Saudi Arabia·6 min read·19 days ago

ZATCA Wave 24: SAR 375k Threshold & XML/PDF-A3 Steps

Wave 24 pulls another tier of Saudi businesses into Phase 2 e-invoicing by 30 June 2026. Here is your technical checklist — XML format, PDF-A/3, cryptographic stamping, UUID, and real-time clearing — before ZATCA comes knocking.

By the SuperAccountant Editorial Team

ZATCA Wave 24: SAR 375k Threshold & XML/PDF-A3 Steps · zatca wave 24 sar 375k threshold steps 2026 — SuperAccountant Journal illustration

If your client's taxable revenue crossed SAR 375,000 in 2022 or 2023, Wave 24 is their deadline — 30 June 2026 (5 Muharram 1448H). Most advisors are still updating Wave 23 checklists; this post cuts straight to what is different at the SAR 375k tier and the exact technical steps your team needs to execute now.

Who Is Caught by Wave 24?

ZATCA's phased rollout of Phase 2 (Integration / Fatoorah) targets taxpayers by descending revenue band. Wave 24 captures businesses whose VAT-registrable revenue — per their VAT return filings — exceeded SAR 375,000 during the calendar years 2022 or 2023.

Practically, this means a large slice of what the market calls "SME Plus": companies too big to ignore Phase 2 but small enough that their finance teams have been watching larger peers go first. If you act as external accountant, finance controller, or VAT consultant for any such entity, the onboarding window with ZATCA's Fatoorah portal opens six months before the go-live date — meaning you should already be in the integration queue.

Official guidance and the current wave schedule are published at zatca.gov.sa.

What Changes at Phase 2 vs. Phase 1

Phase 1 (December 2021) required a structured digital invoice but allowed simple PDF/image formats stored on the taxpayer's device. Phase 2 is a different animal:

  • B2B and B2G invoices must be cleared in real time through ZATCA's Fatoorah platform before they are delivered to the buyer.
  • Simplified tax invoices (B2C) require reporting to ZATCA within 24 hours.
  • The invoice must be a UBL 2.1-compliant XML document with a specific KSA extension (KSA-EN16931 profile).
  • A PDF/A-3 file embedding the UBL XML may be used as the human-readable layer, but the XML is the authoritative record.
  • Every invoice carries a cryptographic stamp (ECDSA digital signature), a UUID, and a QR code generated per ZATCA's specification in the Implementing Regulation Annex 2.

If your ERP produces a plain PDF today, it does not meet Wave 24 requirements — full stop.

The XML / PDF-A/3 Technical Requirements in Detail

This is where most SME implementations stall. The ZATCA e-invoicing standard (released under the Implementing Regulations for E-Invoicing, Article 53 and the accompanying Technical Specifications) mandates:

RequirementSpecification
Invoice schemaUBL 2.1 with KSA-EN16931 extension
File formatXML (primary); PDF/A-3 with embedded XML permitted
Digital signature algorithmECDSA (secp256k1 curve)
Certificate sourceZATCA-issued CSID (Cryptographic Stamp Identifier)
UUIDVersion 4 random UUID per invoice, unique across the taxpayer's system
QR codeBase64-encoded TLV structure per ZATCA Annex 2
HashSHA-256 of the canonical invoice XML, included in the signature
PIH (Previous Invoice Hash)SHA-256 of the prior cleared invoice — creates an audit chain

The PDF/A-3 wrapper matters because it makes the invoice human-readable for clients who cannot parse raw XML, while the embedded XML remains the legal document. Your ERP or middleware must generate both layers atomically from the same data source — do not create the PDF separately and stitch the XML in afterwards, as the hash will not match.

Step-by-Step: Wave 24 Onboarding Workflow

Work through these in order. Skipping steps creates cryptographic failures that block clearance.

Step 1 — Confirm revenue eligibility and notify ZATCA Log into the Fatoorah portal (accessible via zatca.gov.sa) and verify your entity is listed under Wave 24. If not listed but threshold is met, contact ZATCA's helpdesk — do not self-onboard to the wrong wave.

Step 2 — Select or upgrade your ERP/solution to a Mu'tamad-certified system ZATCA maintains a list of approved (Mu'tamad) e-invoicing solutions. Using a non-certified solution is a compliance risk even if the output XML looks correct, because the signing library may not pass ZATCA's validation checks. Check the approved solutions register on the official portal.

