Country deep dive
ZATCA's rollout is a genuine two-phase model: first everyone had to generate e-invoices, then β much more demandingly β integrate directly with the government in waves by turnover.
All VAT-registered taxpayers must generate e-invoices using a compliant electronic system and store them digitally β no live integration with ZATCA required yet at this stage.
The largest taxpayers (annual revenue above SAR 3 billion) must directly integrate their billing systems with ZATCA's Fatoora platform. Every subsequent wave brings smaller businesses into scope, each notified at least 6 months in advance.
Businesses with turnover between SAR 750,000 and SAR 1 million (2022β2024 tax years) must complete Phase 2 integration.
The threshold drops to effectively match the mandatory VAT-registration threshold, bringing nearly every VAT-registered resident business into Phase 2 integration.
Phase 2's technical bar is genuinely high: cryptographic stamping, mandatory Arabic content, and a QR code that packs in nine distinct data tags.
The PDF/A-3-with-embedded-XML packaging mirrors France's Factur-X approach β a human-readable rendering alongside the machine-readable data in a single file.
The chain of trust runs supplier β ZATCA β recipient: your ECDSA signature proves the invoice came from you, and ZATCA's own stamp on top of that is what actually makes it legally valid.
A "Hash Mismatch" rejection means the XML content was altered after the hash was calculated β this is one of the most common Phase 2 integration errors.
Base64-encoded, TLV (Tag-Length-Value) format, packing in:
Anyone can verify these instantly using ZATCA's official mobile app β a scan confirms the invoice exists in the central system, its signatures are valid, and its printed data matches, typically in 2β5 seconds.
Saudi Arabia runs one of the strictest clearance models in this tracker: a B2B invoice without ZATCA's clearance response simply has no tax effect.
This is stricter than Poland's KSeF or Italy's SDI in one specific sense β clearance must happen before delivery, not just before the invoice is considered "final."
Unlike B2B, simplified invoices can be issued to the customer immediately β the 24-hour clock covers reporting to ZATCA, not pre-clearance.
Renewing your CSID before expiry and locking down post-hash XML modification are the two highest-leverage fixes for reducing rejection volume.
If you're VAT-registered in Saudi Arabia without local residency, you're out of scope for now β but confirm this hasn't changed, since GCC e-invoicing scope has shifted before.
Integration is a genuinely multi-stage technical process β budget real time for certificate generation and sandbox testing, not just format mapping.
This is the prerequisite step before you can generate any certificates or begin technical onboarding.
Obtain this through ZATCA's compliance API β it's required before you can sign any invoice, so treat it as a blocking dependency for everything downstream.
Set up all mandatory fields, correct Arabic translations, and proper QR code positioning β get this right before moving to signing and testing.
Configure ECDSA signing and generate valid hashes, then explicitly test signature verification before touching the sandbox.
Don't skip this step even under deadline pressure β it's specifically designed to catch integration errors before they hit production.
Make sure staff understand the new processes, common rejection codes, and troubleshooting procedures β this is a genuine operational change, not just a system upgrade.
Only switch from sandbox to production once testing has genuinely succeeded β and watch for your specific wave notification, since ZATCA gives roughly six months' notice ahead of each deadline.
The fine itself is only part of the exposure β prohibited software behaviours carry their own separate scrutiny.