Why is Peppol changing its certificates?
The Peppol network relies on a Public Key Infrastructure (PKI) to authenticate every message exchange between Access Points. Since the network's early days, those certificates have been issued through DigiCert Managed PKI v8 (MPKI8). That platform is being retired by DigiCert, which means Peppol must move to a new certificate authority infrastructure: DigiCert One Trust Lifecycle (DOTL).
This is not a minor version bump. The migration from the G2 certificate chain to the G3 chain is the largest infrastructure change to hit Peppol since the network was established. It affected every participant in the ecosystem: every Access Point and Service Metadata Publisher, and by extension the millions of registered participants that depend on them.
The core reason is straightforward: the old infrastructure is reaching end-of-life, and continuing to rely on it would create security and operational risks. The new DOTL platform brings a modernised certificate lifecycle, but it requires every Service Provider to actively migrate before the cutoff.
What is the migration timeline?
T0: Aug 2025, G3 available. T1: 11 Feb 2026, dual support required. T2: 1 Apr 2026, G2 revoked.
OpenPeppol defined three milestones. T0 (11 August 2025): the new G3 root CA chains were published and the DOTL enrolment portal opened. From that date, Access Points could request G3 certificates and test them in the Peppol Testbed environment. No disruption to production traffic - G2 certificates continue to work normally.
T1 (11 February 2026): every Service Provider had to support the G2 and G3 certificate chains simultaneously, signing and encrypting outgoing messages with the new G3 certificate while still validating incoming messages signed with either. Before T1, every AP had to have passed the Peppol Testbed conformance tests to prove dual-chain capability.
T2 (1 April 2026): all G2 certificates were revoked and DigiCert stopped issuing replacements. Any Access Point still on the old chain was disconnected outright, able neither to send nor to receive. There was no grace period.
What must Access Points do?
Each Access Point must replace its existing MPKI8-issued certificates with new ones from the DOTL certificate authority. OpenPeppol offers two enrolment methods: a web-based approach through the DOTL portal, or a CSR-based (Certificate Signing Request) method for organisations that prefer to generate keys locally. Both produce valid G3 certificates.
During the transition window between T0 and T2, Access Points had to run dual-capability: sign outgoing messages with the G3 certificate while still validating incoming messages that might carry G2 signatures from providers yet to switch. This bidirectional tolerance is what keeps the network running smoothly during the migration.
Service Metadata Publishers (SMPs) have their own obligation: metadata records must be re-signed with G3 certificates so that other Access Points can discover and trust them. Conformance testing via the Peppol Testbed is mandatory before any provider can request production-grade G3 certificates.
Does this affect businesses using Peppol?
Businesses that send and receive e-invoices via Peppol do not manage certificates themselves - that is handled entirely by their Access Point provider. So in principle, this migration is invisible to end users. Your invoices will continue to flow as normal, provided your AP completes the switch on time.
The risk was real at the time. A provider that missed 1 April 2026 stopped carrying traffic: no outgoing invoices, no incoming invoices, no workaround. For businesses in countries where Peppol-based e-invoicing is mandatory, Belgium and Singapore among them, that would have meant non-compliance with legal obligations.
If you are choosing a provider now, the question has changed: a provider still trading is on G3 by definition, so ask instead how it handled the cutover and what its plan is for the next PKI rotation. If you are in the process of selecting a new provider through the vendor directory, G3 readiness should be a qualifying criterion. The e-Invoice Readiness Scorecard includes vendor ecosystem assessment as one of its five evaluation categories.
What other infrastructure changes are happening alongside?
The certificate migration is not happening in isolation. The SML (Service Metadata Locator) - the DNS-based lookup mechanism that allows Access Points to find each other - is also undergoing a change. The legacy method used CNAME DNS records, but as the network grew into the millions of participants, the number of CNAME entries became unwieldy.
As of 1 February 2026, CNAME lookups were fully deprecated and NAPTR DNS records are now the sole lookup method. NAPTR is better suited to large-scale service discovery and reduces the DNS footprint significantly. Access Points that had not already migrated their SML integration to NAPTR before that date would have experienced lookup failures.
Together, the G3 PKI migration and the NAPTR switch represent a significant modernisation of Peppol's underlying infrastructure. Neither changes how e-invoicing works from a business perspective, but both are essential to keeping the network secure and scalable as adoption accelerates worldwide.
Explore e-Invoice.app
Real-time compliance data, peer discussions, and cross-functional tools for every stakeholder.
Compare Countries
Side-by-side comparison of mandates, timelines, and technical requirements.
Open Compare ModeFind the Right Vendor
Get matched with e-invoicing vendors for your countries and ERP.
Start vendor match