
ISO 27001 Is Now Mandatory for All Peppol Service Providers
ISO 27001 Is Now Mandatory for All Peppol Service Providers: What ISVs Need to Do Before July 2027
ISO 27001 Is Now Mandatory for All Peppol Service Providers: What ISVs Need to Do Before July 2027
Here is the short version: on December 10, 2025, OpenPeppol's Managing Committee voted at its MC200 meeting to require ISO/IEC 27001 certification from every Peppol Service Provider globally, effective July 1, 2027. If your product routes invoices through a Peppol Access Point (AP) you do not directly control, this deadline is your problem too.
What MC200 Actually Decided
The MC200 resolution formalizes ISO/IEC 27001 as the mandatory certification tied to global Peppol accreditation. It applies to all Service Providers regardless of which national Peppol Authority they are registered under.
The governance structure matters here. Until now, national Peppol Authorities set their own supplementary requirements through Peppol Authority Specific Requirements (PASR), the country-level documents that sit on top of OpenPeppol's baseline rules. These PASR documents cover things like participant identification schemes, security posture, reporting obligations, and SLAs. MC200 sets a universal floor that no PASR can route around.
Why This Is Significant: The Pre-MC200 Patchwork
The e-invoicing ecosystem has a dirty secret: security requirements for Peppol Access Points varied wildly by jurisdiction before this decision.
The Netherlands had ISO 27001 as a hard PASR requirement since 2022-2023, with a Third Party Memorandum (TPM) accepted as a transitional substitute. A TPM is a report from a registered independent IT auditor certifying that an organization's security posture meets ISO 27001 controls without going through formal certification.
Australia and New Zealand enforced equivalent requirements under their national frameworks.
Belgium had no information security requirements in its PASR at all. The "Information Security" field in the official Belgian Peppol Authority (BPA) Specific Requirements document was explicitly set to "No." This means Access Points active in a market now subject to a mandatory e-invoicing obligation since January 2026 could operate without any formal information security certification.
MC200 closes that gap permanently.
What This Means for ISVs Embedding Peppol Connectivity
If your platform embeds a Peppol Access Point via a "Peppol as a Service" component or a third-party AP provider, you inherit that AP's compliance obligations, at least operationally. An AP that loses its OpenPeppol accreditation on July 1, 2027 takes your invoice flows down with it.
The due diligence questions to ask your AP provider now:
- Do you hold ISO 27001 certification, and does the scope explicitly cover your Peppol services?
- When is your next surveillance or renewal audit?
- How does your roadmap address the MC200 mandate from December 10, 2025?
Vague answers are their own signal.
What ISO 27001 Actually Requires
ISO 27001 is not a technical checklist. It is a full Information Security Management System (ISMS): access governance, risk management, business continuity planning, incident response procedures, and annual third-party audits conducted by an accredited certification body. The scope must cover the relevant service activities, so a certificate that does not explicitly include Peppol services is not sufficient.
Certification is not a one-time exercise. It requires annual surveillance audits and a full recertification cycle every three years. Organizations that have never been through the process typically need 6 to 12 months from gap assessment to certificate, depending on their size and existing security maturity. Belgian APs starting the process now, in mid-2026, are within the window. Those waiting until H2 2026 are not.
An Open Question: Does the TPM Route Survive MC200?
The MC200 decision uses the phrase "mandatory certification." That language suggests the actual ISO 27001 certificate, not a TPM equivalent, is what is required. However, some national Peppol Authorities, including the NPa in the Netherlands, currently accept the TPM as a substitute. Whether the global MC200 mandate eliminates the TPM route or leaves it as a national-level option post-2027 is not yet publicly clarified by OpenPeppol. This matters for any AP provider considering the TPM path as a shortcut. Direct confirmation from OpenPeppol is worth getting before committing to that approach.
Where Iopole Stands
Iopole holds ISO 27001 certification covering its full operations, including its Accredited Platform (PA) infrastructure for the French mandate and its Access Point services in Belgium. That certification predates the MC200 decision and is maintained through regular audit cycles. The scope explicitly covers Peppol services.
ISVs and software vendors building on Iopole's infrastructure have nothing to do here. Compliance with the July 2027 global requirement is already in place.


