What OpenPeppol has actually decided
Every Peppol Certified Service Provider must hold a valid ISO/IEC 27001 certificate, or an approved equivalent, from 1 October 2027.
689
Certified Service Providers on the Peppol network
OpenPeppol list, 4 August 2026
1 Oct 2027
Certification deadline
Implementation plan v1.0
30%
Of data breaches globally come from third-party and supply chain compromise
OpenPeppol's stated rationale
On 24 June 2026 the OpenPeppol Managing Committee approved the final version of the ISO/IEC 27001 Implementation plan, following a member review of an earlier draft. The plan turns a principle that several Peppol Authorities already applied nationally into a single obligation across the whole network: each Peppol Certified Service Provider must hold a valid ISO/IEC 27001 certification, and the scope of that certification must cover the Peppol services it operates.
One detail is worth pinning down before anything else, because a good deal of the coverage published in July got it wrong. The draft that circulated during the member review set the compliance deadline at 1 July 2027. The Managing Committee moved it. In its own words, the final documentation "has been made available three months later than planned", so the certification deadline shifts by three months. The operative date is 1 October 2027.
The July date has proved persistent for a reason. The Italian Peppol Authority's notice of 8 July 2026 is the one public announcement of the mandate by a Peppol Authority, and it carries 1 July 2027 in its headline and attaches the release candidate rather than the approved plan. Most of the vendor briefings and trade coverage that followed take their date from there. OpenPeppol has not carried the decision on its own public news channel, so the approved plan in the Security space of its documentation wiki is the primary source.
The obligation is not a questionnaire, a self-declaration or a contractual warranty. OpenPeppol has set out its reasoning plainly: independent, recurring verification against an internationally recognised standard is the response it considers credible, because self-attestation and contractual commitments alone are not sufficient to manage the risk. The plan cites third-party and supply chain compromises accounting for 30% of data breaches globally, and points to NIS2, DORA, NIST CSF 2.0, the NYDFS Cybersecurity Regulation, Singapore's amended Cybersecurity Act 2024, Australia's Cyber Security Act 2024 and UK government supply chain security guidance as evidence that the regulatory direction was already set.
OpenPeppol, ISO/IEC 27001 Implementation plan, Status: Final, Version 1.0, published 2026.06.24, approved by the Managing Committee on 24 June 2026. Publicly available from the Security space of the OpenPeppol documentation wiki.
Agenzia per l'Italia Digitale (Italian Peppol Authority), "ISO/IEC 27001 Certification Mandatory for Peppol Service Providers from 1 July 2027", 8 July 2026. Cited as the public announcement of the mandate; its dates follow the release candidate, not the approved plan.
Who is caught, and the 1 January 2027 gate nobody is talking about
The obligation attaches to Peppol Certified Service Providers, and the plan ties it directly to one thing: holding a Peppol PKI Production certificate. Service Providers that do not hold a PKI Production certificate are not subject to the requirement. That is the test to apply, not whether you describe yourself as an Access Point, an SMP operator or a platform.
There is a second deadline buried in chapter 3.1 that arrives well before the headline one, and it changes how anyone plans a Peppol launch. New Service Providers issued a first PKI Production certificate on or before 31 December 2026 comply with the deadlines in force when the certificate was issued, so they have until 1 October 2027 to certify. From 1 January 2027, a new Service Provider will only be issued a first PKI Production certificate if it already holds a valid ISO/IEC 27001 certificate or an approved equivalent.
In practice that converts certification from a compliance project into a market-entry gate. Anyone planning to go live on Peppol as a Service Provider during 2027 or later needs the certificate in hand before applying, not afterwards. PKI Test certificates are unaffected and can still be issued to organisations without certification, so development and conformance testing can proceed while an ISMS programme runs in parallel.
For scale: the OpenPeppol list of certified Service Providers carried 689 entries when it was last updated on 4 August 2026. That is the population the plan applies to, spread across every jurisdiction the network reaches.
Do you hold a Peppol PKI Production certificate?
This is the test, not how you describe your role on the network.
No
Not subject to the requirement
PKI Test certificates are still issued to organisations without certification, so development and conformance testing can continue while an ISMS programme runs.
