Most businesses understand Phase 2 of ZATCA’s e-invoicing programme in outline: your system connects to the authority, and invoice data flows to it. That summary is correct, and it is also where the preparation usually stops.
The gap between understanding Phase 2 and being ready for it is technical. Phase 1 changed how invoices are created. Phase 2 changes what has to happen to an invoice between the moment you raise it and the moment your customer can use it. That distinction is the whole difference, and it is worth being precise about.
This guide covers what integration actually requires, how standard and simplified invoices are treated differently, and how to work out where your business sits in the rollout.
Where the rollout has reached
Phase 2, the Integration phase, has been enforceable since 1 January 2023, brought in through waves rather than all at once. ZATCA works down the scale of VAT-taxable revenue, largest businesses first, and notifies each group at least six months before its integration date.
The detail worth noticing is how far down that scale has now travelled.
Wave 24 captured taxpayers whose taxable turnover exceeded SAR 375,000 in 2022, 2023, or 2024, with compliance required by 30 June 2026. That figure is the mandatory VAT registration threshold. In other words, the mandatory e-invoicing net has already reached every business that is required to register for VAT.
Wave 25 goes further still. ZATCA has confirmed it covers taxpayers whose revenues subject to VAT exceeded SAR 187,500 during 2022, 2023, 2024, or 2025, and those taxpayers must integrate with the Fatoora platform no later than 1 February 2027. SAR 187,500 is the voluntary registration threshold, which means the programme now extends to businesses that chose to register rather than had to.
The practical conclusion: if your business is VAT-registered in the Kingdom and you are not integrated yet, you are almost certainly in a wave already announced. The question is no longer whether Phase 2 applies to you but how much time is left.
Clearance and reporting are not the same thing
This is the single most important operational point in Phase 2, and it is where system configuration most often goes wrong.
Under Phase 2, your two invoice types follow two different paths.
Standard tax invoices, used mainly for business and government customers, go through clearance. The invoice is submitted to the Fatoora platform through an API, and ZATCA validates it against the XML implementation standard and runs additional referential checks. Once it passes, ZATCA clears the invoice by adding a cryptographic stamp and a QR code to the XML.
The consequence is a change to your workflow, not just your software. A standard invoice is not a finished document until ZATCA has cleared it. The cleared version, carrying the authority’s stamp, is the one your customer should receive.
Simplified tax invoices, used mainly for consumer sales, go through reporting instead. They are submitted in XML format to the Fatoora platform within 24 hours of being generated. There is no wait for authorisation before handing the invoice to the customer, which suits a retail counter, but the 24 hour obligation is firm and it applies continuously.
If you sell to both businesses and consumers, your system has to handle both routes correctly and classify each transaction properly on its own. Misclassification is not a cosmetic error. It puts an invoice down the wrong compliance path entirely.
What has to be attached to every invoice
Phase 2 introduces requirements that have no equivalent in ordinary invoicing, and they are the reason a compliant solution is not optional.
A UUID. Every electronic invoice and associated note carries a universally unique identifier, a 128 bit number generated by your system so that no two documents can collide.
A cryptographic stamp. Each e-invoicing solution that generates simplified tax invoices must hold its own unique cryptographic stamp identifier, issued and managed through ZATCA’s portal, and that stamp is applied to each simplified invoice it produces.
The previous invoice hash. Each invoice includes a hash, a digital fingerprint produced by a standard hashing algorithm, of the invoice immediately before it. Because every document references the one preceding it, the sequence forms a chain. Altering an invoice after the fact breaks the chain in a way that is detectable, which is precisely the point.
That last requirement deserves a moment’s thought, because it changes something cultural rather than technical. Under a hash chain, quietly correcting a past invoice is no longer possible. Corrections have to run through credit and debit notes, properly issued. Businesses used to informal adjustments find this the hardest adaptation, and it is better discovered during preparation than during a review.
Preparing properly, rather than at the deadline
Six months of notice sounds generous until you map what has to happen inside it: selecting or upgrading a solution, onboarding it with ZATCA and obtaining credentials, configuring invoice types against how you actually sell, testing against the authority’s validation rules, and training the people who raise invoices every day.
Testing is where timelines usually slip. Validation failures rarely surface as one obvious fault. They tend to appear as a handful of specific invoice scenarios that fail referential checks, and each takes time to diagnose and correct. Businesses that start early treat that as a normal part of the work. Businesses that start late discover it in the final fortnight.
A reasonable sequence looks like this. Confirm which wave you fall into and the date attached to it. Establish whether your current system can be made compliant or has to be replaced, and get a straight answer rather than a reassuring one from your vendor. Map your transaction types to standard and simplified invoices deliberately. Then test, using real scenarios from your own sales, including the awkward ones.
Where this connects to everything else
Phase 2 is often handed to whoever manages the ERP, on the reasonable-sounding basis that it is a systems project. It is worth resisting that instinct.
E-invoicing sits directly on top of VAT. The data leaving your system for the Fatoora platform is the same data that supports your VAT returns, and once it is transmitted to the authority in structured form, the relationship between your invoicing and your filings becomes considerably more visible. Configured well, that is an advantage, because clean structured invoicing makes returns easier to prepare and easier to defend. Configured poorly, it means inconsistencies are now recorded rather than buried.
That is the argument for treating Phase 2 as part of your VAT compliance rather than as an IT deliverable with a deadline.
SRR Consultants supports accounting and VAT compliance in Saudi Arabia, including ZATCA e-invoicing readiness, working alongside FinSoul Network member firms in the Kingdom. If you want to confirm which wave applies to your business and what your systems still need, get in touch.
For the wider picture, see our guide to ZATCA e-invoicing and the Fatoora programme, and our guide to VAT registration and returns in Saudi Arabia.
This article is general information based on ZATCA’s published rules and announcements as at July 2026, not tax advice. E-invoicing obligations depend on your specific circumstances and should be confirmed for your business.