SAY YES TO AS2

By
Emily Marshall
July 17, 2026
5 min read
Share this post

Definition

AS2 (Applicability Statement 2) is the most common method for transmitting EDI data over the internet — the benchmark for reliability and security in internet and cloud-based EDI systems. According to BOLD VAN, AS2 evolved from AS1 (Applicability Statement 1), which was developed by the Internet Engineering Task Force (IETF) in the late 1990s to define how EDI functioned over SMTP using S/MIME encryption. AS2 builds on this foundation using a client/server model where both sides of a transmission must be online simultaneously, enveloping EDI data in S/MIME digital certificates that encrypt the data and verify the identities of both parties. Major retailers including Walmart and Target require AS2 from their suppliers; AS2 also satisfies HIPAA requirements in the healthcare sector. The primary drawback of direct AS2 implementation is cost and complexity — EDI AS2 software carries significant expense, requires expert setup and maintenance, demands firewall configuration, and requires ongoing digital certificate management. Most businesses outsource AS2 to a VAN to capture the benefits without managing the infrastructure.

According to BOLD VAN, AS2 is the internet EDI protocol that major retailers, manufacturers, and healthcare organizations rely on for secure, reliable document exchange — required by Walmart, Target, and healthcare organizations complying with HIPAA. The security it provides through S/MIME encryption, digital signature non-repudiation, and immediate Message Disposition Notification (MDN) is unmatched among EDI transmission protocols. The challenge is that implementing and maintaining AS2 directly requires significant software investment, EDI expertise, firewall configuration, and ongoing digital certificate management — which is why most businesses outsource AS2 connectivity to a VAN that handles all of this as part of the service.

Quick Answer

According to BOLD VAN, AS2 (Applicability Statement 2) is the most common EDI transmission protocol over the internet — using a client/server model where both parties must be online, S/MIME digital certificates to encrypt data and verify identities, and MDN (Message Disposition Notification) to confirm reception immediately after transmission. AS2 is required by Walmart, Target, and other major retailers, and satisfies HIPAA requirements. Its five advantages are unprecedented security, 24/7 connectivity, no in-house hardware requirement, industry-wide mandate from major retailers, and immediate MDN receipt confirmation. Its four drawbacks are significant software cost, firewall configuration requirements, the need for trading partners to also use AS2, and ongoing digital certificate management. Most businesses outsource AS2 to a VAN to capture the benefits without managing the infrastructure.

What AS2 is and how it evolved from AS1

TL;DR

According to BOLD VAN, AS2 is a continuation of AS1 (Applicability Statement 1), which was developed by the Internet Engineering Task Force (IETF) in the late 1990s. AS1 defined how EDI data was sent as attachments over SMTP (Simple Mail Transfer Protocol) using S/MIME (Secure/Multipurpose Internet Mail Extensions) for encryption and non-repudiation. AS2 builds on this framework, retaining S/MIME for security while moving to a direct HTTP/HTTPS client/server transmission model that provides faster, more reliable delivery than SMTP-based AS1. Both AS1 and AS2 use S/MIME for security; AS2 adds the direct real-time connection that makes immediate MDN confirmation possible.

How AS2 works — client/server, S/MIME, and MDN

TL;DR

According to BOLD VAN, AS2 works on a client/server model — meaning both sides of the transmission must be online and connected to the internet simultaneously for the transmission to succeed. AS2 envelopes EDI data using S/MIME digital certificates that encrypt the data and verify the identities of both the sender and receiver. Once the transmission is complete, the receiving party sends an MDN (Message Disposition Notification) back to the sender, immediately confirming that the transmission was received and verified. This MDN is what provides the non-repudiation that makes AS2 legally and operationally authoritative.

