If your company issues invoices from an in-house program, a customised ERP or an invoicing module built into its management system, that program has a deadline: 1 January 2027 if you pay Spanish corporate income tax (Impuesto sobre Sociedades), 1 July 2027 if you are self-employed, an entity under the income attribution regime (a pass-through entity) or a non-resident with a permanent establishment. From that day on, the computerised invoicing system must comply with the Regulation approved by Royal Decree 1007/2023 (Real Decreto 1007/2023), known as Verifactu, and its producer must have signed a self-declaration (declaración responsable). This guide explains, as at 16 September 2026, who is bound, exactly what the software has to do, how Verifactu mode differs from non-Verifactu mode, what happens with a custom development that the company itself has commissioned, and what penalties there are for the manufacturer and for the user.

What is Verifactu and where do the dates come from?

Law 11/2021 on measures to prevent and combat tax fraud (Ley 11/2021) added, in Article 29.2.j) of Spain’s General Tax Law (Ley General Tributaria, LGT), the obligation for the computer systems that support invoicing processes to guarantee the integrity, preservation, accessibility, legibility, traceability and inalterability of the records, and created the infringement in Article 201 bis for anyone who manufactures, markets or holds programs that do not comply. Royal Decree 1007/2023 of 5 December approved the technical regulation, and Order HAC/1177/2024 of 17 October (Orden HAC/1177/2024) specified the formats, the hash, the signature, the QR code and the service for submitting records to the Spanish Tax Agency (Agencia Tributaria).

The timetable changed twice. Royal Decree 254/2025 (Real Decreto 254/2025) moved the dates for users to 2026, and Royal Decree-Law 15/2025 of 2 December (Real Decreto-ley 15/2025), published in the BOE (Boletín Oficial del Estado, the official state gazette) on 3 December 2025, set the final ones: 1 January 2027 for corporate income tax payers and 1 July 2027 for everyone else who is bound. As at 16 September 2026, no further postponement has been published.

Who it binds and who it does not

It binds every business or professional that uses a computerised invoicing system and is taxed in the common tax territory (all of Spain except the Basque Country and Navarre), with these main exceptions:

  • Those covered by the VAT Immediate Supply of Information (Suministro Inmediato de Información, SII) system, who already send their invoicing records to the Tax Agency by another route.
  • The foral territories, which have their own tax regimes and their own systems: TicketBAI in the Basque Country (and Batuz in Bizkaia) and Navarre’s system.
  • Certain transactions and schemes that the regulation itself excludes, such as invoices documented under the special scheme for agriculture or certain transactions with no obligation to invoice.

It makes no difference whether the program is a commercial product, a sector-specific ERP or a custom development commissioned by the company itself: if it issues invoices, it is a computerised invoicing system and it has to comply. What changes is who signs the self-declaration, as we shall see.

What the software has to do: the requirements of RD 1007/2023

The regulation does not govern the invoice, which is still governed by Royal Decree 1619/2012 (Real Decreto 1619/2012); it governs the system that produces it. These are the requirements the software has to build in:

  1. A registration record (registro de facturación de alta) for every invoice issued, with a defined minimum content: the issuer’s tax identification number (NIF) and name, invoice number and series, date, invoice type, description, amounts, VAT breakdown and the technical data of the record.
  2. A cancellation record (registro de facturación de anulación) when an invoice issued in error is cancelled, without deleting or overwriting the original record.
  3. A fingerprint or hash of each record, calculated with the algorithm set by Order HAC/1177/2024 and including the hash of the previous record: this is the chaining that makes any later alteration, insertion or deletion detectable.
  4. An electronic signature on the records in non-Verifactu mode; in Verifactu mode, immediate submission to the Tax Agency takes the place of the signature.
  5. An event log: the system must automatically record the relevant events (start-up, shutdown, export, incidents, changes of mode) and keep them with the same safeguards.
  6. A QR code on every invoice, containing the Tax Agency’s verification URL and the data that allow the recipient to verify it, and the wording “VERI*FACTU” when the system submits the records.
  7. Retention of the records and the events throughout the limitation periods, with readable access and the ability to export them to the defined formats whenever the Tax Agency or the user asks.
  8. Inalterability: nothing that has been recorded can be modified afterwards; corrections are new records.
  9. Separation by taxpayer: if the same system invoices on behalf of several companies, it must handle each one independently.

In addition, the system must be designed so that it can operate in Verifactu mode, even if the user chooses the other one, and its technical specifications must be documented.

Verifactu or non-Verifactu mode: which to choose

The regulation allows two ways of operating:

  • Verifiable invoice issuing system (Verifactu): the software submits each invoicing record to the Tax Agency immediately and automatically, through the web service defined in the Order. In return, it does not have to sign the records, the Tax Agency presumes that it meets the requirements, and the invoices carry the wording that allows the customer to check them. It is the option the Tax Agency recommends and the one that leaves the least technical burden on the company’s side.
  • Non-Verifactu system: the software keeps the records electronically signed, together with their event log, and hands them over only when the Tax Agency requires it. This means managing signing certificates, safeguarding the records and being in a position to export them at any time. It makes sense when connectivity is unreliable or when the company does not want continuous submission, but it does not reduce the requirements.

In practice, a custom ERP that is already connected to the Tax Agency for other procedures usually opts for Verifactu mode: the development is one more integration module and it avoids the signing infrastructure.

