ZATCA Phase 2 ERP Integration Cost in Saudi Arabia (2026)
Published 26 September 2026 · 9 min read
What ZATCA Phase 2 e-invoicing integration costs in Saudi Arabia in 2026: wave deadlines, four routes, SAR budget ranges, timeline and checklist.
The short answer
For most mid-sized companies in Saudi Arabia, connecting an existing ERP to ZATCA's Fatoora platform for Phase 2 (the Integration Phase) is a four-to-ten week project. Budget roughly SAR 25,000–70,000 for a supported ERP with a ready-made connector, SAR 70,000–200,000 for a custom or heavily modified system, plus SAR 6,000–40,000 a year in ongoing licence, hosting and support costs. The single largest cost driver is not the API work itself — it is the state of your invoice master data and the number of billing systems you run.
Stratgik is a technology firm, not a law firm or a tax advisory practice. The figures below are planning ranges we use when scoping work, not quotations, and nothing here is legal or tax advice. Confirm your obligations with ZATCA or a qualified Saudi tax adviser.
What Phase 2 actually requires
Phase 1 (Generation), which began on 4 December 2021, only required you to stop issuing handwritten or free-form invoices and to generate them electronically. Phase 2 is a different order of work: your billing system has to talk to ZATCA directly.
According to ZATCA's Detailed E-Invoicing Guideline, Phase 2 splits invoices into two flows:
- Standard tax invoices (B2B and B2G) must be submitted in XML to the Fatoora platform for clearance through the API. ZATCA clears the invoice, applies its cryptographic stamp and QR code, and returns it. Clearance is a prerequisite for sharing the invoice with the buyer.
- Simplified tax invoices (B2C) are stamped locally by your solution and reported to the platform within 24 hours of issuance.
Underneath that sit the technical requirements that generate most of the engineering effort: invoices in UBL-based XML (or PDF/A-3 with embedded XML), a 128-bit UUID stored inside the XML, a cryptographic stamp, a hash that chains each invoice to the previous one, a compliant QR code, and onboarding through the Fatoora portal to obtain a Cryptographic Stamp Identifier (CSID) using an OTP issued against your ERAD credentials.
The hash chain deserves special attention. Because each invoice references the hash of the one before it, your integration cannot simply retry blindly on failure or process invoices out of order. Getting sequencing, idempotency and failure recovery right is where in-house teams most often lose time.
Which wave are you in?
ZATCA rolls Phase 2 out in waves, notifying taxpayers at least six months before their integration date. Each wave lowers the VAT-taxable revenue threshold, so the programme now reaches very small businesses.
| Wave | VAT-taxable revenue threshold | Reference years | Integration deadline |
|---|---|---|---|
| Wave 23 | Above SAR 750,000 | 2022, 2023 or 2024 | 1 January – 31 March 2026 |
| Wave 24 | Above SAR 375,000 | 2022, 2023 or 2024 | By 30 June 2026 |
| Wave 25 | Above SAR 187,500 | 2022, 2023, 2024 or 2025 | By 1 February 2027 |
Wave 24 and Wave 25 criteria are published on ZATCA's own newsroom (Wave 24, Wave 25); EY's tax alert covers Wave 23. Later waves had not been announced at the time of writing, and the criteria for them are still pending — if your revenue is below SAR 187,500 you should plan on the assumption that a wave will eventually reach you rather than assume you are permanently out of scope.
Four routes to compliance, and what each costs
There is no single price for ZATCA Phase 2 because there is no single technical approach. Four routes cover almost every situation we see.
| Route | Typical fit | Indicative one-off cost (SAR) | Typical elapsed time |
|---|---|---|---|
| Replace billing with a ZATCA-ready SaaS product | Single entity, simple invoicing, no deep ERP | 0–20,000 (setup and data migration) | 1–3 weeks |
| Vendor module for a mainstream ERP (SAP, Oracle, Dynamics, Odoo, ERPNext) | Standard ERP with limited customisation | 25,000–70,000 | 4–8 weeks |
| Middleware layer between your systems and Fatoora | Several billing systems, or an ERP you cannot safely modify | 60,000–150,000 | 6–12 weeks |
| Custom integration built into a bespoke or legacy system | In-house billing, heavy customisation, unusual invoice logic | 90,000–220,000 | 8–16 weeks |
These are planning ranges for a single legal entity in one currency. They assume a competent finance team is available for testing and that you are not also re-engineering your pricing or tax logic at the same time. Treat them as a starting point for budget conversations, not a quote. If you want to pressure-test the choice between a vendor module and building your own layer, our build vs buy tool walks through the same trade-offs we use in client workshops.
