Skip to main content
KSA ZATCA Phase-2 E-Invoicing for ERPNext — A build-to-order ERPNext application that makes your Sales Invoices ZATCA Fatoora — 1/1Illustrative preview

A build-to-order ERPNext application that makes your Sales Invoices ZATCA Fatoorah Phase-2 compliant

— CSID onboarding, UBL 2.1 XML, cryptographic stamping, clearance/reporting to the Fatoora platform, and a TLV QR code.

ECOSIRE scopes, builds, installs, and supports it for you.

What is KSA ZATCA Phase-2 E-Invoicing for ERPNext?

A build-to-order ERPNext application that makes your Sales Invoices ZATCA Fatoorah Phase-2 compliant — CSID onboarding, UBL 2.1 XML, cryptographic stamping, clearance/reporting to the Fatoora platform, and a TLV QR code. ECOSIRE scopes, builds, installs, and supports it for you. Built to order by ECOSIRE for ERPNext v15, v16 — indicative price from $999.00 USD; request a quote for a scoped proposal.

Key Features

Standard (B2B) tax-invoice clearance: synchronous call to the ZATCA Fatoora clearance API on Sales Invoice `on_submit`, storing the returned cleared XML and clearance UUID
Simplified (B2C) invoice reporting: queued within 24 hours via a `scheduler_events` background job so POS and cashier submission is never blocked by ZATCA latency
UBL 2.1 XML generation mapped from ERPNext Sales Invoice, Sales Invoice Item, and Sales Taxes and Charges, including VAT category codes and exemption reason codes
XAdES-B enveloped digital signing of the invoice XML using your device's ECDSA private key
CSID onboarding flow: ECDSA keypair + CSR generation, compliance CSID request, and production CSID issuance handled from dedicated configuration DocTypes
SHA-256 invoice hash plus PIH (Previous Invoice Hash) chaining so each invoice is cryptographically linked to the last, preserving the ZATCA counter chain
TLV-encoded, base64 cryptographic-stamp QR code embedded in both A4 and 80mm thermal print formats
Dedicated `ZATCA E-Invoice` DocType per Sales Invoice storing generated XML, hashes, clearance/reporting status, UUID, and ZATCA warning/error payloads for audit
`doc_events` hook on Sales Invoice that validates ZATCA-required fields (buyer VAT/ID for B2B, seller registration, address, item tax codes) before submission
Whitelisted Frappe REST methods to re-submit clearance, poll status, and re-run device onboarding for integration and retry tooling
Compliance/simulation vs production environment toggle so you can validate against the ZATCA sandbox before going live
`ZATCA Manager` role profile and DocType-level permissions restricting credential, key, and CSID management to authorized users
Automatic retry with backoff and full request/response logging for every clearance and reporting call, surfaced in the ERPNext desk
Client Script enhancements on the Sales Invoice form to show live ZATCA clearance status, QR preview, and returned errors inline
Built for Frappe/ERPNext v15 and v16 as a clean installable app that survives `bench migrate` and version upgrades

Built to order, done for you

No DIY setup — a working app, built, installed and supported by ECOSIRE.

  1. 1

    You order

    Start with a one-time build price. We scope it with you at kickoff.

  2. 2

    We build & install

    ECOSIRE builds, configures and installs it on your ERPNext.

  3. 3

    Go live + support

    You go live in about one working week, with two weeks of go-live support. Defects in the code we deliver are fixed free of charge.

Technical Specifications

ERPNext Compatibility
—
License
Licence confirmation required
Python Requirement
Python 3.10+
Database
MariaDB 10.6+

About this Product

Saudi businesses in the ZATCA integration phase have a hard problem that ERPNext core does not solve: every standard tax invoice must be cleared with ZATCA in real time before it is valid, and every simplified invoice must be reported within 24 hours — both as signed UBL 2.1 XML carrying a cryptographic stamp and a TLV-encoded QR code. Stock ERPNext prints a Sales Invoice and can compute VAT, but it has no concept of a CSID, no UBL generator, no XAdES signing, no PIH invoice-chaining, and no client that talks to the Fatoora clearance and reporting APIs. Teams that try to bolt this on with print formats and manual portal uploads end up with rejected invoices, broken invoice hash chains, and audit exposure.

