Methodology: how we identify Peppol Access Point providers
1. SML DNS lookup (every participant)
For every participant in our dataset, we query the official Peppol Service Metadata Locator (SML), the central DNS-based discovery service for the Peppol network. We compute the participant's SML hostname using a Base32-encoded SHA-256 hash of the participant identifier and query its U-NAPTR record, which points to the SMP registered for that participant. This is the same discovery mechanism used by sending Access Points to locate a recipient's service metadata.
2. Access Point certificate (shared / national SMPs)
The most authoritative signal for identifying the receiving Access Point provider is its Peppol certificate. For participants on shared or multi-tenant SMP platforms, we fetch the SMP metadata over HTTPS and read the AS4 endpoint and its certificate. The certificate identifies the Service Provider through its Peppol Seat ID and organisation name. This takes precedence over the SMP host, so a provider using another company's SMP infrastructure is attributed to the provider identified by the Access Point certificate, not to the platform operator.
3. Classification & caching
We use the Peppol Seat ID as the primary identity of the Service Provider. Each Seat ID and certificate organisation name is mapped to the provider's business name; providers we do not yet recognise retain an automatically derived name. New providers are detected automatically and their names are reviewed, allowing the classification to remain accurate as the network grows.
Limitations
- Participants are attributed to their receiving Access Point provider, using the Access Point certificate on shared platforms or, where appropriate, a dedicated SMP host. They are not attributed to a platform that merely hosts the underlying infrastructure. A small number of Access Points publish a non-standard or unreadable certificate; these retain an automatically derived name until they can be resolved.
- Only participants published in the public Peppol Directory are counted. Listing in the Directory is not mandatory, so the actual Peppol network - and the number of participants served by some providers - may be larger than shown.
- Participants that no longer resolve in the Peppol SML are excluded from provider attribution.
- For periods before August 2026, historical figures are reconstructed using participants' registration dates and their currently identified providers. Provider migrations can therefore affect these historical estimates. From August 2026 onward, stored snapshots preserve the provider attribution observed at the time.
- Figures before August 2026 are estimated from the current network state and may understate earlier periods because participants that have since left the network are no longer observable. From August 2026 onward, measured snapshots are stored regularly, so the history from that point reflects the network state observed at the time.
- All data comes from public Peppol infrastructure, including SML DNS records and SMP endpoints. No private or commercial data source is used.
← Peppol Access Point Market Share · Last updated: 2026-08-25