The role in the four-corner model
Peppol works on the four-corner model: sender, their provider, the recipient's provider, recipient. The two middle corners are the access points.
1Sender ──► Access Point A ──► Access Point B ──► RecipientAn access point is therefore not optional plumbing but the ticket in. The framework deliberately foresees no direct attachment for individual companies — that is the mechanism that makes it scale: rules, certificates and liability sit with a manageable number of providers rather than with hundreds of thousands of participants.
What an access point actually does
Take documents in. From your system, over an interface, a portal or a file handover.
Resolve addressing. Determine from the recipient's participant identifier which access point the document belongs to — through SML and SMP.
Pass it on. By the prescribed protocol, with the prescribed certificates, to the counterpart.
Return acknowledgements. The framework has technical confirmations: was the document accepted? The access point surfaces that feedback for you.
Register you in the directory. Your identifier, with the document types you accept, in an SMP. Without that entry you are unreachable.
🔵 What an access point is not: an accounting system, an archive or an invoice review. It transports. The duty to keep the structured original in an audit-proof way stays with you.
Certification is checkable
Access points are certified and listed in a publicly visible directory. That is more than a formality — it is the reason you can hand documents to a provider you do not otherwise know.
🔴 Check the entry rather than believing the claim. "Peppol-capable", "Peppol-ready" or similar wording on a website is not certification; providers who are themselves attached through a third party use those phrases too. That can be perfectly fine — you should simply know it.
What to look at when choosing
Who owns the participant identifier? The most important question, and the one asked least. Your identifier should be tied to your company so a change remains possible without trading partners having to record a new address.
Which document types? Invoice and credit note are the start. Anyone working with the public sector will sooner or later need order or order response too.
How do failures come back? A rejected delivery nobody notices is worse than no delivery at all. Ask how you learn that a document did not arrive — and whether that happens automatically.
What does the interface look like? A portal somebody uploads files into is fine for ten invoices a month and not for a thousand.
Where is data processed? Invoice data is business data and contains personal details. Place of processing and retention period belong settled before the first document flows.
What you can prepare regardless
Attaching to a provider is an organisational decision. The document is not.
Generating Peppol BIS Billing 3.0 and checking it against its rule set can be implemented independently of the route the delivery later takes. Doing that first shortens the attachment to a configuration question later — instead of handling format work and provider selection at the same time.
The current state of our own Peppol gateway is on the roadmap.