ISO 27001 certification becomes mandatory for all Peppol service providers from July 2027
OpenPeppol's Managing Committee has mandated ISO/IEC 27001 certification for all Peppol Service Providers globally, effective July 1, 2027. Non-compliant providers will lose accreditation.
OpenPeppol has made ISO/IEC 27001 certification mandatory for all Peppol Service Providers worldwide, starting July 1, 2027. The requirement applies to Access Point providers and Independent Software Vendors routing invoices through third-party Access Points. Non-compliance will result in loss of accreditation.
OpenPeppol’s Managing Committee has mandated that all Peppol Service Providers must hold ISO/IEC 27001 certification by July 1, 2027. The requirement replaces a patchwork of national security standards with a single global baseline.
The mandate covers two groups: direct Peppol Access Point providers and Independent Software Vendors (ISVs) whose products route invoices through third-party Access Points. Providers that do not comply will lose their accreditation, disrupting invoice flows for their customers.
What ISO 27001 requires
ISO 27001 certification requires establishing a comprehensive Information Security Management System (ISMS). Certified providers must undergo annual audits to maintain their status. Initial certification typically takes 6 to 12 months of effort.
ISVs and businesses using Peppol should act now. Verify whether your current or prospective Peppol provider holds ISO 27001 certification or has a documented roadmap to achieve it before the deadline. Waiting until mid-2027 creates risk of service disruption.