Tax & Compliance (ZATCA/VAT)#ZATCA#Saudi Arabia#E-Invoicing#VAT#Compliance#Fatoora

ZATCA Phase 2 E-Invoicing (Fatoora) Compliance & Clearance

Technical guide to Saudi Arabia ZATCA Phase 2 e-invoicing: cryptographic stamp generation, UBL 2.1 XML structure, clearance API, and reporting workflows.

3 min read·Updated 2026-09-20

ZATCA Phase 2 E-Invoicing (Fatoora) Compliance & Clearance

Under Saudi Arabia's Zakat, Tax and Customs Authority (ZATCA) regulations, businesses must integrate their ERP and billing systems with the Fatoora platform for Phase 2 (Integration Phase) compliance. BIZA provides an end-to-end native implementation supporting both B2B Clearance and B2C Reporting flows.


1. Clearance vs. Reporting Workflows

ZATCA defines two distinct document types with separate legal requirements:

Parameter Standard Tax Invoice (B2B / B2G) Simplified Tax Invoice (B2C)
Primary Audience Companies and government entities Consumers and retail customers
Workflow Clearance: Must be sent to ZATCA API and approved before delivery to customer Reporting: Issued immediately to customer; reported to ZATCA within 24 hours
Buyer Details Mandatory Legal Name, National Address, and VAT/CR Number Optional for amounts under SAR 1,000
Visual Stamp Cryptographic Stamp + ZATCA Clearance Status Standard TLV QR Code
Output Document XML UBL 2.1 + PDF/A-3 embedded Printed Thermal/A4 Receipt or digital PDF

2. Technical Architecture & Cryptographic Stamping

For every generated invoice, BIZA automatically executes the mandatory cryptographic pipeline:

  1. UBL 2.1 XML Construction: Invoices are structured in strict compliance with ZATCA XML schemas, including tax categories (S, Z, E, O), supplier/buyer identification schemes, payment means, and line item calculations.
  2. Invoice Hash (SHA-256): The canonical XML representation is hashed using SHA-256.
  3. Cryptographic Stamp (ECDSA secp256k1): The hash is signed with the enterprise's private key linked to the active Compliance or Production CSID (Cryptographic Stamp Identifier).
  4. Previous Invoice Hash (PIH) Chaining: Invoices are cryptographically chained. Each new invoice includes the hash of the preceding invoice, preventing retroactive insertion or tampering with historical records.
  5. Invoice Counter (ICV): A sequential, unalterable integer counter incremented with every document.
  6. QR Code Generation: Encodes mandatory Tag-Length-Value (TLV) byte structures:
    • Tag 1: Seller's name
    • Tag 2: Seller's VAT registration number
    • Tag 3: Invoice timestamp (ISO 8601)
    • Tag 4: Invoice total (with VAT)
    • Tag 5: VAT total
    • Tag 6: SHA-256 Invoice Hash
    • Tag 7: Cryptographic Signature
    • Tag 8: ECDSA Public Key (for simplified invoices)

3. Onboarding & CSID Lifecycle Management

Connecting BIZA to your ZATCA portal requires completing the official device onboarding workflow:

  1. OTP Generation: Obtain a one-time onboarding password from the ZATCA Fatoora portal.
  2. CSR Generation: BIZA automatically generates an X.509 Certificate Signing Request (CSR) embedding your Commercial Registration (CR), VAT number, and device identity.
  3. Compliance CSID: BIZA submits the CSR to ZATCA's compliance endpoint, executes the mandatory test scenarios (Standard Invoice, Simplified Invoice, Debit Note, Credit Note), and verifies clearance.
  4. Production CSID: Upon passing all compliance checks, BIZA requests the final Production CSID and securely stores the production certificate and private keys.

4. Bilingual PDF/A-3 Layouts & Archival

  • Bilingual Documents: Invoices render in full Arabic and English, meeting all statutory language requirements.
  • Embedded XML (PDF/A-3): Conforms to PDF/A-3 standards, embedding the signed, cleared XML file directly inside the human-readable PDF.
  • 10-Year Archival: All cryptographic artifacts (raw XML, signed XML, ZATCA API response headers, and verification tokens) are preserved in tamper-evident storage for the statutory retention period.