ZATCA E-Invoicing: Phase 2 Waves, Fatoora Onboarding, and Penalties

ZATCA e-invoicing is Saudi Arabia’s mandatory system for generating, stamping, and transmitting VAT invoices electronically through the Fatoora platform. If your business is registered for VAT in the Kingdom, you must issue every sales invoice through compliant software, and once your revenue-based wave takes effect you must also connect that software to ZATCA for either near-real-time clearance (B2B and B2G) or 24-hour reporting (B2C). Non-compliance carries fines from SAR 5,000 to SAR 50,000 per violation, with the numbers climbing for repeat offenses.1

Who Has to Comply

Every taxable person registered for VAT in Saudi Arabia falls within scope. The one carve-out is non-resident taxpayers with no permanent establishment in the Kingdom. If a third party issues invoices on your behalf, that third party has to meet the same technical requirements you do. Both B2B and B2C transactions are covered, so every sale you make inside Saudi Arabia has to flow through a compliant electronic system.

Businesses that deal exclusively in VAT-exempt supplies are outside the rules entirely. Fully exempt supplies and any advance payments tied to them are excluded by the implementation resolution. If you handle a mix of taxable and exempt transactions, the taxable portion still needs a compliant system.

Standard and Simplified Invoices

ZATCA recognizes two invoice types, and the distinction drives everything about how the invoice reaches the platform.

A standard tax invoice is used for B2B and business-to-government sales where the buyer has a valid tax registration number and a full address. Under Phase 2, standard invoices go through a clearance model: your system sends the invoice to Fatoora, ZATCA validates and applies its own cryptographic stamp, and only then can you share the cleared invoice with the buyer. This happens in near-real-time, so your integration needs a reliable connection.

A simplified tax invoice covers B2C sales where the buyer lacks a tax registration number or doesn’t provide full details. These follow a reporting model. You issue the invoice directly to the customer with a QR code and your own cryptographic stamp already applied, then report the invoice data to ZATCA within 24 hours. The customer doesn’t wait for approval, but your reporting window is tight.

Getting the classification wrong can block a transaction from clearing or delay your reporting, so your software has to pick the right type based on the buyer’s information.

Credit and Debit Notes

The rules apply to more than sales invoices. Credit notes (reducing what a buyer owes, such as for returns) and debit notes (increasing the amount) have to be generated in the same XML or PDF/A-3 format, carry cryptographic stamps, and reference the original invoice. A note tied to a standard invoice goes through clearance. A note tied to a simplified invoice follows the 24-hour reporting model. These notes are required for claiming input tax deductions, so generating them outside your compliant system can create audit problems later.

What Your Software Must Do

Your accounting or ERP system has to generate invoices in XML or PDF/A-3 with embedded XML. Machine-readable structure is what lets Fatoora validate invoices automatically. Every invoice must include the seller’s name, VAT registration number, a transaction timestamp, line-item detail, and tax totals.

Each invoice also needs a Universally Unique Identifier (UUID) to prevent duplicates and a cryptographic hash that chains it to the previous invoice. That hash chain creates a sequential, tamper-evident log: any attempt to insert, delete, or reorder invoices after the fact breaks the chain. Cryptographic stamps use the ECDSA (Elliptic Curve Digital Signature Algorithm) standard and must comply with Saudi Arabia’s National Cryptographic Standards.

Simplified invoices carry a QR code that encodes transaction data in Tag-Length-Value (TLV) format. Under Phase 2, the QR code holds nine data elements: seller name, VAT registration number, invoice timestamp, total with VAT, total VAT, the XML hash, the ECDSA digital signature, the public key used to generate that signature, and ZATCA’s own cryptographic stamp signature. The concatenated byte array is Base64-encoded. Standard invoices also need QR codes under Phase 2, though the encoding differs because ZATCA applies its own stamp during clearance.

What Your Software Must Not Do

ZATCA also lists features that automatically make a solution non-compliant, whether or not the feature was used:

  • Uncontrolled access: anonymous login, unchanged default passwords, or missing user session management.
  • Tampering capabilities: any ability to alter or delete generated invoices, modify or delete system logs, generate invoices with inaccurate timestamps, produce logs out of sequence, or reset the invoice counter.
  • Multiple invoice sequences: no more than one invoice sequence per unit at a time.
  • Cryptographic key export: no option to export the private key used for stamping (Phase 2).
  • Time manipulation: no ability to change the software clock or modify timestamps during invoice generation (Phase 2).

