Australian accreditation process for Peppol service providers

OpenPeppol are introducing a mandatory security requirement – all accredited Peppol service providers must hold a valid ISO/IEC 27001 certificate, or an equivalent certification, by 1 October 2027. For more information read step 4 of the accreditation process.

On this page

About Peppol service providers

Peppol service providers are integral to the Peppol framework. They support the secure transmission of eProcurement documents between buyer’s and supplier’s software through the Peppol network.

They do this by providing one or both of these functions:

  • Access point – Access points are gateways that connect business through their software to the Peppol network, allowing them to send and receive documents including eInvoices.
  • Service metadata publisher (SMP) – SMPs publish the capabilities of a business to receive documents, so others on the network can look them up and then connect.

All Peppol service providers are members of OpenPeppol.

For more information for, and about, Peppol service providers visit OpenPeppol’s Guidance for service providers.

Why accreditation matters

The Australian Taxation Office (ATO), as the Australian Peppol Authority, sets the requirements for Peppol service providers to be authorised to operate in Australia. The Australian Peppol Authority Specific Requirements are in place to:

  • protect the interests of end-users and other Peppol service providers
  • ensure interoperability of the Peppol network and the ability to send and receive valid A-NZ eInvoices
  • mitigate against security risks to the network.

All Peppol service providers accredited to operate in Australia and hold a PKI production certificate from OpenPeppol are listed on the Peppol service provider register.

Who should apply

If you want to provide Peppol access point or SMP services in Australia you must apply for Australian accreditation.

If you are a Peppol service provider accredited overseas but would like to operate in Australia you must apply for Australian accreditation.

If you are a business and only intend to send or receive eInvoices, you do not need to apply for accreditation. Instead, you can connect to the Peppol network through an already accredited Peppol access point, or by using an eInvoicing Ready software product or service provider.

Mutual accreditation with New Zealand

The Australian and New Zealand Peppol Authorities have an aligned accreditation process that supports mutual accreditation of Peppol service providers.

If you are accredited in New Zealand, you may apply for mutual accreditation in Australia. Find out more about how to do this by contacting us at eInvoicing@ato.gov.au.  

If you are already accredited in Australia, you can request mutual accreditation in New Zealand by contacting the New Zealand Peppol Authority at support@nzpeppol.govt.nz.

Before you apply

If you are not already an OpenPeppol member you should become one. Note that OpenPeppol charges an annual membership fee.

You should become accredited in your ‘home’ country first. You can contact OpenPeppol to help you determine which Peppol Authority you should complete accreditation with first. 

Before starting the accreditation process with us, you should understand the technical, legal, and policy framework of Peppol and our Australian-specific requirements by reviewing the resources listed below.

Peppol technical and policy documents

Australian technical and guidance documentation

Questions

If you have any questions before applying, contact us through our Online Services for DSPs or email eInvoicing@ato.gov.au

Accreditation steps

There are 6 accreditation steps. How long this process takes is largely depends on how ready you are to complete it.

1. Submit an application

Start by submitting an application:

2. Sign a legal agreement

The Peppol Service Provider Agreement is a legal agreement outlining the roles and responsibilities for Peppol service providers, and the Australian Peppol Authority.

If Australia is your home Peppol Authority

Provide a signed copy of the Peppol Service Provider Agreement to the Australian Peppol Authority. A countersigned copy will be returned once all other steps of accreditation have been completed.

If Australia is not your home Peppol Authority

Provide a countersigned copy of your Peppol Service Provider Agreement that was returned to you by your home Peppol Authority.

3. Pass due diligence checks

To protect the interests of end users and the other Peppol service providers operating in the network, we will use the information in your application to complete due diligence checks including confirming:

  • you are a registered business
  • you are not insolvent
  • that senior office holders are not banned, disqualified or bankrupt, and pass a criminal record check if required.

Evidence of an enforceable professional indemnity insurance policy equivalent to at least A$1 million (per occurrence) must also be provided. We recommend you consider the risk of damage extending to other network participants, and determine if you need a higher level of coverage.

4. Meet security requirements

New security requirements

OpenPeppol has introduced a mandatory security requirement – all certified Peppol service providers must hold a valid ISO/IEC 27001 certificate, or an equivalent certification, by 1 October 2027.

Important dates

Under the OpenPeppol implementation plan:

  • before 1 January 2027: service providers issued their first Peppol PKI production certificate on or before 31 December 2026 must obtain ISO/IEC 27001 certification no later than 1 October 2027
  • from 1 January 2027: service providers will only be issued a first Peppol PKI production certificate if they already hold a valid ISO/IEC 27001 certification or an OpenPeppol-approved equivalent certification. 

