Why does security matter in e-invoicing?
Every e-invoice carries sensitive financial data: VAT numbers, bank details, pricing, and transaction volumes.
E-invoicing systems handle some of the most sensitive data a business produces: VAT registration numbers, bank account details, pricing structures, supplier relationships, and transaction volumes. That combination makes e-invoicing infrastructure a target for fraud, phishing and data theft.
The shift from paper and PDF to structured electronic exchange has multiplied both the volume of data in transit and the number of systems that touch it. Access points, clearance platforms, ERP integrations, and archiving services all become potential attack surfaces. A single compromised node can expose thousands of organisations' financial data.
As more countries have mandated e-invoicing, national authorities and network operators have attached security conditions to the platforms that carry it. Those conditions differ by jurisdiction, and since June 2026 they include a requirement that applies across the whole Peppol network.
What is ISO 27001?
ISO 27001 is the international standard for information security management systems (ISMS). The current version, ISO 27001:2022, replaced the 2013 edition, with the transition period for certificates issued against the 2013 edition ending on 31 October 2025. It is published jointly by ISO and IEC.
The standard is built around three pillars: confidentiality (only authorised people can access the data), integrity (data has not been tampered with), and availability (systems are up and running when needed). An organisation that holds certification has demonstrated, through independent audit, that it operates a management system addressing all three.
ISO 27001 is not a point-in-time assessment. It requires continuous improvement: regular risk assessments, internal audits, management reviews, and corrective actions. The certificate is valid for three years, with surveillance audits in years one and two, so the organisation must maintain its security posture year-round.
What does ISO 27001 cover?
11
Controls introduced for the first time in the 2022 revision
3 years
Certificate validity, with surveillance audits in years one and two
The 2022 edition defines 93 controls across four themes, a restructuring of the 2013 version's 14 domains.
Eleven controls are entirely new in the 2022 revision. Among the most relevant for e-invoicing platforms are Web Filtering (controlling access to malicious or inappropriate web content), Secure Coding (requiring secure development practices for software), and Threat Intelligence (actively monitoring for emerging threats). Other key areas include access control, data encryption at rest and in transit, incident response procedures, risk assessment methodologies, and compliance monitoring.
For an e-invoicing service provider, the controls cover areas such as encrypting invoice data in transit (AS4 with TLS), controlling who can access the SMP registry, logging all document exchanges for audit, and having a tested incident response plan for when things go wrong.
| Theme | Controls | Examples relevant to e-invoicing |
|---|---|---|
| Organisational | 37 | Policies, supplier relationships, incident management, compliance monitoring |
| Technological | 34 | Access control, encryption at rest and in transit, secure coding, logging |
| Physical | 14 | Facility access, equipment security, secure disposal of media |
| People | 8 | Screening, awareness training, responsibilities on termination of employment |
How hard is it to get certified?
Certification typically involves multiple teams (IT, legal, operations, HR, and senior management) working together over several months to document policies, implement controls, conduct a risk assessment, and run internal audits before an external certification body arrives for the formal audit.
The audit itself comes in two stages. Stage 1 reviews the documentation and readiness of the ISMS. Stage 2 is the on-site (or remote) assessment where auditors verify that the controls are actually implemented and effective. Gaps found during the audit must be remediated before the certificate is issued.
Annual surveillance audits check that the ISMS is still operating as described, and the full recertification cycle repeats every three years.
On the organisational side, OpenPeppol's implementation plan notes that the standard places explicit and non-delegable obligations on senior leadership, and that organisations treating certification as a technical workstream without sustained leadership engagement "regularly encounter this gap at the surveillance audit stage". The same document advises engaging a certification body at the earliest possible stage of the process.
Stage 1
Documentation and readiness review of the ISMS
Stage 2
On-site or remote assessment that controls are implemented and effective
Certificate issued
Valid for three years, once any gaps found at Stage 2 are remediated
Surveillance, year 1
Confirms the ISMS is still operating as described
Surveillance, year 2
The audit most often failed where leadership engagement has lapsed
Recertification
At the end of the three-year cycle, and the cycle repeats
Certification bodies must be accredited by a recognised national accreditation authority, and their audit slots are booked months ahead. For anyone working to a fixed deadline, the date the certification body can offer for Stage 2 is usually the binding constraint, not the pace of the internal work.