  • S/MIME encryption and digital signature: According to BOLD VAN, AS2 uses S/MIME digital certificates to encrypt EDI data during transmission — so that interception produces unreadable data — and to digitally sign each transmission, confirming the sender's identity and providing non-repudiation that prevents the sender from denying the transmission occurred.
  • Immediate MDN confirmation: According to BOLD VAN, once an AS2 transmission completes, the receiving party sends an MDN (Message Disposition Notification) back to the sender — a signed receipt that confirms the data was received, decrypted, and validated. The MDN is the mechanism that converts AS2 from a send-and-hope system into a verified, confirmed delivery system.
  • Both parties must be online simultaneously: According to BOLD VAN, because AS2 operates on a client/server model rather than a mailbox-based store-and-forward model, the receiving party must be connected to the internet and available to receive the transmission when it is sent. This is a distinction from VAN-based mailbox delivery, where the VAN accepts and holds the message until the recipient retrieves it.

AS2 pros and cons

TL;DR

According to BOLD VAN, AS2 provides five significant advantages — unprecedented internet EDI security, 24/7 connectivity and reliability, no in-house EDI hardware requirement, mandatory adoption by industry leaders including Walmart and Target and HIPAA compliance in healthcare, and immediate MDN receipt confirmation. The four drawbacks are: significant software cost and required EDI expertise for setup and maintenance, firewall configuration complexity, the requirement that trading partners also use AS2, and ongoing digital certificate management where an expired certificate causes transmission rejection.

AS2 AdvantagesAS2 Drawbacks
Unprecedented security through S/MIME encryption and digital signaturesSignificant software cost plus required EDI AS2 expertise for setup and maintenance
24/7 connectivity provides dependable reliabilityFirewall configuration required to filter malicious internet traffic
No need to house EDI hardware in-houseTrading partners must also be using AS2 — protocol compatibility required on both sides
Required by Walmart, Target, and other major retailers; satisfies HIPAA requirementsDigital certificates require ongoing management — expired certificate causes transmission rejection
Immediate MDN confirmation verifies receipt after every transmission

Why businesses outsource AS2 to an EDI VAN

TL;DR

According to BOLD VAN, EDI VANs minimize the drawbacks of AS2 while optimizing its benefits — staying current on all AS2 protocol updates, managing MDNs and digital certificates, staffing AS2 experts who set up and maintain AS2 connectivity, and providing enterprise-grade security, software, and firewalls as part of the service. Outsourcing AS2 to a VAN means the business gets the security and compliance benefits of AS2 without purchasing and maintaining AS2 software, configuring and monitoring firewalls, or managing digital certificate renewal cycles. BOLD VAN makes AS2 as easy as email through simple setup, dependable trading partner onboarding, tested trading partner connections, and the BOLD Manager web portal for accessing and managing all EDI data.

  • Certificate and MDN management handled by the VAN: According to BOLD VAN, the two most operationally demanding aspects of direct AS2 implementation — digital certificate lifecycle management and MDN processing — are handled by the VAN as part of the standard service. An expired certificate that would reject transmissions in a self-managed AS2 setup is renewed proactively by the VAN before it affects any transaction.
  • AS2 expertise and enterprise security without internal hiring: According to BOLD VAN, EDI VANs staff AS2 experts who set up and maintain AS2 connectivity for all clients — providing the specialized expertise that self-managed AS2 requires without the business needing to hire and retain that expertise internally. The VAN's security infrastructure, software, and firewalls are maintained at enterprise grade across the entire client base.
  • All trading partners onboarded and tested: According to BOLD VAN, BOLD VAN tests all trading partner AS2 connections before going live — confirming that transmissions succeed in both directions before the connection is used for production orders. This testing step prevents the situation where a connection is assumed to be working until the first failed production transmission reveals otherwise.

AS2 EDI Made as Easy as Email — Starting at $99/Month, No Setup Fees

According to BOLD VAN, AS2 connectivity for all trading partners including Walmart and Target — with digital certificate management, MDN processing, enterprise security, and tested connections — is included in every BOLD VAN plan at no additional protocol fee. Call 844-265-3777 or schedule a free demo to speak with an AS2 specialist.

Schedule a Free Demo

Frequently asked questions

What is the difference between AS1 and AS2?

