VeriFactu: what it is and when it actually becomes compulsory
The dates have been pushed back twice. The ones in force are 1 January 2027 for companies and 1 July 2027 for the self-employed, and they were set by Real Decreto-ley 15/2025. Here is everything else, with the rule cited alongside each statement.
The dates that are in force today
If you came looking for when your turn is, this is it. And if what you read somewhere else says 2025 or 2026, it is out of date.
| Who | From when | Rule |
|---|---|---|
| Corporation Tax payers Sociedades limitadas and anónimas, cooperatives, associations, foundations and clubs | 1 January 2027 | Fourth final provision of RD 1007/2023, as worded by RDL 15/2025 |
| Everyone else who is covered Autónomos taxed under IRPF, comunidades de bienes and other entities under the income attribution regime, and non-residents with a permanent establishment | 1 July 2027 | The same provision |
| Whoever makes or sells the program It is our obligation, not yours, and its deadline has already passed | 29 July 2025 Nine months from the entry into force of Orden HAC/1177/2024 | The same provision, third paragraph |
Be careful what you read elsewhere: these dates have been pushed back twice. First RD 254/2025 moved them to 2026, and then Real Decreto-ley 15/2025, of 2 December, moved them to 2027. A great deal of content published in 2024 and 2025 still gives dates that no longer hold.
What you need to know, without reading the regulation
It is about your software, not about you
The rule demands almost everything of the invoicing software. Your job comes down to using one that complies before your date.
Every invoice leaves a hash behind
A record chained to the one before it. Touching an invoice from six months ago breaks the chain and it shows.
QR code and legend on the PDF
The invoice comes out with a code that allows it to be checked and, in VERI*FACTU mode, with its legend.
€50,000 per financial year
This is the fine for having a program that does not comply. The manufacturer is hit with €150,000 per financial year and per type of program.
What VeriFactu is, in one sentence
It is the obligation for your invoicing software to leave a trail that cannot be tampered with. Every time you issue an invoice, the program also generates a billing record holding that invoice's data, calculates a hash for it and chains it to the hash of the previous record. If anyone alters or deletes an old invoice, the chain breaks and it shows.
That is all there is to it. The rest — the QR code, the legend on the PDF, the submission to the Spanish Tax Agency — follows from that one idea.
The stated aim is to put an end to dual-use software: programs that kept two sets of books, one to show and one that was real. That is why the rule asks nothing unusual of the business owner and asks almost everything of the program.
What VeriFactu is not
It is not compulsory business-to-business electronic invoicing. They are two different rules, with different timetables and different aims, and confusing them is the most widespread mistake in the market. We separate them further down.
The two modes: VERI*FACTU and non-VERI*FACTU
The regulation does not require you to send anything to Hacienda. It lets you choose between two ways of complying, and the choice has very different consequences.
| VERI*FACTU system | Non-VERI*FACTU system | |
|---|---|---|
| What it does | Sends every billing record to the Spanish Tax Agency at the moment the invoice is issued | Keeps the records inside the system itself and does not send them |
| What it demands in return | Little more: by sending them, the system is presumed to comply by design | An electronic signature on the records and an event log noting what happens inside the program |
| Retention | The AEAT has them; you keep your own | You have to keep them and be able to hand them over if asked |
| A legend on the invoice | «Factura verificable en la sede electrónica de la AEAT» or «VERI*FACTU» (the wording is prescribed and stays in Spanish: "invoice verifiable at the AEAT's electronic office") | It does not carry that legend |
| Who it suits | Almost everybody: fewer technical requirements and less to prove | Anyone who does not want to send information in real time and can take on the signature and the event log |
In short: VERI*FACTU mode is the easy road. You send the record and in exchange the rule spares you the electronic signature and the event log. That is how Cairos works.
Two practical points. First: if the connection goes down one day, you do not stop invoicing. The system carries on issuing, tells you how many submissions are outstanding and retries — the order requires it to try at least once an hour — until the service comes back; there is no maximum period that leaves you blocked. Second: once you start in VERI*FACTU mode, that choice holds until the end of the calendar year; the other way round — moving from non-VERI*FACTU to VERI*FACTU — can be done at any time.
And the invoice can still be on paper
Neither VeriFactu nor VERI*FACTU mode obliges you to issue electronic invoices. The invoicing regulation says, word for word, «sean electrónicas o no» — whether they are electronic or not: a printed invoice with its QR code complies just the same. What has to be electronic is the record, not the paper you hand the customer.
Who it applies to, and who falls outside it
It applies to anyone carrying on a business or professional activity who issues invoices: companies, autónomos, comunidades de bienes and other entities under the income attribution regime, and non-residents with a permanent establishment in Spain.
And it applies to non-profit organisations that issue invoices, which is a question that comes up a great deal: an association or a club invoicing for sponsorship, tickets or the bar is not outside it by virtue of being non-profit. With two qualifications the regulation itself makes: entities fully exempt from Corporation Tax — those in article 9.1 of its act: the State, the autonomous communities, local authorities and little else — fall outside; and partially exempt entities, which is where almost every association, foundation and club sits, are covered only for transactions generating income that is taxable and not exempt. What actually puts an entity outside it is invoicing nothing that is taxed.
Who is not covered
- Anyone already in the SII. Those who keep their record books through the Immediate Supply of Information — large companies, VAT groups and businesses registered in REDEME, the monthly refund register, plus anyone who has opted in voluntarily — already send that information and do not duplicate it. Article 3.3 of the regulation says so, referring across to article 62.6 of the VAT Regulation.
- Anyone whose tax domicile is in one of the foral territories. The regulation applies «cuando tengan su domicilio fiscal en territorio común» — when their tax domicile is in the common territory. Álava, Bizkaia and Gipuzkoa have TicketBAI, now fully in force in all three and on a different timetable in each. Navarra has no approved equivalent system: a project has been announced — NaTicket — but no rule has been published, so today there is nothing to comply with there by this route.
- Anyone invoicing on paper with no computerised system at all. They exist, and it is still legal, but it stops being so the moment any program is used to issue invoices.
- The transactions the regulation itself excludes in its article 4: invoicing in the electricity market, anything invoiced through permanent establishments located abroad, and invoices physically issued by the recipient — or by a third party, because a rule requires it — where that recipient keeps its books through the SII.
The Canary Islands, Ceuta and Melilla are covered, even though you often read the opposite: the regulation applies across the whole of the common territory, and references to VAT are read as references to IGIC and IPSI.
What your program has to do
This is the list on which a program either works or does not. It is not negotiable and it is not configurable: either it is there, or the program does not comply.
- An issue record for every invoice raised, holding its data and generated at the very moment of issue.
- A cancellation record when an invoice is cancelled. It is never deleted: it is cancelled, leaving a trace.
- A huella or hash of every record, chained to the previous one. It is what makes touching an invoice from six months ago detectable.
- A QR code on the invoice, carrying the data that allows it to be checked.
- The legend «VERI*FACTU», or its equivalent, if you operate in that mode.
- Integrity, retention, accessibility, legibility, traceability and inalterability of the records: those are the regulation's six words, and they mean the program cannot allow anyone to rewrite the past.
- A declaración responsable from the manufacturer — a formal self-declaration of compliance — inside the program itself.
Cairos already does all of this, on every plan
On the free plan too. Charging you to meet a legal obligation strikes us as indefensible: it would leave precisely those who invoice least unable to invoice properly.
Can I carry on invoicing with Excel or Word?
It is the most repeated question, and the honest answer comes in two parts.
Today, yes. Until your date arrives — 1 January or 1 July 2027, depending on who you are — there is no new obligation at all. You can carry on as you are.
Afterwards, no. And not because Excel is banned, but for something simpler: the moment you use a spreadsheet to issue invoices, that spreadsheet is a computerised invoicing system for the purposes of the regulation, and it would have to generate chained records with a hash, a QR code and a declaración responsable. A spreadsheet does none of that, and no template will fix it.
It is set out in full, with the regulation's definition and the date up to which you can carry on like this, under is Excel a computerised invoicing system?. The same goes for a Word template and for a desktop program that no longer gets updates. The question to put to whatever program you use today is a specific one: is it going to add the billing record and the declaración responsable before my date? If the answer is not a clear yes, it is time to look at something else.
Does the Spanish Tax Agency approve invoicing software?
No. There is no official list of programs approved or certified by the Spanish Tax Agency, however many advertise themselves that way.
What the regulation requires is a declaración responsable: whoever makes or sells the program declares, on their own responsibility, that it meets the requirements, and that declaration has to be visible inside the program itself and handed over free of charge to anyone who asks for it. The responsibility lies with the manufacturer, and so do the penalties for failing.
So when someone sells you a «programa homologado por Hacienda», a program approved by the tax authority, what they are telling you — at best — is that they have signed their declaración responsable. Which is the right thing to do, but it is not an approval. How to check it in five minutes, on this page.
Where the confusion comes from
The Spanish Tax Agency does publish lists of approved software, but they are for something else: the certified digitisation of paper invoices, which is a separate and older matter. Seeing those lists and assuming there is a VeriFactu approval is a leap plenty of people make.
The AEAT's free application: when it is enough
The Spanish Tax Agency offers a free application for issuing compliant invoices. It is real and it is a legitimate option, and it is worth saying who it works for rather than pretending it does not exist.
It is enough for you if you issue few invoices a year, all of them full invoices, one recipient each, and you need nothing beyond issuing them.
It is not enough for you if you issue till receipts or simplified invoices, if you need quotes, expenses, payments or tax forms, if you want to get your data out into another system, or if you invoice at any volume. The AEAT's application is designed to make you compliant, not to run a business.
