Why does security matter in e-invoicing?
Every e-invoice carries sensitive financial data: VAT numbers, bank details, pricing, and transaction volumes.
E-invoicing systems handle some of the most sensitive data a business produces: VAT registration numbers, bank account details, pricing structures, supplier relationships, and transaction volumes. Every invoice exchanged is a packet of financial intelligence, and that makes e-invoicing infrastructure an attractive target for fraud, phishing, and data theft.
The shift from paper and PDF to structured electronic exchange has multiplied both the volume of data in transit and the number of systems that touch it. Access points, clearance platforms, ERP integrations, and archiving services all become potential attack surfaces. A single compromised node can expose thousands of organisations' financial data.
Regulators have taken notice. As more countries mandate e-invoicing, the question is no longer just "can your platform transmit a valid invoice?" but "can it do so without leaking data, being spoofed, or going offline at the worst possible moment?" Security certification is the mechanism governments are reaching for to answer that question.
What is ISO 27001?
ISO 27001 is the international standard for information security management systems (ISMS). The current version, ISO 27001:2022, replaced the 2013 edition, with the transition period completing in October 2025. It is published by ISO and IEC and is recognised across virtually every industry and jurisdiction worldwide.
The standard is built around three pillars: confidentiality (only authorised people can access the data), integrity (data has not been tampered with), and availability (systems are up and running when needed). An organisation that holds certification has demonstrated, through independent audit, that it operates a management system addressing all three.
ISO 27001 is not a one-time checklist. It requires continuous improvement: regular risk assessments, internal audits, management reviews, and corrective actions. The certificate is valid for three years, with surveillance audits in years one and two, so the organisation must maintain its security posture year-round.
What does ISO 27001 cover?
93
Controls in the 2022 edition, across four themes
11
Controls introduced for the first time in the 2022 revision
3 years
Certificate validity, with surveillance audits in years one and two
The 2022 edition defines 93 controls organised into four themes: People (8 controls), Organisational (37 controls), Technological (34 controls), and Physical (14 controls). This is a restructuring from the 2013 version, which grouped controls into 14 domains.
Eleven controls are entirely new in the 2022 revision. Among the most relevant for e-invoicing platforms are Web Filtering (controlling access to malicious or inappropriate web content), Secure Coding (requiring secure development practices for software), and Threat Intelligence (actively monitoring for emerging threats). Other key areas include access control, data encryption at rest and in transit, incident response procedures, risk assessment methodologies, and compliance monitoring.
For an e-invoicing service provider, these controls map directly to operational realities: encrypting invoice data in transit (AS4 with TLS), controlling who can access the SMP registry, logging all document exchanges for audit, and having a tested incident response plan for when things go wrong.
| Theme | Controls | Examples relevant to e-invoicing |
|---|---|---|
| Organisational | 37 | Policies, supplier relationships, incident management, compliance monitoring |
| Technological | 34 | Access control, encryption at rest and in transit, secure coding, logging |
| Physical | 14 | Facility access, equipment security, secure disposal of media |
| People | 8 | Screening, awareness training, responsibilities on termination of employment |
How hard is it to get certified?
Certification is a serious undertaking. It typically involves multiple teams (IT, legal, operations, HR, and senior management) working together over several months to document policies, implement controls, conduct a risk assessment, and run internal audits before an external certification body arrives for the formal audit.
The audit itself comes in two stages. Stage 1 reviews the documentation and readiness of the ISMS. Stage 2 is the on-site (or remote) assessment where auditors verify that the controls are actually implemented and effective. Gaps found during the audit must be remediated before the certificate is issued.
Maintaining certification is an ongoing commitment, not a trophy for the wall. Annual surveillance audits check that the ISMS is still operating as described, and the full recertification cycle repeats every three years. Most organisations find that expert guidance, whether from a consultant or an experienced internal team, significantly reduces the time and cost of the process.
Two points are worth flagging for anyone starting now. The standard places explicit, non-delegable obligations on senior leadership, so programmes run purely as a technical workstream tend to pass the initial audit and then come apart at the surveillance stage. And certification bodies book up: the Stage 2 slot, not the internal work, is often what sets the earliest realistic completion date.
Stage 1
Documentation and readiness review of the ISMS
Stage 2
On-site or remote assessment that controls are implemented and effective
Certificate issued
Valid for three years, once any gaps found at Stage 2 are remediated
Surveillance, year 1
Confirms the ISMS is still operating as described
Surveillance, year 2
The audit most often failed where leadership engagement has lapsed
Recertification
At the end of the three-year cycle, and the cycle repeats
Certification bodies must be accredited by a recognised national accreditation authority, and their audit slots are booked months ahead. For anyone working to a fixed deadline, the date the certification body can offer for Stage 2 is usually the binding constraint, not the pace of the internal work.
