Do you mainly use Peppol for invoicing? Then you do not need to delve into this: your software vendor or service provider arranges the Access Point for you. What is Peppol? and Forms of e-invoicing are more relevant for you.
Network access
The Access Point is the functionality that gives software access to the Peppol network: validating, looking up, securing and sending.
Under the control of a service provider
An Access Point always runs under the responsibility of a service provider that is a member of OpenPeppol and has an agreement with a Peppol Authority.
Build or integrate
Software vendors can become a service provider themselves, or integrate the Access Point functionality of a specialist into their package.
What exactly is an Access Point?
Compare Peppol to the mobile phone network. You make a call with an Apple phone, the person you are calling answers on a Samsung, and you are both with a different provider. Yet the call goes through. That is because telecom providers are connected to each other’s networks according to fixed international agreements.
In that comparison, the Access Point is the provider’s network access: the part of the infrastructure that determines who may enter the network, converts the signal to the network standard, looks up where the other party can be reached and routes the call to the other provider. It is not a separate device that you buy. It is a functionality that a provider offers.
In Peppol, your accounting or ERP package is the phone, the service provider is the telecom operator, and the Access Point is the network access that the operator arranges for you.
Important clarification: An Access Point is a functionality, not an organization. The service provider is the party that offers this functionality and is responsible for it towards OpenPeppol and the Peppol Authority, just as a telecom operator is responsible for its network connections.
What does an Access Point do?
The tasks of an Access Point
- Receive: take over the document from the sender’s software.
- Validate: check whether the document complies with the Peppol specifications.
- Look up: use the central address book (SML) and the recipient’s profile (SMP) to determine where and in which format the recipient can be reached.
- Secure: sign and encrypt the message with a Peppol certificate.
- Send: send the message to the recipient’s Access Point via the AS4 transport protocol.
- Confirm: technically confirm receipt, so that the sender knows the message has arrived.
What the service provider also arranges
The service provider verifies the identity of every sender and recipient it connects. In the phone comparison, this is the registration of your SIM card. In addition, it registers its customers in the network, reports statistics to OpenPeppol and provides support. It often also delivers additional services, such as archiving or conversion.
Access Point versus service provider
The difference between the functionality and the organization that offers it, at a glance:
| Aspect | Access Point | Service provider |
|---|---|---|
| What is it? | Functionality: the network access | Organization that offers that functionality |
| Responsible for | Validation, lookup, security and transport of messages | Identity verification, registration, reporting, support and compliance with the agreements |
| Agreements and certificate | Runs with a Peppol certificate issued to the service provider | Is a member of OpenPeppol and signs the service provider agreement with the Peppol Authority of the country where it is established |
| Who do you contact? | Not directly | Your service provider |
Practical example: A phone manufacturer does not build its own telecom network. It makes sure its device works on every network. In the same way, a software vendor does not need to build its own Access Point: it can integrate the network access of a specialized service provider into its package. If it does want to become a network operator itself, that is also possible, but it then takes on all the obligations of a service provider.
Three routes for software vendors
Route A: become a service provider yourself
Route B: integrate Access Point functionality
Route C: hybrid
Which route suits you?
Whether you become a service provider yourself or integrate the functionality is a strategic choice. These factors carry the most weight:
- Role of e-invoicing in your proposition: is it a core feature with which you want to differentiate yourself, or a requirement that simply has to work?
- Customer base and volume: with a large customer base and high volumes, your own Access Point can become cheaper in the long run. With smaller numbers, the fixed management burden weighs more heavily.
- Countries and specifications: each Peppol Authority can impose its own additional requirements, and outside Europe separate invoice models apply. The more countries, the greater the maintenance burden.
- Operational capacity: a service provider must run reliably all year round, renew certificates on time, implement new versions of the specifications, identify customers and report periodically to OpenPeppol.
- Time-to-market: via a specialist, you are usually live within weeks. Your own track with membership, agreement and test environment takes considerably longer.
- Dependency and exit: when integrating via a specialist, you want to agree in writing how you can take your customers with you if you later switch or become a service provider yourself.
- Other channels: do your customers also need EDI or closed networks? Then a specialist that bundles multiple channels may be more attractive than your own Access Point for Peppol only.
Typical profiles
An accounting package for SMEs in one or a few countries usually chooses integration (route B): live quickly, with focus on its own product. A software vendor with a large, international customer base for which e-invoicing is a core proposition is more likely to consider route A or C. ERP vendors and integration partners often combine: their own role for the main markets and a specialist for the rest.
For the technical experts: how does it work?
Transport: Access Points exchange messages via the Peppol AS4 profile, based on the AS4 profile of the European eDelivery building block. Each message is wrapped in a standardized envelope: the Peppol Business Message Envelope, based on the Standard Business Document Header (SBDH).
Addressing and lookup: recipients are found via the SML, a central, DNS-based reference, and the recipient’s SMP. For each participant, the SMP publishes which document types and processes they can receive, at which address and with which certificate. Participants, document types and processes are identified according to the Peppol rules for identifiers and the Peppol code lists.
Security: Access Points and SMPs work with Peppol certificates, issued by the Peppol certificate authority, with separate certificates for test and production.
Content: e-invoices follow Peppol BIS Billing 3.0, an implementation of the European standard EN 16931 in UBL. Outside Europe, the international invoice model PINT is used. The validation rules (Schematron) are publicly available on GitHub.
Connecting as a service provider: membership of OpenPeppol, the service provider agreement with the Peppol Authority in the country of establishment, a test certificate, the mandatory AS4 tests in the Peppol test environment, and then a production certificate. OpenPeppol describes this step by step in How to set up a Peppol Access Point.
Ongoing obligations: identity verification of senders and recipients (Internal Regulations Part II, §3.3.1), mandatory statistics reporting (EUSR and TSR, since 1 January 2024), and the timely implementation of new versions of the specifications and certificates.
Documentation: the specifications are available on docs.peppol.eu, policies and rules on peppol.org, the validation rules on GitHub (OpenPEPPOL), and working documents on OpenPeppol’s Confluence environment (partly for members only).
For end users: your service provider takes care of all of this.
Choosing an Access Point partner as a software vendor
Are you opting for integration (route B or C)? Then pay attention to:
API and documentation
Document types, countries and invoice models
Identity verification and registration
Own brand
Obligations
Exit
Pricing model and availability guarantees
Future
See in the comparison tool on peppol.nu which providers offer a Peppol Access Point or Access point as a Service.
View the comparison tool


