Saudi Arabia·6 min read·11 days ago

ZATCA Wave 24 Phase 2: SAR 375,000 Deadline 30 June 2026

Everything KSA accountants managing SME clients need to know about Wave 24 integration steps, UBL 2.1 XML requirements, cryptographic stamps, and the penalty framework — before the 30 June 2026 deadline hits.

By the SuperAccountant Editorial Team

ZATCA Wave 24 Phase 2: SAR 375,000 Deadline 30 June 2026 · zatca wave 24 phase 2 compliance deadline 30 june 2026 — SuperAccountant Journal illustration

If you handle accounts for any SME that cleared SAR 375,000 in VAT-taxable revenue during 2024, ZATCA's clock is already running. Wave 24 of Phase 2 (Fatoorah) goes live on 30 June 2026 / 6 Muharram 1448H, and the integration work required — API onboarding, UBL 2.1 XML structuring, cryptographic stamping — typically takes ten to fourteen weeks from a standing start. You have less runway than you think.

Who Exactly Is Caught by Wave 24?

ZATCA releases taxpayers into Phase 2 in rolling waves, each defined by a VAT-taxable revenue threshold measured over a specific calendar year. Wave 24 targets taxpayers whose VAT-taxable revenue exceeded SAR 375,000 in the calendar year 2024.

The figure that matters is the one on your client's VAT return Box 1 (total sales subject to VAT at standard, zero, and exempt rates combined). If the aggregate across all four quarterly or twelve monthly returns for 2024 crosses SAR 375,000, the entity is in scope. Newly registered taxpayers who crossed the threshold mid-year are not exempt — the pro-rated annual equivalent is used per ZATCA's published guidance on zatca.gov.sa.

Practically, this sweeps in a large share of KSA's SME sector: retail pharmacies, small trading companies, single-branch restaurants, and professional services firms that were previously untouched by earlier waves targeting SAR 3 million and above.

What Phase 2 Actually Requires (Beyond Phase 1)

Phase 1 (Generation) required compliant e-invoices to be created and stored. Phase 2 (Integration) is a different obligation entirely. Under ZATCA E-Invoicing Implementing Regulation, Article 53, Phase 2 mandates real-time or near-real-time electronic exchange with ZATCA's Fatoorah portal via API. The two invoice categories behave differently:

Invoice TypeTransmission ModeClearance / Reporting
Standard Tax Invoice (B2B / B2G)Real-time API callClearance required — invoice is invalid until ZATCA cryptographic stamp is returned
Simplified Tax Invoice (B2C)Batch reporting within 24 hoursReporting only — QR code generated by ERP at point of sale

The technical stack is non-negotiable:

  • UBL 2.1 XML formatted to ZATCA's KSA business rules (KSA-BR) and KSA-specific extension fields (KSA-EXT)
  • Cryptographic stamp generated via ZATCA's Cryptographic Stamp Identifier (CSID) certificate, issued after the FATOORAH onboarding process
  • Fatoorah API — either the Clearance API (Standard invoices) or Reporting API (Simplified invoices), both authenticated via OAuth 2.0 with a device-specific certificate

ERPs that are not on ZATCA's Mu'tamad (accredited solutions) list cannot generate valid CSID-stamped invoices. Check your client's ERP against the current Mu'tamad list on zatca.gov.sa before touching any configuration.

The Step-by-Step Integration Checklist for Wave 24

Work through these in sequence. Skipping steps — especially CSID issuance — is the most common reason firms arrive at the go-live date with a non-functional integration.

1. Confirm scope (by end of April 2026)

  • Pull 2024 VAT returns; confirm aggregate taxable revenue exceeds SAR 375,000
  • List every establishment (branch + head office) that issues VAT invoices — each device or ERP instance requires its own CSID

2. Assess ERP readiness (by end of April 2026)

  • Confirm ERP is on the Mu'tamad list or that a ZATCA-accredited middleware connector is in place
  • For ERPNext: the community ZATCA module supports Phase 2, but must be configured with your client's VAT registration number and legal address in Arabic
  • For Zoho Books: Zoho's KSA edition includes a built-in ZATCA Phase 2 connector; verify the version is current and UBL 2.1 output is enabled under Settings → E-Invoicing

3. Generate the Compliance CSID (6–8 weeks before go-live)

  • In the FATOORAH portal, create a new onboarding request using the taxpayer's VAT number
  • Submit the Certificate Signing Request (CSR) generated by your ERP/middleware
  • ZATCA returns a Compliance CSID; run the compliance check APIs against this before moving to production

4. Obtain the Production CSID (3–4 weeks before go-live)

  • After passing all compliance checks, request the Production CSID
  • This certificate has a defined validity period; calendar a renewal reminder at 12 months

