VCA as a Service
July 5, 2026
VCA - veiligheidscertificaat aannemers, or "safety certificate for contractors" - is a license to operate for most contracting firms in the Netherlands and Belgium. Client organizations increasingly require it before they'll let a contractor on site, and the checklists, audit formats, and required documentation are published and maintained centrally at vca.nl. Holding the certificate is non-negotiable for many contracts. Managing the administration behind it is where most of the actual work sits.
Who Carries the Administrative Load
VCA compliance breaks down differently depending on organization size.
Larger contracting firms usually have an in-house compliance or HSE team dedicated to keeping the certificate current: managing the register of required actions, tracking training and toolbox records, preparing for audits.
Mid-sized firms tend to outsource the administrative setup to third-party specialists, who build and maintain the structure but still need the organization to feed them accurate, timely data.
Smaller contracting teams are the hardest case. Someone - usually the owner, director, or operations manager - is doing VCA administration on top of a full-time job running the business. Checklists live in scattered folders, toolbox talks get logged after the fact if at all, and audit prep becomes a scramble every time renewal comes around.
That third group is where "VCA as a service" is aimed: giving smaller and mid-sized contractors the same structured administration that larger compliance teams already have, without requiring them to build it themselves.
What VCA-as-a-Service Actually Provides
The idea is straightforward: instead of every contractor assembling its own spreadsheets, folders, and reminder systems from scratch, the required administrative structure - the register of actions, the checklists, the audit-ready documentation - is delivered as a managed service on top of inspection and workflow software.
That splits into two parts. Subject matter experts get tooling to build and maintain the templates and workflows that VCA compliance actually requires - so the checklists reflect the current standard, not a version from a few renewal cycles ago. Contracting organizations get the other half: a system they can use directly to log the required activities, assign actions, track completion, and produce the audit trail an inspector or certifying body will ask for.
The result isn't a document library. It's a live register: what's been done, what's due, who's responsible, and what evidence backs it up - searchable instead of reconstructed from memory every time someone asks for it.
Why This Matters More at Seveso Sites
VCA and Seveso compliance are different systems solving different problems, but they overlap constantly in practice. VCA certifies that a contractor's own organization manages safety competently. Seveso III (Directive 2012/18/EU) governs the operator of a major-hazard site and requires a veiligheidsbeheersysteem (VBS) - a safety management system covering seven Annex III elements, from hazard identification to audit and review.
A contractor working at a Seveso-classified site sits at the intersection of both. Holding a valid VCA certificate is usually the entry ticket. But the site operator's VBS extends beyond its own personnel - it has to account for contractor activity too, particularly under Annex III element (c), operational control, which covers how work is planned, permitted, and supervised, including work carried out by third parties.
In practice, that means a contractor's VCA administration doesn't stay internal. Site operators and their auditors want to see it: current certification status, toolbox records for work performed on site, incident and near-miss history, proof that method statements were followed. A contractor whose VCA administration is a folder of PDFs updated once a year is a weak link in the site's own compliance picture - and DCMR or the Nederlandse Arbeidsinspectie will treat contractor oversight as part of what they're inspecting, not a footnote to it.
For contractors that regularly work Seveso or BRZO sites, VCA-as-a-service stops being a back-office convenience and becomes something closer to a commercial requirement: the difference between winning repeat work at major-hazard sites and losing it to a competitor who can produce a clean audit trail on request.
The Structural Fit
The reason VCA administration and Seveso VBS documentation fit the same underlying system is that they're asking for the same things: a register of required actions with owners and due dates, evidence that those actions actually happened, and a way to retrieve that evidence quickly when someone asks for it. Whether the question comes from a VCA auditor checking a contractor's toolbox records or a DCMR inspector reviewing a site operator's management-of-change file, the answer needs to be a record, not a reconstruction.
That's also why generic document-management tools tend to fall short here - they store files, but they don't structure the underlying register, assign ownership, or flag what's overdue. For a longer look at where generic safety management software runs into trouble specifically on Seveso-classified sites, see why generic safety management software falls short for Seveso III companies.
Capptions builds this kind of structure through its inspection and audit software: custom forms and workflows for the checklists a standard actually requires, corrective-action tracking so gaps get closed and not just logged, and Clara, an AI assistant that helps surface what's due and what's missing. The same underlying approach applies whether the register being maintained is a VCA administration or a Seveso VBS - which is precisely where VCA-certified contractors and Seveso-classified operators end up needing to speak the same language.