Peppol has made it mandatory network-wide
From 1 October 2027, every Peppol Certified Service Provider must hold a valid ISO/IEC 27001 certificate or an approved equivalent.
On 24 June 2026 the OpenPeppol Managing Committee approved the final ISO/IEC 27001 Implementation plan, making certification a condition of continued participation for every Peppol Certified Service Provider. The compliance deadline is 1 October 2027, moved back three months from the 1 July 2027 date that appeared in the draft circulated for member review.
The requirement is tied to holding a Peppol PKI Production certificate. Two further rules follow. From 1 January 2027, a new Service Provider will only be issued a first PKI Production certificate if it already holds a valid ISO/IEC 27001 certificate or an approved equivalent. Holding a certificate is also not sufficient on its own: the Statement of Applicability has to cover the end-to-end provision of the Peppol services operated under the Service Provider Agreement, and it has to name the legal entity that signed that agreement.
Providers running on a white-labelled or SaaS platform cannot rely on their host's certificate. Missing the deadline triggers a defined escalation that runs from a warning note through internal and public blacklisting to revocation of the PKI Production certificate and, finally, termination of the Service Provider Agreement.
Where else is ISO 27001 required?
National requirements came first, and they differ. Some require the certificate itself; others require assessment against the standard without the certificate.
The Netherlands requires the certificate itself, though it accepts a Third-Party Memorandum from an independent registered IT-audit company as an alternative. Australia and New Zealand do not require certification at all: their Peppol Authorities ask for a security questionnaire backed by evidence, which under the Australian accreditation process means self-assessment or independent audit against ISO/IEC 27001 or the ASD/NZ Information Security Manual.
France requires a security certificate for accredited platforms under its own regime, and since the July 2026 order it must be issued through an accredited certification chain; a certificate from an unaccredited certifier no longer counts, as the approved platforms decree explainer sets out. The DGFiP became a Peppol Authority on 8 July 2025, so French platforms operating as Peppol Service Providers now sit under both regimes.
| Regime | What is required | Certificate required? |
|---|---|---|
| Peppol, network-wide | ISO/IEC 27001, or an equivalent on the OpenPeppol list of allowable certificates, from 1 October 2027 | Yes, or an approved equivalent |
| Netherlands | ISO27001 certification applicable at least to the Peppol services, or a Third-Party Memorandum from an independent registered IT-audit company attesting an equal or better level of information security | Yes, or a TPM |
| Australia and New Zealand | Security questionnaire plus evidence under Guidance Note 03. Self-assessment or independent audit against ISO/IEC 27001 or the ASD/NZ Information Security Manual | No |
| France | Security certificate for accredited platforms, issued through an accredited certification chain | Yes |
Is it becoming a global requirement?
Across the Peppol network it now is. The 2026 decision replaces requirements previously set by each Peppol Authority with a single obligation, on the stated reasoning that "self-attestation and contractual commitments alone are not sufficient to manage this risk".
Outside Peppol the same plan points to NIS2 and DORA in the EU and comparable regimes in the United States, Singapore and Australia, several of which name ISO/IEC 27001 as the baseline for suppliers to critical public services.
For vendors operating on the Peppol network, the date to work to is 1 October 2027. Businesses assessing their own e-invoicing preparedness, including vendor and security requirements, can use the e-Invoice Readiness Scorecard for a structured review.
Sources: the OpenPeppol ISO/IEC 27001 Implementation plan, and the Peppol Authority Specific Requirements published for the Netherlands, Australia and New Zealand.
Explore e-Invoice.app
Real-time compliance data, peer discussions, and cross-functional tools for every stakeholder.
Compare Countries
Side-by-side comparison of mandates, timelines, and technical requirements.
Open Compare ModeFind the Right Vendor
Get matched with e-invoicing vendors for your countries and ERP.
Start vendor match