Skip to content
Back to Kworia
peppolEU NEWS

OpenPeppol Approves Updated Security Policy, Expands Compliance Pathways

As of September 30, 2026, OpenPeppol's Managing Committee has approved an updated Security Policy that will replace Section 6 of Internal Regulations Part II. The policy introduces three new certification frameworks as equivalent to ISO/IEC 27001, broadening compliance options for Peppol network participants.

Kworia 2 min read AI-generated content — How this site is made
As of September 30, 2026, OpenPeppol's Managing Committee has approved an updated Security Policy that will replace Section 6 of Internal Regulations Part II. The policy introduces three new certification frameworks as equivalent to ISO/IEC 27001, broadening compliance options for Peppol network participants.

Key takeaways

  • OpenPeppol's updated Security Policy, approved on September 30, 2026, will replace Section 6 of Internal Regulations Part II.
  • The policy introduces three new certification frameworks as equivalent to ISO/IEC 27001, providing broader compliance options.
  • The policy is currently in its integration phase, with implementation obligations forthcoming.

Context

The approval of the OpenPeppol Security Policy marks a significant governance milestone for the Peppol Network, which facilitates electronic invoicing and other business document exchanges across Europe. The policy is currently in its integration phase, indicating that while the approval has been granted, the full implementation and enforcement mechanisms are still under development. This update follows a consultative process that included member reviews, although the specifics of those comments are not publicly detailed.

The Peppol Network operates under strict security and compliance protocols, which are crucial for its role in facilitating cross-border digital transactions. The existing Section 6 of Internal Regulations Part II has governed network security obligations for Peppol service providers and participants. The new policy aims to modernize these regulations, reflecting evolving cybersecurity standards and practices.

What's Changing

The novel element of this approval is the formal recognition of three certification frameworks as equivalent to ISO/IEC 27001 under the new Security Framework:

  • BSI IT Grundschutz: The German Federal Office for Information Security's baseline protection methodology.
  • CyFun Essential: The Belgian Centre for Cybersecurity's Cyber Fundamentals framework.
  • eIDAS Qualified Trust Service Provider (QTSP) certification: An EU-wide framework for trust services.

This equivalency list is significant because it broadens the compliance pathways available to Peppol Access Point providers and other network participants. Previously, obtaining ISO/IEC 27001 certification was a requirement for demonstrating adequate security measures. The new policy allows participants operating in Germany, Belgium, and EU trust-service contexts to meet security obligations through these alternative certifications.

Implications for Peppol Network Participants

The updated Security Policy provides several practical benefits for Peppol network participants:

  • Compliance Flexibility: Participants can choose from multiple certification frameworks that best fit their operational context, reducing the need for additional certifications.
  • Regional Alignment: The inclusion of BSI IT Grundschutz and CyFun Essential aligns the policy with national cybersecurity standards in Germany and Belgium, respectively.
  • EU-Wide Recognition: The eIDAS QTSP certification provides a harmonized pathway for trust service providers across the EU.

However, participants should note that the policy is currently in its integration phase. While the approval has been granted, the specific implementation obligations and timelines are forthcoming. Participants should monitor updates from OpenPeppol to ensure timely compliance with the new requirements.

Outlook and What to Watch

The integration phase of the OpenPeppol Security Policy will be a critical period for stakeholders. Key developments to watch include:

  • Implementation Timeline: The release of specific deadlines and steps for integrating the new policy into existing compliance frameworks.
  • Guidance Documents: The publication of additional guidance or FAQs to clarify the equivalency criteria and application processes for the new certification frameworks.
  • Member Feedback: Any further updates or adjustments based on ongoing member reviews and feedback.

As the Peppol Network continues to evolve, these updates will play a crucial role in maintaining its position as a leading platform for secure digital transactions across Europe.

Frequently asked questions

What are the three new certification frameworks recognized by OpenPeppol?
The three certifications are BSI IT Grundschutz (Germany), CyFun Essential (Belgium), and eIDAS Qualified Trust Service Provider (QTSP) certification.
How does this policy change affect existing Peppol network participants?
Participants will have more flexibility in meeting security obligations, as they can now choose from multiple certification frameworks that align with their operational context.
When will the full implementation of this policy take effect?
The policy is currently in its integration phase, with specific deadlines and steps for implementation expected to be announced in the near future.
Are there any specific requirements for participants operating outside of Germany and Belgium?
The policy provides a harmonized pathway through the eIDAS QTSP certification, which is recognized across the EU.
What should participants do to prepare for these changes?
Participants should monitor updates from OpenPeppol and review the new compliance pathways to ensure timely adherence to the updated security obligations.
Share: X LinkedIn Email

Related articles

OpenPeppol has introduced a new Peppol Lookup Service, enabling real-time verification of participant publication status on the Peppol network. This tool addresses long-standing operational uncertainties caused by asynchronous Directory propagation delays, benefiting Service Providers and technical implementers involved in e-invoicing workflows.
peppolEU NEWS

OpenPeppol Launches Real-Time Participant Lookup Service

OpenPeppol launched the Peppol Lookup Service on September 14, 2026, enabling real-time verification of participant publication status on the Peppol network. The service addresses asynchronous Directory propagation delays and reduces friction in EU e-invoicing compliance workflows for Service Providers and technical implementers.

2 min read