10 KiB
Becoming our own Digital Postman (CPDS) — company playbook
Companion to efaktura_2027_report.md. Researched 2026-07-19. Goal: our company becomes an accredited "poskytovateľ doručovacej služby" (Digitálny poštár / CPDS) so our ERP backend pushes e-invoices directly into the Peppol network — no third-party middleman — and we can act as the delivery provider for all of our ERP customers.
1. What we are actually applying to be
In the 5-corner model we would operate corners 2 and 3 (sender-side and receiver-side Access Point) and carry the corner-5 duty: generating a Tax Data Document (TDD) from every invoice we transport and reporting it to the Financial Administration within statutory deadlines.
Formally this is two certifications stacked on top of each other:
- OpenPeppol Service Provider certification — international, run by OpenPeppol AISBL (Brussels). Makes us a legitimate Peppol Access Point.
- Slovak accreditation (PASR scheme) — national, run by Finančná správa SR acting as the Slovak Peppol Authority. Makes us a certified CPDS allowed to serve the Slovak eFaktúra mandate, listed on the official register.
Both are prerequisites; the Slovak one explicitly requires the OpenPeppol one first. As of July 2026 there are 48 certified CPDS with ~17 more in the pipeline — the process is well-trodden and completable in months.
2. Eligibility — what the company must satisfy before applying
- Legal entity with registered office in an EU member state (our s.r.o. qualifies; the entity applies, not an individual).
- Bezúhonnosť — clean criminal record for the company and its statutory representatives (extracts from criminal register required).
- Technical readiness proven by passing testbed scenarios (see Phase 3).
- Capability to reliably identify senders and recipients (KYC-ish duty toward the participants we register).
3. Phase plan
Phase 0 — Decision & scope (now)
Decide the certification scope. Two realistic options:
| Option | What it covers | OpenPeppol fees (S1, 1–10 employees) |
|---|---|---|
| Access Point only | We send/receive via AS4; participant metadata is published via an existing/national SMP | €1,050 sign-up + €1,850/yr + €1,500 certification |
| Access Point + SMP | We also run our own Service Metadata Publisher (we publish our participants' capabilities ourselves) | €1,800 sign-up + €2,750/yr + €2,500 certification |
Note: the Slovak accreditation pack includes an "SMP Access Request Form" — FS SR grants accredited CPDS access to SMP registration, which suggests AP-only plus the national SMP arrangement is a viable lean start. Recommendation: start AP-only, add SMP scope later if we want full independence over participant publishing.
Phase 1 — OpenPeppol onboarding
- Join OpenPeppol as a Service Provider member (peppol.org/join).
- Request the Transport Infrastructure Agreement (TIA) package via our chosen Peppol Authority — for us that is Finančná správa SR (choosing the national authority is the norm and required for the Slovak scheme anyway).
- Sign the Peppol agreements; request test certificates from the Peppol PKI via the OpenPeppol Service Desk. Only OpenPeppol-issued certificates are valid on the network; self-signed is non-compliant. TLS endpoints must chain to CAs trusted by mainstream trust stores.
Phase 2 — Stand up the Access Point capability
What the AP must be able to do (capability list, not implementation prescription):
- Peppol AS4 profile messaging (eDelivery AS4) between access points, with message signing + acknowledgements using our Peppol PKI certificates.
- SMP/SML lookup to discover recipients' access points; registration of our own participants in SMP/SML.
- Peppol BIS Billing 3.0 (UBL 2.1, EN 16931) send and receive, including credit notes and self-billing profiles.
- Validation of documents against EN 16931 + Peppol Schematron artifacts before dispatch; handling of Message Level Responses / error flows.
- Slovak participant addressing: DIČ under Peppol identifier scheme 0245 (SG:DIC), per Peppol Code Lists v9.5+.
- SK TDD generation and submission to corner 5 per FS SR technical specification, within statutory deadlines (supplier-side at issuance; buyer-side within 5 days unless deferred by amendment LP/2026/282).
- Logging/audit trail, and 10-year archiving support consistent with §-level integrity requirements.
Phase 3 — Testing (both testbeds)
- OpenPeppol acceptance testing on the Peppol Testbed following the official Test and Onboarding procedure — AS4 testing is mandatory for all service providers.
- Slovak Peppol Testbed scenarios required by the PASR accreditation scheme: Billing and Self-Billing flows plus SK TDD reporting validation (XML/Schematron rules published by FS SR).
Phase 4 — Slovak accreditation (PASR)
- Download the accreditation pack from the FS SR eFaktúra page: Accreditation Schema (PASR), Specific Requirements of Peppol Authority SR, the detailed accreditation guide (SK/EN), and the SMP access request form.
- Submit the formal žiadosť o akreditáciu with corporate documents (EU seat proof, criminal-register extracts) and testbed results.
