A practical readiness guide for Saudi businesses moving from invoice generation to integrated, continuous compliance.
Electronic invoicing in Saudi Arabia has moved far beyond replacing paper invoices with digital files. Under the Integration Phase of ZATCA’s Fatoora program, an invoice is no longer simply generated inside a business system. It must be created in the required structured format, exchanged with ZATCA through an integrated solution, and processed according to rules that differ by invoice type.
For organizations running SAP, this makes e-invoicing a connected business process involving tax configuration, customer and company master data, billing, technical integration, security, monitoring, and operational ownership.
ZATCA’s latest Wave 25 announcement reinforces the need for businesses in the affected group to begin their readiness activities early. ZATCA’s Twenty-Fifth Wave includes taxpayers whose revenues subject to VAT exceeded SAR 187,500 during 2022, 2023, 2024, or 2025. ZATCA stated that affected taxpayers will be notified and must integrate their e-invoicing solutions with Fatoora by February 1, 2027.
| The deadline is the end of the journey, not the beginning. SAP assessment, remediation, onboarding, integration, and end-to-end testing should start well before the mandatory date. |
From generation to integration
Saudi Arabia introduced e-invoicing in two phases. Phase 1, the Generation Phase, has required taxpayers since December 4, 2021 to generate and store compliant electronic invoices and associated notes through an electronic solution.
Phase 2, the Integration Phase, has been enforced in waves since January 1, 2023. It introduces additional technical and business requirements and connects taxpayers’ invoicing solutions directly with ZATCA systems. ZATCA notifies taxpayers of their applicable wave at least six months in advance.
In practical terms, Phase 2 adds requirements such as:
- Integration of the e-invoicing solution with ZATCA’s Fatoora platform.
- Generation of invoices and related notes in the required structured electronic format.
- Additional mandatory invoice data and business rules.
- Security and identification controls for registered e-invoicing solution units.
- Different submission flows for standard tax invoices and simplified tax invoices.
- Reliable handling of responses, rejections, failures, and invoice status tracking.
A standalone PDF generated from an invoice is not sufficient to meet the Phase 2 electronic invoicing requirements. Compliance depends on the required structured data, invoice format, security controls, integration or reporting process, and supporting audit trail, not simply on the human-readable document.
What Phase 2 means for an SAP environment
SAP can support Saudi electronic customer invoicing through localized processes and electronic document capabilities. Depending on the SAP product, release, architecture, and integration model, organizations may use tools such as the Manage Electronic Documents app or eDocument Cockpit to create, monitor, and submit electronic documents. The exact technical architecture should therefore be determined from the customer’s SAP product, release, localization scope, existing middleware, and selected integration approach.
However, having an SAP system does not automatically mean the business is ready. Each organization must verify that its specific environment, configuration, integrations, custom developments, and invoice scenarios meet the applicable ZATCA requirements.
1. Master data must be complete and consistent
Electronic invoices rely on structured data. Missing, outdated, or inconsistent information can prevent an invoice from being generated correctly or accepted downstream. Readiness reviews should cover company and branch information, VAT registration details, buyer identification, addresses, tax categories, units of measure, payment data, and other fields used by the relevant invoice scenarios.
This is often where a technical compliance project becomes a data-quality project. If data ownership is unclear, the same errors will continue to appear even after the integration is live.
2. Tax and billing configuration must reflect real transactions
Businesses rarely issue only one type of invoice. Standard tax invoices, simplified tax invoices, credit notes, debit notes, exports, zero-rated supplies, exemptions, discounts, advances, and industry-specific scenarios can follow different rules.
The SAP design should therefore be validated against actual business cases, not only a single successful test invoice. Tax codes, document types, pricing conditions, rounding, references to preceding documents, and source-to-billing flows all need to produce the expected electronic document data.
3. Standard and simplified tax invoices follow different flows
A key design consideration is the difference between standard tax invoices, commonly used for business-to-business transactions, and simplified tax invoices, commonly used for business-to-consumer transactions.
The core difference is the operational model: standard tax invoices follow the clearance model, where the invoice is transmitted to ZATCA for validation before it is issued to the customer, while simplified tax invoices follow the reporting model, where the invoice is issued and then reported to ZATCA within 24 hours. In SAP, this distinction must be reflected correctly in the e-invoicing configuration, document flow, integration architecture, and response handling.
Under Phase 2, the applicable processing model differs where in standard tax invoices follow the clearance model, while simplified tax invoices follow the reporting model. The SAP solution must correctly identify the invoice type and route it through the applicable workflow, including the required response handling and timing. Misclassification can create compliance risk even when the invoice looks correct to the end user.
4. Security and onboarding cannot be left until the end
Integration requires the relevant e-invoicing generation solution units to be identified and onboarded. SAP documentation for Saudi Arabia includes processes for generating an E-Invoicing Generation Solution Unit ID and requesting a Cryptographic Stamp Identifier from ZATCA.
These steps should be planned alongside system configuration and testing. Certificate management, authorization, endpoint controls, renewal responsibilities, and production access should have named owners before go-live.
5. Monitoring is part of compliance
A successful API connection is not the same as a controlled operating model. Businesses need visibility into which invoices were submitted, accepted, cleared, reported, warned, rejected, or left pending.
