme. Spreadsheets work up to roughly a hundred certificates. Beyond that, you need a system that keeps the cycle under control.

Multi-scheme

Multiple certifications in parallel

For trade associations managing more than one scheme, or a platform hosting schemes from different scheme owners: separate data per scheme with central identity and payments. A design decision, not a plugin.

Integrations

Examination, payment and register in step

When examination software, payment processing and register publication live in separate tools and your team synchronises them manually every month. One portal that carries the entire chain removes manual work and gives you better management information.

Certification by use case.

The rules and integrations differ greatly by type of certification. A selection of the contexts for which we have built or advised on certification and register systems.

Trade and personal certification

Tradespeople, mechanics and self-employed professionals

For trade associations that issue their own trade certification to individual tradespeople, under schemes such as CCV, CKB, KOMO vakmanschap or comparable occupational certifications, we build portals where candidates register, sit theory and practical tests, receive a personal certificate with QES and QR code, and track their continuing-education points. Together with a public register that clients and consumers can consult directly.

Personal certificateTheory + practiceContinuing educationPublic register
Quality marks and certification marks

Product certification and certification mark audits

For quality marks in ornamental horticulture (MPS), forestry and paper (FSC, FFP), horticulture (GLOBALG.A.P.) and food, we coordinate the entire audit process: annual planning, self-assessments, on-site inspections with mobile data entry, scoring according to the scheme, issuance with a validity date, and publication in an open register that trading partners use to verify provenance and quality.

On-site auditsMobile data entryAudit reportProvenance chain
Educational certification and diplomas

Examination boards and training institutes

For training institutes, examination boards and organisations that issue formal diplomas or educational certificates, comparable in scale to CITO or the operational practice of CAOP, we build portals for registration, examination, assessment by multiple independent markers, diploma issuance with QES and integration with DUO or the Diplomaregister. This complements our wider educational app development.

ExaminationTwo markersDiploma issuanceDUO integration
Trade associations and professional bodies

Member certification with supervision and sanctions

For trade associations and professional bodies that link membership to certification, with continuing professional development requirements, codes of conduct and a supervision and sanctions procedure, we build portals that connect membership, certification and subscriptions. A suspension automatically affects certification, a complaint about a member runs through a structured committee workflow, and the register shows the current status.

Members + certificateCPD pointsComplaints committeeSanctions workflow
Company certification and management systems

ISO 9001, IATF 16949, AS9100 and sector variants

For certification bodies that issue company certification based on international management system standards (ISO 9001, 14001, 27001, IATF 16949 for automotive, AS9100 for aerospace), we build client portals for audit planning, certificate history, transfers between bodies, IAF reporting and integration with the accreditation body (RvA). The portal forms the client-facing side alongside your internal audit management system.

Client portalAudit historyRvA reportingTransfer protocol
Insurance and the repair sector

Repair businesses, FCN-style certification

For insurance-related certification, where approved repair businesses (Focwa, FCN-style) or assessment firms are periodically audited on quality, environment, safety and customer focus, we build portals that combine the audit cycle, mystery shopper results, customer NPS and claims statistics into a current certification status, with integrations to insurers who act on that status when allocating claims.

Periodic auditCustomer satisfactionInsurer APIClaims statistics

Schema engine, multiple reviewers and eIDAS explained.

Four modules that clients often want to hear more about in a first conversation: how we build them, and why we make some choices differently from a standard package.

  • Schema engine as data, not codeWe define schemes as configuration: requirements, evidence, scoring rubrics, weighting factors, pass thresholds, validity periods and grounds for revocation. A scheme administrator publishes a new version without us releasing a update; every version is kept as a historical snapshot. During an accreditation audit, you can show which scheme applied on which date, which is crucial for ISO/IEC 17024 and 17065 conformity.
  • Multiple reviewers with blind review and escalationApplications are assigned in parallel to two or three independent assessors. Until each reviewer has submitted their own judgement, they cannot see one another's scores. In the event of disagreement, the case escalates automatically to an arbitration role or committee. Conflict-of-interest detection covers employer, region and prior relationships, so no assessor is assigned to an applicant they know.
  • eIDAS QES, AES and public verifiabilityFor certificates with legal consequences, we sign with QES through a Qualified Trust Service Provider (Signhost QTSP, ValidSign QTSP, KIK-cap). For standard certificates, AES. In addition, public verifiability through a published hash (RFC 3161 timestamp or blockchain anchoring) allows anyone to independently check that a certificate has not been altered after issue.
  • Public register with webhooks to the marketThe register is also a live data source. External systems, such as tendering platforms, marketplaces, insurers and industry bodies, subscribe to webhooks that fire on every status change. This removes the need for daily export files. The API is documented, versioned and has clear rate limits.
Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

How a certification portal project works with us.

