Skip to content
ERP Expert

ZATCA phase two — on your software, not your accountant

Ahmed Hassan Algammal6 min read
The Riyadh skyline at night

Most of what is said about phase two is aimed at the accountant: what to add to the invoice, what to review before issuing it. That framing is misleading.

Phase two is, in substance, a list of conditions on the software rather than on the person using it. ZATCA’s detailed guideline names functions that are prohibited from existing in the solution — not prohibited from being used, prohibited from being present. Read that list once and it becomes obvious why some products cannot comply however hard their implementation team works.

The two phases, briefly

The generation phase has been in force since 4 December 2021. It requires invoices to be created and stored through a compliant electronic solution.

The integration phase has been in force since 1 January 2023 and is applied in waves. ZATCA notifies taxpayers of their wave at least six months in advance.

The waves expand by lowering the revenue threshold, not raising it:

Wave Taxable revenue threshold Integration deadline
Twenty-fourth Above SAR 375,000 in 2022, 2023 or 2024 30 June 2026
Twenty-fifth Above SAR 187,500 in 2022, 2023, 2024 or 2025 1 February 2027

Read the direction of travel: the threshold halved between two consecutive waves. “My business is too small to be targeted” is a sentence with a short shelf life.

Clearance versus reporting — the distinction that gets confused

Two kinds of invoice, on entirely different paths:

Tax invoice (business to business) Simplified invoice (consumer)
Path Clearance Reporting
Timing Before it is given to the buyer Within 24 hours of issue
Who stamps it The Fatoora platform, after it passes validation Your own system, using the cryptographic stamp identifier issued to you
What is transmitted XML only, not PDF/A-3 XML only, not PDF/A-3
What the buyer receives XML, or PDF/A-3 with the XML embedded An immediate printed copy, or another agreed format

The operational difference between the first two rows is everything. A tax invoice is not an invoice until the platform has cleared it — meaning your system stops and waits for an external response. A simplified invoice is handed over immediately and reported afterwards, within twenty-four hours.

The design consequence is worth stating plainly: a loss of connectivity halts business-to-business invoicing and does not halt the point of sale. Anyone who knows that writes a correct contingency procedure. Anyone who does not learns it during the first outage.

On the QR code carried by a simplified invoice, the specification is precise: nine tags in TLV format, base64 encoded. That is not an image pasted into a print template; it is data generated from the invoice itself.

The seven prohibited functions

This is the heart of it, taken from the prohibited functions section of the detailed guideline. An e-invoicing solution must not have these functions, from the generation phase onward:

Prohibited function What it means in practice
Anonymous access No access to the system without a username and password or a biometric attribute
Operating with a default password The user must be forced to change it at first use
No session management Every user action on the invoice-generation path is logged, from sign-in onward
Amending or deleting an issued invoice Forbidden, even if the invoice was created outside the system
Amending or deleting system logs Logs are stored with no alteration possible
Inaccurate timestamps No changing of time or date in a way that produces a document carrying false information
A non-sequential log Every invoice carries the hash of the previous invoice, so the sequence cannot be reordered

Stop at the fourth row; it is the most consequential line on this page. The text is explicit that cancellation has exactly one route: issue a linked credit note, then issue a new invoice.

That is a condition on the product before it is a condition on the employee. A system with a delete button on an approved invoice is non-compliant by design, and no amount of training, internal policy or withdrawn permission fixes it.

Four anti-tampering mechanisms

Beyond the above, the guideline requires the solution to be tamper-resistant, and to detect tampering attempts rather than merely prevent them. Four mechanisms are named:

No resetting the invoice counter. Resetting is not a function that exists, and the counter value is protected from system users.

No changing the date. Setting the system date is not available to users.

No uncontrolled access. All access is through a signed-in user, with that role’s permissions and no more.

No exporting the stamping keys. The private key associated with the cryptographic stamp identifier is generated by the solution such that it can be neither viewed nor copied.

That last item is the one most often skipped in a product evaluation, and its effect is decisive: anyone who can copy your stamping key can issue invoices in your name. If a provider offers to hold your key somewhere either you or they could copy it from, the evaluation is over.

Testing your system in twenty minutes

Do not ask your vendor whether you are compliant. The answer is always yes. Ask to see the following on screen, in this order:

  1. Try to delete an approved invoice. If it succeeds, the evaluation is finished.
  2. Try to change the amount on an approved invoice. The correct outcome is a refusal that directs you to a credit note.
  3. Open the user activity log and read who did what and when. Its absence is not a missing report; it is a breach of a stated requirement.
  4. Ask for a sample XML of a cleared invoice and look in it for the previous-invoice hash field.
  5. Ask where the private key is stored and who can reach it.

A system that passes all five is serious. A system that fails the first does not need configuration — it needs replacing.

Where to go from here

  • The figures and requirements above were read from the ZATCA e-invoicing pages and their detailed documentation on 6 September 2026. Check your own wave there, since waves are announced one after another.
  • If you also trade in the UAE, the model there is structurally different — five corners, with an accredited service provider standing between you and the authority — and it is set out in UAE e-invoicing.
  • If the question is which system to choose, the comparison is in Gulf e-invoicing readiness.
E-invoicingSaudi ArabiaZATCAERP

About the author

Ahmed Hassan Algammal

ERP implementation consultant. More than 60 deliveries across the UAE, Saudi Arabia and Egypt in manufacturing, contracting and distribution.

Book a call →

Read next