Fatoora Platform Onboarding Saudi: 2026 ZATCA Guide

Fatoora Platform Onboarding Saudi: 2026 ZATCA Guide

Fatoora Platform Onboarding Saudi: 2026 ZATCA Guide

Fatoora platform onboarding Saudi is the ZATCA process of registering your e-invoicing software (EGS unit) on the Fatoora portal at fatoora.zatca.gov.sa — typically 5 core steps: log in with your ZATCA credentials, generate an OTP, request a Compliance CSID, pass the compliance checks, then obtain your Production CSID. Most businesses complete onboarding in 1–3 working days once their solution is ready, and Saudi VAT remains 15% in 2026. Every VAT-registered business in the Kingdom must issue and clear electronic invoices through this pipeline.

What the Fatoora platform actually is

Fatoora is the e-invoicing platform operated by the Zakat, Tax and Customs Authority (ZATCA) — the Saudi authority responsible for VAT, zakat, excise and customs. It is the government endpoint your invoicing software talks to. It is not, in itself, an invoicing application: ZATCA does not write your invoices for you. Instead, Fatoora is where your invoice-generation solution gets cryptographically identified, authorised and then either reports or clears each invoice you issue.

The rules sit under the Saudi E-Invoicing Regulation and its implementing resolutions, published on the official ZATCA e-invoicing hub at zatca.gov.sa e-invoicing. Two phases apply:

  • Phase 1 — Generation (live since 4 December 2021). All VAT-registered taxpayers must issue invoices electronically in a structured format, with a QR code on simplified invoices. No connection to ZATCA is required in this phase.
  • Phase 2 — Integration (rolling out in waves since 1 January 2023). Your e-invoicing solution must connect to ZATCA through the Fatoora APIs. Standard tax invoices (B2B/B2G) must be cleared in real time before you give them to the buyer; simplified invoices (B2C) must be reported within 24 hours of issuance.

Onboarding is the bridge between those two worlds. Until your EGS unit — “E-invoice Generation Solution” in ZATCA’s language — is onboarded and holds a valid Production CSID (Cryptographic Stamp Identifier), it cannot legally clear or report anything.

Who needs to complete Fatoora platform onboarding in Saudi Arabia

The obligation follows VAT registration, not company size, ownership or sector. If you hold a Saudi VAT registration number, e-invoicing applies to you. Phase 2 integration, however, arrives in waves: ZATCA notifies each group of taxpayers by email and SMS at least six months before their integration date, using annual taxable revenue thresholds that have stepped steadily downward since 2023 — from the largest enterprises in Wave 1 down to businesses with modest turnover in the later waves published on the ZATCA portal.

In practice, these are the groups that must onboard:

  • Resident Saudi companies registered for VAT, including 100% foreign-owned entities licensed by the Ministry of Investment (MISA).
  • Branches of foreign companies registered in the Kingdom and holding VAT registration.
  • Third parties issuing tax invoices on behalf of a resident taxable person — for example, an outsourced accounting firm or a marketplace issuing on a seller’s behalf.
  • Establishments (sole proprietorships) with a Commercial Register and VAT registration.

Non-resident taxable persons are outside the scope of the e-invoicing obligation, and so are transactions that are exempt from VAT. If you have just formed your entity and are still below the mandatory VAT registration threshold of SAR 375,000 in annual taxable supplies, e-invoicing follows once you register. Anyone planning market entry should look at the sequencing early — our guide to company formation in Saudi Arabia sets out where VAT and e-invoicing sit in the wider licensing timeline.

Before you onboard: the prerequisites checklist

Onboarding fails more often from missing prerequisites than from technical faults. Have all of the following ready before you touch the portal:

  • Active VAT registration with ZATCA and your 15-digit VAT number (it begins and ends with “3”).
  • ZATCA e-services credentials — the same username and password you use for VAT returns on the ZATCA taxpayer portal. Onboarding is done under this login, not a separate Fatoora account.
  • A registered mobile number on your ZATCA profile, because the OTP is delivered there.
  • A compliant EGS unit — invoicing software that supports UBL 2.1 XML, the ZATCA data dictionary, cryptographic stamping, hashing, UUIDs and the QR code (TLV, Base64-encoded).
  • Commercial Register (CR) number and other identifiers your solution embeds as the seller’s additional ID — CR, MISA licence, 700 number, national ID or Iqama, depending on the entity type.
  • Your national address as registered with the Saudi Post / Ministry of Commerce records — building number, street, district, city, postal code and additional number.
  • A CSR configuration (Certificate Signing Request) for each EGS unit, containing the common name, serial number, organisation identifier (your VAT number), organisation unit, country code “SA”, invoice type flags and business category.

