Agreement number: ESTONIA - LC-01685408
Annex IV – Model technical implementation report
Activation of Emergency Support Instrument in response to the COVID-19
Pandemic - Support for the interoperability of the Digital Green Certificate
Project number: LC-01685408
Project acronym: EMERGENCY SUPPORT INSTRUMENT ESTONIA
Project name: EU DCC issuance and verification in Estonia
GRANT AGREEMENT FOR AN ACTION UNDER THE EMERGENCY SUPPORT
INSTRUMENT ESTONIA - AGREEMENT NUMBER: LC-01685408
1) Start date of the action: 01/04/2021
2) End date of the action: 30/09/2021
3) Detailed description of the action:
Short oveview and main milestones
This grant enabled the development of the issuance of the EU Digital COVID Certificates
(vaccination, recovery and test certificates) according to the EU standards, connection of the
Estonian backend solutions to the EU Gateway, development of the Estonian verification
solution and adoption of the web app to validate the authenticity of the certificates. Adaption
of the validation and verification in Estonia included purchase of the devices for border guards
and Health Boards inspectors.
Main milestones:
TestDryRun for Connectivity to the EU DCC Gateway – May 20th, 2021
Successful connection in production between Estonia’s backend server and the “EU Digital
COVID Certificate” Gateway – June 2nd, 2021
EU DCC vaccination, recovery and test certificates in production in Estonia – June 9th, 2021.
Verification web app kontroll.digilugu.ee in production – June 9th, 2021.
EU DCC json scehma 1.3.0 – in production July 1st, 2021
EU DCC Value Sets and Business Rules/Validation Rules – in production September 7th,
2021. In addition, also EU DC Business Rules of the other Member States – adding a
functionality to the national verification web app to verify the COVID certificate against the
Business Rules of the Member States who have uploaded their Business Rules to the EU
Digital Gateway.
In August and September, additional improvements of the EU DCC issuance and verification
in Estonia, including
development the issuance service to be able to have test certificates based on RATs;
development of the booster dose (3/3 and 2/2) issuance and verification;
development a special issuance possibility for the citizens without access to the
National Patient Portal and to the foreigners without Estonian ID numbers.
Development and adaption of the Estonian solution for issuing, verifying
certificates
Analysis and design were the prerequisite of the issuance. We analysed and designed the
Estonian EU DCC systems so that we were able to use the data available in the Estonian
National Health Information System (ENHIS). We used the already present immunization
notifications and lab results as part of the data collection. We also actively took part in the
development of the EU wide design and standards of the EU DCC.
Please see the visualisation for data collection:
Issuance included:
Development of the EU DCC Certificates (incl the developmenf of the Estonian National
Health Information System and national backend to connect the EU Gateway
Development of the necessary interfaces
o National Patient Portal for creating and managing EU DCC Certificates by the
citizens
o Support application for creating EU DCC certificates for those who are unable to
access National Patient Portal and create the certificate themselves.
Please see the visualisation of the issuance in Estonia:
Our CSCA certificate is issued by the same organization (Police and Boarder Guard Board
and SMIT) as the Estonian national travel documents electronic parts. DSC related key and
certificate generation is supervised by the Police and Boarder Guard official responsible for
the process. Our private key is stored in the hardware security module (HSM) at the Health
and Welfare Information Systems Centre (HWISC).
Verification included:
Development of the EU DCC verification Service, uploading scripts with DSC and
CSCAs via DCC Gateway.
Development of the EU DCC verification web app kontroll.digilugu.ee
Development of the Value Sets and Business Rules Service, uploading and downloading
the business rules jsons via DCC Gateway.
Uploading the PKIs and business rules json files to the DCC Gateway.