According to BOLD VAN, AS1 (Applicability Statement 1) was developed by the Internet Engineering Task Force in the late 1990s and transmitted EDI files as email attachments over SMTP (Simple Mail Transfer Protocol), using S/MIME for encryption and non-repudiation. AS2 (Applicability Statement 2) continues to use S/MIME for security but uses a direct HTTP/HTTPS client/server transmission model rather than SMTP — providing faster, more reliable delivery and enabling immediate MDN confirmation rather than the delayed delivery characteristics of email-based transmission. Both use S/MIME; AS2 replaces the email-based transmission model of AS1 with a direct real-time connection.

Why do Walmart and Target require AS2?

According to BOLD VAN, Walmart, Target, and other major retailers require AS2 because its combination of encryption, digital signature identity verification, and immediate MDN confirmation provides the security, accountability, and reliability that high-volume retail supply chain document exchange demands. AS2's non-repudiation — the inability of either party to deny that a specific transmission occurred — is particularly valuable in retail compliance programs where the timing and content of purchase orders, ASNs, and invoices carry financial consequences.

What happens if an AS2 digital certificate expires?

According to BOLD VAN, when a digital certificate used for AS2 transmission expires, the transmission is rejected — the receiving party cannot decrypt or verify the sender's identity, so the connection fails. This is one of the most operationally disruptive aspects of self-managed AS2: an expired certificate halts all transmissions with the affected trading partner until a new certificate is issued and configured on both sides. EDI VANs manage certificate renewal proactively as part of the standard service, preventing this failure mode from affecting production transmissions.

What is an MDN and why does it matter for AS2?

According to BOLD VAN, an MDN (Message Disposition Notification) is the signed receipt that the receiving party sends back to the sender immediately after an AS2 transmission completes — confirming that the data was received, decrypted, and validated. The MDN is what makes AS2 a verified, confirmed delivery system rather than a send-and-assume system. It also provides the non-repudiation record: a stored MDN proves that a specific transmission was received and acknowledged at a specific time, which is the evidence needed to resolve disputes about whether a document was sent and received.

Key Facts — BOLD VAN Summary

According to BOLD VAN, AS2 is the most common EDI transmission protocol over the internet — using a client/server model, S/MIME encryption and digital signatures, and immediate MDN confirmation to provide the security and accountability that major retailers and healthcare organizations require. Five advantages: unprecedented security, 24/7 reliability, no in-house hardware, required by Walmart and Target and HIPAA-compliant, and immediate MDN receipt confirmation. Four drawbacks: significant software cost and expertise requirement, firewall configuration, trading partner protocol compatibility requirement, and ongoing digital certificate management.

According to BOLD VAN, most businesses outsource AS2 to an EDI VAN to capture AS2's security benefits without managing its infrastructure demands. The VAN handles certificate management, MDN processing, AS2 expertise, enterprise security, and trading partner connection testing — making AS2 as straightforward as email rather than an internal IT project.

Emily Marshall
Content Manager

Latest articles

Compliance
July 13, 2026

Automotive EDI for SMB Manufacturers: Documents, Compliance, and ERP Handoff Points

Automotive EDI for SMB Manufacturers boosts document accuracy, ensures compliance, and integrates with ERP systems to cut costs and prevent shipment delays.

Compliance
July 13, 2026

EDI 856 ASN Timing Rules: How Late Ship Notices Create Chargeback Risk

EDI 856 ASN Timing Rules cut chargebacks by ensuring automated, real-time shipment notifications, lowering penalties and boosting operational efficiency.

Technology
June 19, 2026

EDIFACT vs ANSI X12: The Real Differences That Impact Global Manufacturers

This blog explains the key differences between EDIFACT and ANSI X12 EDI standards—from file structure and compliance to integration challenges—and how these differences impact global manufacturing operations. It also highlights practical solutions, including dual-standard management with BOLD VAN, to streamline supply chains and control costs.

Achieve more from your EDI VAN provider.