One clarification that saves a great deal of confusion: an EGS unit is a device or instance, not a company. A retailer with 12 point-of-sale terminals across three branches will onboard 12 units, each with its own CSID. A single cloud ERP issuing all invoices from one instance onboards once.

Step-by-step: how to complete Fatoora platform onboarding

The sequence below reflects the current Fatoora portal flow. ZATCA does refresh the interface, so treat button labels as a guide and confirm current screens on the official portal.

  1. Open the Fatoora portal. Go to fatoora.zatca.gov.sa and choose “Login”. You will be redirected to ZATCA’s single sign-on; enter your taxpayer username and password and complete the OTP sent to your registered mobile.
  2. Choose your onboarding mode. On the landing dashboard select Onboard New Solution Unit / Device. The portal asks how many OTP codes you need — enter the number of EGS units you are onboarding (up to 100 in one batch). Each unit consumes exactly one OTP.
  3. Generate the OTP codes. Click Generate OTP. The portal displays the codes on screen and emails them to the registered address. Each OTP is valid for one hour only, so generate them when your technical team is ready, not the night before.
  4. Feed the OTP to your EGS unit. In your invoicing software’s ZATCA/e-invoicing settings, paste the OTP. The software generates a CSR and calls the ZATCA Compliance CSID API. ZATCA returns a Compliance CSID — a temporary certificate valid only for testing.
  5. Run the compliance checks. Your software must submit sample invoices to the compliance endpoint — typically a standard invoice, a simplified invoice, and their associated credit and debit notes. ZATCA validates the XML structure, the hash chain, the UUID, the cryptographic stamp and the QR code. Every required sample must pass.
  6. Request the Production CSID. Once all compliance checks return successful, your solution calls the production CSID endpoint using the compliance certificate. ZATCA issues the Production CSID, the live certificate that signs and identifies your real invoices.
  7. Store the certificate securely. The Production CSID and its private key must be protected. Losing them means re-onboarding the unit from step 2.
  8. Go live. Standard invoices now go to the clearance endpoint and must be cleared before delivery to the buyer; simplified invoices go to the reporting endpoint within 24 hours. Confirm in the portal’s device list that the unit shows as active.

Sandbox first, always

ZATCA publishes a developer portal and sandbox environment alongside the production APIs. Run your full invoice set through the sandbox before requesting a real OTP. Sandbox failures cost you nothing; production compliance failures burn OTPs and consume time.

Renewing and managing your CSIDs

Production CSIDs are not permanent. They carry a validity period, and your solution should call the renewal endpoint before expiry — again using an OTP generated from the Fatoora portal. The portal’s device management screen lets you view all onboarded units, check certificate status and revoke a unit if a device is retired or replaced. Set a calendar reminder well ahead of expiry; an expired certificate means rejected invoices.

Documents, IDs and data you must have correct

Fatoora onboarding requires exact identifier accuracy, because the certificate is issued against the data in your CSR. Cross-check the following before submission:

Field Where it comes from Common format
VAT registration number ZATCA taxpayer portal 15 digits, starts and ends with 3
Commercial Register (CR) number Ministry of Commerce / Saudi Business Center New unified national CR starts with “7” from 3 April 2026
MISA investment licence Ministry of Investment (MISA) Used as seller additional ID for foreign-owned entities
Organisation identifier in CSR Must equal the VAT number 15 digits
Common name in CSR Your chosen EGS unit name Free text, keep it unique per device
Serial number in CSR Solution name, version, device serial 1-SolutionName|2-Version|3-SerialNo
National address Saudi Post / Ministry of Commerce record Building no., street, district, city, postal code, additional no.
GOSI / labour identifiers GOSI and Qiwa (for payroll, not invoices) Not required on invoices, but keep aligned

Note the Commercial Register change: under the new Commercial Register Law effective 3 April 2026, Saudi Arabia moved to a single unified national CR with IDs beginning with “7”, no expiry date (replaced by an annual confirmation), a five-year grace period for transition, and permission to register English trade names. If your invoicing templates hard-code an old CR format or an expiry date, update them.