Verifying that these features are genuinely absent is the first technical check when you evaluate any ERP or e-invoicing add-on.

When You Have to Integrate: The Phase 2 Wave Schedule

Phase 1, the Generation Phase, has been mandatory since December 4, 2021, and applies to every VAT-registered taxpayer in scope. Phase 2, the Integration Phase, began on January 1, 2023, and rolls out in waves keyed to your annual taxable revenue. ZATCA sends direct notifications at least six months before your integration deadline, but the revenue figures come from your filed VAT returns, so ZATCA already knows which wave you’re in.

The most recent waves reach mid-sized and smaller businesses:

  • Wave 13 (Jan–Mar 2025): revenue above SAR 7 million in 2022 or 2023.
  • Wave 14 (Feb–Apr 2025): above SAR 5 million in 2022 or 2023.
  • Wave 15 (Mar–May 2025): above SAR 4 million in 2022 or 2023.
  • Wave 16 (Apr–Jun 2025): above SAR 3 million in 2022 or 2023.
  • Wave 17 (May–Jul 2025): above SAR 2.5 million in 2022 or 2023.
  • Wave 18 (Jun–Aug 2025): above SAR 2 million in 2022 or 2023.
  • Wave 19 (Jul–Sep 2025): above SAR 1.75 million in 2022 or 2023.
  • Wave 20 (Aug–Oct 2025): above SAR 1.5 million in 2022 or 2023.
  • Wave 21 (Sep–Nov 2025): above SAR 1.25 million in 2022, 2023, or 2024.
  • Wave 22 (Oct–Dec 2025): above SAR 1 million in 2022, 2023, or 2024.
  • Wave 23 (Jan–Mar 2026): above SAR 750,000 in 2022, 2023, or 2024.
  • Wave 24 (Apr–Jun 2026): above SAR 375,000 in 2022, 2023, or 2024.

From Wave 21 onward, ZATCA widened the lookback to include 2024 revenue. If you crossed the threshold in any of the applicable years, you’re in scope. Vendors and integrators get swamped as deadlines approach, so if your revenue puts you near an upcoming threshold, start work well before the notification arrives.

How Onboarding to Fatoora Works

Integration follows a set sequence. Your software generates a Certificate Signing Request (CSR) and submits it to ZATCA’s platform. ZATCA issues a Compliance Cryptographic Stamp Identifier (CCSID), which lets your system authenticate with Fatoora during testing.

Before going live, you have to pass compliance checks by sending test invoice samples to ZATCA’s Compliance API. The count depends on what you issue: three samples for standard-only (one invoice, one credit note, one debit note), three for simplified-only, or six if you issue both. After passing, you request a Production Cryptographic Stamp Identifier (PCSID), which replaces the compliance credential and authorizes live submissions.

Sandbox and Simulation

ZATCA runs a simulation environment where developers validate integration before touching production data. The sandbox at sandbox.zatca.gov.sa provides CSR templates, test certificates, and compliance checks against ZATCA’s specifications. A separate simulation environment covers both clearance and reporting flows so you can verify XML structure, digital signatures, hash values, and QR codes. The recommended path is simulation first, then sandbox for formal compliance verification, then production.

Storage and Local Access

If your e-invoicing solution or data center is outside Saudi Arabia, you need a terminal or system extension inside the Kingdom that can reach all invoice records and related data. The original supporting documents for entries kept electronically also have to be held locally. You can outsource storage to a third party, but legal responsibility for compliance stays with your business.

Electronic invoices and their associated notes must be kept for at least five years from the date of issuance. That includes the invoice files themselves, cryptographic stamps, QR code data, and any credit or debit notes. ZATCA can audit throughout the retention period, so archives have to preserve the original XML or PDF/A-3 format without altering content or cryptographic elements.

Penalties and the Current Waiver Window

Failing to issue or archive e-invoices carries fines from SAR 5,000 to SAR 50,000, with first-time violations landing at the lower end and repeat offenses climbing toward the ceiling. Missing required data fields or running non-compliant software carry their own penalty ranges.

ZATCA is running a penalty waiver initiative covering e-invoicing and VAT field-detection violations committed before January 1, 2026. To qualify, you have to file all outstanding VAT returns and either pay your full tax debt or enter an approved installment plan before the initiative closes on June 30, 2026. If you’ve been operating with a non-compliant system and haven’t yet drawn enforcement, that window is the cleanest way to reset. Once it closes, the standard penalty schedule applies without relief.

  • 1