Accreditation criteria

What accreditation actually requires — and why ISO 27001 is not an advantage

Plenty of providers lead with an ISO 27001 badge as though it sets them apart. The Ministry requires it of all of them — it is the entry ticket, not a reason to choose. Here are the real criteria, and what actually separates one provider from another.

Last updated: 30 August 2026·5 min read
The core condition

No provider reaches the accredited list without holding ISO 27001 (information security) and ISO 22301 (business continuity), enforcing multi-factor authentication and data encryption, and evidencing a minimum two-year operating track record. All 48 accredited providers therefore meet it.

The criteria, as they stand

RequirementWhat it means in practice
ISO/IEC 27001A certified, externally audited information security management system
ISO 22301A business continuity system — a tested plan for recovering from disruption
Multi-factor authenticationA username and password alone cannot reach your invoice data
Data encryptionProtection both in transit and at rest
Two-year track recordRules out companies incorporated purely to ride the mandate

On top of that sits the technical side: operating as an access point on the Peppol network, issuing invoices in PINT AE, and reporting to the authority in real time within the five-corner model.

Why this inverts how you compare

When a certification is an entry condition, its presence carries no information. A provider telling you "we are ISO 27001 certified" has told you nothing that separates it from the other 47 — only that it qualified to be on the list at all.

What actually differentiates Certifications above the floor: SOC 2 (independent audit of operating controls), ISO 9001 (quality management), Peppol access-point accreditation, recurring penetration testing. Of the 48 accredited providers, only 13 publish anything beyond the mandatory minimum.

The questions that expose the difference

Instead of "do you have ISO 27001?" — the answer is always yes — ask:

  1. Do you hold SOC 2 Type II?The Type I / Type II distinction matters: the first is a point-in-time snapshot, the second audits controls across a real operating period.
  2. Where exactly is my invoice data stored?Accreditation does not require data to stay in the UAE. Only 14 of 48 providers state that it does.
  3. What does continuity mean in numbers?Ask for recovery time objective (RTO) and recovery point objective (RPO), not just the ISO 22301 badge.
  4. Do you support receiving, or only sending?Only 24 of 48 advertise inbound receiving, and the system requires both directions.
  5. When were your certificates issued and when do they expire?Ask for a dated copy, not a logo on a website.

So why do they keep marketing it?

Because it works. A buyer who does not know it is mandatory reads it as evidence of seriousness — which it genuinely is. It is just not evidence of superiority. That gap between "qualified" and "better" is what sends an entire selection process in the wrong direction if you do not catch it early.

Compare on what actually differs

Our table carries an "extra certifications" column that strips out the mandatory floor and shows only what sits above it — alongside data residency, inbound receiving and published pricing.

Open the ASP directory

Read next

Frequently asked

What are the UAE requirements to become an accredited e-invoicing service provider?

A provider must hold ISO 27001 and ISO 22301, enforce multi-factor authentication and data encryption, and evidence a minimum two-year operating track record, alongside the technical capability to operate as a Peppol access point, issue PINT AE invoices and report to the authority in real time.

Does ISO 27001 distinguish one provider from another?

No. It is a mandatory accreditation condition met by all 48 accredited providers. What differentiates is what sits above that floor — SOC 2 Type II, ISO 9001 — which only 13 providers publish.

Does accreditation require invoice data to stay in the UAE?

No, data residency is not among the published accreditation criteria. That makes it a live negotiating point: only 14 of 48 accredited providers publicly state that invoice data remains in-country.

What is the difference between SOC 2 Type I and Type II?

Type I attests that controls were suitably designed at a point in time. Type II attests that they operated effectively across an extended period, typically six to twelve months. Type II is substantially stronger.

This content is general awareness, not tax or legal advice. Figures are based on the official Ministry of Finance list and each provider's own published materials as at 30 August 2026. The lists change — verify on mof.gov.ae and tax.gov.ae before contracting. Our method is documented in the methodology page.