1

Introduction and intake

A no-obligation conversation in which we map out the schemes, estimate issuance volumes, review the compliance requirements (GDPR, eIDAS, ISO/IEC 17024 or 17065, RvA requirements) and determine whether custom development is the right choice, or an existing certification package. Sometimes we recommend the latter; that saves you time and budget.

2

Discovery of your scheme and workflow

A working session with your scheme owner, assessors, planners and a few certified professionals. We map out the scheme, identify the real pain points (where assessors diverge, where renewal deadlines slip, where the market fails to consult the register) and define the scope in an initial screen flow.

3

Scheme modelling and compliance design

We translate the scheme into a formal data model: requirements, evidence, rubric, scoring, validity, renewal, revocation. At the same time, we establish the privacy and security design: data classification, GDPR lawful bases for each data flow, and a DPIA where justified. For accreditation-compliant schemes, we test against ISO/IEC 17024 or 17065.

4

Building in sprints

Application and issuance flow first, then scheme management, then the multi-reviewer review flow, then the public register and API, then eIDAS QES and the complaints and revocation flow, then integrations with payments, accounting and external registers. You test alongside us, as do scheme managers and, where possible, real applicants and assessors.

5

Migration of existing certificates

Any existing certificates and historical audit reports held in your current system, Excel lists or Access environment are migrated in phases: new applications go into the new portal first, followed by historical certificates with integrity hashing and linkage to the scheme version that applied at the time.

6

Pilot, training and go-live

A pilot group of assessors and a test group of applicants work in parallel on the old and new systems, and any discrepancies are resolved. Training sessions for scheme managers and assessors, short videos for applicants, and a go-live with a clear fallback procedure.

7

Operations and ongoing development

After go-live, we monitor performance, security and usage. New scheme versions, additional integrations or a new scheme are handled in small development sprints, so your portal grows with new standards and accreditation requirements.

Compliance: GDPR, eIDAS and publication requirements.

What sets a certification portal apart is that compliance is not a coat of paint but the blueprint itself. We build the rules in so they cannot be circumvented, even by accident, and so that an accreditation audit of the system brings no surprises.

GDPR and special category personal data. Application files contain personal data and, depending on the scheme, CV details, examination scores, possibly health data or criminal record information. For every processing activity we record the lawful basis, restrict access to what is strictly necessary, and maintain a record of processing activities that updates automatically. A Data Protection Officer can run a report without needing a developer.

eIDAS QES and AES. For certificates with formal legal status, we work with a Qualified Trust Service Provider that signs with a QES, which is legally equivalent to a handwritten signature. For standard certificates, an AES is sufficient. The signature certificate and timestamp are recorded in the audit trail, so a client can later verify that the document was issued by your organisation at a specific moment.

Publication requirement and right to erasure. Alongside the confidentiality of the file sits the requirement to publish on the register. We build the register so that only data that may be public is published (name, scheme, validity, scope), and personal data and file contents remain strictly separated. The GDPR right to erasure runs through a separate workflow that respects your retention obligations.

NEN 7510 and ISO 27001 where applicable. For certifications with a healthcare link, we align with NEN 7510. For the portal itself, we build to ISO 27001 requirements so that your organisation can include the system in its own management system certification.

The technology choices we make along the way.

Our stack is deliberately conservative: certificates with validity periods of several years and renewal cycles that can run for decades call for a foundation that does not need to be rebuilt over and over.

Backend in Postgres with RBAC. Row-level security for multi-schema separation. The role-permission model lives in the database, so that even an ad hoc query passes through the same access control. For the public register, a separate read replica ensures that a surge in public traffic does not affect the assessors' work.

Frontend in Astro or Next.js. For your visibility, the public register is a marketing tool; we build it so that search engines index each certificate as its own page. For the assessors' workspace, React with TanStack Table for the more demanding data table screens.

