KodDeltaGuides

Gulf e-invoicing: what ZATCA and the UAE mandate actually require from your systems

~14 min read

In Saudi Arabia, ZATCA Phase 2 integration deadlines have all passed and the requirement now applies to every VAT-registered business: invoices must be UBL 2.1 XML, cryptographically stamped with an X.509 certificate issued by ZATCA, chained by hash, and carry a TLV Base64 QR code. Standard B2B invoices are cleared with ZATCA before they reach the buyer; simplified B2C invoices are reported within 24 hours. In the UAE the model is Peppol-based with the PINT AE format, transmitted through an accredited service provider — and businesses over AED 50 million must appoint one by 30 October 2026.

Two Gulf regimes now sit directly in the path of any company invoicing from or into the region, and they work differently enough that a single “e-invoicing module” rarely covers both.

The purpose of this article is to state what each one actually requires from a system, in terms specific enough to scope work against.

Saudi Arabia: Phase 2 is no longer a schedule

The most important change since most guidance was written is that the waves are finished.

WaveThresholdDeadline
Wave 23VAT-subject revenue above SAR 750,000Q1 2026
Wave 24VAT-taxable revenue above SAR 375,000 in 2022, 2023 or 202430 June 2026

Wave 24 was announced in September 2025, carried the lowest threshold of any wave, and closed on 30 June 2026. It was the last one. The practical consequence is that Phase 2 integration is no longer a question of when your wave arrives — it applies to VAT-registered businesses generally, and a company that is not integrated is late rather than waiting.

What a compliant invoice has to be

Five requirements, each of which is a separate piece of work:

RequirementDetail
FormatStructured XML aligned with the UBL 2.1 schema, or PDF/A-3 with the XML embedded
Cryptographic stampStamped using a CSID — an X.509 certificate issued by ZATCA to your invoicing solution
SigningXAdES signature over the document
Hash chainEach invoice references the previous one, so the sequence cannot be edited after the fact
QR codeTLV (tag-length-value), Base64 encoded, nine tags in Phase 2 against five in Phase 1

The QR requirement is worth dwelling on, because it is a common and quiet failure. Phase 2 does not accept a QR code containing a URL or human-readable text. It expects a prescribed TLV structure carrying the seller’s name, VAT registration number, timestamp, invoice total and VAT total alongside the cryptographic elements. A code that scans and shows something sensible to a human can still be non-compliant.

Clearance and reporting are two different workflows

This is the distinction that shapes the architecture, and it is regularly missed:

Invoice typeWorkflowTimingWhere it sits
Standard (B2B, B2G) Clearance Real time, before the invoice reaches the buyer In the critical path of the sale
Simplified (B2C) Reporting Within 24 hours of issue Outside the critical path

A standard invoice is submitted to ZATCA and approved before it is delivered. That makes ZATCA availability a dependency of your sales process, which in turn makes queuing, retry behaviour and clear failure states part of the requirement rather than refinements.

Simplified invoices are gentler: the sale completes and the report follows within 24 hours. A retail till does not wait on the network. But the 24-hour window is a real obligation, so the queue has to be monitored rather than merely present.

The UAE: a pilot now, deadlines through 2027

The UAE model is Peppol-based. Invoices are issued as structured XML conforming to the PINT AE specification — Peppol International Invoice, UAE — and are not submitted directly to the authority. Transmission goes through an accredited service provider (ASP) approved by the Ministry of Finance.

MilestoneDate
Pilot phase begins1 July 2026
Businesses above AED 50 million must have appointed an ASP30 October 2026
Large businesses go live1 January 2027
Small and medium businesses1 July 2027
Government transactions1 October 2027

The line in bold is the one that matters today. It was originally 31 July 2026 and was moved to 30 October 2026 — worth noting both because it is the live deadline and because it shows these dates do move. Plan against them, but do not build a schedule that only works if none of them shift.

You will not be your own ASP

Teams occasionally ask whether the ASP layer can be built internally. The accreditation criteria answer it: an applicant must already be an active Peppol-certified service provider, and must satisfy company registration, tax registration and information security requirements. An experience requirement introduced in May 2026 additionally requires the proposed solution to have been in operation for a minimum of two years.

For any business facing the current deadline, that closes the option. As of the May 2026 extension, 32 providers had been approved with more in the final stages of accreditation, so the work to plan is selecting one and integrating with it — a procurement decision with a technical tail, not a build.

What this means for your ERP

The instinctive reaction — “we need an ERP that supports ZATCA” — is usually the expensive answer to the wrong question.

The obligation is that a compliant document is produced, stamped, chained and submitted. Nothing requires the ERP itself to do all of that. The pattern that survives contact with both regimes is a compliance layer beside the ERP:

ERP keeps invoicing

Customers, prices, tax rates, ledger postings and document numbering stay where they are. No core customisation, no upgrade debt.

Compliance layer builds and submits

Reads the invoice, serialises UBL 2.1 or PINT AE, applies the stamp and signature, maintains the hash chain, handles clearance or reporting.

Result written back

Clearance status, authority reference and QR payload return to the ERP so finance sees one version of the truth.

Two properties make this worth the separation. Statutory rules change on the authority’s timetable rather than yours, and a self-contained layer can be updated without touching the ERP. And where a company operates in both countries, the same canonical invoice feeds two adapters instead of one system trying to be both.

The reasoning behind keeping statutory work inside the packaged system while building everything else beside it is set out in packaged versus custom.

