Files
komp_ac/digital_postman_playbook.md
2026-07-19 20:09:36 +02:00

10 KiB
Raw Permalink Blame History

Becoming our own Digital Postman (CPDS) — company playbook

Companion to efaktura_2027_report.md. Researched 2026-07-19. Goal: our company becomes an accredited "poskytovateľ doručovacej služby" (Digitálny poštár / CPDS) so our ERP backend pushes e-invoices directly into the Peppol network — no third-party middleman — and we can act as the delivery provider for all of our ERP customers.


1. What we are actually applying to be

In the 5-corner model we would operate corners 2 and 3 (sender-side and receiver-side Access Point) and carry the corner-5 duty: generating a Tax Data Document (TDD) from every invoice we transport and reporting it to the Financial Administration within statutory deadlines.

Formally this is two certifications stacked on top of each other:

  1. OpenPeppol Service Provider certification — international, run by OpenPeppol AISBL (Brussels). Makes us a legitimate Peppol Access Point.
  2. Slovak accreditation (PASR scheme) — national, run by Finančná správa SR acting as the Slovak Peppol Authority. Makes us a certified CPDS allowed to serve the Slovak eFaktúra mandate, listed on the official register.

Both are prerequisites; the Slovak one explicitly requires the OpenPeppol one first. As of July 2026 there are 48 certified CPDS with ~17 more in the pipeline — the process is well-trodden and completable in months.

2. Eligibility — what the company must satisfy before applying

  • Legal entity with registered office in an EU member state (our s.r.o. qualifies; the entity applies, not an individual).
  • Bezúhonnosť — clean criminal record for the company and its statutory representatives (extracts from criminal register required).
  • Technical readiness proven by passing testbed scenarios (see Phase 3).
  • Capability to reliably identify senders and recipients (KYC-ish duty toward the participants we register).

3. Phase plan

Phase 0 — Decision & scope (now)

Decide the certification scope. Two realistic options:

Option What it covers OpenPeppol fees (S1, 110 employees)
Access Point only We send/receive via AS4; participant metadata is published via an existing/national SMP €1,050 sign-up + €1,850/yr + €1,500 certification
Access Point + SMP We also run our own Service Metadata Publisher (we publish our participants' capabilities ourselves) €1,800 sign-up + €2,750/yr + €2,500 certification

Note: the Slovak accreditation pack includes an "SMP Access Request Form" — FS SR grants accredited CPDS access to SMP registration, which suggests AP-only plus the national SMP arrangement is a viable lean start. Recommendation: start AP-only, add SMP scope later if we want full independence over participant publishing.

Phase 1 — OpenPeppol onboarding

  1. Join OpenPeppol as a Service Provider member (peppol.org/join).
  2. Request the Transport Infrastructure Agreement (TIA) package via our chosen Peppol Authority — for us that is Finančná správa SR (choosing the national authority is the norm and required for the Slovak scheme anyway).
  3. Sign the Peppol agreements; request test certificates from the Peppol PKI via the OpenPeppol Service Desk. Only OpenPeppol-issued certificates are valid on the network; self-signed is non-compliant. TLS endpoints must chain to CAs trusted by mainstream trust stores.

Phase 2 — Stand up the Access Point capability

What the AP must be able to do (capability list, not implementation prescription):

  • Peppol AS4 profile messaging (eDelivery AS4) between access points, with message signing + acknowledgements using our Peppol PKI certificates.
  • SMP/SML lookup to discover recipients' access points; registration of our own participants in SMP/SML.
  • Peppol BIS Billing 3.0 (UBL 2.1, EN 16931) send and receive, including credit notes and self-billing profiles.
  • Validation of documents against EN 16931 + Peppol Schematron artifacts before dispatch; handling of Message Level Responses / error flows.
  • Slovak participant addressing: DIČ under Peppol identifier scheme 0245 (SG:DIC), per Peppol Code Lists v9.5+.
  • SK TDD generation and submission to corner 5 per FS SR technical specification, within statutory deadlines (supplier-side at issuance; buyer-side within 5 days unless deferred by amendment LP/2026/282).
  • Logging/audit trail, and 10-year archiving support consistent with §-level integrity requirements.

