A digital certificate is not merely an installation file. It identifies SEF to ATK’s system and enables electronic signing of receipts. Each SEF installed at a point of sale requires a certificate, while its private key must be kept highly secure and confidential.
What the certificate connects
Certificate provisioning includes the taxpayer NUI or fiscal number, unit number, POS number, software-solution code and fiscalization number obtained from ATK’s electronic system. It ties the taxpayer to a specific unit, device context and solution.
Copying configuration from one location to another without a controlled process can therefore create incorrect identification.
The private key must not circulate
The private key supports signing and should be available only to the component and people with a genuine operational need. Do not email it casually, place it in a public folder or include it in unencrypted backups.
Ask where the key is stored, who can access it, how it is backed up and what happens if compromise is suspected.
Controls for each point of sale
Keep a certificate inventory mapped to units and POS installations. The inventory records ownership, device, date, status and responsible person—not the private key itself.
- One record per installed SEF.
- Role-based access and intervention logs.
- Protected backup with a restore test.
- Procedure for lost or replaced devices.
- Review after location or maintainer changes.
When device or configuration changes
Do not treat computer replacement like an ordinary app installation. Confirm which identifiers and certificates are affected, follow the ATK procedure and document removal of old access before enabling the replacement.
Security begins with identity and access
Each operator should use an individual account. Roles determine what they can see and do, while sensitive actions—corrections, configuration changes or report access—should be logged. Shared passwords remove that accountability.
Review access when an employee changes role or leaves. Old permissions should not remain active by accident.
Technical and organizational controls
Encryption and digital signatures matter, but they do not replace backups, updates, device control and staff training. Durable security is layered.
- Individual accounts and least privilege.
- Audit trail for critical actions.
- Backups with a restore test.
- Controlled devices and updates.
Pre-launch check
Use this guide as a basis for discussion with your team and software provider. The actual setup depends on your activity, locations and internal procedures.
- Define items, tax rates, prices and payment methods.
- Set operator roles and shift responsibilities.
- Test sales, corrections, offline work and reports.
- Document the workflow and train staff before activation.
Practical questions
Should every operator have a separate account? +
Yes. Individual accounts enable role-based access and keep actions attributable in the audit trail.
Is an untested backup sufficient? +
No. A business should know that the backup can be restored and how long operational recovery takes.
Is a digital certificate required for every installed SEF? +
Yes. The instruction requires a certificate for each SEF installed at a point of sale, and its private key must be kept highly secure and confidential.
Want to see easyPos in your business?
Tell us your type of activity and sales locations. We will show you a tailored workflow.
Request a demonstration