Step 3 — Generate the Compliance CSID (CCSID) Call ZATCA's Compliance API with your OTP (issued via the Fatoorah portal). This returns your Compliance Cryptographic Stamp Identifier. This step validates that your solution can produce a correctly structured and signed invoice.

Step 4 — Run compliance checks Submit sample invoices (standard tax invoice + simplified tax invoice + credit note) to the Compliance API. ZATCA will return pass/fail against ~40 validation rules. Common failures at this stage: missing seller address fields, incorrect VAT category code (S/Z/E/O), wrong QR TLV encoding.

Step 5 — Generate the Production CSID (PCSID) Once compliance checks pass, renew your CSID for the production environment. The PCSID is what signs live invoices. It has a validity period — calendar it for renewal.

Step 6 — Go live: real-time clearance for B2B For every standard tax invoice, your system POSTs the signed XML to ZATCA's Clearance API. ZATCA returns a cleared invoice with its own stamp appended within seconds (in normal load conditions). You deliver the cleared invoice — not the pre-clearance version — to your buyer. This is the step that changes your AR workflow: you cannot issue a VAT-compliant B2B invoice until ZATCA has cleared it.

Step 7 — Reporting for B2C simplified invoices Batch-report simplified invoices to ZATCA within 24 hours of issuance. Most certified solutions handle this automatically, but verify that the reporting queue is monitored and any failed submissions are retried.

If your team wants to benchmark their current knowledge of Phase 2 mechanics before the implementation sprint, the SuperAccountant skills quiz covers ZATCA e-invoicing concepts and flags gaps quickly.

Common Pitfalls and How to Avoid Them

PIH chain breaks. If an invoice is voided in your ERP without being properly cancelled in Fatoorah, the next invoice's PIH reference points to a hash that ZATCA does not recognise. Result: every subsequent invoice fails clearance. Establish a formal cancellation protocol before go-live.

Certificate expiry. The PCSID has a finite validity. An expired certificate means invoices cannot be signed and clearance is blocked. Set automated alerts at 30 days before expiry.

VAT category mismatches. Wave 24 businesses often have a mix of standard-rated, zero-rated, and exempt supplies. Each line item needs the correct UNCL5305 tax category code mapped correctly in the UBL XML. A mismatch between the category code and the VAT rate triggers a ZATCA validation error.

Credit notes and debit notes. These require reference to the original cleared invoice's UUID. If your original UUID was not stored correctly in your ERP, you cannot issue a compliant adjustment document.

Archiving. Per the VAT Implementing Regulations, e-invoices must be retained for a minimum of six years. Cleared XML files — not just PDFs — must be archived in a manner that preserves their cryptographic integrity.

What Penalties Apply If You Miss the Deadline?

ZATCA's penalty framework under the E-Invoicing Regulations and the VAT Law (Royal Decree M/113 of 1438H) treats non-compliance with Phase 2 clearance as a failure to issue a valid tax invoice. Penalties for non-issuance of a compliant VAT invoice can reach SAR 50,000 per violation under Article 41 of the VAT Law, and ZATCA has been active in enforcement following Wave 1 and Wave 2 go-lives. There is no automatic grace period at the SME tier — the obligation is binary on the go-live date.

Your Six-Month Action Plan Before 30 June 2026

  • Now: Confirm revenue threshold and wave assignment on the Fatoorah portal.
  • Month 1: Select or confirm Mu'tamad ERP/solution; begin vendor scoping if upgrading.
  • Month 2: Complete CCSID generation and compliance API testing in the sandbox environment.
  • Month 3: Fix all validation failures; conduct end-to-end testing including credit notes.
  • Month 4: Train AR, AP, and IT teams on the new clearance workflow and exception handling.
  • Month 5: Generate PCSID; run parallel production testing with a subset of live invoices.
  • Month 6 (by 30 Jun 2026): Full production go-live; monitor clearance queue daily for first 30 days.

Accountants advising Wave 24 clients should also be briefing finance directors now on the AR timing impact: cleared invoices typically return from ZATCA within 2–5 seconds under normal load, but your client's cash flow assumptions should account for any API downtime during the transition period.

For those building a practice in VAT advisory and e-invoicing implementation, the SuperAccountant cohort covers live client scenarios including Phase 2 onboarding — exactly the type of work Wave 24 is going to generate across the next 12 months.


Sharpen your edge with SuperAccountant's next live cohort — small batches, real client workpapers, taught by partners. Details and seats at https://app.superaccountant.in/en/cohort.