Document store on S3-compatible storage with KMS. Object storage (AWS S3, GCS, Azure Blob or an EU-hosted variant), encryption at rest with KMS keys that you manage; for on-premises, MinIO. Versions are stored immutably with object lock where the retention obligation requires it; each upload receives an integrity hash in the audit trail.

Authentication via SSO, iDIN, eHerkenning and magic links. For staff, SSO on your existing identity provider with MFA. For applicants, iDIN, eHerkenning or magic link. For external clients, API keys with scope and rate limiting to the register.

Webhooks, retries and API versioning. Retry policy with exponential back-off, a dead-letter queue for failed events, signed payloads, and clear versioning so that an integration does not break when you add a schema field.

Frequently asked questions.

The questions we almost always receive in a first conversation.

What is the difference between a certification portal and an LMS?
An LMS manages learning material, progress and, where relevant, an examination. A certification portal manages the formal issuance: registration, identity verification, payment, assessment by independent reviewers, issuance with legal status (eIDAS QES), public register, renewals and the revocation workflow. The two can complement each other; for training institutions we often build a combination of both.
Do you replace an existing certification package or audit management system?
For a small certification, usually not. We come into the picture when your schema, integrations or publication requirements are so specific that a standard package only works with costly customisation. During intake, we weigh your current licence and customisation costs against the custom development trajectory. Some clients keep their audit management system in-house and only have us build the client and register portal.
How do you technically safeguard the independence of assessors?
Conflict-of-interest detection runs automatically on employer, previous relationship and region, and blocks assignment as soon as a match is found. Reviewers work blind: they cannot see each other's scores before submitting their own judgement. In the event of a discrepancy, the application escalates automatically. Every assessment is traceable in the audit trail.
Which eIDAS providers do you integrate with?
Signhost (Evidos), ValidSign, KENA, Adobe Sign, DocuSign and, for specific domains, domain-specific QTSPs. For QES, we work with QTSPs that have a valid status on the EU Trusted List. Which provider fits depends on the schema, cost per issuance and your contractual situation; we advise on that.
How secure is the public register against misuse or scraping?
We build rate limiting, CAPTCHA for abnormal patterns, and a structured API for parties who need high volumes (with API keys, contracts and logging). Bulk export runs through a formal arrangement, not scraping. For sensitive schemes, we can restrict search to exact match on certificate number only.
How do you handle the right to be forgotten for revoked certificates?
A revocation keeps the certificate visible with the status 'revoked' and the date, as that is precisely the reason for publication. Personal data of an applicant who was never certified is destroyed after the retention period. For revoked certificates, you often have a legal retention obligation; we build that trade-off as an explicit workflow with a final check by your DPO.
Do you work alongside our current IT provider or our in-house IT team?
More often than not, yes. We deliver the codebase, build instructions, architecture overview and runbook so that an external managed service provider can take over. This is a deliberate design choice to avoid vendor lock-in. Some clients have us continue under a maintenance contract; others hand management to their own team.
Can a certification portal run on-premises, or does it have to be in the cloud?
Both are possible. For government or accreditation-sensitive environments, we run the stack in a Dutch single-tenant private cloud or your own data centre. For other contexts, an EU-based cloud by arrangement. Encryption keys remain with you in both scenarios.
What if we want to add an extra scheme along the way?
That is why we build the scheme engine as data, not as code. A new scheme or a new version can be set up by a scheme administrator themselves through an editorial interface. For schemes with entirely new technical requirements, we run a short further-development sprint.
What determines the cost?
The biggest cost drivers are the number of schemes, the complexity of the assessment process, the depth of integrations (payment, accounting, external registers, accreditation reporting), the requirements around eIDAS QES and publication, and the migration of existing certificates. We work with fixed sprint budgets so that you can adjust scope from sprint to sprint.

Talk to us about your certification portal.

A no-obligation introductory conversation of half an hour. We listen to your scheme, ask questions about your issuance volumes, assessment process and publication requirements, and give direction that is useful to you, even if the outcome is that an existing package suits you better than custom development. You can find more about our approach on the web development overview page.

Fabian van Dijk Business developer fabian.vandijk@appfront.nl
Share LinkedIn Email

Edit content