§ 00 · Knowledge

Saudi e-invoicing Phase 2: the readiness checklist.

Phase 2 is not a tax filing. It is a change to the systems that issue your invoices, and it fails in the places tax teams do not own.

Our Saudi compliance overview covers what changed in 2026 and why. This is the companion piece: what to actually work through, in what order, before the integration deadline for your wave.

The pattern we see is consistent. Scope gets set from the ERP, the POS estate and the e-commerce platform surface late, and the work that was sized as a tax project turns out to need IT for onboarding, credentials and connectivity. Sections A and C are where that goes wrong, and they are the two worth reading first.

§ 01 · Which wave applies

Phase 2 is being rolled out in waves by revenue subject to VAT. Wave 25, announced on 24 July 2026, is the one currently in front of most businesses that are not yet integrated.

Current and immediately preceding waves
WaveWho it coversIntegration deadline
Wave 24Revenue subject to VAT above SAR 375,00030 June 2026, now passed
Wave 25Revenue subject to VAT above SAR 187,500 in any of 2022, 2023, 2024 or 20251 February 2027

Earlier waves covered higher thresholds and their deadlines have passed. The direction is the point: each wave reaches further down, so a business outside the current one is usually looking at the next rather than at an exemption.

§ 02 · Clearance or reporting

Phase 2 splits invoices into two flows with different timing. Which one applies is decided by the invoice type, not by the system issuing it, so a business selling both B2B and B2C has to support both.

The two invoice flows
Standard tax invoiceSimplified tax invoice
TypicallyB2BB2C
ModelClearanceReporting
TimingSubmitted to ZATCA before the invoice reaches the customerReported to ZATCA within the prescribed period after issuance
What the customer getsThe cleared invoiceThe invoice at the point of sale, carrying a QR code

The consequence worth planning for is the clearance one. If a standard invoice has to reach ZATCA before it reaches the customer, then an outage is not an IT incident, it is a billing stoppage. Agree what the business does in that case before go-live, not during it.

§ 03 · The checklist

A. Scope and channels

Most of the cost of getting this wrong is decided here, before a single technical change is made.

  • A/01Applicable wave confirmed from revenue subject to VAT in each of 2022, 2023, 2024 and 2025, with the working retained rather than the conclusion alone.
  • A/02Any notification received from ZATCA filed with the compliance record, and the assessment done without waiting for one to arrive.
  • A/03Every channel that issues an invoice listed: ERP, each POS terminal, e-commerce platforms, billing and subscription systems, and any manual or spreadsheet invoicing still in use.
  • A/04Each channel identified as issuing standard invoices, simplified invoices, or both, because the two follow different models.
  • A/05Each channel confirmed as running a compliant e-invoicing solution, rather than producing a PDF and stopping there.
  • A/06Integration deadline for the applicable wave recorded, and the plan worked backwards from it with the go-live date fixed first.

B. Invoice data and structure

The invoice the customer reads is not the invoice ZATCA receives. Both have to be right.

  • B/01Structured invoice data generated in the required XML format, produced by the system rather than converted from a document.
  • B/02Mandatory fields present and correctly populated for each invoice type, tested against real transactions and not only sample data.
  • B/03A unique identifier generated for every invoice.
  • B/04Hash chaining implemented so each invoice references the one before it, with the chain unbroken across restarts and channel outages.
  • B/05QR code generated, and present on the invoice the customer actually receives where that is required.
  • B/06Arabic present where required, and the invoice legible in the form it reaches the customer.

C. Cryptography and connectivity

This is where projects slip, because it is the part finance cannot complete without IT.

  • C/01Cryptographic stamp identifier obtained and installed for every solution unit and device that issues invoices.
  • C/02Onboarding completed for every POS terminal and every unit, not only the primary system.
  • C/03Cryptographic stamping applied as required for the invoice type.
  • C/04Connectivity to ZATCA tested from each channel through the firewall and network restrictions that will apply in production, not from a developer machine.
  • C/05Credential expiry and renewal tracked with a named owner and a date, because a lapsed credential stops invoicing.

D. Clearance and reporting

Two flows, two sets of behaviour, including when ZATCA cannot be reached.

  • D/01Standard invoices submitted for clearance before reaching the customer, with the cleared version being the one the customer receives.
  • D/02Simplified invoices reported within the prescribed period after issuance.
  • D/03Defined behaviour for a failed, delayed or rejected submission, agreed with the business before go-live rather than during an outage.
  • D/04Credit and debit notes routed through the same flow as the invoice they relate to, carrying the reference and the reason.

E. Process, controls and evidence

Integration is the start of an ongoing control, not the end of a project.

  • E/01Reconciliation between invoices issued in the source system and invoices accepted by ZATCA, run on a schedule with someone owning the differences.
  • E/02Rejected and warned invoices monitored and cleared rather than allowed to accumulate.
  • E/03Structured invoice data archived and retained, not only the human readable copy.
  • E/04A named owner in finance and a named owner in IT, because this stops being deliverable the moment it is treated as a tax-only exercise.
  • E/05End to end tests run in ZATCA's sandbox before go-live, covering every channel and every invoice type the business actually issues.

§ 04 · Take it with you

The working file

Phase 2 readiness checklist

All 26 checks as a workbook, with owner, status and evidence columns left blank for your team. Useful as the shared list between finance and IT, which is usually the thing that is missing.

Download the checklist (XLSX)

One caution on using it. The checks are deliberately task-level rather than a restatement of ZATCA’s technical specification, which is versioned and updated. Confirm the detail of each requirement against the current specification and against any notification you have received.

§ 05 · Questions we get asked

01

ZATCA has not notified us. Are we out of scope?

No. A notification confirms the wave, it does not create the obligation, and waiting for one costs you the lead time you need for onboarding and testing. Work the thresholds against your own VAT-subject revenue for each year, reach a conclusion, and keep the working. If the conclusion is that you are in Wave 25, the deadline is 1 February 2027 whether or not the letter has arrived.

02

Our accounting software already produces a PDF invoice with a QR code. Is that Phase 2?

No. Phase 1 asks you to generate and retain electronic invoices. Phase 2 asks your system to produce structured XML data, stamp it, chain it to the invoice before it, and talk to ZATCA directly, either for clearance or for reporting. A PDF with a QR code satisfies neither the format nor the integration requirement, and the gap between the two is a systems project rather than a settings change.

03

We run one ERP but forty POS terminals. What does that change?

It changes the size of section C. Onboarding and cryptographic stamp identifiers apply per solution unit and per device, so forty terminals is forty onboardings, forty sets of credentials, and forty things whose expiry someone has to track. Teams routinely scope this from the ERP alone and discover the terminals late.

04

Is this the same as the transfer pricing work?

Different regime, same direction, and usually the same overstretched team. E-invoicing gives ZATCA transaction-level visibility; transfer pricing asks you to evidence the basis of related-party dealings. Our overview of both sits in the Saudi compliance note this checklist belongs to.

The deadline is fixed. The scope is the part you control.

We read the invoicing estate, confirm which wave and which flows apply, and hand back a scoped readiness plan your finance and IT teams can run against. Fixed scope, fixed fee, and the file stays with you.

Scope a Phase 2 readiness review

This is a general preparation aid reflecting the position as at August 2026, and does not constitute tax, legal, or regulatory advice. Daftar is a non-attest advisory practice and does not act as your auditor or as a certified e-invoicing solution provider. Confirm every requirement against ZATCA’s current technical specifications, the applicable regulations, and any notification issued to you.