Key takeaways
- AS4 is the transport protocol of the Peppol network: it carries the document from one access point to the other, regardless of its content.
- It is a profile of the OASIS ebMS 3.0 standards, aligned with the CEF eDelivery AS4 profile used across the European Union.
- Every AS4 message is signed, encrypted and confirmed with a receipt, using the Peppol PKI.
- AS4 has been mandatory on the network since 1 February 2020; it replaced the older AS2 profile.
AS4, the transport layer of the Peppol network
A compliant e-invoice is not enough: it still has to reach the right recipient, safely and verifiably. On the Peppol network, that transport rests on a precise protocol, the AS4 protocol. It is what moves the document from one business to another, protects it in transit and confirms its delivery.
Two things are often confused and worth separating. The format describes what the invoice contains: that is the job of Peppol BIS Billing 3.0, built on UBL 2.1. The transport describes how that file travels: that is the job of AS4. The two are independent. The protocol ignores what it carries, and the format ignores which channel moves it.
This article explains what AS4 is, where it operates in the network and what it guarantees. The good news, stated up front: you will never handle it yourself. But understanding its role clarifies what happens behind every Peppol send.
AS4: a profile built on open standards
AS4 was not invented for Peppol. It is a messaging standard published by the OASIS organisation, built on the ebXML Messaging Services 3.0 specification (ebMS 3.0). AS4 is a streamlined profile of it, designed to exchange business documents over the internet using web services.
Peppol does not reuse that raw standard: it adopts a precise profile aligned with the CEF eDelivery AS4 profile defined by the European Commission. That alignment is what makes the network interoperable beyond Peppol, with the other public exchange infrastructures of the Union. A Belgian business and its software provider never negotiate a protocol: both follow the same public specification.
The layers AS4 builds on
OASIS ebMS 3.0
The ebXML messaging standard that defines the structure of messages and their security.
The AS4 profile of ebMS 3.0
A streamlined subset of ebMS 3.0, designed for a lighter document exchange to implement.
The CEF eDelivery AS4 profile
The European profile OpenPeppol follows to guarantee interoperability beyond the Peppol network alone.
Where AS4 operates: between the access points
To place AS4, keep the Peppol four-corner model in mind. The sender (corner 1) hands its invoice to its access point (corner 2); that access point sends it to the recipient's access point (corner 3), which finally delivers it to the recipient (corner 4). AS4 governs exactly the central link: the exchange between corner 2 and corner 3, that is, from one access point to the other.
The two access points do not know each other in advance. Before sending, the sending access point queries the network directory, the SMP and SML, to discover the recipient's technical address and the certificate to use. Once that address is known, it opens an AS4 connection and transmits the message.
AS4 mandatory
transport profile required across the whole Peppol network
the corners linked
between the sending access point and the recipient's
only exchange pattern
the only pattern OpenPeppol allows for any transmission
What AS4 requires of every message
This is where the protocol earns its keep. AS4 does not merely carry a file: it guarantees its security and traceability. On the Peppol network, every message must meet three conditions, backed by the Peppol PKI, the certificate infrastructure managed by OpenPeppol.
The three guarantees of every AS4 transmission
An electronic signature
The message is signed at message level with the sender's Peppol certificate, proving its origin and integrity.
Encryption of the payload
The business content is encrypted: unreadable to a third party who might intercept it in transit.
A signed receipt
The receiving access point returns a signed receipt confirming that the message was properly delivered.
That receipt is a key point, often misread. It covers the transport: it confirms that the message was received and decrypted by the access point on the other side. It says nothing about the business acceptance of the invoice, that is, whether the recipient recognises it and books it in its accounts. That business response is handled by a separate message, the Message Level Response, distinct from the transport.
Finally, certificates play a central role. An access point verifies its counterpart's certificate before any exchange, and only certificates issued by OpenPeppol are accepted. That check is what closes the network to unauthorised actors.
