ISO 27001 becomes mandatory for Peppol service providers

Peppol ISO 27001

Key takeaways

  • What? ISO 27001 certification is becoming mandatory for Peppol service providers.
  • Who? All Peppol service providers worldwide, regardless of which country they operate in.
  • Why? To guarantee a single international security standard across the entire Peppol network, instead of a patchwork of national requirements.
  • Mandatory from when? From 1 July 2027.
  • Introduced by whom? OpenPeppol took this decision on 13 July 2026.

Are you a Peppol service provider? Then an ISO 27001 certificate will become mandatory from 1 July 2027. Certification will be a hard condition for staying active on the network. If you don’t yet hold the certificate, the clock is ticking. In this blog, you’ll find out what you need to know now as a Peppol service provider, and why waiting will end up costing you more.

Why Peppol service providers, and why now?

Peppol turned the world upside down in 2026. Since 1 January 2026, every VAT-liable organisation in Belgium has had to send and receive its B2B invoices digitally and in a structured format via the Peppol network. Paper or PDF invoices? A thing of the past. Businesses had to overhaul their invoicing systems at speed. Peppol service providers, also known as Peppol Access Points, play a crucial role in this as the gateway to the network.

That makes them both a crucial and a vulnerable party in a highly important process for the business world. For that reason, OpenPeppol, the non-profit organisation that manages the Peppol network, is making ISO 27001 certification mandatory for Peppol providers from 1 July 2027.

From a patchwork to a single standard

Until now, security requirements differed from country to country. The Netherlands had long required an ISO 27001 certificate, or a statement from an independent IT auditor demonstrating that security meets the standard. Belgium applied a more flexible framework, while other countries imposed yet other requirements. OpenPeppol has now put an end to that fragmented patchwork.

OpenPeppol is the international non-profit organisation that manages the Peppol network and sets the rules for everyone who uses it. To operate as a Peppol service provider, you will now need to meet three conditions:

  • Membership of OpenPeppol
  • Support for the Peppol Business Interoperability Specifications (BIS) and the Service Metadata Publisher (SMP)
  • The ability to provide an ISO 27001 certificate

If you are not yet certified, a transition period with temporary minimum requirements applies, so the network doesn’t suddenly lose providers who are still in the process of certification.

What is the timeline?

OpenPeppol is following a phased approach with interim milestones, so this remains a feasible project even if you haven’t started certification yet. This allows both OpenPeppol and service providers themselves to keep track of progress.

Date

Milestone

31 July 2026

Deadline to request equivalence for other security certifications (this deadline has now passed)

1 September 2026

Deadline for submitting already obtained ISO 27001 certificates

1 October 2026

Submission of evidence of an ongoing certification process

January 2027

New service providers will only gain access to the production network if they are already certified, or can provide a complete pre-audit package

1 May 2027

First progress report on the certification process

1 August 2027

Second progress report on the certification process

1 October 2027

ISO 27001 certification becomes fully mandatory for all active Peppol service providers

This phasing makes clear from the outset that ISO 27001 is not a formality you can sort out at the last minute. But what does the standard actually involve?

What is ISO 27001, exactly?

ISO 27001 is the international standard for information security. It describes how an organisation systematically identifies, manages and continuously improves information security risks, following the PDCA principle (Plan, Do, Check, Act). The standard is based on a wide range of controls. An independent certification body verifies, through an external audit, whether you genuinely meet the standard.

Curious about the detail behind the ISO 27001 standard? Read more about it here.

 

What does this mean in practice for you as a Peppol service provider?

If you already hold an ISO 27001 certificate, little will change in practice. Do check carefully whether the scope of that certificate covers your full Peppol activity: a certificate that covers your whole organisation doesn’t automatically mean it fully covers your role as a Peppol service provider.

If you’re still at the starting point, you have roughly a year to complete the process. That’s a tight but achievable deadline. A certification process usually takes six to twelve months, provided you approach it in a structured way and with the right priorities.

Those who start now will comfortably meet the deadline. Those who still need to begin in 2027 are playing Russian roulette with their Peppol membership.

The biggest pitfall is often the timing of when you start. Those who wait until a few months before the deadline risk being unable to schedule the internal and external audit in time, or discovering along the way that more work remains than the time available allows.

How Cingulum helps you with this

We support organisations in building an ISMS that not only delivers the certificate, but genuinely works in day-to-day practice. Our approach follows clear steps within our “journey”:

This way, you work steadily towards the deadline, without it turning into a race against the clock.

Start your journey with a 50% subsidy

Are you a Flemish SME? Then you could receive up to 50% subsidy on part of your ISO 27001 process. As a recognised VLAIO service provider, Cingulum can offer a Cybersecurity Improvement Programme for this purpose.

So don’t wait until the deadline gets closer, but get support from a specialist. Want to know how much of your ISO 27001 process is eligible for subsidy? Cingulum will work it out for you. Get in touch with Cingulum for a no-obligation conversation about your path to certification.

Subscribe op onze nieuwsbrief

Ontvang updates rond onze blogs, events en meer.


Cingulum doet er alles aan om je privacy te beschermen en te respecteren. Je kunt je op elk moment afmelden voor onze mailings. Voor meer informatie over hoe wij jouw gegevens verwerken, lees ons privacybeleid.

More To Explore

Maak kennis met ons.

Plan een vrijblijvend kennismakingsgesprek in met een van onze experts. Samen zoeken we naar de beste securityoplossing voor jouw organisatie.

Consultants working together