For more information about these changes including the scope, how to submit documentation and milestone dates read the OpenPeppol ISO/IEC 27001 Implementation plan. 

Submit a security questionnaire

Complete and submit the A-NZ eInvoicing Security Questionnaire.

Security control requirements include:

  • self-assessment or independent audit against ISO/IEC 27001 or ASD/NZ ISM, which includes suitable evidence for:
    • encryption key management
    • network segregation
    • audit logging
    • patch and vulnerability management program
    • information security awareness, education and training
    • physical and environmental security
    • operational procedures and responsibility
    • system acquisition, development and maintenance, including secure coding practices
    • system access control
    • personnel security
    • backup
  • encryption at rest
  • security monitoring practices
  • encryption in transit (access points only)
  • multifactor authentication (access points only).

For more detail read the A-NZ Information Security Guidance Note.

5. Test your service

You must complete testing to verify your service offering conforms to Peppol specifications and additional local A-NZ requirements. These 3 steps must be completed in order:

  1. Unit testing.
  2. Peppol acceptance testing.
  3. Interoperability testing using Peppol Testbed.

Note: Peppol service providers already accredited in another jurisdiction only need to complete interoperability testing using Peppol Testbed.

1. Unit testing

Complete unit testing in an internal environment to verify that your service can send and receive Peppol BIS documents in line with the eDelivery documentation.

Obtain the test PKI certificate

Obtain the test certificate via the OpenPeppol Jira Service Desk portal.

On the portal main page, select ‘PKI Certificate Request’ and choose ‘test’ at the certificate purpose option. Complete the remaining fields and include any attachments as needed such as your company registration details.

Once OpenPeppol approves, a test certificate will be available for download within 10 days. Certificates not downloaded in time will expire and a new service desk request will need to be raised to reissue the certificate.

2. Peppol acceptance testing – eDelivery network compliance (access points only)

Peppol acceptance tests are conducted in the Peppol Testbed and formally tests compliance with the Peppol eDelivery Network specifications. You may complete this without OpenPeppol intervention, using your test PKI certificate as a log on to enter the central Testbed.

Acceptance testing involves:

  • verification of certificates (both the Peppol and TLS certificate)
  • validating sending and receiving business documents to and from the test access point
  • generating acknowledgement of the documents sent.

For more about this testing read OpenPeppol Test and Onboarding (PDF, 1.6MB). For more about the testing environment read the eDelivery test suite environment description (PDF, 334KB).

Once completed, submit the test results via the OpenPeppol Jira Service Desk portal. On the portal main page, select ‘Test and Onboarding’ and complete the remaining fields. OpenPeppol will advise if they accept the test results. Send us a copy of this via Online services for DSPs or eInvoicing@ato.gov.au.

3. Complete interoperability testing

You must complete interoperability testing to ensure you can send and receive valid PINT A-NZ documents. In the Peppol Testbed, use the Australia/New Zealand Test Suites.  

These suites cover the current effective PINT A-NZ specifications - Billing (mandatory) and Self-billing (optional). Before a new version of the PINT A-NZ specifications is released, the Testbed will be updated to include both current effective and the newly published but not yet effective versions. 

For accreditation, you must complete the test suite for the current effective PINT A-NZ Billing specification. Instructions are on the PINT A-NZ Testbed homepage.  When you successfully complete the test suite, a downloadable report is generated. Provide a copy of this to us via Online services for DSPs or eInvoicing@ato.gov.au.

6. Receive accreditation

All Peppol service providers

Once steps 1–5 of the accreditation process are completed, we will confirm your accreditation in Australia. We will ask you to confirm details for:

Australian Peppol service providers ONLY

We will return a countersigned copy of the Peppol service provider agreement.

To begin transacting in the Peppol network you will need to request a production certificate from the OpenPeppol Jira Service Desk portal. Select ‘G3 PKI Certificate Request (Remember mandatory attachments)’, then complete the remaining fields.

Once OpenPeppol approves your certificate, you must download it within 10 days. Certificates not downloaded in time will expire and you will need to lodge a new Service Desk request to have the certificate reissued.

Accreditation annual review

To ensure all Australian accredited Peppol service providers continue to meet their obligations, your accreditation will be reviewed annually. The Australian Peppol Authority will ask you to provide the following evidence:

  • A current professional indemnity insurance policy of at least A$1 million (or equivalent) per occurrence
  • Continued adherence to A-NZ eInvoicing security requirements by completing section A of the A-NZ eInvoicing Security Questionnaire
  • Reviewing your evidence to ensure it aligns with the current security requirements and is up to date, and submitting updated evidence where required
  • Any changes to your business or product environment.

Contact us

If you have any questions email eInvoicing@ato.gov.au.

 

Last modified date