Files
komp_ac/digital_postman_playbook.md
2026-07-19 20:09:36 +02:00

128 lines
10 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Becoming our own Digital Postman (CPDS) — company playbook
*Companion to `efaktura_2027_report.md`. Researched 2026-07-19. Goal: our company becomes an accredited "poskytovateľ doručovacej služby" (Digitálny poštár / CPDS) so our ERP backend pushes e-invoices directly into the Peppol network — no third-party middleman — and we can act as the delivery provider for all of our ERP customers.*
---
## 1. What we are actually applying to be
In the 5-corner model we would operate **corners 2 and 3** (sender-side and receiver-side Access Point) and carry the **corner-5 duty**: generating a **Tax Data Document (TDD)** from every invoice we transport and reporting it to the Financial Administration within statutory deadlines.
Formally this is **two certifications stacked on top of each other**:
1. **OpenPeppol Service Provider certification** — international, run by OpenPeppol AISBL (Brussels). Makes us a legitimate Peppol Access Point.
2. **Slovak accreditation (PASR scheme)** — national, run by Finančná správa SR acting as the Slovak **Peppol Authority**. Makes us a certified CPDS allowed to serve the Slovak eFaktúra mandate, listed on the official register.
Both are prerequisites; the Slovak one explicitly requires the OpenPeppol one first. As of July 2026 there are **48 certified CPDS** with ~17 more in the pipeline — the process is well-trodden and completable in months.
## 2. Eligibility — what the company must satisfy before applying
- **Legal entity with registered office in an EU member state** (our s.r.o. qualifies; the entity applies, not an individual).
- **Bezúhonnosť** — clean criminal record for the company and its statutory representatives (extracts from criminal register required).
- **Technical readiness** proven by passing testbed scenarios (see Phase 3).
- Capability to **reliably identify senders and recipients** (KYC-ish duty toward the participants we register).
## 3. Phase plan
### Phase 0 — Decision & scope (now)
Decide the certification scope. Two realistic options:
| Option | What it covers | OpenPeppol fees (S1, 110 employees) |
|---|---|---|
| **Access Point only** | We send/receive via AS4; participant metadata is published via an existing/national SMP | €1,050 sign-up + €1,850/yr + €1,500 certification |
| **Access Point + SMP** | We also run our own Service Metadata Publisher (we publish our participants' capabilities ourselves) | €1,800 sign-up + €2,750/yr + €2,500 certification |
Note: the Slovak accreditation pack includes an **"SMP Access Request Form"** — FS SR grants accredited CPDS access to SMP registration, which suggests AP-only plus the national SMP arrangement is a viable lean start. Recommendation: **start AP-only**, add SMP scope later if we want full independence over participant publishing.
### Phase 1 — OpenPeppol onboarding
1. Join **OpenPeppol** as a Service Provider member ([peppol.org/join](https://peppol.org/join-new/)).
2. Request the **Transport Infrastructure Agreement (TIA)** package via our chosen Peppol Authority — for us that is **Finančná správa SR** (choosing the national authority is the norm and required for the Slovak scheme anyway).
3. Sign the Peppol agreements; request **test certificates** from the Peppol PKI via the OpenPeppol Service Desk. Only OpenPeppol-issued certificates are valid on the network; self-signed is non-compliant. TLS endpoints must chain to CAs trusted by mainstream trust stores.
### Phase 2 — Stand up the Access Point capability
What the AP must be able to do (capability list, not implementation prescription):
- **Peppol AS4 profile** messaging (eDelivery AS4) between access points, with message signing + acknowledgements using our Peppol PKI certificates.
- **SMP/SML lookup** to discover recipients' access points; registration of our own participants in SMP/SML.
- **Peppol BIS Billing 3.0** (UBL 2.1, EN 16931) send **and** receive, including credit notes and self-billing profiles.
- **Validation** of documents against EN 16931 + Peppol Schematron artifacts before dispatch; handling of Message Level Responses / error flows.
- **Slovak participant addressing**: DIČ under Peppol identifier scheme **0245 (SG:DIC)**, per Peppol Code Lists v9.5+.
- **SK TDD generation and submission** to corner 5 per FS SR technical specification, within statutory deadlines (supplier-side at issuance; buyer-side within 5 days unless deferred by amendment LP/2026/282).
- Logging/audit trail, and **10-year archiving** support consistent with §-level integrity requirements.
### Phase 3 — Testing (both testbeds)
1. **OpenPeppol acceptance testing** on the [Peppol Testbed](https://www.testbed.peppol.org/) following the official *Test and Onboarding* procedure — **AS4 testing is mandatory** for all service providers.
2. **Slovak Peppol Testbed** scenarios required by the PASR accreditation scheme: **Billing** and **Self-Billing** flows plus **SK TDD reporting validation** (XML/Schematron rules published by FS SR).
### Phase 4 — Slovak accreditation (PASR)
1. Download the accreditation pack from the FS SR eFaktúra page: **Accreditation Schema (PASR)**, **Specific Requirements of Peppol Authority SR**, the **detailed accreditation guide** (SK/EN), and the **SMP access request form**.
2. Submit the formal **žiadosť o akreditáciu** with corporate documents (EU seat proof, criminal-register extracts) and testbed results.
