Skip to content
2026-08-05
PeppolNews
Briefed on Peppol.
PN-20260713 mandates
Mandates

ISO 27001 certification becomes mandatory for all Peppol service providers from July 2027

OpenPeppol's Managing Committee has mandated ISO/IEC 27001 certification for all Peppol Service Providers globally, effective July 1, 2027. Non-compliant providers will lose accreditation.

OpenPeppol has made ISO/IEC 27001 certification mandatory for all Peppol Service Providers worldwide, starting July 1, 2027. The requirement applies to Access Point providers and Independent Software Vendors routing invoices through third-party Access Points. Non-compliance will result in loss of accreditation.

OpenPeppol’s Managing Committee has mandated that all Peppol Service Providers must hold ISO/IEC 27001 certification by July 1, 2027. The requirement replaces a patchwork of national security standards with a single global baseline.

The mandate covers two groups: direct Peppol Access Point providers and Independent Software Vendors (ISVs) whose products route invoices through third-party Access Points. Providers that do not comply will lose their accreditation, disrupting invoice flows for their customers.

What ISO 27001 requires

ISO 27001 certification requires establishing a comprehensive Information Security Management System (ISMS). Certified providers must undergo annual audits to maintain their status. Initial certification typically takes 6 to 12 months of effort.

ISVs and businesses using Peppol should act now. Verify whether your current or prospective Peppol provider holds ISO 27001 certification or has a documented roadmap to achieve it before the deadline. Waiting until mid-2027 creates risk of service disruption.

References

  1. www.vatupdate.com