Teams should define how errors are detected, who investigates them, how corrections are made, how the original transaction is preserved, and how unresolved exceptions are escalated. Without this, integration failures can become finance, customer service, and audit issues.
Common readiness gaps
The most difficult issues usually sit between systems, teams, and process ownership. Common gaps include:
- Incomplete customer, branch, address, or tax master data.
- Custom billing processes that do not map cleanly to required invoice fields.
- Tax codes or pricing conditions that create inconsistent totals.
- Invoice scenarios that were excluded from initial testing.
- Incorrect classification of standard and simplified tax invoices.
- Unclear ownership of certificates, credentials, and registered solution units.
- Weak monitoring of ZATCA responses and unresolved document errors.
- No tested continuity procedure for connectivity or system failures.
- Insufficient reconciliation between SAP accounting documents, billing documents, and submitted e-invoices.
- Insufficient user training on exception handling, rejection management, and escalation procedures during Testing and UAT phase.
A practical SAP readiness roadmap

A structured approach reduces last-minute remediation and helps the business test compliance across the full invoice lifecycle.
- Confirm scope and timeline. Verify whether the organization has received a formal ZATCA notification, identify the mandatory integration date, and map the legal entities, VAT registrations, branches, systems, and invoice channels in scope.
- Assess the current SAP landscape. Document the SAP product and release, localization content, billing sources, electronic document capabilities, middleware, custom code, third-party platforms, and current invoice output process.
- Build a complete scenario inventory. List real transaction types across B2B and B2C invoicing, credit and debit notes, advance payments, exports, adjustments, cancellations, and relevant special cases. Prioritize by volume, value, and compliance risk.
- Review data and configuration. Validate mandatory master data, VAT configuration, document mapping, numbering, calculations, references, and output fields. Assign owners to correct data at source.
- Design and validate the integration and security model. Define how SAP will exchange documents with Fatoora, how solution units will be onboarded, how security credentials will be managed, and how environments will be separated.
- Test end to end. Test successful and unsuccessful cases across both clearance and reporting flows, including validation errors, warnings, rejected documents, connectivity failures, retries, duplicate submissions, corrections, and reconciliation.
- Prepare operations and support. Create monitoring views, error categories, response procedures, escalation paths, support ownership, user guidance, and business-continuity steps.
- Stabilize after go-live. Monitor document status closely, reconcile submitted invoices with SAP records, analyze recurring failures, and update controls as business processes or ZATCA requirements evolve.
SAP DRC Integration Architecture with ZATCA Portal
SAP Document and Reporting Compliance (DRC) provides SAP customers with capabilities to generate, manage, monitor, and submit electronic documents and statutory reports, including Saudi Arabia-specific e-invoicing processes. The exact architecture depends on the SAP product, release, deployment model, integration services, and customer’s existing landscape.
A key architectural consideration for SAP in the context of ZATCA Phase 2 is that having SAP DRC does not by itself guarantee ZATCA compliance. Compliance depends on the complete solution architecture, configuration, transaction flows, integration, security controls, monitoring and operational processes.
The architecture should be designed to:
- Enforce the required legal sequence of events for tax invoices.
- Manage the complete lifecycle of digital certificates and API integrations.
- Handle communication failures and ZATCA responses, including warnings and rejections, through robust and auditable processes.
- Operate as a controlled integration and monitoring process rather than simply as a document-generation mechanism.
Questions business and IT leaders should ask
- Have we received a formal ZATCA wave notification, and who owns the response?
- Which legal entities, branches, SAP systems, and invoice channels are included?
- Can we trace every electronic invoice back to its source transaction and accounting document?
- Have we tested all material invoice and note scenarios, including failures?
- Who monitors rejected, warned, or delayed documents each day?
- How are credentials and Cryptographic Stamp Identifiers governed and renewed?
- What happens if SAP, middleware, or the external connection becomes unavailable?
- Are finance, tax, IT, customer service, and support teams working from one operating model?
Compliance is continuous, not a one-time interface
The value of a well-designed e-invoicing program extends beyond meeting a deadline. Better master data, standardized billing processes, clearer exception ownership, stronger reconciliation, and improved transaction visibility can reduce manual work and strengthen financial control.
The opposite is also true. A rushed implementation may technically connect to Fatoora while leaving the business with recurring rejections, manual workarounds, unclear ownership, and poor visibility into compliance status.
The goal should therefore be sustainable compliance: an SAP-enabled process that remains accurate, monitored, secure, and adaptable as regulations and business operations evolve.
How Altivate can support your readiness journey
Altivate helps organizations connect regulatory requirements with the realities of their SAP landscape. Support can include readiness assessment, process and scenario mapping, SAP configuration review, master-data validation, integration design, onboarding support, end-to-end testing, error monitoring, user enablement, and post-go-live stabilization.
Whether your organization is approaching its mandatory integration date or reviewing an existing implementation, the right starting point is a clear view of the gaps across process, data, technology, security, and ownership.
| Is your SAP environment ready for ZATCA Phase 2?
Altivate can help you assess your SAP landscape, identify process and integration gaps, validate invoice scenarios, and establish a practical roadmap toward ZATCA Phase 2 readiness. Contact Altivate to start your SAP and ZATCA readiness assessment. |