EU DCC data warehouse development, testing and final visualization of the data resulted
in the Tableau special feature on EU digital COVID certificates. This data is also
automatically available each day for the management dashboard. Please see the example
recent excerpt:
Connection of the national backend solutions to the EU gateway
Our Test Dry Run was on May 20th, 2021, we successfully tested the connection as well as
planned for the production. We have a script-based uploading system of the PKI certificates
and business rules json files to the EU Gateway. The connection to the EU Gateway was
established on June 2nd, 2021. We started issuing all 3 certificates on June 9th, 2021.
We first uploaded the national business rules on September 3rd and started officially using them
via Gateway on September 7th, 2021.
Supporting Member States in testing the issuance, verification and wallet apps,
participating in piloting activities, and onboarding to the Gateway
We have actively taken part of the community wide testing of the issuance and verifications.
During the Spring and Summer, our testers took part of the testing sessions following the
guidance of the main team and submitting testing reports weekly, biweekly or according to the
plans set by the core team.
We have also actively participated at the Piloting Community weekly meetings, Technical and
Semantical Subgroups to ensure the EU wide common understanding the standards of the EU
certificates and its solutions.
Validation and verification adoption activities according to the plan
Police and Border Guard Board acts as a organization responsible for verifying the EU
DCCs on the boarders. As planned, the mobile phones were purchased and put to good use
on the boarders. 140 border guards in various borders are using mobile devices to validate
and verify the EU digital COVID certificates.
In order to prevent the spread of COVID-19, the Health Board carries out random
inspections of border crossings by the supervisory body to verify the authenticity of
submitted digital certificates of vaccination and recovery, on the basis of which those
entering Estonia are released from self-isolation. As planned, 60 health inspectors of the
Regional Departments of the Health Board and Heads of the Procedure Group received a
mobile phone to verify the EU digital COVID certificates.
Activities related to risk assessment and security plans.
Estonian system was designed taking into account various possibilities. The system was
designed to issue certificates based on the data only in the National Health Information
System (ENHIS, managed by HWISC) to eliminate possibilities of the fraud and other risks.
Our risk assessment and security plans for the EU DCC are part of the regular risk
assessment and security ISKE processes which we follow daily. ISKE is an information
security standard that is developed for the Estonian public sector. ISKE is based on a
German information security standard – IT Baseline Protection Manual (IT-Grundschutz in
German) – which has been adapted to suit the Estonian situation. For more information,
please see https://www.ria.ee/en/cyber-security/it-baseline-security-system-iske.html
As part of the grant, we commissioned two specific security testing sessions to ensure the
safety of the solutions – both National Patient Portal (issuance of the certificates) and
toend.digilugu.ee (issuance of the certificates for the foreigners and Estonians who are
unable to use National Patient Portal) and kontroll.digilugu.ee together with the
microservices (verification and validation of the certificates) received a full security testing.
The reports brought out some risks however countermeasures were taken to mitigate and
eliminate the risks before going to the production.
4) Visibility of the action:
EU DCC have been popular in Estonia since its launch. Media coverage has been extensive.
EU flag/logo and support of the action is noted on following main places:
The EU flag/logo is both on the certificate Estonia issues as well as on the verification web
app kontroll.digilugu.ee.
The logo of the EU with the specific note to funding is specially highlighted at the Guide
for Verification (document distributed to all the possible users of the already being
discussed with the designers how to include into the issuance and verification web app).
The EU flag/logo with the specific note to funding is explicitly highlighted at the web
page of the HWISC https://tehik.ee/el-digitaalsed-covid-toendid which is the main
information channel for the COVID certificates to focus on issuance and verification.
5) Date of connection to the EU Gateway
02/06/2021
6) Modifications to initial planning (if applicable)
EU DCC Value Sets and Business Rules/Validation Rules – in production September 2nd, 2021.
Initially promised and planned at the end of August.
Development of the test certificates based on the results of RAT (August)
In August and September we had planned to make necessary enhancement to the services
according to the feedback from the users and institutions. It resulted two main additions:
Development of the better solution for the foreigners who need an EU COVID
Certificate in Estonia. Enhanced solution added possibility to create certificate to the
foreigners without Estonian ID number and make the process smoother for the citizens.
