Joulo holds ISO 27001: what it means for a registration provider

Joulo is certified to ISO/IEC 27001:2022, the international standard for information security. What the standard requires, how the audit went, what we built for it, and what the certificate does and does not say.

Ruben StolkRuben Stolk· Co-founder~6 min readUpdated 30 Sept 2026

Joulo holds ISO 27001: what it means for a registration provider
ISO 27001 at a registration provider
ISO 27001 at a registration provider

Good to know

Joulo B.V. has been certified to ISO/IEC 27001:2022, the international standard for information security, since 26 September 2026. An independent auditor from CertPro assessed our policy, our technology and our records, in two rounds. Nothing changes in the service, and it costs you nothing extra. But you now have outside proof that we handle your data with care. The certificate says nothing about your ERE calculation: the verifier checks that.

Why we wanted this

You trust us with quite a lot. Your EAN code. Your address. Your IBAN. Your identity through iDIN. The authorisation we use to book on your behalf. And every charging session of your charger, with start and end time.

A year of charging sessions shows when someone is home, when they go on holiday and what time they drive to work. Whoever manages that must be able to show it is secure.

"We handle your data with care," says every company. We wanted someone else to say it, after checking.

What ISO 27001 is

ISO/IEC 27001 is the international standard for information security. The standard prescribes no software and no supplier. It requires a fixed way of working:

  • you know which data you manage
  • you know which risks you run with that data
  • you take measures against those risks
  • you can prove all of that, every year again

Such a way of working is called an information security management system. The abbreviation is ISMS.

The standard has two parts. The main text says what the system must do: set the scope, assess risks, arrange people and resources, measure and improve. The annex contains 93 concrete controls in four themes.

ThemeNumberExamples
Organisational37policy, roles, suppliers, incidents
People8screening, confidentiality, awareness
Physical14equipment, workplaces, storage media
Technological34access, encryption, logging, backups

For each control you state whether it applies to you, and how you implement it. That document is called the Statement of Applicability. It is the first thing an auditor asks for.

Why this matters for a registration provider

The Energy for Transport Regulation sets one requirement for our organisation: a suitable administrative organisation. That is all it says.

Whoever holds an account in the register of the NEa (the Dutch Emissions Authority) is registered. That registration is not a quality assessment of the substance. So it does not say how well a party runs its business.

The independent verifier does check the substance, every year. The verifier looks at kWh, at MID meters and at authorisations. How secure the systems holding that data are falls outside the verifier's assignment.

So nobody in the chain tests the security. ISO 27001 does.

How the audit went

The audit has two rounds.

Round 1: the design. The auditor reads the policy, the risk analysis and the Statement of Applicability. Does the design match the standard? The outcome is not a verdict but a list of gaps.

Round 2: the operation. Do we also do what it says? The auditor holds interviews, looks over our shoulder and asks for evidence: logs, completed tasks, incident files, the results of technical checks.

In round 2 the auditor found not a single nonconformity.

Our auditor was CertPro. That is an independent party that deliberately gives no advice and does not help with the setup. An auditor who also advises you is judging their own work. We had to close every gap on their list ourselves.

The auditor got their own account in our dashboard. That role can read everything in the security system and nothing else: no customer data, no payouts. So the auditor saw the real system, not a presentation. And we gave nobody from outside admin rights.

What we built for it

We bought no package. We built the security system ourselves, as part of our admin dashboard. So policy, risks, evidence and checks sit next to the production data they are about.

Policy with an owner. Access, passwords and keys, secure development, changes, incidents, backups, suppliers, retention periods, staff, the quality of ERE data and the use of AI. Every document has an owner, a version and an approval. On approval we freeze the exact text. So we know later which version someone signed.

A risk register. A stolen laptop. A founder's account taken over. A charger that pretends to be another one. A double payout through two accounts. kWh without a MID meter that still end up in a booking. For each risk, the register shows the measure, the residual score, and the name of the person who accepted that residual risk.

Access at database level. Every table is shielded per user. Your IBAN is encrypted in a vault and can only be written through one secured route. Admins only log in with a Google account with two-step verification.

One pipeline to production. Nobody puts software live by hand. Every change goes through automated checks, and we record who changed what and when.

Evidence that cannot disappear. We keep every OCPP message from your charger. The log of the security system can only be added to, never erased. We make backups every day, also outside our main supplier.

Checks that run every day. Is the shielding still on for every table? Does every admin have two-step verification? Did the nightly jobs run? We measure part of the standard live on the production data.

Recurring tasks with evidence. Access review, patch round, check of authorisations and EANs, supplier review, awareness session. You cannot tick one off with only a date. Every run is a row with outcome, name and evidence.

Internal audit and management review. Once a year we test the system ourselves against the standard. Management reviews the results and records decisions. The auditor read those reports too.

What it gives you

  • Outside proof. You do not have to take our word for it.
  • The same bar for our suppliers. For each supplier we record which certification it holds, whether there is a data processing agreement, and how critical it is for us.
  • Faster answers for business customers and partners. Energy companies, lease companies and homeowners' associations (VvEs) ask for this as standard.
  • No extra cost. The service fee stays 20%, cancellable annually, paid out every quarter.

What it is not

  • No guarantee that nothing ever goes wrong. It does mean we notice it, record it, report it and fix it. Incidents sit in a register with cause and measure.
  • No verdict on your ERE calculation. The verifier checks whether your kWh are correct and whether your meter is MID-certified. How that works is in our process description (in Dutch).
  • No GDPR stamp. The GDPR is a law, ISO 27001 a standard. The certificate helps us comply with the law. It does not replace our privacy statement.
  • No certificate from the NEa. An account with the NEa is a registration. This is a separate, independent test.

What happens next

LMS Assessments Limited issued the certificate, with number NL26092601. It is valid until 25 September 2029. Every year the auditor comes back for a surveillance audit, the first by 25 September 2027 at the latest. After three years the cycle starts again. So the system has to keep running, also when nobody is watching.

Read more

joulo.nl/iso-27001 (in Dutch) explains the standard and our approach step by step. Do you work at an energy company, lease company or homeowners' association and want to see the certificate? Send us a message through your dashboard. You then also get a summary of the Statement of Applicability and our data processing agreement.

About the author

Ruben Stolk
Ruben StolkCo-founder

Co-founder of Joulo and builder of the platform. Previously Capptions (compliance infrastructure). Writes about engineering, integrations and MID meters.

About Joulo

Joulo is an ERE booking service provider for residential charging sessions.

34,000,000 MID kWh this year (forecast)

ERE registration

Steps, costs and proceeds of booking through Joulo.

How it works
Booking service

Charge data booked automatically as ERE, paid out quarterly.

How it works
White-label platform

The ERE backend for CPOs and energy companies, under their own brand.

White-label
Partner programme

For installers and energy companies who refer customers.

Become a partner

Joulo B.V. • NEa-registered • in line with RED III

Newsletter

Stay in the loop

The occasional email on ERE, chargers and earning from home charging. No spam, unsubscribe anytime.

Earn on every kWh you charge at home

Connect your charger once. We register your sessions and pay out every quarter. 20% service fee, cancel yearly.