ZATCA Wave 25: the threshold just halved, and the deadline is 1 February 2027
ZATCA announced Wave 25 on 24 July 2026, cutting the e-invoicing integration threshold to SAR 187,500. What Phase 2 actually requires, what it costs to be late, and the failure modes I have watched teams hit.
On 24 July 2026, ZATCA announced Wave 25 of Phase 2 e-invoicing integration. The threshold dropped to SAR 187,500 of VAT-subject revenue in 2022, 2023, 2024 or 2025, and the integration deadline is 1 February 2027.
That number matters more than it looks. SAR 187,500 is the voluntary VAT registration threshold in Saudi Arabia. Mandatory registration starts at SAR 375,000. So Wave 25 reaches down past the mandatory line into businesses that registered by choice. If you are VAT-registered here and you have somehow not been called yet, assume this is your wave and check.
I have built ZATCA-compliant invoicing into a multi-company ERP, so this is written from the implementation side rather than the brochure side.
Phase 1 and Phase 2 are different jobs
People conflate these constantly, usually because a vendor told them they were "already compliant."
Phase 1, Generation. In force for everyone since 4 December 2021. Invoices must be generated electronically in a structured format, no handwriting and no free-text Word documents, with a QR code on simplified invoices and tamper-evident storage. Most businesses cleared this years ago.
Phase 2, Integration. Started 1 January 2023 and has been rolled out in waves ever since. This is the one that requires your system to talk to ZATCA directly, in real time, with cryptography. Being fine under Phase 1 tells you nothing about Phase 2.
Am I in scope?
Two tests.
Revenue. For Wave 25: VAT-subject revenue above SAR 187,500 in any of 2022, 2023, 2024 or 2025. Note the "any of." A good year in 2022 pulls you in even if the last two were quieter.
Who you are. The requirements apply to all resident taxpayers, and also to any other party issuing tax invoices on behalf of a supplier subject to VAT. That second limb catches more people than expected: outsourced billing providers, agents invoicing for a principal, and shared-service centres issuing for group companies. Non-resident taxpayers are outside the regulation.
If you are unsure which wave you were called in, ZATCA notifies taxpayers directly, and each wave has been announced with roughly six months of notice. Six months sounds generous until you have priced an ERP change against it.
What integration actually requires
This is the part vendors summarise as "we handle it." Here is the real list.
1. Onboard every generation unit. Each e-invoice generation solution unit, meaning each system or POS that issues invoices, is onboarded through the Fatoora portal with an OTP, submits a certificate signing request, and receives a compliance CSID. You then pass ZATCA's compliance checks with sample invoices before receiving a production CSID. A group with several entities and a POS estate is onboarding many units, not one.
2. Generate the right format. Invoices must be XML in the UBL-based format, or PDF/A-3 with the XML embedded where a human-readable version is shared. For transmission to ZATCA, XML is the format that counts. A PDF that looks like an invoice is not an invoice under this regime.
3. Carry the mandatory technical fields. A UUID, a tamper-resistant non-resettable invoice counter, the hash of the previous document, the cryptographic stamp, and a QR code carrying the required fields. The counter and previous-document hash are the ones that catch people, because they mean your invoice numbering can no longer be reset, edited or backdated, and any system that lets a user do so is now a compliance problem.
4. Route each invoice type correctly. This is the distinction that decides your architecture:
| Standard tax invoice (B2B, B2G) | Simplified invoice (B2C) | |
|---|---|---|
| Process | Clearance, in real time | Reporting |
| Who stamps it | ZATCA applies its cryptographic stamp | Your own solution stamps locally |
| Timing | Before you give it to the buyer | Within 24 hours of generation |
| If it fails validation | It is not cleared, and must not be shared | Reporting obligation still stands |
Read the clearance row again. For B2B invoices you may not share the invoice with the customer until ZATCA has cleared it. That is not a reporting requirement bolted onto month-end. It sits inside your order-to-cash flow, in real time, and it needs a failure plan for when the connection is down.
What it costs to be late
Three layers, in increasing order of seriousness.
The fines. Field-level violations run from around SAR 5,000, with a statutory ceiling of SAR 50,000 under Article 45 of the VAT Law, applied per violation and escalating on repetition. Deleting or amending an issued e-invoice by any route other than a proper credit or debit note sits at the higher end.
No amnesty. Businesses have been leaning on ZATCA's fines and penalties initiative, which was extended in June 2026 to run to 31 December 2026. It covers late registration, late payment, late filing and return corrections. It explicitly excludes fines under Article 45 of the VAT Law, which is the e-invoicing article. There is no amnesty coming for this one.
The one that actually hurts: input tax. Deductibility is tied to invoices having been properly cleared or reported. That exposure is not limited to your own invoicing discipline; it runs across your supplier base. If a supplier is out of scope for compliance and you are recovering input tax on their invoices, that is your problem at audit, not only theirs.
That third point is why this is a CFO issue and not an IT ticket.
The failure modes I actually see
From doing this rather than reading about it.
"Our ERP is compliant." Usually means the vendor supports Phase 1, or supports Phase 2 in a version you are not on, or supports it for one entity and not the multi-company structure you actually run. Ask for the production CSID onboarding to be demonstrated in your environment, not a compliance certificate in a slide.
Arabic fields treated as a translation task. Certain fields must be present in Arabic. This is a data problem, not a UI problem: it means customer names, addresses and item descriptions in your master data, populated for records created years ago by someone who did not expect this.
Numbering that can be reset. Any process where a user voids and reissues, or where a new sequence starts per branch per year, collides with the non-resettable counter and previous-document hash. This tends to surface late, because it is a business practice rather than a system setting.
POS treated as out of scope. Simplified invoices still have to be stamped locally and reported within 24 hours. A retail or F&B estate is often the bigger part of the project.
The wave date read as the project date. The deadline is when you must be integrated and live. Working backwards through vendor selection, ERP upgrade, master-data clean-up, testing in ZATCA's compliance environment and onboarding across entities, six months is a normal project, not a comfortable one.
Credit and debit notes forgotten. They are in scope, they follow the same rules, and the linkage back to the original invoice has to hold.
What I would do in the next 30 days
- Confirm your wave in writing. Check the revenue test against 2022 to 2025 and find ZATCA's notification. Do not rely on "we would have heard."
- Get a straight answer from your ERP vendor, in writing, naming the version and the module, covering multi-entity, clearance and reporting flows, credit and debit notes, and Arabic fields.
- Audit your invoice numbering for anything that resets, voids or backdates. Fix the process, not just the config.
- Look at master data now. Arabic names and addresses, VAT numbers for B2B customers, item descriptions. This is the long pole and nobody wants to own it.
- Decide the offline plan. What happens to a B2B sale when clearance is unavailable. Agree it before it happens at month-end.
- Check your supplier base, because your input tax deduction depends on their compliance as well as yours.
If this is landing on your desk
The teams that struggle are rarely the ones with bad finance people. They are the ones where nobody owns the intersection of tax, systems and process, so tax assumes IT has it, IT assumes the vendor has it, and the vendor is answering a narrower question than anyone realises.
That intersection is the work I do. If you want someone to own it, tell me where you are and I will tell you whether you have a project or a problem.
Position as of 29 July 2026, based on ZATCA's published announcements and the Implementing Resolution. Wave thresholds and dates change; verify against ZATCA and your own advisers before acting. This is general guidance, not tax advice.
