Spain is closing the door on invoicing software that can be quietly edited after the fact. Under the Verifactu mandate, every invoice your system produces must be secure, traceable, and unalterable, and the tax agency can check it. Get it wrong, and the cost is concrete: businesses using non-compliant software face fines of up to 50,000 euros per year.
That figure alone is reason enough to take the software question seriously. But the penalty is only part of the story. Below is a clear guide to what Verifactu compliant software requires technically, who has to comply and when, how the fines actually work, and how to make sure the invoicing software you rely on will not land you with a bill from the AEAT.
Table of Contents
What Is Verifactu?
Verifactu is an anti-fraud system run by Spain's tax authority, the AEAT (Agencia Estatal de Administración Tributaria). Introduced under Royal Decree 1007/2023, its purpose is straightforward: to make sure billing software creates invoice records that cannot be manipulated or destroyed. The rules it sets are, in effect, the standard any Royal Decree 1007/2023 software must meet to be legal to use.
It is important to be precise about what Verifactu governs. It sets the technical requirements that invoicing software (known in Spain as a SIF, or Sistema Informático de Facturación) must meet. It does not regulate how invoices are exchanged between businesses. That is a separate mandate, the B2B e-invoicing regime under the Crea y Crece law, which runs in parallel and has its own timeline. Many companies will eventually need to comply with both, but they are distinct obligations with different technical specifications.
In practice, Verifactu requires your invoicing software to guarantee the integrity, traceability, unalterability, accessibility, and legibility of every record it creates.
The Technical Requirements: What Compliant Software Must Do
Verifactu is a system-level requirement, which means compliance lives in your software architecture, not in manual checks. Verifactu invoicing software has to build the following into the invoicing process itself.
Hash chaining (the "huella"): This is the core anti-fraud mechanism. Each billing record carries a cryptographic hash, typically SHA-256, that incorporates part of the hash from the immediately preceding record. Thus, invoices are linked in an unbroken chronological chain, so if anyone alters a past invoice, the chain breaks and the tampering becomes detectable. This is what makes records genuinely unalterable rather than just "hard to edit."
Digital signature: Each invoice record must be electronically signed in line with the AEAT's requirements, adding a second integrity guarantee on top of the hash chain.
Records created at the right moment: The software must generate the record simultaneously with, or immediately before, issuing the invoice, never afterwards. Corrections and cancellations cannot overwrite anything; they must generate a new record, preserving the original.
A tamper-proof event log: The system must keep a hidden, automatic log of relevant events, including who logs in, when an invoice is issued, and any attempt to change system parameters. Traceability here is a control, not a feature: Verifactu expects a complete, provable history with no silent edits.
QR code and labelling: Every full and simplified invoice needs a QR code that lets both the customer and the AEAT verify its details. In many cases the invoice also carries the legend "VERI*FACTU" or a phrase confirming it is verifiable on the AEAT's electronic portal.
A compliance mode. Businesses comply through one of two modes:
- Verifactu mode: The software transmits each invoice record to the AEAT in near real time as it is issued. The AEAT stores those records, so you do not need local retention, and the invoice can carry the verifiable-at-AEAT legend.
- Non-Verifactu mode: Records are stored locally under the same strict integrity and signature rules and made available to the AEAT on request. This mode carries no AEAT legend, and the business is fully responsible during an audit for producing the stored records and proving they are unchanged. Records must be retained for four years in tamper-proof storage.
The practical implication is that Verifactu touches how invoices are created, stored, corrected, and transmitted across every channel. The good news is that most businesses can adapt existing systems rather than replace them, connecting their ERP, POS, or e-commerce platform to a certified compliance layer that supplies the hashing, signing, and submission.
Who Must Comply, and When?
The timeline has shifted more than once, so the current dates matter. On 2 December 2025, the Spanish government postponed the mandate by a year, the second such delay, to give small and medium businesses and self-employed workers more time to absorb the cost of new certified software.
The current deadlines are:
- 1 January 2027: Companies subject to corporate income tax (SLs, SAs, and similar).
- 1 July 2027: Self-employed workers (autónomos) and, in many summaries, non-resident entities.
One detail that trips businesses up: while business use of Verifactu is delayed to 2027, non-compliant invoicing software has been banned from sale since July 2025. In other words, the obligation on vendors to produce compliant software is already live, even though the obligation on you to use it starts later.
