ERC Group
Quality and certification

Qualified to build systems a country depends on

National health systems are procured against standards before they are procured against features. These are the certifications we hold as a company, independent of any product.

Certified and compliant to
ISO 9001ISO 27001IHEHL7 FHIRGDPR / KVKK / HIPAA
01

Certifications held by ERC

Every certificate below is current, accredited, and carries the number a reviewer needs to verify it independently. Full copies accompany tender submissions.

ISO 9001:2015
Quality management system covering the supply of software products to healthcare providers and regulators, system integration in healthcare IT, and project management, development, maintenance and support.
Certificate
IFC-Q-4-24-1959
Issued by
IFC Global Certification
Accreditation
TÜRKAK AB-0138-YS · IAF
Valid until
23 April 2027
Quality management
ISO/IEC 27001:2022
Information security management system governing how patient and operational data is handled, stored and transferred. Certified against the 2022 edition, following the transition from the withdrawn 2013 edition.
Certificate
IFC-I-4-24-1959
Issued by
IFC Global Certification
Accreditation
TÜRKAK AB-0138-YS · IAF
Valid until
23 April 2027
Information security
TS ISO/IEC 15504 — SPICE Level 2
Organisational process maturity, assessed against AviCenna as a named product rather than against the company in general. Staged Level 2, Type A, Class 1, across sixteen engineering, support and management processes.
Certificate
SPICE-059
Issued by
ICT Certify
Accreditation
TÜRKAK AB-0126-U (ISO/IEC 17065)
Assessor
intacs-registered Competent Assessor
Valid until
28 January 2027
Software process maturity
IHE and HL7 FHIR
Conformance to the integration profiles and exchange standards that national interoperability frameworks are written against. Demonstrated in deployment rather than certified by a body.
Interoperability

Project Management Professional (PMP) is held by individual project managers and is a personal credential, not a company certification, which is why it sits outside the list above. ERC holds no CMMI appraisal; the equivalent process-maturity assessment we do hold is the SPICE certificate listed above.

02

How quality is actually run

A certificate proves an audit was passed. These are the practices behind it.

01

Defined engineering process

Requirements, design, implementation and verification follow a documented lifecycle with traceability from specification through to release.

02

Independent verification

Testing is separated from development. Release candidates are validated against acceptance criteria agreed with the customer before go-live.

03

Controlled release management

Versioned releases, documented change control and rollback procedures, because national systems cannot be taken down to fix a mistake.

04

Security by design

Encryption at rest and in transit, role-based access control and audit logging built into the platform rather than added per deployment.

05

Continuous audit readiness

Internal audits run on a fixed cycle between external surveillance audits, so evidence is current when a tender asks for it.

06

Post-deployment support

Defined service levels, incident response and maintenance for systems that have been running for over a decade.

03

Regulatory posture by market

Data protection obligations differ by jurisdiction. Deployments are configured to the regime that applies.

  • European UnionGDPR compliance including lawful basis, data subject rights, de-identification and EU data residency where required by the contracting authority.
  • TürkiyeKVKK compliance and conformance to Ministry of Health data standards, including national data residency.
  • United StatesHIPAA-aligned safeguards for protected health information, applied on deployments serving US-based customers.
  • Other marketsNational data protection and health information requirements assessed per programme, in coordination with the contracting ministry.

This page covers certification of ERC as a supplier. For how the platform itself implements interoperability, clinical coding and data protection standards, see platform compliance.

Need our certificates for a tender?

We can supply current certification documents, audit summaries and compliance statements for procurement submissions.