Development of the specific solution for the Estonians without possibility of access to
the National Patient Portal to create their own EU COVID Certificate. During the
summer, we learned that a lot more people needed more support to create their EU
COVID certificates all over in Estonia. Their digital skills were lacking, their ID cards,
incl their PINs had not been renewed. Therefore, we developed an extra functionality
for IT helpdesk at the HWISC and Service Desk at the Social Insurance Board1. Issuing
the certificates in the service centres of the Social Insurance Board was a logical
solution, as they already have the necessary infrastructure for that and are able to reach
people all over Estonia. Therefore we were able to help people with lower digital
competences and people like foreign workers and international students, who do not
have access to the Estonian authentication solutions to access National Patient Portal
themselves.
5) Any other relevant information
High priority development, we needed to be really flexible as the EU wide standards and rules
changed rapidly in May as well as in June and now later at the end of August and September.
1
If interested, please see web page EU COVID certificates to be issued by the Social Insurance Board |
Government installation profile (sotsiaalkindlustusamet.ee) https://sotsiaalkindlustusamet.ee/en/news/eu-covid-
certificates-be-issued-social-insurance-board
11/30/21, 8:30 AM ATR - Auditors Activities Register
Auditors Activities Register
Accessibility
Estonian
In English
Sign in
Register
Exams
Activity licence
Cources
General information Qualifications and recognitions
Professional activity Proceedings
Additional qualification
General data
Sworn auditor's number: 437
First name: Tiina
Surname: Maalinn
Professional activities form: Auditors company
Right to represent authority Yes
to perform audit service:
Represented company in Audiitorbüroo Maalinn OÜ
the meaning of Auditors
Activities Act section 78.:
https://www.audiitortegevus.ee/atr/web/valisaudit/register/vaata/247/yld 1/3
11/30/21, 8:30 AM ATR - Auditors Activities Register
Contact information
Contact type Value
GSM 51 45 992
Mandatory e-mail address
[email protected]
E-mail
[email protected]
Education
Educational Educational Education obtaining
qualification institution Speciality period
No records found.
Back
The Ministry of Finance of Estonia
Suur-Ameerika 1, 15006 Tallinn
Tel:
https://www.audiitortegevus.ee/atr/web/valisaudit/register/vaata/247/yld 2/3
11/30/21, 8:30 AM ATR - Auditors Activities Register
Tel:
E-mail:
[email protected]
https://www.audiitortegevus.ee/atr/web/valisaudit/register/vaata/247/yld 3/3
Certificate on the financial statement (CFS)
Tervise ja Heaolu Infosüsteemide Keskus
(in English Health and Welfare Information Systems Centre)
Uus-Tatari 25, 10134 Tallinn, ESTONIA
We, Audiitorbüroo Maalinn OÜ , established in Ööbiku 2a-2, Tallinn 11315 ESTONIA, represented for signature
of this audit certificate by Tiina Maalinn ja sworn auditor and member ot the board,
hereby certify
that:
1. We have conducted an audit relating to the costs declared in the financial statement of Health and Welfare
Information Systems Centre (the beneficiary), to which this audit certificate is attached and which is to
be presented to the European Commission under Grant Agreement No LC-01685408 — EMERGENCY
SUPPORT INSTRUMENT ESTONIA, covering costs for the following reporting period: 01.04.2021 –
30.09.2021.