The 50,000 Euro Penalty, Explained
Here is where precision pays off, because two different fines are often confused.
For businesses and self-employed professionals, using invoicing software that is not compliant can carry a fine of up to 50,000 euros per fiscal year. This is the penalty most likely to apply to you as an end user, and it is charged per year, so a prolonged period on the wrong system compounds the exposure.
For software developers and vendors, producing or selling non-compliant software, or software that enables data manipulation, carries a heavier fine of up to 150,000 euros per year, per type of product.
Two features of the enforcement regime make this more serious than a typical compliance rule. First, penalties can be automatic: ignoring the Verifactu rules can trigger a fine from the AEAT regardless of whether there was any fraudulent intent. The offence is using non-compliant software, not committing fraud with it. Second, the consequences reach beyond the headline fine. A business that cannot produce compliant records risks being unable to issue valid invoices to the AEAT, having billing processes blocked or invalidated, and lacking the traceability needed to justify its operations during an inspection. Each of those carries a real commercial cost in delayed billing and collections, on top of the penalty itself.
The practical takeaway is that the risk cuts both ways along the supply chain, but your exposure as a business comes from the software you choose to run. Picking a certified system is the single most effective way to remove that 50,000 euro risk entirely.
Are You Exempt? The SII Question
Not every business is in scope. Companies that report through the SII system (Suministro Inmediato de Información) are exempt from Verifactu obligations.
The logic is simple: SII already sends invoice data to the AEAT in near real time, so those businesses are not required to implement Verifactu-compliant software, generate QR codes, or display the VERI*FACTU label. SII applies mandatorily to large companies with turnover above 6 million euros, VAT groups, and businesses in the REDEME monthly refund regime, while others can opt in voluntarily.
If you are not under SII, you should assume Verifactu applies to you.
How to Choose Compliant Software
Avoiding the fine comes down to one decision made well: the electronic invoicing software you run. A few checks to apply when you assess whether a system is genuinely AEAT compliant invoicing software:
- Ask for the "declaración responsable." Any compliant vendor must issue a responsible declaration confirming their product meets the AEAT's technical standards. If a provider cannot produce one, walk away.
- Confirm the integrity mechanics. The system must deliver the hash chaining, digital signature, and tamper-proof event log described above, not just claim to be "compliant."
- Map every channel. ERP, point of sale, and e-commerce all need to produce compliant records, not just your main accounting system.
- Think ahead to B2B e-invoicing. Verifactu is not the only mandate coming. A platform that also handles the Crea y Crece B2B regime saves you a second migration later.
Why SMARTeIS Is Built for Spanish E-Invoicing Compliance
Verifactu is one piece of a bigger picture. Spain also has the Crea y Crece B2B mandate, SII real-time VAT reporting, and the wider EU shift toward continuous transaction controls under ViDA. The smart move is to solve all of it on one platform rather than bolting on point tools. For many companies, the best Verifactu software is the one that also doubles as Facturae software for the B2B mandate, so a single system covers both. SMARTeIS, developed by Skill Quotient Technologies, is an AEAT-certified service provider built for exactly this: Verifactu-ready, FacturaE-compliant, and Peppol-based.
Strengths.
- Verifactu-ready and AEAT-certified, handling Verifactu submission, SII real-time reporting, and Crea y Crece B2B invoicing in a single platform, so every transaction type stays compliant.
- Built for Spain's five-corner decentralised CTC model, connecting your ERP directly to AEAT and approved platforms while managing FacturaE, UBL, CII, and EDIFACT formats without manual effort.
- Aligned with Spain's phased Verifactu and Crea y Crece rollout, so both large enterprises and SMEs get a smooth, planned go-live.
- Automatically adapts to AEAT and ministerial order updates, keeping your Verifactu and Crea y Crece compliance accurate with no added effort and no extra cost.
- Deploys as PaaS or SaaS and integrates with leading ERPs including SAP, Sage 200, A3, Microsoft Dynamics, and Odoo, via Peppol and point-to-point EDI, across 150+ supported ERP and POS systems.
- Enterprise-grade foundations: ISO 27001, SOC 2 Type II, ISO 22301, and CMMI Level 3, with real-time validation under 200ms and over 2 billion invoices processed per year.
This is what separates a compliance-grade platform from a basic invoicing tool: one setup that keeps you on the right side of Verifactu today and Crea y Crece tomorrow, with the certifications and scale to back it. For a business choosing Spain e-invoicing compliance software, that combination is the difference between a system that merely issues invoices and one that keeps you compliant as the rules evolve.
