diff --git a/digital_postman_playbook.md b/digital_postman_playbook.md new file mode 100644 index 0000000..8e1a534 --- /dev/null +++ b/digital_postman_playbook.md @@ -0,0 +1,127 @@ +# Becoming our own Digital Postman (CPDS) — company playbook + +*Companion to `efaktura_2027_report.md`. Researched 2026-07-19. Goal: our company becomes an accredited "poskytovateľ doručovacej služby" (Digitálny poštár / CPDS) so our ERP backend pushes e-invoices directly into the Peppol network — no third-party middleman — and we can act as the delivery provider for all of our ERP customers.* + +--- + +## 1. What we are actually applying to be + +In the 5-corner model we would operate **corners 2 and 3** (sender-side and receiver-side Access Point) and carry the **corner-5 duty**: generating a **Tax Data Document (TDD)** from every invoice we transport and reporting it to the Financial Administration within statutory deadlines. + +Formally this is **two certifications stacked on top of each other**: + +1. **OpenPeppol Service Provider certification** — international, run by OpenPeppol AISBL (Brussels). Makes us a legitimate Peppol Access Point. +2. **Slovak accreditation (PASR scheme)** — national, run by Finančná správa SR acting as the Slovak **Peppol Authority**. Makes us a certified CPDS allowed to serve the Slovak eFaktúra mandate, listed on the official register. + +Both are prerequisites; the Slovak one explicitly requires the OpenPeppol one first. As of July 2026 there are **48 certified CPDS** with ~17 more in the pipeline — the process is well-trodden and completable in months. + +## 2. Eligibility — what the company must satisfy before applying + +- **Legal entity with registered office in an EU member state** (our s.r.o. qualifies; the entity applies, not an individual). +- **Bezúhonnosť** — clean criminal record for the company and its statutory representatives (extracts from criminal register required). +- **Technical readiness** proven by passing testbed scenarios (see Phase 3). +- Capability to **reliably identify senders and recipients** (KYC-ish duty toward the participants we register). + +## 3. Phase plan + +### Phase 0 — Decision & scope (now) + +Decide the certification scope. Two realistic options: + +| Option | What it covers | OpenPeppol fees (S1, 1–10 employees) | +|---|---|---| +| **Access Point only** | We send/receive via AS4; participant metadata is published via an existing/national SMP | €1,050 sign-up + €1,850/yr + €1,500 certification | +| **Access Point + SMP** | We also run our own Service Metadata Publisher (we publish our participants' capabilities ourselves) | €1,800 sign-up + €2,750/yr + €2,500 certification | + +Note: the Slovak accreditation pack includes an **"SMP Access Request Form"** — FS SR grants accredited CPDS access to SMP registration, which suggests AP-only plus the national SMP arrangement is a viable lean start. Recommendation: **start AP-only**, add SMP scope later if we want full independence over participant publishing. + +### Phase 1 — OpenPeppol onboarding + +1. Join **OpenPeppol** as a Service Provider member ([peppol.org/join](https://peppol.org/join-new/)). +2. Request the **Transport Infrastructure Agreement (TIA)** package via our chosen Peppol Authority — for us that is **Finančná správa SR** (choosing the national authority is the norm and required for the Slovak scheme anyway). +3. Sign the Peppol agreements; request **test certificates** from the Peppol PKI via the OpenPeppol Service Desk. Only OpenPeppol-issued certificates are valid on the network; self-signed is non-compliant. TLS endpoints must chain to CAs trusted by mainstream trust stores. + +### Phase 2 — Stand up the Access Point capability + +What the AP must be able to do (capability list, not implementation prescription): + +- **Peppol AS4 profile** messaging (eDelivery AS4) between access points, with message signing + acknowledgements using our Peppol PKI certificates. +- **SMP/SML lookup** to discover recipients' access points; registration of our own participants in SMP/SML. +- **Peppol BIS Billing 3.0** (UBL 2.1, EN 16931) send **and** receive, including credit notes and self-billing profiles. +- **Validation** of documents against EN 16931 + Peppol Schematron artifacts before dispatch; handling of Message Level Responses / error flows. +- **Slovak participant addressing**: DIČ under Peppol identifier scheme **0245 (SG:DIC)**, per Peppol Code Lists v9.5+. +- **SK TDD generation and submission** to corner 5 per FS SR technical specification, within statutory deadlines (supplier-side at issuance; buyer-side within 5 days unless deferred by amendment LP/2026/282). +- Logging/audit trail, and **10-year archiving** support consistent with §-level integrity requirements. + +### Phase 3 — Testing (both testbeds) + +1. **OpenPeppol acceptance testing** on the [Peppol Testbed](https://www.testbed.peppol.org/) following the official *Test and Onboarding* procedure — **AS4 testing is mandatory** for all service providers. +2. **Slovak Peppol Testbed** scenarios required by the PASR accreditation scheme: **Billing** and **Self-Billing** flows plus **SK TDD reporting validation** (XML/Schematron rules published by FS SR). + +### Phase 4 — Slovak accreditation (PASR) + +1. Download the accreditation pack from the FS SR eFaktúra page: **Accreditation Schema (PASR)**, **Specific Requirements of Peppol Authority SR**, the **detailed accreditation guide** (SK/EN), and the **SMP access request form**. +2. Submit the formal **žiadosť o akreditáciu** with corporate documents (EU seat proof, criminal-register extracts) and testbed results. +3. **30-day evaluation** by Finančná správa (organizational + security compliance review). +4. On approval: certificate issued, **SMP registry access granted, listed on the public CPDS register**. + +### Phase 5 — Production go-live + +1. After Peppol Authority notification, request **production certificates** via the OpenPeppol Service Desk. +2. Register in production SML/SMP; smoke-test against at least one other live CPDS. +3. **Register our ERP customers as participants** (by DIČ, scheme 0245) — this is the moment our ERP users become legally reachable for eFaktúra through us. +4. Wire the ERP billing flow through our own AP; keep one external certified CPDS integration as **fallback** until we have months of stable production behind us. + +### Phase 6 — Operating as regulated infrastructure (ongoing) + +- **TDD reporting within statutory deadlines** — our outage is our customers' compliance exposure. The law excuses taxpayers when their provider has a technical failure *if data is reported without delay after resolution* — that clause is about us, so we need incident response, monitoring, and on-call coverage. +- **Availability & security standards** per the Specific Requirements of Peppol Authority SR; expect periodic compliance attestations. +- **Track the release cadence**: Peppol code lists and BIS updates land roughly twice a year; EN 16931 and the Slovak TDD spec will evolve toward ViDA 2030 (intra-EU DRR, new document flows, abolition of ESL/control statement). +- **Fees**: OpenPeppol annual membership + certification fee rolls into the annual invoice after first certification. +- **KYC duty**: reliable identification of the senders/recipients we onboard. + +## 4. Budget (S1 company size, AP-only path) + +| Item | One-off | Annual | +|---|---|---| +| OpenPeppol sign-up | €1,050 | — | +| OpenPeppol membership | — | €1,850 | +| OpenPeppol AP certification | €1,500 (first year) | rolls into annual thereafter | +| Slovak accreditation | no fee published; admin costs (criminal extracts, notarizations) | — | +| Infrastructure (hosted AP, monitoring, backups) | — | our own hosting costs | +| **Ballpark** | **~€2,600–3,000** | **~€3,400/yr** | + +(AP+SMP path: ~€4,300 one-off, ~€5,300/yr.) Compare against per-invoice or per-customer fees of a third-party CPDS multiplied across our whole ERP customer base — the economics favor self-accreditation quickly if we have more than a handful of active customers. + +## 5. Timeline (realistic) + +| When | Milestone | +|---|---| +| Month 0–1 | OpenPeppol membership, TIA signed, test certificates, accreditation pack studied | +| Month 1–3 | AP capability stood up; internal validation green against Peppol + SK artifacts | +| Month 3–4 | OpenPeppol acceptance tests + Slovak Testbed scenarios (Billing, Self-Billing, TDD) passed | +| Month 4–5 | Accreditation application filed → 30-day FS SR evaluation | +| Month 5–6 | Production certificates, SML/SMP registration, customer participant registration | +| **Buffer** | Aim to file accreditation **no later than early autumn 2026** so we are on the register comfortably before **1 Jan 2027** | + +## 6. Risks & mitigations + +| Risk | Mitigation | +|---|---| +| Accreditation slips past Jan 2027 | Keep a contract + working API integration with one existing CPDS as fallback so ERP customers are compliant on day one regardless | +| Small-team operations of regulated infra (outages at 3 a.m.) | Monitoring/alerting from day one; document incident procedure — the statutory outage defense requires reporting "without delay after resolution" | +| Spec drift (code lists, BIS, TDD changes) | Subscribe to OpenPeppol and FS SR release channels; calendar the ~2×/year update windows | +| Buyer-side 5-day reporting uncertainty (LP/2026/282) | Build it; treat deferral to 2030 as relief, not a plan | +| Scope creep into SMP operation | Start AP-only with national SMP access; revisit SMP scope after stable operation | + +## 7. Official resources + +- FS SR eFaktúra hub (accreditation pack, CPDS register, TDD spec): +- Official CPDS register (PDF, updated continuously): [zoznam certifikovaných poskytovateľov](https://www.financnasprava.sk/_img/pfsedit/Dokumenty_PFS/Podnikatelia/Dan_z_pridanej_hodnoty/efaktura/2026/2026.06.11_Certif_poskyt_doruc_sluzby_akred.pdf) +- OpenPeppol membership & fees: +- How to set up a Peppol Access Point (official guide): +- Peppol Test and Onboarding procedure: +- Peppol Testbed: +- Peppol AS4 profile spec: +- Community guide to the Slovak CPDS process: +- Digital postmen explainer (Podnikajte):