Peppol · · 5 min read

Peppol Software Providers: How to Choose the Right Access Point & SMP for E-Invoicing (2026 Guide)

Peppol software providers explained: the types of provider, what a certified Access Point and SMP do, and how to choose the right one for e-invoicing.

Peppol software providers, in one sentence

A Peppol software provider is any vendor that lets your business exchange invoices and other documents over the Peppol network — but the label covers several very different things, and only some of them can legally transmit on the live network. Getting the distinction right is the difference between a clean, one-time integration and a stack of overlapping tools that still leaves you non-compliant.

This guide maps the landscape: the types of Peppol software provider, what a certified Access Point and SMP actually do, and the criteria that separate a safe provider from a risky one. If you have already shortlisted vendors and want a scoring checklist, read how to choose a Peppol Access Point next — this article is the wider map.

The four kinds of "Peppol provider"

The term gets used loosely. In practice you are looking at four layers, and a good provider covers more than one of them:

  • Certified Access Points (AP). The party that actually sends and receives your documents over the Peppol AS4 transport, and validates them before transmission. This is the only layer that must be certified to operate on the live network. See what a Peppol Access Point is.
  • Service Metadata Publishers (SMP). The service that publishes your participant registration so other parties can discover you on the network. Also certified. A provider that runs its own SMP can register and manage your identity directly, rather than depending on a third party.
  • ERP-embedded connectors. A module inside your accounting or ERP system (SAP, Oracle, Microsoft Dynamics, Odoo, and others) that formats invoices and hands them to an Access Point. Useful, but it is not itself on the network — it needs an AP behind it.
  • Middleware / API platforms. A layer that sits between your finance systems and the network, normalising data, mapping fields, handling retries and status, and exposing a single API. This is where multi-country complexity is absorbed.

The key mental model: the ERP or middleware prepares the document; the certified AP and SMP put it on the network. A "Peppol provider" that is only a connector, with no certified transmission behind it, is an incomplete solution.

Certification is the gate — verify it yourself

Only certified Access Points and SMPs may operate on the live Peppol network. Certification is issued through OpenPeppol, and every legitimate provider is listed on the OpenPeppol public directory with its provider ID. Treat this as a hard gate before you evaluate anything else:

  1. Search the provider on the public directory.
  2. Confirm it is listed as a certified Access Point (and, ideally, SMP).
  3. Note the provider ID — you will reference it during onboarding.

If a vendor cannot be found and confirmed, nothing else about the pitch matters. A reseller or connector can be perfectly legitimate, but there must be a certified Access Point named somewhere in the chain.

Country coverage is where most selections go wrong

Peppol is not one uniform format. Each jurisdiction layers its own profile, validation rules, and sometimes a tax-clearance step on top of the baseline:

A provider limited to the EU baseline simply cannot serve a PINT-profile or clearance-model country. If you trade — or plan to trade — across several markets, coverage is the single most important selection factor, because it determines whether you integrate once or re-integrate per country. For the deeper distinction between the baseline and national profiles, see Peppol vs PINT.

What separates a safe provider from a risky one

Beyond certification and coverage, weigh these:

  • Validation before transmission. A good provider validates against XSD, EN16931 business rules, code lists, and the relevant national Schematron before sending — so errors are caught as feedback, not as a rejected legal document. See invoice validation errors you can prevent.
  • In-house SMP. A provider that runs both AP and SMP can publish and manage your participant registration directly, shortening onboarding and removing a coordination dependency.
  • One API for all markets. Multi-country businesses should not integrate a different endpoint per country. A single, well-documented API that abstracts the profiles is what keeps growth cheap. See one API for multi-country e-invoicing.
  • A real test bed. You should be able to validate and send test documents in a sandbox before go-live, ideally with the same code you will run in production. (We cover this in depth in the companion guide on the Peppol test bed.)
  • Security and continuity. Look for ISO/IEC 27001 and 22301, encryption in transit and at rest, tenant isolation, and a clear uptime SLA.
  • Transparent pricing. Ask for the all-in cost for your actual volume and markets — not a headline per-document rate that hides setup, per-country, or overage charges.
  • Support with defined SLAs. Response and resolution targets, an escalation path, and, where mandates are local, in-country support.

Questions to ask any Peppol software provider

Use these in a first call to separate substance from marketing:

  • Are you a certified Access Point — and an SMP — and what is your provider ID on the OpenPeppol directory?
  • Which countries and document profiles do you support in production today?
  • Do you validate before transmission, and against which rule sets?
  • Is it one API for all markets, and how is tenant data isolated?
  • Do you provide a test bed / sandbox, and does test code move to production unchanged?
  • What are your uptime and support SLAs, and how do you handle mandate changes?
  • What is the all-in price for my volume and my markets, including setup and any per-country fees?

Where GoRoute fits

GoRoute is a certified Peppol Access Point and SMP (provider ID POP000991), run in-house — no third-party broker in the network path — with production coverage across multiple markets from a single API, layered validation before transmission, ISO/IEC 27001 and 22301 certification, and a sandbox test bed you can build against before go-live. If you are evaluating providers, book a call with our team or start with the onboarding checklist for finance teams.

Choosing a Peppol software provider is a compliance decision as much as a procurement one. Get certification and country coverage right first; let everything else follow.

Frequently asked questions

What are Peppol software providers?
Peppol software providers are the vendors that let you send and receive documents over the Peppol network. The category spans certified Access Points (which transmit on the network), Service Metadata Publishers (which register your participant identity), ERP-embedded connectors, and middleware or API platforms that sit between your finance system and the network. Only certified Access Points and SMPs may operate on the live network; everything else is software that connects to one.
How do I find a certified Peppol provider?
Verify any provider on the OpenPeppol public directory at directory.peppol.eu. A legitimate Access Point or SMP is listed there with its provider ID. If a vendor cannot be found and confirmed as certified, it cannot legitimately transmit on the live network on your behalf, regardless of what the sales page claims.
What is the difference between an Access Point and an SMP provider?
An Access Point (AP) is the party that actually sends and receives your documents over AS4 and validates them. A Service Metadata Publisher (SMP) publishes your participant registration so other parties can discover you. Some providers run both in-house, which shortens onboarding and removes a third-party dependency; others only run an AP and rely on a separate SMP.
Do I need a Peppol software provider if my ERP already supports Peppol?
Usually yes. Many ERPs ship a Peppol module, but the ERP still needs a certified Access Point behind it to reach the network, and often a country-specific profile (such as PINT OM or a national CIUS) plus a tax-clearance step the base module does not cover. The ERP handles the invoice; the provider handles compliant transmission.
How much do Peppol software providers cost?
Pricing models vary — per-document, tiered by monthly or annual volume, flat platform subscription, or a managed implementation plus subscription. Watch for hidden per-transaction fees, per-country charges, and separate setup or certification costs. Ask for the all-in cost for your actual volume and markets, not a headline per-document rate.
Can one provider cover multiple countries?
Yes, if the provider supports the document profiles and clearance models of each market you trade in. This is the single biggest selection factor. A provider limited to the EU baseline cannot serve Oman's PINT OM, a national CIUS, or a clearance-model country. Choose one whose coverage matches your current and planned markets so you integrate once, not per country.
How do I switch Peppol providers later?
You can migrate — your participant registration and integration move to the new provider — but it takes effort and coordination. Choosing a provider with broad country coverage, a stable API, and in-house SMP up front avoids most migrations, because growth into new markets becomes configuration rather than a change of provider.

Related posts

Building on Peppol?

GoRoute is a certified Peppol Access Point & SMP. Book a demo or read the docs to get started.

Book a demo Read the docs