ECOSIRE builds a dedicated Frappe app (its own hooks.py, module, and DocTypes) that plugs directly into your existing ERPNext Sales Invoice workflow. We add configuration DocTypes for your ZATCA credentials and CSID/device state, and a per-invoice ZATCA E-Invoice DocType that stores the generated XML, the invoice hash, the previous-invoice hash (PIH), the returned clearance UUID, and the ZATCA warning/error payload. A doc_events hook on Sales Invoice on_submit builds the UBL 2.1 document from your invoice, its items, and tax lines, signs it, and — depending on whether the invoice is standard (B2B) or simplified (B2C) — either calls the clearance endpoint synchronously or queues the invoice for reporting via a scheduler_events background job, so a slow ZATCA response never blocks your cashiers.

Technically, the app implements the full Phase-2 cryptographic chain: ECDSA key generation, CSR creation, compliance CSID and production CSID onboarding against ZATCA's APIs, XAdES-B enveloped signing of the UBL invoice, the SHA-256 invoice hash, the PIH linkage that chains each invoice to the last, and the base64 TLV QR code embedded in your A4 and thermal print formats. Communication uses ERPNext's server-side request layer with retries and full logging; whitelisted methods (exposed over the Frappe REST API) let you re-trigger clearance, fetch status, and re-onboard a device. Role profiles and DocType permissions keep credential and CSID management restricted to a ZATCA Manager role while accounts users simply submit invoices as they always have.

Because this is build-to-order, we start from your real ERPNext data — your company tax registration, invoice volume, B2B vs B2C mix, and existing customizations — and tailor the app to it rather than shipping a one-size-fits-all connector. After a short scoping call we confirm scope, then build, test on a staging clone of your site, run UAT with your finance team against ZATCA's sandbox, and cut over to production with a rollback plan. Typical delivery is one working week from confirmed scope. You receive the full source code and git repository, so you are never locked to us; we hand it over and back it with a post-go-live support window on Frappe/ERPNext v15 and v16.

What you get

  • Installable source code of your version of the ZATCA Phase-2 Frappe app, tailored to your ERPNext site
  • Installation and configuration on your instance: app install, CSID onboarding, credentials, and print-format wiring
  • Technical documentation: DocType reference, hooks/scheduler map, whitelisted API methods, and configuration guide
  • End-user guide plus a live training session for your finance/accounts team on submitting and monitoring e-invoices
  • UAT on a staging clone against the ZATCA sandbox, with a documented production cutover and rollback plan
  • Post-go-live support window for defect fixes, ZATCA response handling, and onboarding questions
  • Full git repository handover so you own and can maintain the code
  • ZATCA compliance test evidence: sample cleared standard and reported simplified invoices with validated XML, stamp, and QR

Who this is for

Finance / Tax Manager at a Saudi company

Accountable for VAT and ZATCA compliance and needs standard invoices cleared and simplified invoices reported correctly, with an audit trail they can defend to ZATCA. Wants confidence over cleverness.

ERPNext Administrator / IT Lead

Runs the company's ERPNext site and needs a clean, upgrade-safe app that installs via bench, survives `bench migrate`, and doesn't fork core. Cares about the source code, permissions, and logs.

Retail / POS Operator required to comply with Phase-2

High-volume B2C business that cannot let a slow ZATCA response stall the checkout, so needs simplified-invoice reporting queued in the background with a compliant QR on the thermal receipt.

Group Finance Controller (multi-branch / multi-company)

Operates several ERPNext companies or branches, each with its own ZATCA device and CSID, and needs per-company onboarding, credential isolation, and consistent clearance behavior across all of them.

How KSA ZATCA Phase-2 E-Invoicing for ERPNext Compares

CriterionECOSIRECustom BuildCompetitorERPNext Native
ZATCA Phase-2 clearance & reportingFull clearance (B2B) + queued reporting (B2C) built into Sales Invoice submitPossible but you build the whole API client, retries, and chaining yourselfOften partial — reporting only or a generic connector needing reworkNone — ERPNext core has no ZATCA integration
UBL 2.1 XML + XAdES signingGenerated and XAdES-B signed from your invoice, item, and tax dataHand-built XML mapping and signing — error-prone and time-consumingGeneric UBL that may not map your VAT categories or exemptionsPrints a PDF only; no UBL, no signing
CSID onboarding & key managementCSR, compliance + production CSID, restricted to a ZATCA Manager roleYou implement ECDSA, CSR, and onboarding flows from scratchSometimes manual or under-documented onboarding stepsNo concept of CSID or device onboarding
PIH invoice-hash chainingSHA-256 hash + PIH linkage preserving the ZATCA counter chainMust be designed carefully or the chain breaks silentlyVaries; chain integrity not always guaranteedNot present
QR code on print formatsTLV base64 cryptographic-stamp QR on A4 and 80mm thermal formatsExtra work per print formatUsually A4 only; thermal/POS often missingNo compliant QR
Fit to your ERPNext siteBuilt from your real data, volumes, and customizationsFully custom but no reuse, longer timelineOne-size-fits-all; adapts poorly to customizationsN/A
Ownership & lock-inFull source + git repo handover; any Frappe dev can maintainYou own it but carry all the build risk and timeOften closed-source or license-gated per siteN/A
Support & spec-change updatesPost-go-live window + optional retainer for ZATCA spec revisionsYou own all future ZATCA changes yourselfDepends on vendor SLA and renewal feesNone

