Service outage or capacity failure
Platform unavailability stops invoice submission, receipt, validation, and status updates simultaneously. The most visible form is a complete outage, but capacity failures are equally damaging — peak-volume periods around month-end, quarter-end, and tax deadlines create bottlenecks that manifest as API throttling, growing queues, time-outs, and delayed acknowledgements. Platform availability and successful end-to-end delivery are not the same thing. A platform can be technically reachable while invoices are stacking up unprocessed. When evaluating providers, ask specifically about tested transaction capacity and performance headroom — not just uptime figures.
Interoperability and routing failure
Approved platforms must exchange invoices with one another through the PPF directory. When that exchange breaks — because of a directory lookup error, an addressing defect, or a routing failure between platforms — invoices don’t reach their destination even if your platform is functioning normally. Format transformation problems involving Factur-X, UBL, or CII can produce duplicate, rejected, misdirected, or unacknowledged invoices. Distinguishing an internal integration error from an ecosystem-level failure matters for diagnosis and remediation — the root cause determines who’s responsible for fixing it.
Cybersecurity or data-integrity incident
Ransomware, credential compromise, API abuse, and denial-of-service attacks all present distinct risk profiles for an approved platform. Each can result in alteration, loss, disclosure, or duplication of invoice data. The sensitivity of that data — pricing, counterparty details, bank account information, and tax data — makes confidentiality a compliance concern as well as a commercial one. Recovery must preserve the authenticity, integrity, and auditability of invoice records. Incident notification obligations and evidence-preservation expectations should be defined in the contract before an incident occurs.
Loss, withdrawal, or expiry of PDP accreditation
DGFiP registration is not permanent. Repeated regulatory failures, inability to provide required technical evidence or reports, and nonrenewal can each result in suspension, expiry, or withdrawal of approved status. A platform that loses its accreditation can no longer legally fulfil the approved-platform role — and businesses using it face an urgent, unplanned migration. The DGFiP official list of approved platforms should be monitored throughout the contract term, not just at the point of selection. Define internal escalation triggers for any change in a provider’s accreditation status.
Commercial failure, acquisition, or market exit
Insolvency, product discontinuation, withdrawal from France, and abrupt restructuring each create immediate migration pressure. Acquisition can lead to platform consolidation that forces migration on someone else’s timeline. Reduced support quality, slower development, and changing commercial terms can signal strategic instability before a formal exit occurs. Dependence on critical subcontractors and cloud infrastructure introduces further concentration risk. A provider can remain technically live while becoming strategically unreliable — contract protections need to account for that scenario as well as outright failure.
Implementation failure that resembles provider failure
Not all failures originate with the platform. Incorrect data mapping, master-data configuration errors, ERP release incompatibility, poor exception management, and unresolved rejection queues can all produce compliance failures that are initially misattributed to the provider. Distinguishing a vendor defect, a customer defect, and shared responsibility requires structured diagnosis. Avoid selecting a new provider before identifying the true failure domain — switching platforms doesn’t fix a data quality problem.