Fees and timelines: what onboarding actually costs

ZATCA does not charge a fee for Fatoora onboarding itself — the OTP, the Compliance CSID and the Production CSID are issued free of charge. Your real costs are software and implementation. The table below gives indicative market ranges in Saudi Riyals; confirm current figures with your vendor and on the official portal.

Item Indicative cost (SAR) Typical timeline
ZATCA Fatoora onboarding (OTP + CSIDs) No government fee Same day once software is ready
Cloud e-invoicing / ZATCA-ready software (small business, per year) 2,000 – 9,000 (indicative) 1 – 5 days to configure
ERP e-invoicing module or middleware (mid-size) 15,000 – 60,000 (indicative) 3 – 8 weeks
Custom API integration with an existing ERP 40,000 – 150,000+ (indicative) 6 – 16 weeks
Sandbox testing + compliance dry run Included or 3,000 – 10,000 (indicative) 3 – 10 days
Per-device onboarding (multi-POS retail) Vendor-dependent, often per-terminal Minutes per device after first
VAT registration with ZATCA No government fee Usually within a few working days
Commercial Register issuance 1,200 – 2,000 (indicative) 1 – 3 working days
Chamber of Commerce membership (annual) 2,000 – 3,000 (indicative) 1 – 2 working days
MISA investment licence Issue/renew fees suspended in 2026 ≈ 3 – 10 business days

For context on the licensing side of the equation, our breakdown of the MISA licence in Saudi Arabia explains why the fee suspension has changed the arithmetic of market entry for foreign investors in 2026.

Clearance versus reporting: getting the model right

A large share of onboarding rework comes from teams building the wrong flow. The distinction matters operationally, not just technically.

Standard tax invoices (B2B and B2G)

These must be submitted to ZATCA’s clearance endpoint before they are shared with the buyer. ZATCA validates and applies its own cryptographic stamp, returning a cleared XML plus the QR code. Only the cleared version is a legally valid invoice. If your accounts team is used to emailing a PDF the moment the sale closes, that habit has to change: no clearance, no valid invoice.

Simplified tax invoices (B2C)

These are stamped by your own solution, given to the customer immediately with the QR code printed, and then reported to ZATCA within 24 hours. This keeps retail checkout fast. Your solution must queue and retry failed submissions — connectivity problems do not extend the 24-hour window.

Credit and debit notes

Notes follow the same route as the invoice they amend: a credit note against a standard invoice is cleared; a credit note against a simplified invoice is reported. Each must reference the original invoice and state the reason for issuance.

How Fatoora fits with the rest of your Saudi compliance stack

E-invoicing does not stand alone. A functioning Saudi entity generally touches several government platforms, and the identifiers must agree across all of them:

  • Ministry of Commerce and the Saudi Business Center — Commercial Register, trade name, articles of association.
  • MISA — the investment licence for foreign-owned entities, with issuance and renewal fees suspended in 2026.
  • ZATCA — VAT registration at 15%, VAT returns, zakat, customs and the Fatoora e-invoicing pipeline.
  • Qiwa (MHRSD) — labour file, employment contracts, Saudization percentage.
  • GOSI — social insurance registration; total contributions for a Saudi employee run to roughly 21.5% combining employer and employee shares.
  • Muqeem and Absher — residency, Iqama issuance and renewal (government fee around SAR 650 per year plus applicable levies), exit/re-entry.
  • Balady — municipal licence for physical premises, which your invoices’ national address should match.
  • Najiz and Etimad — judicial services and government procurement; Etimad tenders increasingly expect clean ZATCA standing.
  • Monsha’at — SME support programmes, including digital-adoption help for smaller businesses.

The practical point: a mismatch between the CR number on your invoice and the CR on file at the Ministry of Commerce, or a national address that differs from your Balady record, creates avoidable friction during audits. Align them once, at onboarding, rather than reconciling later.

Troubleshooting the most common Fatoora onboarding errors

“Invalid OTP” or OTP expired

OTPs expire after one hour and are single-use. If your integration was interrupted, generate a fresh one. Also confirm you pasted the OTP into the right unit — batch-generated codes are easy to mix up. Keep a simple spreadsheet mapping each OTP to its intended device.

CSR rejected

Almost always a formatting issue. The organisation identifier must be exactly your 15-digit VAT number. The country must be “SA”. The serial number field must follow the pipe-delimited pattern. Invoice type flags must correctly declare whether the unit issues standard invoices, simplified invoices, or both — a POS terminal flagged for standard invoices only will fail its simplified samples.

