Message IconCustomer SupportUser IconContact SalesLock IconLogin
Arratech logo

The Reality Check Behind OpenPeppol’s ISO 27001 Requirements: What Peppol Providers Need to Know

OpenPeppol ISO 27001 requirement and readiness timeline for Peppol Service Providers

OpenPeppol is making ISO/IEC 27001 certification mandatory for all Peppol Service Providers by 1 July 2027. The certificate is, however, only the final step. The substantive work is building an information security management system (ISMS) that governs how a provider identifies, controls and reviews security risks across its end-to-end Peppol services. Providers should confirm their scope and start now rather than wait for the deadline.

At a glance

Key QuestionAnswer
What is required?Valid ISO/IEC 27001 certificate, or a certificate OpenPeppol accepts as equivalent
Who is affected?All Peppol Service Providers, covering the Access Point and Service Metadata Publisher (SMP) roles
Who introduced it?OpenPeppol (Managing Committee decision)
When is it mandatory?1 July 2027
What must be certified?The provider’s end-to-end Peppol services
Current statusPublished implementation plan

Why is OpenPeppol requiring ISO 27001?

Peppol has grown from an electronic procurement initiative into an international interoperability framework for exchanging invoices, orders and other business documents. Its four-corner model lets buyers and suppliers exchange documents through their respective Peppol Service Providers instead of building bilateral connections. That design gives Peppol its scale, but it also means the network’s trust depends on every Service Provider meeting a consistent security standard.

As more governments and enterprises route business-critical documents through Peppol, technical interoperability alone is no longer enough. OpenPeppol’s ISO/IEC 27001 requirement sets a common information security baseline across the network.

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It gives an organisation a structured way to identify security risks, apply controls, and demonstrate that those controls are governed and reviewed.

For the Peppol ecosystem, a shared baseline supports:

  • More consistent security practices across Service Providers
  • Stronger protection of business-critical information
  • Clearer accountability for information security risks
  • Greater confidence among Peppol Authorities, customers and other participants
  • Better resilience as the network grows

Security is becoming a condition of operating in the network, alongside technical conformance and operational capability.

Who must comply, and by when?

The requirement applies to all Peppol Service Providers, covering both the Access Point and SMP roles. Each affected provider must hold a valid ISO/IEC 27001 certificate, or a certificate OpenPeppol accepts as equivalent, by 1 July 2027.

OpenPeppol has published a phased implementation plan outlining the certification milestones below.

DateMilestone
30 June 2026Equivalence request deadline for providers already holding another certification (deadline passed)
1 September 2026Submit an ISO/IEC 27001 certificate (if already held)
1 October 2026Submit evidence of an ongoing certification project
1 February 2027First progress report
1 May 2027Second progress report
1 July 2027ISO/IEC 27001 certification becomes mandatory

Treat these as planning milestones for building your ISMS, not as administrative checkpoints to clear at the last moment. Confirm the current dates against OpenPeppol’s official implementation plan, the schedule can be revised.

Can another certification be accepted instead?

Possibly. A provider that holds another information security certificate can submit it to OpenPeppol for assessment. Acceptance depends on whether the certificate’s scope covers the provider’s end-to-end Peppol services, so holding another certificate does not guarantee automatic acceptance. Under the implementation plan, equivalence requests are due by 30 June 2026.

The plan sets different routes depending on whether a Service Provider:

  • Already holds ISO/IEC 27001 certificate
  • Is working towards certification
  • Holds another information security certificate
  • Has not yet started a certification programme

Providers should confirm which route applies to them and avoid waiting until the final deadline to submit evidence.

What does ISO/IEC 27001 readiness actually mean?

When providers first hear about the requirement, the common question is “how do we get the certificate?” A more useful starting question is “do we already operate in a way that can support certification?”

Certification is an independent confirmation that a provider operates an effective ISMS. The audit does not create the management system. It assesses what is already in place.

The certificate is the evidence. The management system is the work.

OpenPeppol’s requirement is not about individual security tools. The certificate’s scope must cover the end-to-end delivery of Peppol services, including the relevant systems, processes and organisational functions. In ISO/IEC 27001 terms, the Statement of Applicability should reflect the provider’s Peppol operations, such as the Access Point and SMP roles, document handling, logging and business continuity.

The exact work depends on existing maturity. A provider with established security governance may mainly need to confirm scope, close specific gaps and prepare for audit. A provider without a formal ISMS faces a broader organisational programme.

What should Peppol Service Providers do now?

Providers can take the following steps to prepare for certification.

  1. Confirm the scope. Map the systems, processes, teams, locations and third parties involved in delivering the organisation's Peppol services. A certificate whose scope excludes important parts of the Peppol service may not meet the requirement.
  2. Complete a gap assessment. Compare current security practices with ISO/IEC 27001 to identify what exists, what needs formalising and where new controls are required.
  3. Establish ownership. Assign executive responsibility for the ISMS. Leadership involvement and cross-functional accountability are central to a system that works in practice.
  4. Build and operate the management system. Develop the risk-management approach, policies, procedures, controls and review processes, with a focus on sustainable operations rather than audit-only documents.
  5. Build evidence over time. Maintain records that show controls are followed and reviewed, such as risk assessments, access reviews, training records, incident logs, internal audits and management reviews. Evidence cannot always be created retrospectively.
  6. Plan certification early. Engage an accredited certification body and understand the audit process, lead times and evidence expectations.