Phase 3 — Testing (both testbeds)

  1. OpenPeppol acceptance testing on the Peppol Testbed following the official Test and Onboarding procedure — AS4 testing is mandatory for all service providers.
  2. Slovak Peppol Testbed scenarios required by the PASR accreditation scheme: Billing and Self-Billing flows plus SK TDD reporting validation (XML/Schematron rules published by FS SR).

Phase 4 — Slovak accreditation (PASR)

  1. Download the accreditation pack from the FS SR eFaktúra page: Accreditation Schema (PASR), Specific Requirements of Peppol Authority SR, the detailed accreditation guide (SK/EN), and the SMP access request form.
  2. Submit the formal žiadosť o akreditáciu with corporate documents (EU seat proof, criminal-register extracts) and testbed results.
  3. 30-day evaluation by Finančná správa (organizational + security compliance review).
  4. On approval: certificate issued, SMP registry access granted, listed on the public CPDS register.

Phase 5 — Production go-live

  1. After Peppol Authority notification, request production certificates via the OpenPeppol Service Desk.
  2. Register in production SML/SMP; smoke-test against at least one other live CPDS.
  3. Register our ERP customers as participants (by DIČ, scheme 0245) — this is the moment our ERP users become legally reachable for eFaktúra through us.
  4. Wire the ERP billing flow through our own AP; keep one external certified CPDS integration as fallback until we have months of stable production behind us.

Phase 6 — Operating as regulated infrastructure (ongoing)

  • TDD reporting within statutory deadlines — our outage is our customers' compliance exposure. The law excuses taxpayers when their provider has a technical failure if data is reported without delay after resolution — that clause is about us, so we need incident response, monitoring, and on-call coverage.
  • Availability & security standards per the Specific Requirements of Peppol Authority SR; expect periodic compliance attestations.
  • Track the release cadence: Peppol code lists and BIS updates land roughly twice a year; EN 16931 and the Slovak TDD spec will evolve toward ViDA 2030 (intra-EU DRR, new document flows, abolition of ESL/control statement).
  • Fees: OpenPeppol annual membership + certification fee rolls into the annual invoice after first certification.
  • KYC duty: reliable identification of the senders/recipients we onboard.

4. Budget (S1 company size, AP-only path)

Item One-off Annual
OpenPeppol sign-up €1,050
OpenPeppol membership €1,850
OpenPeppol AP certification €1,500 (first year) rolls into annual thereafter
Slovak accreditation no fee published; admin costs (criminal extracts, notarizations)
Infrastructure (hosted AP, monitoring, backups) our own hosting costs
Ballpark ~€2,6003,000 ~€3,400/yr

(AP+SMP path: ~€4,300 one-off, ~€5,300/yr.) Compare against per-invoice or per-customer fees of a third-party CPDS multiplied across our whole ERP customer base — the economics favor self-accreditation quickly if we have more than a handful of active customers.

5. Timeline (realistic)

When Milestone
Month 01 OpenPeppol membership, TIA signed, test certificates, accreditation pack studied
Month 13 AP capability stood up; internal validation green against Peppol + SK artifacts
Month 34 OpenPeppol acceptance tests + Slovak Testbed scenarios (Billing, Self-Billing, TDD) passed
Month 45 Accreditation application filed → 30-day FS SR evaluation
Month 56 Production certificates, SML/SMP registration, customer participant registration
Buffer Aim to file accreditation no later than early autumn 2026 so we are on the register comfortably before 1 Jan 2027

6. Risks & mitigations

Risk Mitigation
Accreditation slips past Jan 2027 Keep a contract + working API integration with one existing CPDS as fallback so ERP customers are compliant on day one regardless
Small-team operations of regulated infra (outages at 3 a.m.) Monitoring/alerting from day one; document incident procedure — the statutory outage defense requires reporting "without delay after resolution"
Spec drift (code lists, BIS, TDD changes) Subscribe to OpenPeppol and FS SR release channels; calendar the ~2×/year update windows
Buyer-side 5-day reporting uncertainty (LP/2026/282) Build it; treat deferral to 2030 as relief, not a plan
Scope creep into SMP operation Start AP-only with national SMP access; revisit SMP scope after stable operation

7. Official resources