What actually drives the cost up
Teams routinely underestimate Phase 2 because they price the API call and forget everything around it. In our scoping work, five factors move the number more than anything else.
1. Number of invoice-issuing systems. An ERP plus a separate point-of-sale plus a booking platform is three integrations, three onboarding flows and three CSIDs — not one project with a bigger scope.
2. Master data quality. Phase 2 XML is strict. Missing buyer VAT numbers, free-text addresses that do not map to the required fields, inconsistent unit codes and item descriptions in mixed Arabic and English all surface as clearance rejections. Cleaning customer and item master data is often a third of the total effort and is almost never in the original estimate.
3. Unusual invoice types. Credit and debit notes, advance payments, export invoices with zero-rated lines, self-billing and summary invoices each need their own mapping and their own test cases.
4. Arabic and bilingual output. The regulation requires Arabic on the invoice. If your ERP has only ever produced English documents, adding correct Arabic rendering to templates is real work, particularly for PDF output with right-to-left layout.
5. Availability and fallback design. Clearance sits in the critical path of issuing a B2B invoice. You need a queue, a retry policy that respects the hash chain, an alerting path when Fatoora is unreachable, and a documented manual procedure. Companies that skip this discover the gap during their first outage. This is the same operational discipline we cover under managed technology.
A realistic timeline
| Stage | What happens | Typical duration |
|---|---|---|
| Assessment | Confirm wave and deadline, inventory invoice-issuing systems, sample real invoices against the XML specification | 3–5 days |
| Data remediation | Fix customer, item and tax master data; resolve missing VAT numbers and address fields | 1–3 weeks |
| Build | XML generation, UUID, hashing and chaining, cryptographic stamping, QR code, clearance and reporting calls | 2–5 weeks |
| Sandbox and compliance testing | Validate against ZATCA's developer sandbox and simulation environment across every invoice type you issue | 1–2 weeks |
| Onboarding and go-live | Generate OTP in the Fatoora portal, obtain production CSID, run parallel for a short period, cut over | 3–5 days |
The sequencing matters more than the totals. Start onboarding before your data is clean and you will spend the testing window debugging rejections that a data fix would have prevented.
Running costs after go-live
Phase 2 is not a one-off project. Recurring costs typically include a solution or middleware licence (commonly SAR 3,000–30,000 a year depending on invoice volume and number of devices or units), hosting for any middleware you operate, certificate renewal and CSID lifecycle management, and engineering time for ZATCA specification updates. Budget a small maintenance allowance each year rather than assuming zero — the specification has been revised repeatedly since 2021 and will be revised again.
There is also an archiving obligation to plan for. E-invoices and their notes must be retained, and Saudi VAT record-keeping rules generally require six years. Storage is cheap; the design decision of where cleared XML lives, and how you retrieve a specific invoice during an audit, is not something to leave to the last week of the project.
Penalties for getting it wrong
ZATCA has published its schedule of e-invoicing violations and fines. Per ZATCA's announcement, failing to issue electronic invoices begins at a fine of SAR 5,000, and deleting or amending electronic invoices after issuance begins at SAR 10,000. Some violations — such as omitting the QR code or the VAT registration number, or failing to report a system malfunction — start with a warning rather than an immediate fine. ZATCA has stated that fines are applied according to the type of violation and the number of repetitions.
The commercial risk is usually larger than the fine. If your clearance integration fails, you cannot lawfully issue B2B tax invoices, which means you cannot bill. For a business invoicing daily, a week of downtime costs far more than any penalty.
Implementation checklist
- Confirm which wave you fall into and the exact deadline, based on VAT-taxable revenue in the relevant reference years.
- List every system in your organisation that issues an invoice or a credit note — including point-of-sale and any departmental spreadsheets.