Yes
When was your first PKI Production certificate issued?
On or before 31 December 2026
You comply with the deadlines in force at the date the certificate was issued. A valid certificate must be in place by 1 October 2027.
From 1 January 2027
A first PKI Production certificate will only be issued if you already hold a valid ISO/IEC 27001 certificate or an approved equivalent. Certification comes first.
From 1 January 2027, no ISO/IEC 27001 certificate means no first PKI Production certificate. Certification becomes the entry ticket, not the follow-up.
Holding a certificate is not the same as being compliant
A certificate that does not cover your Peppol operations, or that names the wrong legal entity, does not count.
This is where most already-certified providers will find their gap. The plan is explicit that holding a certificate is a necessary but not sufficient condition for compliance. The scope of certification must encompass the end-to-end provision of all Peppol services operated under the Service Provider Agreement, including the systems, processes and organisational functions that support those services.
Depending on what you run, that scope will take in Access Point and Service Metadata Publisher operations together with the associated processes: End User Identification, document handling and format conversion where you perform it, message integrity and anti-forgery controls, logging and audit trail management, and backup and business continuity procedures. Service Providers are required to check their Statement of Applicability against that definition before submitting anything, and where the existing scope falls short, to open a scope extension with their certification body first. A scope extension means reassessment of the added areas and, where applicable, an updated Stage 2 audit. The plan warns that this cannot be assumed to take a fixed amount of time.
Three specific traps are called out. A parent company certificate that applies to the whole group only satisfies the requirement if it names the organisation that signed the Peppol Service Provider Agreement and covers the OpenPeppol scope. A certificate that is technically still valid but whose surveillance audits have slipped does not count, because compliance includes maintaining the surveillance audit calendar. And a Service Provider running on somebody else's certified platform must still hold its own certificate.
That last point deserves its own paragraph, because the white-label and SaaS model is common on this network. OpenPeppol's position is that a hosting provider's certificate attests to the security of the platform's physical and logical infrastructure. It says nothing about how you configured identity and access management for your Peppol workloads, whether you enabled encryption on the databases holding participant data, whether your developers left API credentials in a code repository, or whether your administrative portal requires MFA. The plan describes all of these as client responsibilities that sit directly in scope for the most significant attack vectors against Peppol Service Providers. Service Provider certification covers the complementary scope that hosting provider certification excludes by definition.
Required scope
The end-to-end provision of all Peppol services operated under the Service Provider Agreement, including the systems, processes and organisational functions that support them. Depending on the services you run, that takes in:
Running on a white-label or SaaS platform
Your host's certificate covers
- Physical infrastructure of the platform
- Logical infrastructure of the platform
It says nothing about
- How you configured identity and access management for your Peppol workloads
- Whether encryption is enabled on the databases holding participant data
- Whether your developers stored API credentials in a code repository
- Whether your administrative portal requires MFA
OpenPeppol describes all of these as client responsibilities that sit directly in scope for the most significant attack vectors against Peppol Service Providers. Service Provider certification covers the complementary scope that hosting provider certification excludes by definition.
The certificate must also name the legal entity that signed the Peppol Service Provider Agreement. A parent company certificate covering the whole group does not satisfy the requirement unless it names that entity and covers the scope above.
The submission calendar
The plan sets six milestones, T0 to T5, which are deadlines for submitting documents rather than staged obligations to be certified. All submissions go through the OpenPeppol Service Desk under "General support", Peppol area "Agreement Framework".
