News
August 5, 2026

OpenPeppol confirms Semansys meets its ISO/IEC 27001 requirement

OpenPeppol has confirmed that Semansys complies with its requirement on ISO/IEC 27001. The confirmation follows OpenPeppol’s review of the evidence supplied by Semansys for its Peppol service-provider activities.

Semansys already holds an ISO/IEC 27001 certification. OpenPeppol’s confirmation is therefore not a new ISO certificate and it is not a separate certification issued by OpenPeppol. It confirms that the evidence provided by Semansys satisfies the ISO/IEC 27001 requirement applicable to its participation in the Peppol ecosystem.

Peppol and OpenPeppol: framework and organisation

Peppol is the interoperability framework used to exchange standardised electronic business documents. OpenPeppol is the non-profit, member-driven international association responsible for developing, implementing and maintaining that framework.

The distinction matters. Peppol is not a portal and OpenPeppol does not provide an invoicing service to individual businesses. Organisations connect through a Peppol-accredited Service Provider. The shared document specifications, network rules and agreement structure allow different providers and different software systems to exchange documents consistently.

Peppol began in 2008 as a European pilot. When the project ended in 2012, OpenPeppol took over its services and responsibilities. The association is established under Belgian law and brings together public authorities, service providers, end users and observers. Its members contribute to the ongoing development of network, procurement, invoicing, continuous transaction control and logistics specifications.

How the four-corner model supports interoperability

The Peppol network uses a four-corner model. A sender connects to its chosen service provider, which exchanges the document with the receiver’s chosen service provider. The receiving organisation remains connected through its own provider. This means that buyer and supplier do not need to use the same platform or maintain a separate bilateral connection.

The model gives organisations freedom of provider choice while preserving a common method for addressing, capability discovery, document structure and secure transport. In practical terms, an organisation connects once through an accredited provider and can exchange supported documents with other Peppol-enabled organisations.

OpenPeppol’s governance role

Interoperability depends on more than a technical connection. OpenPeppol governs the Peppol Interoperability Framework, the specifications and central network components. Formal agreements define the responsibilities of Peppol Authorities and Service Providers, while common policies and change-management processes help ensure that requirements are applied consistently.

This combination of open specifications, accredited providers and binding governance is what allows the network to scale across sectors and jurisdictions. It also explains why assurance requirements for service providers matter: trust in the network depends on each operational participant managing its responsibilities in a controlled and demonstrable way.

Why this matters

Peppol enables organisations and public authorities to exchange structured electronic business documents through an interoperable network. Service providers are part of the infrastructure that makes that exchange possible. Information-security governance is therefore an essential part of dependable service delivery.

ISO/IEC 27001 provides a management-system framework for identifying, assessing and treating information-security risks. Certification does not mean that risk disappears. It provides independent evidence that an organisation operates a structured information-security management system and is subject to recurring review.

For customers and software partners, the OpenPeppol confirmation adds a clear assurance point: Semansys has demonstrated compliance with the ISO/IEC 27001 requirement that OpenPeppol applies to the relevant service-provider context.

Part of a wider control environment

Security is most effective when it is connected to service management, business continuity, quality management, supplier governance and day-to-day operational controls. Semansys manages these disciplines as parts of the same service environment supporting digital invoicing, regulatory reporting and digital identity.

That integrated approach is important for organisations that depend on regulatory digital infrastructure. They need reliable document exchange, traceable processing and clear responsibility when requirements, systems or circumstances change.

What customers can take from the confirmation

·   Semansys remains independently certified to ISO/IEC 27001.

·   OpenPeppol has confirmed compliance with its ISO/IEC 27001 requirement.

·   The confirmation relates to the applicable OpenPeppol requirement; it is not a new ISO certificate.

·   Customers can use the confirmation as an additional supplier-assurance input alongside the underlying certificate and other available audit evidence.

We thank OpenPeppol for reviewing and confirming our compliance.

Would you like to discuss how Semansys supports secure, interoperable e-invoicing and regulatory data exchange? Book a discovery call