Tax & Compliance (ZATCA/VAT)#ZATCA#Saudi Arabia#E-Invoicing#VAT#Compliance#Fatoora
ZATCA Phase 2 E-Invoicing (Fatoora) Compliance & Clearance
Technical guide to Saudi Arabia ZATCA Phase 2 e-invoicing: cryptographic stamp generation, UBL 2.1 XML structure, clearance API, and reporting workflows.
3 min read·Updated 2026-09-20
ZATCA Phase 2 E-Invoicing (Fatoora) Compliance & Clearance
Under Saudi Arabia's Zakat, Tax and Customs Authority (ZATCA) regulations, businesses must integrate their ERP and billing systems with the Fatoora platform for Phase 2 (Integration Phase) compliance. BIZA provides an end-to-end native implementation supporting both B2B Clearance and B2C Reporting flows.
1. Clearance vs. Reporting Workflows
ZATCA defines two distinct document types with separate legal requirements:
| Parameter | Standard Tax Invoice (B2B / B2G) | Simplified Tax Invoice (B2C) |
|---|---|---|
| Primary Audience | Companies and government entities | Consumers and retail customers |
| Workflow | Clearance: Must be sent to ZATCA API and approved before delivery to customer | Reporting: Issued immediately to customer; reported to ZATCA within 24 hours |
| Buyer Details | Mandatory Legal Name, National Address, and VAT/CR Number | Optional for amounts under SAR 1,000 |
| Visual Stamp | Cryptographic Stamp + ZATCA Clearance Status | Standard TLV QR Code |
| Output Document | XML UBL 2.1 + PDF/A-3 embedded | Printed Thermal/A4 Receipt or digital PDF |
2. Technical Architecture & Cryptographic Stamping
For every generated invoice, BIZA automatically executes the mandatory cryptographic pipeline:
- UBL 2.1 XML Construction: Invoices are structured in strict compliance with ZATCA XML schemas, including tax categories (S, Z, E, O), supplier/buyer identification schemes, payment means, and line item calculations.
- Invoice Hash (SHA-256): The canonical XML representation is hashed using SHA-256.
- Cryptographic Stamp (ECDSA secp256k1): The hash is signed with the enterprise's private key linked to the active Compliance or Production CSID (Cryptographic Stamp Identifier).
- Previous Invoice Hash (PIH) Chaining: Invoices are cryptographically chained. Each new invoice includes the hash of the preceding invoice, preventing retroactive insertion or tampering with historical records.
- Invoice Counter (ICV): A sequential, unalterable integer counter incremented with every document.
- QR Code Generation: Encodes mandatory Tag-Length-Value (TLV) byte structures:
- Tag 1: Seller's name
- Tag 2: Seller's VAT registration number
- Tag 3: Invoice timestamp (ISO 8601)
- Tag 4: Invoice total (with VAT)
- Tag 5: VAT total
- Tag 6: SHA-256 Invoice Hash
- Tag 7: Cryptographic Signature
- Tag 8: ECDSA Public Key (for simplified invoices)
3. Onboarding & CSID Lifecycle Management
Connecting BIZA to your ZATCA portal requires completing the official device onboarding workflow:
- OTP Generation: Obtain a one-time onboarding password from the ZATCA Fatoora portal.
- CSR Generation: BIZA automatically generates an X.509 Certificate Signing Request (CSR) embedding your Commercial Registration (CR), VAT number, and device identity.
- Compliance CSID: BIZA submits the CSR to ZATCA's compliance endpoint, executes the mandatory test scenarios (Standard Invoice, Simplified Invoice, Debit Note, Credit Note), and verifies clearance.
- Production CSID: Upon passing all compliance checks, BIZA requests the final Production CSID and securely stores the production certificate and private keys.
4. Bilingual PDF/A-3 Layouts & Archival
- Bilingual Documents: Invoices render in full Arabic and English, meeting all statutory language requirements.
- Embedded XML (PDF/A-3): Conforms to PDF/A-3 standards, embedding the signed, cleared XML file directly inside the human-readable PDF.
- 10-Year Archival: All cryptographic artifacts (raw XML, signed XML, ZATCA API response headers, and verification tokens) are preserved in tamper-evident storage for the statutory retention period.