Compliance checks failing on the hash chain

Each invoice carries the hash of the previous invoice (PIH). The first invoice from a unit uses the defined initial value. If you re-seed the counter mid-testing, or run two processes writing to the same counter, the chain breaks and validation fails. Keep the invoice counter value (ICV) strictly sequential per EGS unit.

QR code rejected

The QR must be TLV-encoded then Base64-encoded, and for cleared standard invoices it must be the ZATCA-returned QR, not one you generated locally. Field order in the TLV structure matters.

Clearance returns warnings but succeeds

ZATCA distinguishes errors from warnings. A warning still clears the invoice but signals data that will eventually be enforced — for example a missing optional field or a rounding presentation issue. Do not ignore warnings; clear them in the next release cycle.

Certificate expired without notice

Expiry tracking sits with you as the taxpayer. Track the Production CSID expiry per unit and renew ahead of time. For fleets of POS devices, build renewal into your device-management routine.

Common mistakes to avoid

  • Treating onboarding as a one-off company task. Every EGS unit — each POS terminal, each separate billing system — needs its own onboarding and its own certificate.
  • Generating OTPs before the technical team is ready. They expire in an hour, and wasted codes mean repeated portal trips.
  • Skipping the sandbox. Testing straight in production turns small formatting bugs into failed compliance runs.
  • Using a VAT number that differs from the CSR organisation identifier. They must match exactly; a transposed digit fails silently at certificate issuance.
  • Emailing standard invoices before clearance. An uncleared standard invoice is not a valid tax invoice, and the buyer may refuse it for input VAT recovery.
  • Assuming 24-hour reporting is flexible. Build a retry queue; downtime does not pause the clock.
  • Letting the invoice counter or previous-invoice hash reset. The chain must be unbroken per unit for the life of that unit.
  • Ignoring the ZATCA wave notification email. The six-month notice is your project plan; teams that read it late compress a three-month integration into three weeks.
  • Buying software that is “ZATCA-ready” without checking Phase 2 API support. Phase 1 QR-code support is not the same as clearance and reporting integration.
  • Forgetting archiving obligations. Electronic invoices and their XML must be retained in the Kingdom in line with ZATCA record-keeping requirements — a PDF copy alone is not sufficient.
  • Hard-coding the old Commercial Register format. With the unified national CR live from 3 April 2026, templates referencing an expiry date or an old numbering pattern need updating.
  • Losing the private key. There is no recovery; the unit must be onboarded again from scratch.

A realistic onboarding timeline

For a single-entity business on cloud accounting software, onboarding is genuinely quick — often a single afternoon. For a group with multiple ERPs, POS fleets and legacy billing, plan a proper project. A workable sequence:

  1. Weeks 1–2: Inventory every system that issues an invoice. Identify how many EGS units you actually have. Confirm VAT registration and portal credentials work.
  2. Weeks 3–6: Vendor selection or in-house development. Map your invoice fields to the ZATCA data dictionary and fix master data gaps (national address, buyer VAT numbers, item descriptions in Arabic).
  3. Weeks 7–10: Sandbox testing. Run standard, simplified, credit and debit note samples until all pass cleanly.
  4. Week 11: Generate OTPs, obtain Compliance CSIDs, run production compliance checks, obtain Production CSIDs.
  5. Week 12: Parallel run — issue live invoices through the new pipeline while monitoring clearance responses daily. Train finance and cashier staff on what a rejection looks like.
  6. Ongoing: Monitor certificate expiry, warning trends and any new ZATCA resolutions published on the portal.

Language, Arabic fields and practical formatting

Saudi tax invoices must include Arabic. Your solution should carry Arabic seller name, and Arabic item descriptions are strongly advisable for readability and audit comfort. Numbers, VAT breakdowns and totals must be presented clearly, with VAT at 15% shown as a separate line. Rounding rules should be applied consistently — ZATCA validates that line totals, tax amounts and the invoice total reconcile.

Where a business issues invoices in foreign currency, the SAR equivalent and the exchange rate used must appear. This trips up exporters and service companies billing regional clients, and it is far easier to configure at onboarding than to patch after a hundred invoices have cleared.

