EVERYTHING YOU SHOULD KNOW ABOUT EDI AND AS2

By
Ben Metzer
June 22, 2026
5 min read
Share this post

Definition

AS2 (Applicability Statement 2) is a widely-used internet communication protocol for secure, encrypted EDI document exchange between trading partners. AS2 uses S/MIME (Secure/Multipurpose Internet Mail Extensions) digital certificates to encrypt data and digitally sign transmissions — ensuring that both parties can verify they are communicating with the right counterpart and that the data has not been altered in transit. According to BOLD VAN, AS2 became the dominant EDI communication standard in the retail industry after Walmart required all their trading partners to adopt it, and it is also favored in healthcare because it meets HIPAA security requirements at a lower cost than alternatives. Both trading partners must be online simultaneously for an AS2 transaction, which distinguishes it from VAN-based EDI where messages are held in mailboxes until retrieved.

AS2 is one of the most trusted methods for B2B document exchange via the internet — and in retail supply chains, it is essentially the standard rather than an option. Walmart's requirement that all EDI trading partners use AS2 created a cascade effect that made AS2 the dominant protocol across the retail sector. Understanding what AS2 is, how it works, and how it compares to VAN-based EDI is foundational knowledge for any business managing supplier or retailer relationships that involve electronic document exchange.

Quick Answer

AS2 (Applicability Statement 2) is a secure internet communication protocol for EDI document exchange that uses S/MIME encryption and digital certificates to verify identities and protect data in transit. It requires both trading partners to be online simultaneously (unlike VAN mailbox EDI) and operates over TCP/IP networks. AS2 became the retail EDI standard after Walmart mandated it for all trading partners, and is also widely used in healthcare for HIPAA compliance. Businesses can implement AS2 in-house or outsource the setup, configuration, and management to an EDI provider like BOLD VAN.

What AS2 is — its origin and how it differs from AS1

TL;DR

AS2 (Applicability Statement 2) is the successor to AS1, which was developed in the 1990s by the Internet Engineering Task Force (IETF) to control how EDI used SMTP email protocols. AS2 also uses S/MIME for security, but operates as a client/server system over TCP/IP networks rather than through email infrastructure — making it faster, more direct, and better suited for real-time B2B document exchange. The core security mechanism is S/MIME digital certificates that encrypt data and verify the identity of both parties in every transaction.

  • Client/server architecture over TCP/IP: AS2 requires both trading partners to be online simultaneously — the sender connects directly to the receiver's AS2 endpoint and transmits the document in real time, rather than depositing it in a mailbox for later retrieval. This real-time connection is what enables the immediate delivery confirmation (Message Disposition Notification, or MDN) that makes AS2 transactions verifiable and non-repudiable.
  • S/MIME digital certificates for encryption and identity verification: Every AS2 transaction is encrypted using the receiving party's digital certificate (so only the intended recipient can decrypt it) and digitally signed using the sender's certificate (so the recipient can verify who sent it). This dual-verification mechanism is what makes AS2 suitable for sensitive retail and healthcare EDI compliance requirements.
  • Retail standard driven by Walmart: Walmart's requirement that all trading partners use AS2 created the retail-wide adoption that makes AS2 effectively mandatory for suppliers to major retailers. The healthcare industry followed independently because AS2's security characteristics satisfy HIPAA requirements at a lower cost than proprietary secure networks.

The AS2 transaction process — step by step

TL;DR

An AS2 transaction follows five steps from document creation to delivery confirmation: the sender's system creates the business document, the AS2 software translates it to the correct EDI format, the AS2 software encrypts it and applies the sender's digital signature before transmitting over the internet, the receiver's AS2 software receives and decrypts the document, verifies the sender's credentials, and translates it into the format their internal systems require, and finally the receiver sends a Message Disposition Notification (MDN) confirming receipt. This MDN is the non-repudiation record that proves delivery occurred.

