Are you e-Invoice ready? Get your free compliance assessment score in 5 minutes -Are you e-Invoice ready?Take the test now
e-Invoice.app
All Posts
Standards & Networks

Peppol's G3 Certificate Switch: What Changed on 1 April 2026

Every Peppol Access Point had to complete the G3 PKI migration before 1 April 2026 or lose network connectivity. The cutover is done; this is the record of how it worked.

18 March 2026Updated 9 September 20265 min read

Why is Peppol changing its certificates?

The Peppol network relies on a Public Key Infrastructure (PKI) to authenticate every message exchange between Access Points. Since the network's early days, those certificates have been issued through DigiCert Managed PKI v8 (MPKI8). That platform is being retired by DigiCert, which means Peppol must move to a new certificate authority infrastructure: DigiCert One Trust Lifecycle (DOTL).

This is not a minor version bump. The migration from the G2 certificate chain to the G3 chain is the largest infrastructure change to hit Peppol since the network was established. It affected every participant in the ecosystem: every Access Point and Service Metadata Publisher, and by extension the millions of registered participants that depend on them.

The core reason is straightforward: the old infrastructure is reaching end-of-life, and continuing to rely on it would create security and operational risks. The new DOTL platform brings a modernised certificate lifecycle, but it requires every Service Provider to actively migrate before the cutoff.

What is the migration timeline?

T0: Aug 2025, G3 available. T1: 11 Feb 2026, dual support required. T2: 1 Apr 2026, G2 revoked.

OpenPeppol defined three milestones. T0 (11 August 2025): the new G3 root CA chains were published and the DOTL enrolment portal opened. From that date, Access Points could request G3 certificates and test them in the Peppol Testbed environment. No disruption to production traffic - G2 certificates continue to work normally.

T1 (11 February 2026): every Service Provider had to support the G2 and G3 certificate chains simultaneously, signing and encrypting outgoing messages with the new G3 certificate while still validating incoming messages signed with either. Before T1, every AP had to have passed the Peppol Testbed conformance tests to prove dual-chain capability.

T2 (1 April 2026): all G2 certificates were revoked and DigiCert stopped issuing replacements. Any Access Point still on the old chain was disconnected outright, able neither to send nor to receive. There was no grace period.

What must Access Points do?

Each Access Point must replace its existing MPKI8-issued certificates with new ones from the DOTL certificate authority. OpenPeppol offers two enrolment methods: a web-based approach through the DOTL portal, or a CSR-based (Certificate Signing Request) method for organisations that prefer to generate keys locally. Both produce valid G3 certificates.

During the transition window between T0 and T2, Access Points had to run dual-capability: sign outgoing messages with the G3 certificate while still validating incoming messages that might carry G2 signatures from providers yet to switch. This bidirectional tolerance is what keeps the network running smoothly during the migration.

Service Metadata Publishers (SMPs) have their own obligation: metadata records must be re-signed with G3 certificates so that other Access Points can discover and trust them. Conformance testing via the Peppol Testbed is mandatory before any provider can request production-grade G3 certificates.

e-Invoice.app - The e-Invoice Voice

The e-Invoice Voice™

Global e-invoicing mandates explained for finance and tax teams. What's changing and what to do before the deadline.

Newsletter · Published weekly

Subscribe on LinkedIn

Does this affect businesses using Peppol?

Businesses that send and receive e-invoices via Peppol do not manage certificates themselves - that is handled entirely by their Access Point provider. So in principle, this migration is invisible to end users. Your invoices will continue to flow as normal, provided your AP completes the switch on time.

The risk was real at the time. A provider that missed 1 April 2026 stopped carrying traffic: no outgoing invoices, no incoming invoices, no workaround. For businesses in countries where Peppol-based e-invoicing is mandatory, Belgium and Singapore among them, that would have meant non-compliance with legal obligations.

If you are choosing a provider now, the question has changed: a provider still trading is on G3 by definition, so ask instead how it handled the cutover and what its plan is for the next PKI rotation. If you are in the process of selecting a new provider through the vendor directory, G3 readiness should be a qualifying criterion. The e-Invoice Readiness Scorecard includes vendor ecosystem assessment as one of its five evaluation categories.

What other infrastructure changes are happening alongside?

The certificate migration is not happening in isolation. The SML (Service Metadata Locator) - the DNS-based lookup mechanism that allows Access Points to find each other - is also undergoing a change. The legacy method used CNAME DNS records, but as the network grew into the millions of participants, the number of CNAME entries became unwieldy.

As of 1 February 2026, CNAME lookups were fully deprecated and NAPTR DNS records are now the sole lookup method. NAPTR is better suited to large-scale service discovery and reduces the DNS footprint significantly. Access Points that had not already migrated their SML integration to NAPTR before that date would have experienced lookup failures.

Together, the G3 PKI migration and the NAPTR switch represent a significant modernisation of Peppol's underlying infrastructure. Neither changes how e-invoicing works from a business perspective, but both are essential to keeping the network secure and scalable as adoption accelerates worldwide.

e-Invoice.app Knowledge Team

Written by

e-Invoice.app Knowledge Team

Editorial team, e-Invoice.app

The e-Invoice.app editorial team tracks e-invoicing mandates across 130+ countries. Posts are written from primary sources, dated, and corrected in place when the law moves. See our editorial and trust policy at /trust.

Explore e-Invoice.app

Real-time compliance data, peer discussions, and cross-functional tools for every stakeholder.

Explore Country Data

Real-time e-invoicing mandate data for 130+ countries.

Browse countries

Compare Countries

Side-by-side comparison of mandates, timelines, and technical requirements.

Open Compare Mode

Join the Community

Discuss compliance with LinkedIn-verified professionals.

View discussions

Find the Right Vendor

Get matched with e-invoicing vendors for your countries and ERP.

Start vendor match

Country Guides

In-depth compliance guides for key e-invoicing markets.

Read guides

Related Posts

From Point-to-Point to 5-Corner: How e-Invoicing Networks WorkWhat Is Peppol? History, Architecture, and How the Network WorksFrance e-Reporting for Foreign Companies: What Applies, and From When
    TermsPrivacyContact Us

    © 2026 e-Invoice.app