- Export 50 real invoices covering every type you issue and check each required field exists in your data today.
- Decide the route: SaaS replacement, ERP vendor module, middleware, or custom build.
- Fix master data before you begin build, not during testing.
- Implement hashing and chaining with explicit ordering and idempotency; never allow parallel workers to claim the same sequence.
- Test every invoice type in ZATCA's sandbox and simulation environment, including rejection handling.
- Design and document a fallback procedure for Fatoora unavailability, and rehearse it.
- Complete Fatoora portal onboarding and store the production CSID and private key securely, with a documented renewal owner.
- Define your archive: where cleared XML is stored, for how long, and how a single invoice is retrieved for audit.
- Assign a named internal owner for specification changes after go-live.
How this connects to your wider compliance work
ZATCA Phase 2 is a tax obligation, but the systems it touches — customer records, billing data, archived documents — are the same systems governed by Saudi Arabia's Personal Data Protection Law. If you are building or modifying an invoicing integration this year, it is a natural moment to check that the underlying data handling also stands up under the Saudi PDPL. Doing both at once is materially cheaper than doing them a year apart.
Frequently asked questions
Do I need a ZATCA-approved e-invoicing provider?
You need a solution that meets ZATCA's published technical requirements and that you have validated through the developer sandbox and simulation environment. Many businesses choose a provider that has already been through compliance testing because it shortens the project, but the obligation to comply sits with the taxpayer, not the vendor. Verify current requirements directly with ZATCA.
Can we build the ZATCA integration ourselves?
Yes, and for companies with a bespoke billing system it is often the sensible route. The work is well-documented: XML generation against the published specification, UUID, hashing and chaining, XAdES-style cryptographic stamping, QR encoding, and the clearance and reporting APIs. Expect the effort to sit in the tens of developer-days rather than a few days, and budget separately for data remediation and testing.
What happens if Fatoora is unavailable when we issue an invoice?
Standard tax invoices require clearance before being shared with the buyer, so your system needs a queue and a retry path rather than a silent failure. Simplified invoices are reported within 24 hours, which gives more headroom. Build the fallback procedure deliberately and document it — ZATCA's rules also treat failure to report a system malfunction as a violation.
Does Phase 2 mean our data must be hosted inside Saudi Arabia?
Phase 2 itself is about integrating with the Fatoora platform, not about where your servers sit. Hosting and data residency questions are governed separately, principally by the Personal Data Protection Law and its transfer rules, and by sector-specific regulation. If you are choosing cloud infrastructure at the same time, treat residency as its own decision with its own advice.
How much should a small business with one ERP budget?
A single-entity business on a mainstream ERP with reasonably clean data and a vendor connector usually lands in the SAR 25,000–70,000 range for the one-off work, with a modest annual licence afterwards. The number rises quickly with additional billing systems, custom invoice logic or poor master data. An honest one-week assessment before you commit a budget is almost always worth its cost.
We already did Phase 1. How much of that work carries over?
Less than most teams expect. Phase 1 established electronic generation and the basic QR requirement. Phase 2 adds the XML specification, cryptographic stamping, hash chaining, onboarding and the live connection to ZATCA. Treat it as a new project that benefits from clean Phase 1 data, not as an upgrade.
If you are working towards a Wave 24 or Wave 25 deadline and are not yet sure which route fits your systems, a short structured assessment is usually the cheapest first step: our technology decision sprint is built for exactly this kind of scoped, deadline-driven decision, and you can see how we work with organisations across the Kingdom on our Saudi Arabia page. Published by the Stratgik team.
Keep reading
More from Stratgik

27 Sep 2026
DPDP Consent Manager Registration in India: 2026 Rules
Consent Manager registration under India's DPDP Rules 2025: the Rs 2 crore net worth bar, First Schedule conditions and...

25 Sep 2026
AI Voice Agents in the UAE: TDRA Rules, Arabic and Cost (2026)
What UAE law allows, why local numbers limit outbound calls, how Gulf Arabic performs, and realistic per-minute and buil...

24 Sep 2026
Singapore PDPA Cross-Border Data Transfer Rules (2026)
How section 26 PDPA and the 2021 Regulations govern sending personal data out of Singapore: contracts, BCRs, CBPR certif...