What travels: the document and its envelope
Inside an AS4 message travels the invoice, but not on its own. It is packaged in a technical envelope, the SBDH (Standard Business Document Header), a standardised header that accompanies the business document. That envelope states, among other things, who sends, who receives and what type of document it is, before the content is even read.
This split has a practical consequence: the receiving access point can route and process the document from the header, without opening the invoice itself. Here again, transport and content stay separate, which is Peppol's constant logic.
Send your invoices over the Peppol network without touching the protocol
YouInv generates your compliant invoices, transmits them through an access point over AS4 and tracks their delivery for you.
AS4 since 2020: the replacement of AS2
AS4 was not always the network's protocol. Until 2020, Peppol relied mainly on an older profile, AS2. OpenPeppol planned the switch to modernise the transport and align it with the European eDelivery profile.
- 1
AS4 opens to newcomers
August 2019A new provider joining Peppol may go live on AS4 alone; AS2 becomes optional for newcomers, though not yet mandatory.
- 2
AS4 becomes mandatory
1 February 2020The new AS4 profile becomes the mandatory transport on the network; AS2 turns optional.
- 3
AS2 is retired
AfterwardsThe older AS2 profile is phased out gradually, as its volume declines on the network.
The table below sums up what separates the two profiles. The point is not technical nostalgia, but one simple fact for a business: a tool that is compliant today speaks AS4.
| AS2 (older profile) | AS4 (current profile) | |
|---|---|---|
| Mandatory on the Peppol network | ||
| Built on the OASIS ebMS 3.0 standards | ||
| Aligned with the CEF eDelivery AS4 profile | ||
| Built on web services (SOAP) |
What it changes for your business
In practice, nothing you have to do. The AS4 protocol is fully handled by your access point and your invoicing software. You enter your data; the tool produces the document, signs it, encrypts it and transmits it over AS4; the receipt tells you about the delivery. The protocol stays invisible, and that is the sign it works.
What AS4 changes is the foundation of trust that e-invoicing rests on. Where a PDF emailed as an attachment offers no proof of delivery or of integrity, an AS4 transmission signs, encrypts and acknowledges receipt at every step. That reliability, as much as the format, is what justifies moving to the Peppol network for the Belgian B2B mandate.
Further reading
- The Peppol four-corner model explained: where the sender, the access points and the recipient sit.
- Peppol access point: what it is for and how to connect: the link that speaks AS4 on your behalf.
- SMP and SML: the Peppol network directory explained: how an access point discovers its counterpart before sending.
The reference source prevails: the Peppol AS4 specification and the AS2-to-AS4 migration policy, published by OpenPeppol.
What is the AS4 protocol in Peppol?
AS4 is the transport protocol used on the Peppol network to exchange documents between two access points. It is a profile of the OASIS ebMS 3.0 standards, aligned with the CEF eDelivery AS4 profile, that signs and encrypts every message and confirms its delivery with a receipt.
Since when is AS4 mandatory on the Peppol network?
AS4 has been the mandatory transport profile on the Peppol network since 1 February 2020, the transition date set by OpenPeppol. It replaced the older AS2 profile, which was phased out gradually as its volume declined on the network.
What is the difference between AS4 and Peppol BIS Billing 3.0?
AS4 is the transport layer: it carries the document from one access point to the other. Peppol BIS Billing 3.0 is the content: the invoice format that travels inside. AS4 ignores what it carries, and the format ignores which channel moves it.
Do you need to know AS4 to send a Peppol invoice?
No. The AS4 protocol is handled by your access point and your invoicing software. You enter your data, the tool produces the document, signs it, encrypts it and transmits it over AS4. You never configure the protocol or write a single message.
Does AS4 guarantee that an invoice is delivered?
The receiving access point returns a signed receipt confirming that the message was received and decrypted. That receipt covers the transport, not the business acceptance of the invoice, which is handled by a separate message (the Message Level Response).