What Arratech learned from its own certification journey

One of the clearest lessons was that certification requires the whole organisation to be involved, not just a security or compliance function. Every team that touches the ISMS's scope needs to understand and follow its controls. This has a direct sizing implication: the larger the organisation, the more people, processes and systems need to be brought into alignment, which makes certification proportionally harder and more costly to achieve and maintain. As a small organisation, Arratech was able to move through this process with relatively contained effort. Larger Peppol Service Providers should expect a heavier lift.

Lead times should also not be underestimated. Between the gap assessment, building out evidence, and scheduling an audit with a certification body, the process takes months rather than weeks. Engaging a certification consultant early can materially help as they can guide scoping, help prioritise gaps, and keep the process on schedule.

A mature ISMS also provides a structured framework for incorporating jurisdiction-specific regulatory requirements, allowing organisations to address local obligations through additional controls and governance rather than creating separate compliance programmes.

Finally, it is worth pursuing related certifications together rather than separately. Arratech acquired an ISO/IEC 27001 certificate and an ISO 22301 certificate in parallel. ISO 22301 complements ISO/IEC 27001 by focusing on business continuity, including business impact analysis (BIA), recovery planning and governance that helps organisations continue operating during significant disruptions. Since much of the same groundwork, such as engaged teams, risk management processes, internal audits and management reviews, underpins both standards, organisations already mobilising resources for one certification should consider pursuing the other at the same time, rather than repeating the exercise later.

Obligations are growing. Your burden doesn't have to.

Operating and maintaining your own Peppol infrastructure now carries growing security, compliance and continuity obligations. Arratech provides shared and white-label Peppol infrastructure backed by an ISO/IEC 27001-certified information security management system and ISO 22301-certified business continuity management. Running your Access Point or SMP operations on this infrastructure reduces the security and continuity burden your organisation carries internally.

Talk to Arratech about getting certified infrastructure in place before the deadline.

GET A DEMO

FAQs

FAQs

When does ISO/IEC 27001 become mandatory for Peppol Service Providers?

All Peppol Service Providers must hold a valid ISO/IEC 27001 certificate, or an equivalent certification accepted by OpenPeppol, by 1 July 2027, according to OpenPeppol’s implementation plan.

Does the requirement apply to all Peppol Service Providers?

Yes. OpenPeppol’s implementation plan applies the requirement to all Service Providers, covering both the Access Point and SMP roles. The route to compliance differs depending on whether a provider is already certified, working towards certification, holds an equivalent certificate, or has not yet begun.

Can another security certification be accepted instead of ISO/IEC 27001?

Possibly. A provider holding another certificate must submit it to OpenPeppol for assessment, and acceptance depends on whether its scope covers the provider’s end-to-end Peppol services. Equivalence requests are due by 30 June 2026 under the current plan.


Do software vendors or ERPs that connect through a certified provider need their own certificate?

The certification obligation sits with the Peppol Service Provider that operates the Access Point or SMP. A software vendor or ERP that connects through a certified Service Provider is generally not itself the Service Provider subject to this requirement. Software vendors and ERP providers should confirm their specific status and obligations with their relevant Peppol Authority, as roles can overlap.


Is ISO/IEC 27001 only an IT responsibility?

No. ISO 27001 covers governance, risk management, employees, suppliers, operational processes and leadership oversight. Implementation normally requires collaboration across several business functions.


What should a Peppol Service Provider do first?

Confirm the intended certification scope and complete a gap assessment against ISO/IEC 27001. That provides the basis for an implementation plan, resource allocation and a certification timeline.

More Stories

OpenPeppol ISO 27001 requirement and readiness timeline for Peppol Service Providers
The Reality Check Behind OpenPeppol’s ISO 27001 Requirements: What Peppol Providers Need to Know

OpenPeppol is making ISO/IEC 27001 certification mandatory for all Peppol Service Providers. Learn why the requirement has been introduced, who it affects, what ISO 27001 readiness really means, and the practical steps providers should take to prepare before the implementation deadline.

Guidebook image with key points for what people should take notice of for the recent update from DGFIP
Last Minute Guide to French Compliance

France’s e-invoicing deadline remains 1 September 2026, but DGFiP’s latest practical guidance makes clear that business continuity should come first. Companies are expected to prepare seriously, document issues and return to compliant processes quickly, while temporary fallback methods may be used when technical problems arise.

Replacing MLR with MLS
Replacing MLR with MLS, A Move Toward Machine-Coordinated Commerce?

The Peppol network is gradually evolving from a document exchange framework into infrastructure capable of supporting machine-coordinated commercial processes across organizations and jurisdictions.

That may sound abstract at first. But if we look at where the network seems to be heading, particularly through the transition from Message Level Response (MLR) to Message Level Status (MLS), an interesting picture starts to appear.

CTA Banner Image

Ready for a simple connection to the future of e-Invoicing?

Join the next generation of e-Invoicing infrastructure from Arratech.

Cut costs, stay compliant, and integrate effortlessly.

OpenPeppol ISO 27001: What Peppol Providers Need to Know · Arratech AB