Peppol has made it mandatory network-wide
From 1 October 2027, every Peppol Certified Service Provider must hold a valid ISO/IEC 27001 certificate or an approved equivalent.
The biggest change since this article was first published is that Peppol has settled the question for its entire network. On 24 June 2026 the OpenPeppol Managing Committee approved the final ISO/IEC 27001 Implementation plan, making certification a condition of continued participation for every Peppol Certified Service Provider. The compliance deadline is 1 October 2027, moved back three months from the 1 July 2027 date that appeared in the draft circulated for member review.
The requirement is tied to holding a Peppol PKI Production certificate. Two consequences follow that matter more than the headline date. From 1 January 2027, a new Service Provider will only be issued a first PKI Production certificate if it already holds a valid ISO/IEC 27001 certificate or an approved equivalent, which turns certification into a market-entry condition rather than a follow-up project. And holding a certificate is not by itself enough: the Statement of Applicability has to cover the end-to-end provision of the Peppol services operated under the Service Provider Agreement, and it has to name the legal entity that signed that agreement.
Providers running on a white-labelled or SaaS platform cannot rely on their host's certificate. Missing the deadline triggers a defined escalation that runs from a warning note through internal and public blacklisting to revocation of the PKI Production certificate and, finally, termination of the Service Provider Agreement.
Where else is ISO 27001 required?
National requirements arrived before the network-wide one, and they are not all the same. The distinction that matters is between holding a certificate and being assessed against the standard, because the two carry very different costs.
The Netherlands sits at the stricter end: the Dutch Peppol Authority requires service providers to be in possession of an ISO 27001 certificate. Australia and New Zealand take a different approach. Their Peppol Authority Specific Requirements oblige service providers to complete a security questionnaire and provide evidence of meeting the requirements, with the detail set out in Guidance Note 03 on Information Security. Under the Australian accreditation process that means self-assessment or independent audit against ISO/IEC 27001 or the ASD/NZ Information Security Manual, alongside other conditions such as professional indemnity insurance and annual review of accreditation status. Holding a certificate has not been the entry condition in those markets, which is precisely what the OpenPeppol mandate changes for providers there.
France applies a security certification requirement to accredited platforms through its own regime rather than through Peppol, and the July 2026 order tightened who may issue that certificate: it must come through an accredited chain, whether the French accreditation committee, another national accreditation body under the EU accreditation regulation, or an equivalent body signed up to the international recognition agreements covering ISO/IEC 27001. A certificate from an unaccredited certifier no longer counts. The approved platforms decree explainer covers the detail. The DGFiP became an official Peppol Authority on 8 July 2025, so French platforms operating as Peppol Service Providers now sit under both regimes.
| Regime | What is required | Certificate required? |
|---|---|---|
| Peppol, network-wide | ISO/IEC 27001, or an equivalent on the OpenPeppol list of allowable certificates, from 1 October 2027 | Yes |
| Netherlands | Service providers must be in possession of an ISO 27001 certificate | Yes |
| Australia and New Zealand | Security questionnaire plus evidence under Guidance Note 03. Self-assessment or independent audit against ISO/IEC 27001 or the ASD/NZ Information Security Manual | No |
| France | Security certificate for accredited platforms, issued through an accredited certification chain | Yes |
Is it becoming a global requirement?
For Peppol, it now is one. The 2026 decision replaces a patchwork in which each Peppol Authority set its own security bar with a single obligation applying to every certified provider on the network, whatever its jurisdiction. OpenPeppol's stated reasoning is that self-attestation and contractual commitments alone are not sufficient to manage supply chain risk on shared infrastructure, and that independent, recurring verification is the credible alternative.
Outside Peppol the direction is the same, driven by regulation rather than by network rules: NIS2 and DORA in the EU, NIST CSF 2.0 in the United States, Singapore's amended Cybersecurity Act 2024, Australia's Cyber Security Act 2024, and UK government supply chain security guidance that names ISO/IEC 27001 as the baseline for suppliers to critical public services.
The practical consequence for vendors is that certification is shifting from a differentiator to a licence to operate. It stops being a selling point on the day it becomes universal, which for Peppol providers is 1 October 2027. Businesses assessing their own e-invoicing preparedness, including vendor and security requirements, can use the e-Invoice Readiness Scorecard for a structured review.
OpenPeppol, ISO/IEC 27001 Implementation plan v1.0, approved by the Managing Committee on 24 June 2026.
OpenPeppol, Australia and New Zealand Peppol Authority Specific Requirements.
Explore e-Invoice.app
Real-time compliance data, peer discussions, and cross-functional tools for every stakeholder.
Compare Countries
Side-by-side comparison of mandates, timelines, and technical requirements.
Open Compare ModeFind the Right Vendor
Get matched with e-invoicing vendors for your countries and ERP.
Start vendor match