How Noble Core helps

Noble Core Ventures works with founders and finance teams entering the Saudi market, and Fatoora onboarding is usually one item inside a broader compliance picture — licence, Commercial Register, VAT registration, labour file, GOSI, banking. We handle the sequencing so the pieces land in the right order rather than in the order the paperwork happens to arrive.

On e-invoicing specifically, our ZATCA and VAT compliance service covers VAT registration, EGS unit assessment, vendor shortlisting, CSR configuration review, sandbox validation, OTP and CSID onboarding for each unit, and post-go-live monitoring of clearance responses. For businesses still at the entry stage, our full Saudi setup package starts from SAR 36,999 and bundles the licensing and registration work with the tax onboarding, so you are not stitching together three vendors.

Saudi Arabia’s digital government programme under Vision 2030 has made these processes genuinely faster than they were five years ago — MISA licensing now runs roughly 3–10 business days, VAT registration is largely automated, and the unified Commercial Register removes an entire renewal cycle from the calendar. The platforms reward preparation. Arrive with the right identifiers, the right software and a tested configuration, and Fatoora onboarding is a formality rather than an obstacle.

Fees, thresholds and portal screens change. Every figure marked indicative above should be confirmed on the official portal before you budget against it, and the definitive source for e-invoicing rules, wave announcements, developer documentation and technical specifications remains ZATCA’s e-invoicing pages.

Need help setting up in Saudi Arabia? Noble Core handles your MISA licence, commercial registration, and visas end-to-end — done right the first time.

Get a free consultation

Frequently Asked Questions

What is Fatoora platform onboarding in Saudi Arabia?

Fatoora platform onboarding is the ZATCA process of registering your e-invoicing solution so it can connect to the government’s e-invoicing system. You log in at fatoora.zatca.gov.sa with your ZATCA credentials, generate an OTP for each device, obtain a Compliance CSID, pass ZATCA’s compliance checks with sample invoices, then receive a Production CSID that signs live invoices.

How long does Fatoora platform onboarding in Saudi take?

Once your software is genuinely ready, onboarding itself takes minutes to hours per device, and most single-entity businesses finish within one to three working days. The longer work is the preparation: vendor selection, field mapping and sandbox testing typically run three to twelve weeks for organisations with ERPs, multiple point-of-sale terminals or legacy billing systems.

Does ZATCA charge a fee for Fatoora onboarding?

ZATCA does not charge a government fee for Fatoora onboarding. The OTP, the Compliance CSID and the Production CSID are issued free. Your costs come from software and implementation: indicatively SAR 2,000 to 9,000 per year for cloud invoicing tools, SAR 15,000 to 60,000 for ERP modules, and more for custom integrations. Confirm current figures on the official portal.

Who must complete Fatoora platform onboarding Saudi requirements?

Every VAT-registered resident taxable person in the Kingdom, including 100% foreign-owned companies licensed by MISA, branches of foreign companies and establishments, plus third parties issuing invoices on their behalf. ZATCA notifies each Phase 2 wave by email and SMS at least six months before its integration date, working down from the largest taxpayers by annual taxable revenue.

What is the difference between a Compliance CSID and a Production CSID?

The Compliance CSID is a temporary certificate used only to run ZATCA’s validation tests. Your solution submits sample standard invoices, simplified invoices, credit notes and debit notes against it. Once every required sample passes, the software requests the Production CSID, which is the live certificate that cryptographically stamps and identifies your real invoices for clearance and reporting.

How many EGS units do I need to onboard on Fatoora?

One per invoice-generating device or instance, not one per company. A retailer with twelve point-of-sale terminals onboards twelve units, each with its own OTP and certificate, while a single cloud ERP issuing everything from one instance onboards once. The Fatoora portal lets you generate up to 100 OTP codes in a single batch for larger fleets.

What is the difference between clearance and reporting in Saudi e-invoicing?

Standard tax invoices for business and government customers must be cleared by ZATCA before you give them to the buyer; only the cleared version is a valid tax invoice. Simplified consumer invoices are stamped by your own solution, handed over immediately with a QR code, then reported to ZATCA within 24 hours of issuance. Credit and debit notes follow the same route as the original.

Why does my Fatoora onboarding keep failing?

The most frequent causes are an expired OTP, since codes last one hour and are single-use; a CSR whose organisation identifier does not exactly match your 15-digit VAT number; wrong invoice type flags on the device; and a broken hash chain where the invoice counter or previous-invoice hash was reset mid-testing. Run everything through ZATCA’s sandbox before touching production.




Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *