Connecting to the Fatoora platform on a documented path
Odoo ships the Saudi localisation and e-invoicing modules in its standard distribution. What ZATCA certifies is the e-invoicing solution of your own entity, bound to your tax number. We run that path: configuration, sandbox testing, then the live integration and invoice archiving.
The Saudi e-invoicing module ships in the standard distribution
At least ten test invoices submitted to the ZATCA sandbox
A path from Compliance CSID to Production CSID
A seven-year signed-XML archive
01Onboarding in the sandbox
02Compliance CSID — the sandbox test
03Production CSID — the live integration
These are ZATCA’s official stages, and each stage’s document is issued in your entity’s name.
Direct answers
The questions asked first
Is Odoo approved by ZATCA?
Yes — Odoo (odoo.com) is listed in the official Solution Providers directory of the Zakat, Tax and Customs Authority (ZATCA), qualified for Phase One: generation and storage. The listing can be verified directly in the directory on ZATCA’s website.
To be precise, ZATCA attaches a disclaimer to that directory: it is indicative and non-binding, it is not an approval by the authority of the solutions listed in it, and a taxpayer is entitled to work with any provider, listed or not.
Phase Two (integration) is not qualified at brand level: the Compliance CSID and the Production CSID are issued to a single entity bound to its tax number (TIN), and they do not transfer to another entity.
In practice, Odoo ships the Saudi localisation (l10n_sa) and e-invoicing (l10n_sa_edi) modules in its standard distribution, and we deliver the full certification path for your entity through to production — with no accreditation claim of our own.
What is Phase 2 of e-invoicing?
It is the integration stage: a standard (B2B) invoice is sent to the Fatoora platform and cleared before it is issued, while a simplified (B2C) invoice is reported within 24 hours. It requires UBL 2.1 XML, a cryptographic stamp, a unique identifier per invoice, a TLV-format QR code, a clearance and reporting API, and a seven-year archive of the signed XML.
How long does connecting to Fatoora take?
Typically two to four weeks for a single entity: about a week to prepare the device credentials in the sandbox, a week to test at least ten invoices covering the required types, then three to seven business days for ZATCA to review and issue the Compliance CSID, followed by one to three days for the Production CSID. That assumes a system already configured with the tax number and a Saudi chart of accounts; a greenfield setup adds four to six weeks before the certification path can start.
What remains the entity’s responsibility after go-live?
Final approval and statutory compliance rest with the taxpayer. We perform the configuration, testing, integration and documentation handover, but issuing correct invoices and keeping their data matched and archived is the entity’s responsibility. That is why we train your team, hand over written procedures, and document our responsibility boundary in the proposal before work starts.
Requirements
What Phase 2 actually requires
Six mandatory technical requirements. Any solution — embedded in an ERP or standalone — must implement all six to pass the Compliance CSID stage. These are the objective criteria to audit a system against, and where our assessment starts.
1
UBL 2.1 XML structure
Invoice data must be structured as Universal Business Language 2.1 XML — the format the Fatoora platform parses for clearance and reporting.
2
Cryptographic stamp (ECDSA)
Every invoice carries a digital signature using the elliptic-curve algorithm, proving it was not altered after generation.
3
A unique identifier per invoice (UUID)
A unique identifier on each invoice lets ZATCA cross-reference clearance requests without collisions.
4
QR code in TLV format
A simplified (B2C) invoice carries a QR code encoding the seller name, tax number, date, totals and the cryptographic stamp, in Tag-Length-Value encoding.
5
Clearance and reporting API
Standard (B2B) invoices are cleared through the API before issuance and simplified (B2C) ones reported within 24 hours, with the platform managing authentication tokens.
6
A seven-year electronic archive
Signed invoices retained in full for seven years and producible on ZATCA’s request — the archive must hold the signed XML, not merely a PDF rendering.
What Odoo ships
What Odoo provides out of the box
We are not selling you a third-party add-on. The Saudi localisation and e-invoicing modules are part of the standard Odoo distribution, and you can verify that in Odoo’s own documentation.
l10n_sa — Saudi localisation
The Saudi accounting localisation: chart of accounts, VAT rates, tax number handling and local requirements.
l10n_sa_edi — e-invoicing
UBL 2.1 XML generation, the cryptographic stamp, the unique identifier, the TLV QR code, and the clearance and reporting API to Fatoora.
Inside the standard distribution
Both modules are part of the standard Odoo distribution with no third-party add-on required — verifiable in Odoo’s official documentation.
The invoice comes from the same system
Because accounting, inventory, sales and POS share one database, the invoice is issued from the transaction itself rather than copied between systems.
Reviewing the impact of upgrades
Before any Odoo version upgrade we review its impact on your e-invoicing configuration and test it in the sandbox before applying it.
The path
The certification path, step by step
Three official stages. We know who performs each one and what it produces, and we will not call a stage complete before its document is issued by ZATCA.
01
Onboarding in the sandbox
We register the device or solution on the Fatoora platform and generate the certificate signing request (CSR) for your entity’s tax number.
Owner: delivery team · Output: sandbox credentials
02
Compliance CSID — the sandbox test
We generate and submit at least ten test invoices covering the required types (standard, credit note, debit note and simplified). On passing, ZATCA issues the certificate.
Owner: delivery team with ZATCA · Output: Compliance CSID
03
Production CSID — the live integration
We move to the production environment and issue live invoices that ZATCA clears. This is the live integration, and its document is the definitive proof that your entity is operating compliantly.
Owner: delivery team with your entity · Output: Production CSID
Verification
How to verify us before you sign
Because any vendor can write "certified", look at what can be checked. Ask us these four questions and you will know the standard of any proposal you compare — including ours.
1
Ask for a Compliance CSID from a client in your wave
A deck saying "Phase 2 ready" proves nothing. The document carries the tax number, the solution configuration and the wave batch, and you can verify it.
2
Ask for the first-pass acceptance rate
Ask for the first-pass acceptance rate of standard invoices in live production for a reference client. A sound configuration holds a high, stable rate.
3
Ask for two clients who completed a Production CSID
Two callable references in the same wave you are entering, whom you ask about the timeline, the sandbox interactions and post-go-live rejection rates.
4
Ask for a sandbox demonstration
A capable vendor will demonstrate submitting and clearing an invoice in the sandbox before you sign. Declining reveals the maturity of their implementation.
Inside the process
Inside the process
Real screenshots from the sandbox, cleared invoices and system screens — uploaded from the dashboard.
No process screenshots uploaded yet
This page shows no mock-up screens. Real screenshots from the sandbox, a cleared invoice and the system screens will appear here as soon as they are uploaded from the dashboard.
Diagnostics
Why invoices get rejected, and what we do about it
A rejection in production stalls your collections. We train your team to read the error code and resolve it, and hand over a written reference for each type.
XML structure error
A missing mandatory field or a tag that does not match the schema. We correct the template and add pre-submission validation so it cannot recur.
Cryptographic stamp failure
A problem with the certificate or the signing sequence. We check that the certificate is current and that the issuance steps run in order.
Invoice counter value (ICV) mismatch
A break in the invoice sequence or a duplicated number. We review the counter and confirm there are no gaps before resubmitting.
Customer classification error
A standard invoice sent to a customer without a tax number, or the reverse. We set the classification rules on the customer record.
VAT calculation mismatch
A difference between the invoice’s tax total and the line-level calculation. We review the tax configuration on products and accounts.
The seven-year archive — the requirement everyone forgets
The VAT Implementing Regulations require signed invoices to be retained for seven years and produced on ZATCA’s request. Keeping a PDF rendering is not enough.
The full signed XML retained for seven years, not merely a PDF rendering
Files ready to produce on ZATCA’s request within a reasonable time
Backup and restore covered inside the system’s storage layer
Access restricted by role and recorded in the audit trail
What we need from you to start
Prepare these and the timeline shortens. Anything missing we either handle inside the project or state clearly in the proposal.
1
Tax number and VAT registration certificate
The tax number (TIN) is what the certification binds to, and the path cannot start without it.
2
Saudi chart of accounts and tax coding
Output and input VAT accounts defined and linked to the products you sell.
3
The invoice types you issue
A list of document types: standard, simplified, credit and debit notes, and returns — so the test covers all of them.
4
Customer classification (B2B / B2C)
The tax number for each business customer, because the flow differs between clearance and reporting.
5
Access to the Fatoora platform
Your entity’s account on the platform, or written authorisation for us to act on your behalf during the project.
6
An Odoo environment, ready or planned
Either an existing system we start from, or a new configuration folded into the same project before the certification path.
FAQ
What finance and tax leads ask
Is Odoo approved by ZATCA?
Yes — Odoo (odoo.com) is listed in the official Solution Providers directory of the Zakat, Tax and Customs Authority (ZATCA), qualified for Phase One: generation and storage. The listing can be verified directly in the directory on ZATCA’s website.
To be precise, ZATCA attaches a disclaimer to that directory: it is indicative and non-binding, it is not an approval by the authority of the solutions listed in it, and a taxpayer is entitled to work with any provider, listed or not.
Phase Two (integration) is not qualified at brand level: the Compliance CSID and the Production CSID are issued to a single entity bound to its tax number (TIN), and they do not transfer to another entity.
In practice, Odoo ships the Saudi localisation (l10n_sa) and e-invoicing (l10n_sa_edi) modules in its standard distribution, and we deliver the full certification path for your entity through to production — with no accreditation claim of our own.
Can we use a third-party add-on instead of the Odoo module?
Technically yes, but it adds another maintenance vendor and an upgrade path separate from your Odoo version. The l10n_sa and l10n_sa_edi modules are part of the standard distribution, so we start there unless you have a specific reason not to.
Do we have to stop invoicing during implementation?
No. We configure and test in the sandbox without touching your current invoicing, and only move to production once the test is passed and your team is trained on the new procedure.
What happens if an invoice is rejected in production?
A rejected standard invoice cannot be used for VAT purposes until it clears, so we train your team to read the error code and resolve it, and hand over a written reference of common rejection causes and their fixes.
Do you support multiple entities or tax numbers?
Yes, but each entity needs its own certification path because it binds to its own tax number. We run the multiple paths inside one project and document each entity’s status separately.
Does the service include invoice archiving?
Yes. We configure the seven-year signed-XML archive inside the system’s storage layer, with backup, restore and role-restricted access.
What is the difference between a Compliance CSID and a Production CSID?
The Compliance CSID is issued after passing the sandbox test — a prerequisite, not a final clearance. The Production CSID is issued after moving to production and ZATCA confirming the system generates valid signed invoices live. You need both.
Do you work with systems other than Odoo?
Odoo is our core specialism. We can assess another system and document its gaps against the six requirements, but if it does not support the API or digital signing at all, the practical route is usually replacing it rather than patching it.
Do you train our team on the new process?
Yes. Training is delivered in Arabic on your own data and covers issuing an invoice, reading clearance and rejection states, and handling platform downtime, with written user guides that stay with you.
Can I get a readiness assessment before committing to a project?
Yes. The assessment session establishes whether your system meets the six requirements, what the gaps are, and the expected time to a Production CSID — with no obligation to proceed.
What if our historical invoices are not compliant?
The requirement applies to invoices issued after your entity’s wave date, alongside the seven-year retention duty. We review your position during the assessment and state clearly what, if anything, applies retroactively.
Do you display the ZATCA logo?
No. The ZATCA mark belongs to a government authority, and using it commercially implies an endorsement that has not been granted. We describe the path and the documents issued in your entity’s name instead.
Is the service available outside Saudi Arabia?
The ZATCA path is specific to the Kingdom because it binds to the Fatoora platform and a Saudi tax number. Odoo implementation itself we deliver to clients across the region, respecting each country’s local requirements.
How do we verify that another vendor really delivers Phase 2?
Ask for a Compliance CSID document from a client in your own wave, the first-pass acceptance rate in production, two callable references, and a sandbox demonstration before signing. Those four questions separate a ready deck from a tested implementation — and we welcome them.
Request an e-invoicing readiness assessment
Tell us your entity count, tax number status and current system, and we will come back with the gaps and a plan to reach production.
An assessment session with no obligation
A gap report against the six requirements
Scope and responsibilities documented before we start
One session to establish whether your current system meets the six requirements, where the gaps are, and how long reaching a Production CSID would take.
Business Solutions is an independent company specialising in Odoo implementations. We are not Odoo S.A. and we do not claim official partner status. We are also not a certification body: ZATCA is the only authority that issues accreditation documents, and we neither display its logo nor claim its endorsement. Every certificate or document we refer to is issued in your entity’s name and tax number, and our responsibility boundary is documented in the proposal.
We respect your privacy
We use essential cookies to operate the site, plus analytics and marketing cookies to improve your experience. You control your choice.