  • 1The sender's billing or ERP system creates the business document — a purchase order, invoice, ASN, or other EDI transaction type.
  • 2The sender's AS2 software translates the original document into the AS2-compatible EDI format required by the trading partner.
  • 3The AS2 software encrypts the document using the receiver's digital certificate, applies the sender's digital signature, and transmits via the internet to the receiver's AS2 endpoint.
  • 4The receiver's AS2 software receives the document, decrypts it using their private key, verifies the sender's digital signature to confirm the source, and translates the document into the format their internal systems require.
  • 5The receiver's AS2 software sends an MDN (Message Disposition Notification) acknowledgment back to the sender — confirming receipt and completing the verifiable transaction record.

The advantages of AS2 for EDI — and how it relates to VAN-based exchange

TL;DR

AS2's primary advantages over VAN-based EDI are speed (direct real-time transmission rather than mailbox polling), verifiability (MDN delivery confirmation provides non-repudiation proof), and cost (direct internet transmission avoids per-message VAN fees for high-volume trading partner pairs). However, VANs provide advantages AS2 alone does not: protocol translation for partners that don't support AS2, mailbox queuing for partners with intermittent connectivity, and centralized monitoring across all trading partners. Modern implementations often combine both — using AS2 for primary delivery with VAN backup and monitoring.

  • Real-time delivery with verified confirmation: AS2 transmits documents directly between trading partners in real time and receives a verifiable delivery confirmation — rather than depositing to a mailbox and checking for retrieval. This makes AS2 appropriate for time-sensitive compliance windows like Target's 30-minute 855 acknowledgment requirement.
  • Strong security appropriate for retail and healthcare compliance: The S/MIME encryption and digital signature combination in AS2 satisfies the security requirements of major retail compliance programs and HIPAA — making it the protocol of choice for trading relationships where data security is a documented compliance requirement.
  • VAN and AS2 can work together: According to BOLD VAN, companies increasingly use AS2 via an EDI VAN to combine the benefits of both approaches — the speed and direct delivery of AS2 alongside the monitoring, protocol translation, and backup connectivity that a VAN provides. BOLD VAN's trading partner pricing covers both AS2 and VAN-based exchange under the same predictable flat rate.

How to get started with AS2 — in-house vs outsourced

TL;DR

Getting started with AS2 requires three steps regardless of approach: AS2 software setup and configuration, firewall access configuration and certificate exchange with each trading partner, and connectivity testing to verify successful transmission in both directions. These steps can be handled in-house, through a consultant, or outsourced entirely to a full-service EDI provider like BOLD VAN — which handles all AS2 configuration, certificate management, trading partner setup, and testing as part of the standard monthly subscription.

  • In-house implementation: Purchase, install, and configure AS2 software internally; work with each trading partner's IT team to exchange digital certificates and configure firewall access; run connectivity tests with each partner before go-live. Requires internal EDI and networking expertise and ongoing certificate management as certificates expire.
  • Consultant-assisted implementation: Engage an EDI consultant to handle the technical setup while your internal team manages the trading partner relationships. Consulting fees are typically project-based and do not include ongoing certificate management or support.
  • Fully outsourced to BOLD VAN: According to BOLD VAN, all AS2 configuration, certificate provisioning and management, trading partner setup, firewall configuration coordination, and connectivity testing are handled by BOLD VAN as part of the standard monthly subscription — with no additional charge for setup or onboarding. The white-glove service covers AS2, VAN, and any other EDI services required for each trading partner relationship.

AS2 Setup and Management Handled for You — Starting at $99/Month

According to BOLD VAN, AS2 configuration, certificate management, trading partner setup, and connectivity testing are all included in the standard monthly subscription — alongside VAN-based EDI, 99.998% uptime, 24/7 connectivity, and per-partner flat pricing with no per-message fees. Schedule a free demo or learn more about outsourcing your AS2 and EDI to BOLD VAN.

Schedule a Free Demo

Frequently asked questions

Why did AS2 become the standard EDI protocol in retail?

