Almost nothing from the web of 1999 is still in daily use. The browsers are gone, the portals are gone, most of the companies are gone. And yet two standards from that first wave of e-procurement, cXML and OCI, still decide how large organisations buy from their suppliers in 2026.
Punchout is the mechanism those standards exist for: a buyer leaves their procurement system, shops on a supplier's website, and brings the basket back into their system as a requisition. This article is not about how that works. It is about why a pair of standards older than most of the people using them have outlasted almost everything around them.
The e-procurement boom
In the late 1990s, large companies were putting their purchasing onto software for the first time. Ariba, Commerce One, SAP and Oracle were all building buyer-side procurement systems, and the promise was the same from each: every purchase requested, approved and recorded in one place. The problem was the supplier side. A buyer with a thousand suppliers could not build a thousand custom connections, and suppliers could not afford a different integration for every customer.
The contrast with the rest of that era is sharp. Commerce One, one of the biggest names of the boom, no longer exists. Most of the portals, exchanges and marketplaces launched alongside it were gone within a few years. The buyer-side software survived because large organisations had paid for it and built processes around it, and the connection standards survived with it.
Something had to sit in the middle. A shared standard for the shopping step, so that a supplier connected once and worked with any buyer, was the obvious answer, and two of the main vendors produced one.
cXML
Ariba published cXML, commerce XML, in early 1999, and published it openly so that any supplier could connect without a bespoke build per buyer. The decision to make it open rather than proprietary is probably the single biggest reason it is still here. Suppliers adopted it because it cost nothing to adopt. Other procurement vendors adopted it because their customers' suppliers already had it.
Ariba itself was acquired by SAP in 2012, and the standard is now maintained under SAP's ownership, still published at the same place and still open. It has been revised over the years, but a supplier connected a decade ago is, broadly, still connected.
OCI
SAP's own answer was the Open Catalog Interface, built for its own procurement products so that SAP buyers could reach external catalogues from inside their system. Where cXML spread across many vendors, OCI stayed closer to home: it is the native route into SAP's purchasing systems, and it is encountered mainly where an organisation's procurement runs on SAP itself. The version most integrations still use dates from the mid-2000s.
Together, the two cover the great majority of enterprise procurement. A supplier who can handle both can connect to almost any large buyer. We explain who uses which in cXML vs OCI: which punchout protocol does your customer use?
Why they survived
Three forces keep a standard like this in place long after the technology around it has changed.
- Procurement systems change rarely. A large organisation replaces its procurement platform perhaps once a decade, and when it does, it chooses one that works with the suppliers it already has.
- Suppliers connect once and leave it alone. A working connection to a major customer is not something anyone volunteers to rebuild.
- The cost of change sits with the buyer, who has no reason to pay it. Thousands of suppliers already speak cXML or OCI. A new standard would have to be adopted by all of them before it was useful to any buyer, and no buyer is going to fund that.
Standards survive when replacing them would cost more than keeping them, and that has been true of these two for twenty-five years. There have been attempts at newer approaches, and some buyers run additional methods alongside, but none has displaced the pair at the centre.
What changed around them
Everything else moved. Procurement software went from installed systems to cloud platforms. Supplier networks grew up around the buyers, so that onboarding became a process run by a network rather than a conversation between two IT departments. Catalogue governance tightened, with buyers insisting that staff see the contracted range at the contracted price and nothing else. New vendors such as Coupa and Jaggaer arrived and became significant. The ecosystem is unrecognisable from 1999. The two standards at its centre are not.
What it means for a supplier today
Whatever you connect now will be in use for a long time. That is the practical lesson of the history. A punchout connection is not a campaign or a website refresh. It is closer to infrastructure, and it will outlast the people who commissioned it, the platform the buyer is using today, and probably the next one.
Choose who builds it accordingly. A punchout integration done by people who have worked across the main platforms will keep working as the customer's side changes, which it will. If the subject is new to you, What is punchout? gives the commercial picture in plain language, and our SAP punchout page covers the OCI side for suppliers selling into organisations that run SAP.
Been asked for punchout?
Takeoff Digital connects Magento and Shopify stores to Ariba, Coupa, Oracle, SAP and other procurement platforms, and has done it for suppliers across construction, facilities and the public sector. If a customer has just asked you the question, talk to us and we will tell you what it involves for your business.