Frequently Asked Questions about KSA ZATCA Phase-2 E-Invoicing

Is this an existing app I can download and install today?

No. This is a build-to-order engagement. ECOSIRE builds a ZATCA Phase-2 Frappe app tailored to your ERPNext site, invoice types, and existing customizations, then installs and supports it. There is no instant download — we start with a scoping call, confirm scope, and build from your real data.

How long does delivery take?

Typical delivery is one working week from confirmed scope. After the scoping call we agree on requirements, build the app, test on a staging clone against the ZATCA sandbox, run UAT with your team, then cut over to production. Complex multi-company or heavily customized sites can extend that; we tell you honestly during scoping.

Does it handle both standard (B2B) and simplified (B2C) invoices?

Yes. Standard tax invoices are cleared synchronously with ZATCA before they are valid, and simplified invoices are reported within the 24-hour window via a background scheduler job so your POS and cashier flows are never blocked. Both produce signed UBL 2.1 XML with the cryptographic stamp and TLV QR code.

What about CSID onboarding and cryptographic signing?

The app handles the full Phase-2 chain: ECDSA keypair and CSR generation, compliance CSID and production CSID onboarding against ZATCA's APIs, XAdES-B signing, the SHA-256 invoice hash, and PIH chaining that links each invoice to the previous one. Key and CSID management is restricted to a dedicated `ZATCA Manager` role.

Which versions of ERPNext does it support, and how are updates handled?

It is built for Frappe/ERPNext v15 and v16 as a clean installable app that survives `bench migrate`. Your post-go-live support window covers defect fixes and ZATCA response handling. Because ZATCA periodically revises its specification, spec-change updates beyond the support window are handled under a support/maintenance retainer, and you own the git repository either way.

Will we own the code, or are we locked in to ECOSIRE?

You own it. We hand over the full source code and git repository. The app is a standard Frappe application with documented DocTypes, hooks, and whitelisted methods, so your own team or any Frappe developer can maintain it. We are the easiest option to support it, not the only one.

Does it change how our accounts team works day to day?

Minimally. Users keep submitting Sales Invoices in ERPNext as they always have; a `doc_events` hook validates ZATCA-required fields and triggers clearance or reporting automatically. Clearance status, the QR, and any ZATCA errors appear inline on the Sales Invoice via a Client Script, and a per-invoice `ZATCA E-Invoice` record stores the full audit detail.

Request a quote

KSA ZATCA Phase-2 E-Invoicing

A build-to-order ERPNext application that makes your Sales Invoices ZATCA Fatoorah Phase-2 compliant — CSID onboarding, UBL 2.1 XML, cryptographic stamping, clearance/reporting to the Fatoora platform, and a TLV QR code. ECOSIRE scopes, builds, installs, and supports it for you.

  • Standard (B2B) tax-invoice clearance: synchronous call to the ZATCA Fatoora clearance API on Sales Invoice `on_submit`, storing the returned cleared XML and clearance UUID
  • Simplified (B2C) invoice reporting: queued within 24 hours via a `scheduler_events` background job so POS and cashier submission is never blocked by ZATCA latency
  • UBL 2.1 XML generation mapped from ERPNext Sales Invoice, Sales Invoice Item, and Sales Taxes and Charges, including VAT category codes and exemption reason codes
  • XAdES-B enveloped digital signing of the invoice XML using your device's ECDSA private key

Request a Quotation

Tell us about your KSA ZATCA Phase-2 E-Invoicing requirements and we'll send pricing, licensing options and a tailored proposal — usually within one business day.

No payment now. This sends a quote request to our team — we'll follow up by email with pricing and next steps.