5. End-to-end UAT (2–3 weeks before go-live)

  • Issue test Standard invoices via the Clearance API; verify the stamped XML is returned with <cbc:InvoiceTypeCode>388</cbc:InvoiceTypeCode> and a populated <ext:UBLExtensions> block containing the ZATCA cryptographic stamp
  • Issue test Simplified invoices via the Reporting API; verify the QR code decodes correctly using ZATCA's QR verification tool
  • Test credit notes (<cbc:InvoiceTypeCode>381</cbc:InvoiceTypeCode>) — these require the original invoice UUID in <cbc:ID> and are a common failure point

6. Cut-over and monitoring (at go-live, 30 June 2026)

  • Switch the ERP to production certificates
  • Monitor the first 48 hours of clearance API responses for rejection codes (most common: KSA-BR-O-008 — missing seller address in Arabic)
  • Keep Phase 1 PDFs as a fallback for the first week in case of API downtime, but note these cannot be issued to B2B buyers as valid VAT invoices once the entity is in Phase 2

If your team wants to pressure-test knowledge of the UBL 2.1 field-mapping rules before a client go-live, the SuperAccountant skill quiz covers ZATCA Phase 2 scenarios including common XML rejection codes.

Penalties for Non-Compliance and the Correction Window

ZATCA's penalty framework for e-invoicing non-compliance sits under Article 7 of the E-Invoicing Regulations and is enforced alongside the standard VAT penalty regime in Article 41 of the VAT Implementing Regulation.

The headline penalties:

  • Issuing a non-compliant invoice (no clearance/reporting): SAR 1,000 per invoice for first offence, escalating for repeat violations
  • Failure to retain e-invoices in the required format: up to SAR 50,000
  • Sharing or disclosing CSID private keys: criminal referral under the Cybercrime Law

ZATCA has historically offered a grace period for early waves — typically 30–90 days during which penalties are suspended provided the taxpayer can demonstrate active remediation steps. Wave 24 has not had a formal grace period announced as of the time of writing; monitor zatca.gov.sa for any circular. Do not plan your client's timeline around the assumption that a grace period will apply.

For invoices already issued incorrectly before go-live (e.g., PDF invoices that should have been cleared), the correction pathway is a Credit Note referencing the original invoice, followed by a correctly cleared replacement. ZATCA does not require retroactive clearance of pre-go-live invoices, but the transition date must be clean — all invoices dated on or after 30 June 2026 must go through the API.

Common Failure Points Specific to SME ERPs

In practice, Wave 24 clients running ERPNext or Zoho Books hit the same four issues repeatedly:

Arabic legal name mismatch — The seller's legal name in the XML must match the name on the ZATCA portal exactly, including the Arabic text. A single mismatched character causes KSA-BR-B-01 rejections at clearance.

Timestamp timezone errors — ZATCA requires invoice timestamps in AST (Arabia Standard Time, UTC+3) formatted as YYYY-MM-DDTHH:MM:SS. ERPs configured with UTC defaults will generate timestamps three hours behind, triggering clearance failures or, worse, silent acceptance followed by audit queries.

Missing KSA extension fields — The <ext:UBLExtensions> block must include both the cryptographic stamp and the invoice counter value (ICV). ERP modules that implement only the base UBL 2.1 schema without ZATCA's KSA-EXT layer will fail clearance.

Certificate renewal gaps — Production CSIDs expire. Build a renewal calendar now; a lapsed certificate silently fails API calls without alerting the cashier or accountant. The ERP simply cannot clear invoices, and the business does not know until an audit or a customer complaint.

What to Do This Week

You have a defined window. The practical actions in priority order:

  • This week: Pull 2024 VAT returns for every SME client and flag those above SAR 375,000 — these are your Wave 24 portfolio
  • April 2026: Complete ERP assessment and Mu'tamad verification; initiate FATOORAH onboarding for CSID issuance
  • May 2026: Complete UAT in ZATCA's sandbox environment; test all invoice types including credit notes
  • June 1–25, 2026: Deploy production certificates; run parallel dry-run with monitoring
  • 30 June 2026: Go live — all Standard invoices must be cleared before issuance; all Simplified invoices must be batch-reported within 24 hours

If you are managing multiple SME clients simultaneously, the CSID onboarding requests can be staggered but each takes time to process through the FATOORAH portal. Do not batch them all in the final two weeks.

For accountants who want structured support navigating Wave 24 alongside real client workpapers and ERP configuration exercises, the SuperAccountant cohort programme covers ZATCA Phase 2 integration in detail with hands-on scenarios.


Sharpen your edge with SuperAccountant's next live cohort — small batches, real client workpapers, taught by partners. Details and seats at https://app.superaccountant.in/en/cohort.