The self-declaration: who signs it for a custom development

Article 13 of the regulation requires the producer of the system (whoever manufactures or develops it) to issue a self-declaration for each system and version, certifying that it meets the requirements and identifying the product, the version, its components and the date. That declaration is given to the user and must be available to the Tax Agency.

For a commercial program, the manufacturer signs it. For a custom development there are three cases:

  • A software company develops it for you: that company is the producer, and it is the one that signs the self-declaration and is answerable as manufacturer. It must do so in writing and update the declaration with every version that touches invoicing.
  • Your own team has developed it: your company is both producer and user, and signs the self-declaration for its own system. That means documenting the technical specifications, the testing and compliance with each requirement.
  • A commercial ERP with customisations: the manufacturer declares the core, but if the customisation alters how invoices or records are generated, whoever made it has to declare that part. This is where grey areas most often arise.

When you commission a development, ask for the self-declaration to be written into the contract as a deliverable, with an obligation to renew it with every version.

Penalties: for the manufacturer and for the user

Article 201 bis of the General Tax Law defines two infringements:

  • Manufacturing, producing or marketing systems that do not meet the requirements, or that make it possible to keep separate sets of accounts, leave transactions unrecorded, alter records or fail to comply with the required certification: €150,000 for each financial year in which sales have been made and for each different type of system; €1,000 per system marketed if the only infringement is failing to certify it when certification was required.
  • Holding systems that do not meet the requirements, or that are not certified when they should be, or holding them with the certification altered: €50,000 for each financial year for the user.

These penalties are separate from any that may arise from incorrectly issued invoices or from tax left unpaid. And the most immediate practical risk is not the fine, but a customer rejecting invoices that have no QR code or no Verifactu wording from 2027 onwards.

An adaptation plan for a company with its own software

  1. Inventory: which programs issue invoices today, who developed them, whether they are under maintenance and whether they fall inside or outside the SII.
  2. Gap analysis against the nine requirements above and the formats in Order HAC/1177/2024.
  3. Choice of mode: Verifactu or non-Verifactu, with what each implies for connectivity, signing and safekeeping.
  4. Development: registration and cancellation records, hash and chaining, event log, QR code, export, and the submission service if Verifactu is chosen.
  5. Testing in the test environment provided by the Tax Agency, with cases covering cancellation, correction and multiple series.
  6. The producer’s self-declaration, delivered and filed.
  7. Training for the administration team: what changes when cancelling, correcting and printing an invoice.
  8. Go-live before 1 January 2027, leaving a margin for the 2026 year-end close.

If the system also has to issue structured electronic invoices to other companies, it is worth planning this together with the B2B e-invoicing obligation in Royal Decree 238/2026 (Real Decreto 238/2026), which we explain in mandatory B2B e-invoicing: the 2027–2028 timeline: they are different obligations, with different systems, that are best dealt with in the same project.

How CEDESA does it

CEDESA develops and maintains custom management software for industrial and agri-food companies, including ERP systems with built-in invoicing such as those we describe in ERP software for the meat industry and abattoirs. In every system that issues invoices we build in the requirements of RD 1007/2023, sign the self-declaration as producer and renew it with every version. We work under ISO 27001, ISO 9001 and ISO 56001, which means that the development cycle, testing and change management are documented – something the self-declaration itself requires the producer to demonstrate.

Frequently asked questions about Verifactu and custom software

When does Verifactu become mandatory?

From 1 January 2027 for corporate income tax payers and from 1 July 2027 for everyone else who is bound (self-employed people paying personal income tax, or IRPF; entities under the income attribution regime; and non-residents with a permanent establishment), under Royal Decree-Law 15/2025, published in the BOE on 3 December 2025. As at 16 September 2026, no further postponement has been published.

Does a custom ERP have to comply with Verifactu?

Yes. The Regulation approved by RD 1007/2023 applies to any computer system that supports invoicing processes, whether commercial or custom-built. Whoever developed it is the producer and must sign the self-declaration; if the company developed it itself, the company signs.

What is the difference between Verifactu and non-Verifactu?

In Verifactu mode the system submits each invoicing record to the Tax Agency immediately and does not need to sign them. In non-Verifactu mode the system signs the records electronically, keeps them together with their event log and hands them over when the Tax Agency requires them. The other requirements are the same.

What is the Verifactu self-declaration?

The document in which the producer of the system certifies, for each product and version, that it meets the requirements of the regulation, identifying the system, its components and the date. It is required by Article 13 of RD 1007/2023, is given to the user and must be available to the Tax Agency.

What is the penalty for using an invoicing program that does not comply?

Article 201 bis of the General Tax Law imposes a penalty of €50,000 per financial year on a user holding systems that do not meet the requirements or are not certified, and of €150,000 per financial year and per type of system on the manufacturer or seller that produces or sells them.

Conclusion

Verifactu is an obligation on the software, not on the invoice: registration and cancellation records with a chained hash, an event log, a QR code, inalterability, export and a self-declaration from the producer, with Verifactu mode as the simplest route. A custom ERP has to comply just as a commercial program does, and whoever developed it is the one who answers for it. A little over three months remain until 1 January 2027. If you want to know what yours is missing, tell us how you invoice today and we will tell you, with a specific gap analysis.