The certificate submission at T1 is more than a copy of the certificate. It must include the Statement of Applicability, so OpenPeppol can confirm there are no exclusions from the required scope, a reference to the Service Provider Agreement confirming the certificate holder is the signatory legal entity, and an attestation signed by the Service Provider's management stating that the certificate covers the OpenPeppol scope. Until that submission is received and acknowledged, you are treated as not holding a valid certificate and must meet the T2 to T4 deadlines like everyone else.
| Milestone | Date | What is due |
|---|---|---|
| T0 | 31 July 2026 | Request for an equivalent certification to be considered |
| T1 | 1 September 2026 | Existing certificate, Statement of Applicability, Service Provider Agreement reference and signed management attestation |
| T2 | 1 October 2026 | Evidence package for an ongoing certification project, or for a scope update in progress |
| T3 | 1 May 2027 | Status report on certification or scope-update progress, including the scheduled Stage 1 audit date |
| T4 | 1 August 2027 | Second status report |
| T5 | 1 October 2027 | Certification deadline. A valid certificate, or an approved equivalent, must be in place |
T0 closed on 31 July 2026. If you hold a national certification you wanted assessed as equivalent and did not file by then, speak to your Peppol Authority.
What happens if you miss it
The escalation runs from a warning note to termination of the Service Provider Agreement over nine months.
The penalty ladder rests on the non-compliance policy in chapter 9 of the Internal Regulations Part II, Use of the Peppol Network. Enforcement is initiated by the Peppol Authorities rather than by OpenPeppol directly, and the plan is candid that the dates below are an indicative timeline: Authorities may handle cases individually, with the Compliance Board asked to advise on as much synchronisation as possible.
Two categories are singled out for particular attention. Public organisations under national supervision may struggle to meet the Peppol requirement within their own rules, and Service Providers that started late because they were waiting on approval of an alternative scheme that was ultimately rejected are also flagged as a special case.
The commercially significant step is NC-3. External blacklisting puts a Service Provider on a publicly accessible register of non-compliant providers. For anyone selling into procurement-led or regulated accounts, that lands well before the technical consequences do, and it is the point at which a compliance slip becomes a sales problem.
- T031 July 2026
Equivalence requests close
Last date to ask for an alternative scheme to be added to the list of allowable certificates.
- T11 September 2026
Existing certificates due
Certificate, Statement of Applicability, Service Provider Agreement reference and signed management attestation.
- T21 October 2026
Evidence package due
For a certification project or a scope extension already underway, with a letter from the certification body.
- T31 May 2027
First status report
Progress against the submitted plan, including the scheduled Stage 1 audit date.
- T41 August 2027
Second status report
Two months before the deadline, the last checkpoint before enforcement begins.
- T51 October 2027
Certification deadline
A valid ISO/IEC 27001 certificate, or an approved equivalent, must be in place and scoped to Peppol operations.
- NC-11 October 2027
Warning Note
Formal notice setting out the steps required and the timeframe. No loss of access at this stage.
- NC-21 April 2028
Internal blacklisting
Status made available to all OpenPeppol members.
- NC-31 May 2028
External blacklisting
Recorded on a publicly accessible register of non-compliant Service Providers.
- NC-41 June 2028
PKI certificate revoked
Temporary revocation of the PKI Production certificate, preventing further participation in the network.
- NC-51 July 2028
Agreement terminated
Service Provider Agreement terminated and removal from the Peppol network with immediate effect.
Enforcement is initiated by the Peppol Authorities, not by OpenPeppol directly. The plan describes the non-compliance dates as an indicative timeline that Authorities may handle case by case, with the Compliance Board asked to advise on as much synchronisation as possible.
Equivalent certifications and the allowable list
OpenPeppol accepts that some Service Providers hold a security certification other than ISO/IEC 27001. Alternative schemes may be accepted, but only where they appear on the official OpenPeppol list of allowable certificates. Getting a scheme onto that list is a formal process: either the Peppol Authority or the Service Provider submits a request through the Service Desk setting out the alternative, its validity period and issue date, the geographical scope in which it is recognised, the scope it covers, and the documents on which it was granted. The single most important piece of evidence is that the scheme requires an independent third-party audit rather than self-assessment.
Requests had to be submitted no later than T0. The Operating Office and the Security Committee review submissions together, and the Managing Committee takes the final decision on whether a scheme is accepted. Requestors are notified once a decision is reached.
There is one accommodation worth knowing about. OpenPeppol recognises that public sector entities across its countries of operation are subject to stringent regulatory security requirements that may exceed ISO/IEC 27001. For those cases, adherence to frameworks with an equivalent information security level, audited by a third party, will be considered for acceptance. The certification body itself can be chosen freely: the plan states the Service Provider may select its certification body at its discretion, irrespective of the jurisdiction in which that body is established, provided it is accredited by a recognised national accreditation authority.
