Certification · Last verified
Peppol Service Provider Certification
Peppol Service Provider Certification governs who may run an Access Point or Service Metadata Publisher on OpenPeppol's e-procurement network. OpenPeppol requires all providers to hold a valid ISO/IEC 27001 certification from 1 July 2027, with scope covering Access Point, Service Metadata Publisher and end-user identification functions; before that date requirements vary by country's own Peppol Authority.
- Class
- Certification
- Owner
- OpenPeppol (non-profit international association under Belgian law)
- Last verified
What it is
Peppol began in 2008 as the EU-funded "Pan-European Public Procurement OnLine" pilot. "In 2012, the Peppol project was finalised, and its services and responsibilities were taken over by OpenPeppol, a non-profit international association established under Belgian law."
"As of 1st July 2027, all Peppol Service Providers shall be required to hold a valid and active ISO/IEC 27001 certification." Its Statement of Applicability must cover "Access Point, Service Metadata Publisher, End User Identification, document management, integrity controls, logging and audit trail, backup and business continuity."
Before that date, the ISO/IEC 27001 requirement is not uniform: it phases in through interim milestones (an equivalence request by 30 June 2026, submission of existing ISO 27001 certificates by 1 September 2026, evidence of an ongoing project by 1 October 2026, progress reports on 1 February and 1 May 2027) ahead of the 1 July 2027 mandatory date.
Peppol certification itself is not a single national scheme: OpenPeppol sets network-wide rules, while each participating country runs its own national Peppol Authority, and Peppol Authorities have set differing requirements ahead of the 2027 deadline.
Who owns it
OpenPeppol, a Belgian non-profit international association, has run the Peppol network's services and responsibilities since taking them over from the EU-funded pilot project in 2012.
Peppol service provider categories
- Access Point (AP)
- Service Metadata Publisher (SMP)
Sources
- OpenPeppol — About Peppol ↗ — accessed
- AGID (Italian national Peppol Authority) — ISO/IEC 27001 Certification Mandatory for Peppol Service Providers from 1 July 2027 ↗ — accessed
- OpenPeppol — Peppol Certified Service Providers ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.