Put another way: it solves the legal obligation and it does not solve your accounts. If the first is all you are worried about, use it without a second thought.
VeriFactu is not compulsory electronic invoicing
This is the structural confusion of the Spanish market, and it comes from the two rules sounding equally remote. They are different things:
| VeriFactu | Mandatory electronic invoicing | |
|---|---|---|
| Where it comes from | Anti-fraud Law 11/2021 and Royal Decree 1007/2023 | Ley 18/2022 «Crea y Crece» and its implementing regulation |
| What it aims to do | That the invoices you issue cannot be altered | That invoices between businesses travel in a structured electronic format and that their payment status is reported |
| Who it affects | Almost anyone who issues invoices | To transactions between businesses and professionals; not to invoices issued to private individuals |
| What changes for you | Your program generates chained records and a QR code | You have to issue and receive in a structured format and report when you accept and when you pay |
| The invoice can be on paper | Yes, with the QR code printed | No, within its own scope |
| When | 1 January and 1 July 2027 | Still without a firm date |
The full comparison, point by point, is at VeriFactu or electronic invoicing. In summary: VeriFactu looks at the invoice you issue; electronic invoicing looks at how you send it to the other company. One comes out of an anti-fraud act and the other out of an act against late payment. They will end up overlapping, but not because one rule refers to the other — the electronic invoicing regulation does not cite the VeriFactu one even once — but because VeriFactu applies to any system used to issue invoices, «sean electrónicas o no», whether they are electronic or not: the program you issue electronic invoices with will also have to be a compliant system. Today they are two separate obligations.
Why we are not giving you a date for electronic invoicing
Because there is not one. The regulation implementing it, Real Decreto 238/2026, is indeed published and in force since 20 April 2026. But the deadlines — twelve months for anyone invoicing more than eight million and twenty-four for everyone else — run from a ministerial order that has not yet been published. Until it appears, any specific date you read is a forecast, not an obligation.
The penalties, with figures
They are in article 201 bis of the General Tax Act, added by the anti-fraud act. They are among the highest in Spanish tax law, which is why they are worth reading slowly.
| Who | Why | How much |
|---|---|---|
| Whoever uses the program You | Having systems or programs that do not meet the requirements, or having altered them | €50,000 per financial year |
| Whoever makes or sells the program Us | Manufacturing, producing or selling systems that do not comply | €150,000 for each financial year with sales, and for each different type of program |
| Whoever makes or sells the program | Selling it without the certification when one is required | €1,000 for each system sold without it |
Look at how it is divided up: the user's fine is for having a program that does not comply, not for evading tax. That is why the important question is not what you do, but what you invoice with.
And one detail worth knowing if you change program: on the Spanish Tax Agency's own reading, once the date has arrived, merely keeping an unadapted system that is still capable of issuing invoices — even if you never use it — is enough to commit the offence. The AEAT does accept keeping the old program solely as an archive, to look up history, provided you can show that invoices can no longer be issued with it. So when you migrate, you have to leave it unable to issue, not simply stop opening it.
One honest caveat is worth adding: article 201 bis literally speaks of systems «no certificados debiendo estarlo» — not certified when they ought to be — whereas the regulation frames compliance through a declaración responsable rather than through certification. The Spanish Tax Agency applies this penalty to these cases in its own FAQs, and that is how it has to be read.
How Cairos does it
Cairos operates in VERI*FACTU mode: every invoice generates its billing record and it is sent to the Spanish Tax Agency. In practice, for you that means you issue the invoice as you always have and there is no new step.
- An issue record for every invoice and a cancellation record when one is cancelled. No invoice is ever deleted.
- A SHA-256 hash chained to the previous record's.
- A QR code and the compulsory legend on the PDF.
- Sequential numbering within each series, with no gaps.
- Corrective invoices as the invoicing regulation requires, instead of deleting and issuing again.
- A declaración responsable inside the program.
- On every plan, the free one included.
And one more thing, which is not a legal requirement but does matter: your records can be exported. Complying with the rule should not tie you to a supplier.
Cairos already complies, on the free plan too
A chained record, a QR code and submission to the Spanish Tax Agency from the very first invoice. At no extra cost and with no card to start.
Questions about VeriFactu
How this page is kept up to date
The invoicing rules have changed three times in two years, so this page carries a visible review date and is updated when the rules change, not when the blog is due a refresh. Last reviewed: 25 August 2026. If you find anything out of date, write to us at hola@cairos.es.
This is information, not tax advice: for your own circumstances, ask your accountant.
Have this sorted before the date catches you
Cairos issues with VeriFactu from the very first invoice, on every plan. When your 2027 date arrives, you will not have to change a thing.
VeriFactu included on the free plan · No lock-in · Support in Spanish