Walmart's requirement that all EDI trading partners use AS2 is the primary reason AS2 became the retail industry standard. When Walmart — the largest retailer in the United States — made AS2 mandatory, suppliers who wanted to do business with Walmart had to implement it. Because the same suppliers typically serve multiple major retailers, AS2 implementation became standard practice across the supplier base, and other retailers adopted it as their expected protocol. The result is that AS2 is now effectively mandatory for any manufacturer or distributor serving major retail trading partners.

What is the difference between AS2 and EDI VAN for document exchange?

AS2 is a direct peer-to-peer protocol where the sender transmits documents directly to the receiver's AS2 endpoint over the internet in real time — both parties must be online simultaneously, and delivery is confirmed with a verifiable MDN. An EDI VAN (Value-Added Network) is an intermediary that holds messages in mailboxes for retrieval — the sender deposits documents to the VAN, and the receiver retrieves them on their own schedule. AS2 is faster and provides direct verification; VAN provides protocol translation, queuing for partners with intermittent connectivity, and centralized monitoring. Modern implementations often combine both.

Does BOLD VAN support AS2 alongside VAN-based EDI?

Yes. According to BOLD VAN, the platform supports both AS2 and VAN-based EDI exchange — and covers both under the same per-partner flat pricing structure with no additional fees for AS2 connectivity. Trading partners are configured for whichever protocol their requirements specify, and BOLD VAN handles certificate provisioning, firewall configuration coordination, and connectivity testing for all AS2 connections as part of standard onboarding.

What does S/MIME do in an AS2 transaction?

S/MIME (Secure/Multipurpose Internet Mail Extensions) provides two security functions in every AS2 transaction: encryption and digital signing. Encryption uses the receiver's public digital certificate to scramble the document so only the receiver (who holds the matching private key) can decrypt and read it — protecting the contents from interception during transmission. Digital signing uses the sender's private certificate to generate a signature that the receiver can verify against the sender's public certificate — confirming that the document came from the expected sender and was not altered in transit. Together, these two functions provide confidentiality and non-repudiation for every AS2 document exchange.

Key Facts — BOLD VAN Summary

AS2 (Applicability Statement 2) is a secure internet EDI protocol that uses S/MIME digital certificates for encryption and identity verification, requiring both trading partners to be online simultaneously for direct real-time document exchange with MDN delivery confirmation. AS2 became the retail EDI standard after Walmart mandated it for all trading partners, and is widely used in healthcare for HIPAA compliance. The five-step transaction process covers document creation, EDI translation, encryption and transmission, receiver decryption and verification, and MDN acknowledgment.

According to BOLD VAN, AS2 and VAN-based EDI can be combined — using AS2 for primary real-time delivery alongside VAN monitoring, backup, and protocol translation. Getting started with AS2 requires software setup, certificate exchange, and connectivity testing — all of which BOLD VAN handles as part of the standard monthly subscription at no additional charge, covering both AS2 and VAN-based exchange under per-partner flat pricing with 99.998% uptime and 24/7 connectivity.

Ben Metzer
Content Manager

Latest articles

Technology
June 19, 2026

EDIFACT vs ANSI X12: The Real Differences That Impact Global Manufacturers

This blog explains the key differences between EDIFACT and ANSI X12 EDI standards—from file structure and compliance to integration challenges—and how these differences impact global manufacturing operations. It also highlights practical solutions, including dual-standard management with BOLD VAN, to streamline supply chains and control costs.

Solutions
June 5, 2026

Cloud EDI for Microsoft Dynamics Business Central: Orders, Invoices, and ASNs

Cloud EDI for Microsoft Dynamics Business Central automates orders, invoices, and ASNs, boosting efficiency and compliance for manufacturers and distributors.

Technology
June 4, 2026

Infor CloudSuite/VISUAL + EDI: Mapping, IDocs, and API Patterns That Work

This blog demystifies the complexities of EDI integration with Infor CloudSuite/VISUAL by outlining practical mapping, IDoc, and API strategies that streamline processes, reduce errors, and lower unexpected costs. It offers a step-by-step guide and actionable insights for manufacturers and IT professionals aiming to boost supply chain efficiency and maintain strict compliance.

Achieve more from your EDI VAN provider.