2. We confirm that our audit was carried out in accordance with generally accepted auditing standards in
compliance with ethical rules and on the basis of the provisions of the Grant Agreement and its Annexes
3. The financial statement was examined and all necessary tests of all of the supporting documentation and
accounting records were carried out in order to obtain reasonable assurance that, in our opinion and on the
basis of our audit
- total costs of EUR 511 678 (five hundred and eleven thousand six hundred and seventy - eight) are eligible,
i.e.:
- actual (— for actual costs);
- determined in accordance with the beneficiary’s accounting principles (— for actual costs);
- incurred during the period referred to in Art 1.2.2 of the Grant Agreement;
- recorded in the beneficiary’s accounts at the date of 30.11.2021;
- comply with the specific eligibility rules in Art II. 19 of the Grant Agreement;
- do not contain costs that are ineligible under Art II. 19.4 of the Grant Agreement, in particular:
o costs relating to return on capital;
o debt and debt service charges;
o provisions for future losses or debts;
o interest owed;
o doubtful debts;
o currency exchange losses;
o bank costs charged by the beneficiary’s bank for transfers from the Commission;
o excessive or reckless expenditure;
o VAT (deductible or not);
o costs incurred during suspension of the implementation of the action;
o in-kind contributions provided by third parties;
o costs declared under other EU grants (including those awarded by a Member State and
financed by the BU budget or awarded by bodies other than the Commission for the
purpose of implementing the EU budget); in particular, indirect costs if the beneficiary’s
is already receiving an EU operating grant in the same period, unless they can demonstrate
that the operating grant does not cover any costs of the action;
o costs incurred for permanent staff of a national administration, for activities that are part
of its normal activities (i.c. not undertaken only because of the grant);
o costs incurred for staff or representatives of EU institutions, bodies or agencies;
- total receipts of EUR EUR 511 678 (five hundred and eleven thousand six hundred and seventy - eight)
have been declared under Art 11.25 of the Grant Agreement and
- the beneficiary’s accounting procedures are in compliance with the accounting rules of the state in which
it is established and permit direct reconciliation of the costs incurred for the implementation of the action
covered by the EU grant with the overall statement of accounts relating to its overall activity.
4. Wc are qualified to deliver this audit certificate (for additional information, see appendix to this certificate
- Auditors Activity register – activity license no and sworn auditor’s no).
5. The beneficiary paid a price of EUR 2500 (excluding VAT) for this audit certificate. These costs were not
included in the financial statement.
Tallinn, November 30, 2021
Tiina Maalinn
Auditor’s license no 437
Audiitorbüroo Maalinn OÜ
Corporate audit services license no 296
Audiitorbüroo Maalinn OÜ Ööbiku 2a-2 tel +372 514 5992
Äriregistri kood 16080550 11315 Tallinn
[email protected]
Tegevusluba 296
11/30/21, 8:29 AM ATR - Auditors Activities Register
Auditors Activities Register
Accessibility
Estonian
In English
Sign in
Register
Exams
Activity licence
Cources
General information People Activity
Proceedings Member fee
General data
Activity licence number: 296
Audit firm's name: Audiitorbüroo Maalinn OÜ
Commercial register code: 16080550
Location address: Ööbiku tn 2a-2 Kristiine linnaosa, Tallinn,
Harju maakond
Audit firm type: Sworn auditors company
Type of company: Private limited company
Field of activity: Auditeerimine
Activity region (country): Estonia
https://www.audiitortegevus.ee/atr/web/valisaudit/register/ettevotja-vaatamine/1901/yld 1/3
11/30/21, 8:29 AM ATR - Auditors Activities Register
Activity region:
The audit firm has an active
contract with public interest
entity.:
Contact information
Contact type Value
E-mail
[email protected]
GSM +372 5145992
Mandatory e-mail address
[email protected]
Phone +372 5145992
Offices
Name Address
No records found.
Back
https://www.audiitortegevus.ee/atr/web/valisaudit/register/ettevotja-vaatamine/1901/yld 2/3
11/30/21, 8:29 AM ATR - Auditors Activities Register
The Ministry of Finance of Estonia
Suur-Ameerika 1, 15006 Tallinn
Tel:
E-mail:
[email protected]
https://www.audiitortegevus.ee/atr/web/valisaudit/register/ettevotja-vaatamine/1901/yld 3/3