ISO/IEC 27001 Implementation plan
On 24 June 2026, the Managing committee approved the final version of the ISO/IEC 27001 Implementation Plan.
Based on the comments received during the member review, several changes were made to the Implementation Plan. You are advised to thoroughly read the full Implementation Plan.
Most important operational changes:
Certification deadline
The MC recognizes that the timeframe is quite tight. As the final documentation has been made available three months later than planned, the MC decided that the certification deadline shifts with 3 months.
Therefore the certification deadline is set at 1 October 2027. All Service Providers are required to hold a valid ISO/IEC 27001 certificate, or an equivalent certification as of this date.
Submission of ISO/IEC 27001 certificate
Service Providers that are in the possession of an ISO/IEC 27001 certificate need to submit this. The submission must include the following documents.
A copy of the current, valid ISO/IEC 27001 certificate
The Statement of Applicability, to ensure there are no exclusions from the scope as set by OpenPeppol.
The Service Provider Agreement, confirming that the certificate holder is the signatory legal entity
An attestation signed by the management of the Service Provider stating that the submitted certificate covers the scope as set by OpenPeppol
Service Providers that have already submitted their certificate should submit the remaining required documents via the same ticket used for the certificate submission.