3. **30-day evaluation** by Finančná správa (organizational + security compliance review).
4. On approval: certificate issued, **SMP registry access granted, listed on the public CPDS register**.
### Phase 5 — Production go-live
1. After Peppol Authority notification, request **production certificates** via the OpenPeppol Service Desk.
2. Register in production SML/SMP; smoke-test against at least one other live CPDS.
3. **Register our ERP customers as participants** (by DIČ, scheme 0245) — this is the moment our ERP users become legally reachable for eFaktúra through us.
4. Wire the ERP billing flow through our own AP; keep one external certified CPDS integration as **fallback** until we have months of stable production behind us.
### Phase 6 — Operating as regulated infrastructure (ongoing)
- **TDD reporting within statutory deadlines** — our outage is our customers' compliance exposure. The law excuses taxpayers when their provider has a technical failure *if data is reported without delay after resolution* — that clause is about us, so we need incident response, monitoring, and on-call coverage.
- **Availability & security standards** per the Specific Requirements of Peppol Authority SR; expect periodic compliance attestations.
- **Track the release cadence**: Peppol code lists and BIS updates land roughly twice a year; EN 16931 and the Slovak TDD spec will evolve toward ViDA 2030 (intra-EU DRR, new document flows, abolition of ESL/control statement).
- **Fees**: OpenPeppol annual membership + certification fee rolls into the annual invoice after first certification.
- **KYC duty**: reliable identification of the senders/recipients we onboard.
## 4. Budget (S1 company size, AP-only path)
| Item | One-off | Annual |
|---|---|---|
| OpenPeppol sign-up | €1,050 | — |
| OpenPeppol membership | — | €1,850 |
| OpenPeppol AP certification | €1,500 (first year) | rolls into annual thereafter |
| Slovak accreditation | no fee published; admin costs (criminal extracts, notarizations) | — |
| Infrastructure (hosted AP, monitoring, backups) | — | our own hosting costs |
| **Ballpark** | **~€2,6003,000** | **~€3,400/yr** |
(AP+SMP path: ~€4,300 one-off, ~€5,300/yr.) Compare against per-invoice or per-customer fees of a third-party CPDS multiplied across our whole ERP customer base — the economics favor self-accreditation quickly if we have more than a handful of active customers.
## 5. Timeline (realistic)
| When | Milestone |
|---|---|
| Month 01 | OpenPeppol membership, TIA signed, test certificates, accreditation pack studied |
| Month 13 | AP capability stood up; internal validation green against Peppol + SK artifacts |
| Month 34 | OpenPeppol acceptance tests + Slovak Testbed scenarios (Billing, Self-Billing, TDD) passed |
| Month 45 | Accreditation application filed → 30-day FS SR evaluation |
| Month 56 | Production certificates, SML/SMP registration, customer participant registration |
| **Buffer** | Aim to file accreditation **no later than early autumn 2026** so we are on the register comfortably before **1 Jan 2027** |
## 6. Risks & mitigations
| Risk | Mitigation |
|---|---|
| Accreditation slips past Jan 2027 | Keep a contract + working API integration with one existing CPDS as fallback so ERP customers are compliant on day one regardless |
| Small-team operations of regulated infra (outages at 3 a.m.) | Monitoring/alerting from day one; document incident procedure — the statutory outage defense requires reporting "without delay after resolution" |
| Spec drift (code lists, BIS, TDD changes) | Subscribe to OpenPeppol and FS SR release channels; calendar the ~2×/year update windows |
| Buyer-side 5-day reporting uncertainty (LP/2026/282) | Build it; treat deferral to 2030 as relief, not a plan |
| Scope creep into SMP operation | Start AP-only with national SMP access; revisit SMP scope after stable operation |
## 7. Official resources
- FS SR eFaktúra hub (accreditation pack, CPDS register, TDD spec): <https://www.financnasprava.sk/sk/podnikatelia/dane/dan-z-pridanej-hodnoty/e-faktura>
- Official CPDS register (PDF, updated continuously): [zoznam certifikovaných poskytovateľov](https://www.financnasprava.sk/_img/pfsedit/Dokumenty_PFS/Podnikatelia/Dan_z_pridanej_hodnoty/efaktura/2026/2026.06.11_Certif_poskyt_doruc_sluzby_akred.pdf)
- OpenPeppol membership & fees: <https://peppol.org/join/fees/>
- How to set up a Peppol Access Point (official guide): <https://peppol.org/wp-content/uploads/2024/04/how_to_set-up_a__post-award__peppol_access_point_v2.1.pdf>
- Peppol Test and Onboarding procedure: <https://peppol.org/wp-content/uploads/2022/08/Peppol_TestbedAndOnboarding_v1.3.pdf>
- Peppol Testbed: <https://www.testbed.peppol.org/>
- Peppol AS4 profile spec: <https://docs.peppol.eu/edelivery/as4/specification/>
- Community guide to the Slovak CPDS process: <https://cpds.sk/>
- Digital postmen explainer (Podnikajte): <https://www.podnikajte.sk/zakonne-povinnosti-podnikatela/e-faktura-co-vediet-o-digitalnych-postaroch>