If you buy Peppol access rather than operate it
ERP teams, finance systems integrators and businesses that reach Peppol through a third-party Access Point acquire no direct obligation from this decision. The requirement sits with the certified Service Provider. What you acquire is exposure, because the ladder above ends in your provider losing its PKI Production certificate and then its Service Provider Agreement.
The exposure is manageable and the timing is generous, but it is real, and the questions to put to a provider are specific rather than general. Ask whether the certificate names the legal entity that signed the Peppol Service Provider Agreement, not a parent or a sister company. Ask whether the Statement of Applicability covers Access Point and, where relevant, SMP operations along with End User Identification, logging and business continuity. Ask when the last surveillance audit took place and when the next one is scheduled. If the provider runs on a white-labelled platform, ask for its own certificate rather than its host's.
A provider that has already submitted under T1 and had the submission acknowledged by OpenPeppol can tell you so plainly. That is a reasonable thing to ask for during a renewal or a tender, and from 2027 it will be a standard line in procurement questionnaires.
What to do next
If you already hold ISO/IEC 27001, the work is a scope check rather than a certification project, and it should not wait. Read your Statement of Applicability against chapter 2.2 of the plan, confirm the certificate names your Service Provider Agreement signatory, and if there is a gap, open the scope extension with your certification body now. T1 has passed. Where a certificate has not yet been submitted, the plan's guidance is to submit through the Service Desk as soon as possible, and providers that submitted a certificate before the final plan landed need to file the remaining documents, the Statement of Applicability, the Service Provider Agreement reference and the management attestation, on the same ticket.
If you are not certified, the constraint is calendar time rather than effort. A certification body relationship spans a Stage 1 documentation review, a Stage 2 audit and then annual surveillance audits across a three-year certificate cycle, and audit slots are booked months ahead. Our ISO 27001 explainer covers what the standard involves and what certification takes. OpenPeppol asks for proof of engagement with a certification body, and the FAQ deals directly with the case where the earliest available Stage 2 date falls after 1 October 2027: submit a certification process plan with the scheduled audit date confirmed by the certification body. The plan also stresses that ISO/IEC 27001 places non-delegable obligations on senior leadership, and that treating certification as a technical workstream is what causes programmes to fail at the surveillance audit stage.
For partnership, marketing and demand generation teams, this is a rare piece of network-wide news with a fixed date attached, and it will reshape competitive positioning through 2027. Certification stops being a differentiator on the day it becomes universal, so the window for using it as one closes on 1 October 2027. Two things do stay useful afterwards: being early, and being able to evidence scope rather than just wave a certificate. The 1 January 2027 gate is also worth planning around, since it will slow the rate at which new Access Points enter the market and will affect any partner or reseller strategy that assumed a quick route to becoming a Service Provider.
One editorial caveat on the source document. The approved plan carries a drafting inconsistency at T2: the evidence package for providers without a certificate asks for a project plan confirming certification will be achieved by 1 July 2027, the old release-candidate date, while the parallel bullet for scope updates in the same section refers to 1 October 2027. Every other statement in the plan, including the T5 heading, chapter 2.2, chapter 3.2 and the whole non-compliance chapter, uses 1 October 2027. Treat 1 October 2027 as the deadline and raise the T2 wording with the Service Desk if you are relying on it.
OpenPeppol, ISO/IEC 27001 Implementation plan v1.0, chapters 2.2, 3.1 to 3.5, 4 and 5.
OpenPeppol Security space, ISO/IEC 27001 FAQ, updated 25 June 2026.
OpenPeppol, Peppol Certified Service Providers list, updated 4 August 2026.
Explore e-Invoice.app
Real-time compliance data, peer discussions, and cross-functional tools for every stakeholder.
Compare Countries
Side-by-side comparison of mandates, timelines, and technical requirements.
Open Compare ModeFind the Right Vendor
Get matched with e-invoicing vendors for your countries and ERP.
Start vendor match