The Bottom Line
Verifactu turns your choice of invoicing software into a compliance decision with a price tag. Up to 50,000 euros a year is what non-compliance can cost a business, and the 2027 deadlines are closer than they look once you account for testing, ERP mapping, and staff training. The vendors' obligation is already live, so compliant products exist today. There is no reason to carry the risk. Choose certified software now, confirm the responsible declaration, and take the 50,000 euro exposure off the table for good.
Avoid the Fine. Get Verifactu-Ready.
Stay ahead of 2027 compliance with SMARTeIS - AEAT-certified and ready for Verifactu, SII & Crea y Crece.
Built for Spain and the wider EU. Get Verifactu-Ready!
Frequently Asked Questions
What is Verifactu?
Verifactu is an anti-fraud framework run by Spain's tax agency, the AEAT, introduced under Royal Decree 1007/2023. It sets the technical standards that invoicing software must meet so that every invoice record is secure, traceable, and impossible to alter after the fact. The goal is to stamp out manipulated or deleted invoices. Importantly, it governs how your software creates and stores records, not how invoices are exchanged between businesses, which is a separate mandate.
How much is the Verifactu penalty?
For a business or self-employed professional using non-compliant invoicing software, the fine can reach 50,000 euros per fiscal year. There is a separate, larger penalty of up to 150,000 euros per year aimed at software vendors who develop or sell non-compliant products. So your exposure as an end user is the 50,000 euro figure, and it is tied directly to the software you choose to run.
When does Verifactu become mandatory?
After two postponements, the current deadlines are 1 January 2027 for companies subject to corporate income tax and 1 July 2027 for self-employed workers. The delay was granted to give smaller businesses more time to adopt certified software. Note that even though business use is delayed to 2027, the sale of non-compliant software has already been banned since July 2025.
Is Verifactu the same as B2B e-invoicing?
No, and conflating them is a common mistake. Verifactu is about creating secure, unalterable invoice records and optionally submitting them to the AEAT. The B2B e-invoicing mandate, under the Crea y Crece law, is about exchanging invoices between businesses in a structured electronic format. They are separate obligations with different rules and timelines, and many companies will need to comply with both.
Who is exempt from Verifactu?
Businesses that report through the SII system are exempt, because SII already transmits invoice data to the AEAT in near real time. That covers large companies with turnover above 6 million euros, VAT groups, and businesses in the REDEME regime, plus anyone who has voluntarily opted into SII. If you are not under SII, you should assume Verifactu applies to you.
What is a SIF?
SIF stands for Sistema Informático de Facturación, meaning the invoicing software or system a business uses to issue invoices. Verifactu sets the rules a SIF must satisfy, covering integrity, traceability, unalterability, accessibility, and legibility. In short, when the regulation talks about compliant software, it is talking about a compliant SIF.
What is a "declaración responsable"?
It is a signed declaration from your software vendor confirming that their product meets the AEAT's technical standards for Verifactu. When you adopt a new system, the provider must issue one. It is your first and easiest compliance check: if a vendor cannot supply a responsible declaration, that is a clear signal the software is not certified.
What appears on a Verifactu invoice?
Compliant invoices carry a mandatory QR code on both full and simplified invoices, and in many cases the legend "VERI*FACTU" or a phrase confirming the invoice can be verified on the AEAT's electronic portal. Behind the scenes, the system generates a secure, auditable record for each invoice at the moment it is issued.
Does Verifactu apply to point-of-sale and e-commerce?
Yes. The requirement covers every channel through which you issue invoices, not just your central accounting system. That means your ERP, your point-of-sale terminals, and your e-commerce platform all need to produce compliant records. Mapping these flows early is one of the most important preparation steps.
How do I avoid the 50,000 euro fine?
Run certified invoicing software before your deadline and keep the vendor's responsible declaration on file. Confirm the system guarantees record integrity and traceability, supports the QR code and labelling, and covers all your invoicing channels. Choosing a platform that also handles the upcoming B2B e-invoicing mandate means you solve both obligations at once and avoid a second migration later.
Get Ready for Spanish E-Invoicing
Prepare your business for Spain's evolving e-invoicing landscape. Discover how SMARTeIS helps you comply with Verifactu, TicketBAI, and upcoming EU ViDA requirements with confidence.
Enquire Now!