Readiness sequence

  1. Establish the position, honestly. In Saudi Arabia, are you integrated or late? In the UAE, are you above AED 50 million, and has an ASP been appointed?
  2. Check the data before the format. UBL 2.1 and PINT AE both require fields that many ERPs hold inconsistently — buyer tax registration numbers, precise line-level tax categories, correct units. Serialisation fails on missing data far more often than on schema misunderstanding.
  3. Separate the two Saudi workflows. Clearance is synchronous and sits in the sale; reporting is asynchronous with a 24-hour obligation. They need different handling and different alarms.
  4. Onboard and obtain credentials. In Saudi Arabia this is the Fatoora onboarding that produces the CSID. Build sandbox testing into the plan rather than treating it as a formality.
  5. Instrument the failures. Someone must be told when a clearance is rejected or a report is stuck. An unmonitored queue is the most common way a compliant system quietly becomes non-compliant.

What to require from any implementation

  • The XML is produced from your data and can be inspected — not a black box that emits a PDF.
  • The hash chain survives restarts and re-issues, and its state is stored durably.
  • Rejections are visible to a named person, with the authority’s message preserved rather than replaced by a generic error.
  • Credentials are rotatable without redeploying the whole system.
  • The compliance layer is separable, so a change in one country’s rules does not force a change everywhere else.

Compliance work is unusual in that doing it well produces nothing visible — invoices simply keep clearing. The cost of doing it badly is also invisible for a while, which is exactly why the monitoring points above matter more than the feature list.

If you are scoping this against an ERP you intend to keep, tell us about your process. The first call takes 30 minutes and costs nothing, and the bands are on the pricing page. For distributor-facing systems that sit on the same ERP, see B2B dealer portal ERP integration.

Frequently asked questions

Does ZATCA Phase 2 still have waves left to join?

No. The integration waves are complete. Wave 23 covered taxpayers above SAR 750,000 in the first quarter of 2026, and Wave 24 — announced in September 2025 with a threshold of SAR 375,000 in VAT-taxable revenue for 2022, 2023 or 2024 — had a deadline of 30 June 2026. That was the final wave and the lowest threshold, so Phase 2 integration now effectively applies to every VAT-registered business in Saudi Arabia rather than to a scheduled cohort.

What format must a ZATCA Phase 2 invoice be in?

Structured XML aligned with the UBL 2.1 schema, or PDF/A-3 with the XML embedded inside it. A PDF on its own does not satisfy the requirement, whatever it looks like. This is the point most ERP projects underestimate: producing a compliant document is a data-structure exercise, not a printing exercise, and the fields the schema requires have to exist in the system before they can be serialised.

What is a CSID and why does my system need one?

The Cryptographic Stamp Identifier is a digital certificate — an X.509 certificate — issued by ZATCA to a specific invoicing solution. Your system stamps each XML invoice using it, which is how ZATCA establishes that the document came from a registered solution and has not been altered since. Obtaining it is part of onboarding through the Fatoora platform, and it is tied to the solution, so it is not something that can be shared between unrelated systems.

What is the difference between clearance and reporting?

They are two different workflows for two different invoice types. Standard tax invoices, which are B2B and B2G, require real-time clearance: the invoice is submitted to ZATCA and approved before it is delivered to the buyer. Simplified invoices, which are B2C, are reported to ZATCA within 24 hours of being issued. The distinction matters architecturally because clearance sits in the critical path of the sale while reporting does not.

What has to be in the Phase 2 QR code?

A Base64-encoded TLV — tag, length, value — structure. Phase 2 requires nine tags, where Phase 1 required five. The content includes the seller's name, the VAT registration number, the timestamp, the invoice total and the VAT total, alongside the cryptographic elements. Because the encoding is prescribed, this is one of the parts most often failed by systems that generate a QR code containing a URL or free text instead.

Do I need to replace my ERP to comply with ZATCA?

Usually not. The requirement is that a compliant XML document is produced, stamped, chained and submitted — not that your ERP does all of it. The common pattern is to leave invoicing in the ERP and put a compliance layer beside it that builds the UBL document from the ERP's data, signs it, maintains the hash chain, handles clearance or reporting, and writes the result back. That keeps the statutory logic in one replaceable component.

When does the UAE mandate actually start?

It is phased and the pilot began on 1 July 2026. Large businesses go live from 1 January 2027, small and medium businesses from 1 July 2027, and government transactions from 1 October 2027. The deadline that is live right now is different: businesses with annual revenue of AED 50 million or more must appoint an accredited service provider by 30 October 2026, a date already moved once from 31 July 2026.

What is PINT AE and can I submit invoices myself?

PINT AE is the UAE's Peppol International Invoice specification: invoices are issued as structured XML conforming to that schema. They are not sent directly to the authority. Transmission goes through an accredited service provider approved by the Ministry of Finance, so appointing one is a procurement step every affected business has to take rather than something an internal development team can substitute for.

Could we become our own accredited service provider?

In practice no, and the accreditation criteria are the reason. An applicant must already be an active Peppol-certified service provider and satisfy company registration, tax registration and information security requirements. An experience requirement added in May 2026 also requires the proposed solution to have been in operation for at least two years. That effectively rules out building an in-house ASP for the current deadline; the work to plan is integrating with one.

We operate in both countries — can one system serve both?

The internal data can be shared but the compliance layers cannot be merged. Saudi Arabia uses UBL 2.1 with ZATCA clearance and reporting against the Fatoora platform, while the UAE uses PINT AE transmitted through an accredited service provider. Build one canonical invoice model inside your own systems and two adapters that serialise and submit it, so the country-specific parts stay isolated and can change independently.

Related guides

Service page: Custom software service

Let's talk about what you need.

The 30-minute discovery call is free and carries no commitment.