- 30-day evaluation by Finančná správa (organizational + security compliance review).
- On approval: certificate issued, SMP registry access granted, listed on the public CPDS register.
Phase 5 — Production go-live
- After Peppol Authority notification, request production certificates via the OpenPeppol Service Desk.
- Register in production SML/SMP; smoke-test against at least one other live CPDS.
- Register our ERP customers as participants (by DIČ, scheme 0245) — this is the moment our ERP users become legally reachable for eFaktúra through us.
- Wire the ERP billing flow through our own AP; keep one external certified CPDS integration as fallback until we have months of stable production behind us.
Phase 6 — Operating as regulated infrastructure (ongoing)
- TDD reporting within statutory deadlines — our outage is our customers' compliance exposure. The law excuses taxpayers when their provider has a technical failure if data is reported without delay after resolution — that clause is about us, so we need incident response, monitoring, and on-call coverage.
- Availability & security standards per the Specific Requirements of Peppol Authority SR; expect periodic compliance attestations.
- Track the release cadence: Peppol code lists and BIS updates land roughly twice a year; EN 16931 and the Slovak TDD spec will evolve toward ViDA 2030 (intra-EU DRR, new document flows, abolition of ESL/control statement).
- Fees: OpenPeppol annual membership + certification fee rolls into the annual invoice after first certification.
- KYC duty: reliable identification of the senders/recipients we onboard.
4. Budget (S1 company size, AP-only path)
| Item | One-off | Annual |
|---|---|---|
| OpenPeppol sign-up | €1,050 | — |
| OpenPeppol membership | — | €1,850 |
| OpenPeppol AP certification | €1,500 (first year) | rolls into annual thereafter |
| Slovak accreditation | no fee published; admin costs (criminal extracts, notarizations) | — |
| Infrastructure (hosted AP, monitoring, backups) | — | our own hosting costs |
| Ballpark | ~€2,600–3,000 | ~€3,400/yr |
(AP+SMP path: ~€4,300 one-off, ~€5,300/yr.) Compare against per-invoice or per-customer fees of a third-party CPDS multiplied across our whole ERP customer base — the economics favor self-accreditation quickly if we have more than a handful of active customers.
5. Timeline (realistic)
| When | Milestone |
|---|---|
| Month 0–1 | OpenPeppol membership, TIA signed, test certificates, accreditation pack studied |
| Month 1–3 | AP capability stood up; internal validation green against Peppol + SK artifacts |
| Month 3–4 | OpenPeppol acceptance tests + Slovak Testbed scenarios (Billing, Self-Billing, TDD) passed |
| Month 4–5 | Accreditation application filed → 30-day FS SR evaluation |
| Month 5–6 | Production certificates, SML/SMP registration, customer participant registration |
| Buffer | Aim to file accreditation no later than early autumn 2026 so we are on the register comfortably before 1 Jan 2027 |
6. Risks & mitigations
| Risk | Mitigation |
|---|---|
| Accreditation slips past Jan 2027 | Keep a contract + working API integration with one existing CPDS as fallback so ERP customers are compliant on day one regardless |
| Small-team operations of regulated infra (outages at 3 a.m.) | Monitoring/alerting from day one; document incident procedure — the statutory outage defense requires reporting "without delay after resolution" |
| Spec drift (code lists, BIS, TDD changes) | Subscribe to OpenPeppol and FS SR release channels; calendar the ~2×/year update windows |
| Buyer-side 5-day reporting uncertainty (LP/2026/282) | Build it; treat deferral to 2030 as relief, not a plan |
| Scope creep into SMP operation | Start AP-only with national SMP access; revisit SMP scope after stable operation |
7. Official resources
- FS SR eFaktúra hub (accreditation pack, CPDS register, TDD spec): https://www.financnasprava.sk/sk/podnikatelia/dane/dan-z-pridanej-hodnoty/e-faktura
- Official CPDS register (PDF, updated continuously): zoznam certifikovaných poskytovateľov
- OpenPeppol membership & fees: https://peppol.org/join/fees/
- How to set up a Peppol Access Point (official guide): https://peppol.org/wp-content/uploads/2024/04/how_to_set-up_a__post-award__peppol_access_point_v2.1.pdf
- Peppol Test and Onboarding procedure: https://peppol.org/wp-content/uploads/2022/08/Peppol_TestbedAndOnboarding_v1.3.pdf
- Peppol Testbed: https://www.testbed.peppol.org/
- Peppol AS4 profile spec: https://docs.peppol.eu/edelivery/as4/specification/
- Community guide to the Slovak CPDS process: https://cpds.sk/
- Digital postmen explainer (Podnikajte): https://www.podnikajte.sk/zakonne-povinnosti-podnikatela/e-faktura-co-vediet-o-digitalnych-postaroch