Verifactu: companies have until 1 January 2027 to adapt their invoicing
Royal Decree-Law 15/2025 postponed the timetable by one year. Corporate Income Tax payers must be ready on 1 January 2027 and the other obligated parties by 1 July. The fine for having a non-compliant program remains 50,000 euros per financial year.
Madrid, 21 September 2026 Published on
The timetable for Verifactu, the system that requires every invoicing program to generate chained, unalterable records, was set in December 2025 and has not changed since. Corporate Income Tax payers must have their IT systems adapted before 1 January 2027; the rest of taxpayers —self‑employed under Personal Income Tax, entities under the income attribution regime and non‑residents with a permanent establishment— before 1 July 2027.
A POSTPONEMENT, NOT A REPEAL
The dates come from Royal Decree‑Law 15/2025 of 2 December, published in the Official State Gazette (BOE) on 3 December, whose first final provision amended the fourth final provision of Royal Decree 1007/2023. This is the second postponement of the regulation: Royal Decree 254/2025 of 1 April had already moved the original deadlines from July 2025 to January and July 2026, and the December decree‑law added one more year to each of them.
What has not changed is the substance of the obligation. The regulation requires each invoice to generate an invoicing record with a fingerprint or chained “hash” linked to the previous one, an electronic signature when the records are not sent to the Tax Agency, a QR code on the invoice, and export capability in a standardised format. The technical specifications are set out in Order HAC/1177/2024 of 17 October.
TWO OPTIONS AND AN EVENTS LOG
The regulation allows two ways to comply. Under the Verifactu option, the program sends the records to the Tax Agency’s electronic headquarters at the time the invoice is issued and, in return, the business owner is exempt from keeping certain event logs. Under the “no submission” option, the records remain in the taxpayer’s system, which must keep them complete and traceable and maintain a much more stringent events log.
Those already in the Immediate Supply of Information (SII) system and those who do not use any IT system for invoicing are excluded. A paper invoice book is still legal; an invoicing program that does not comply is not.
PENALTIES: THE RISK LIES IN THE SOFTWARE
Article 201 bis of the General Tax Law, introduced by Law 11/2021, defines two separate infringements. Possession of systems or software that do not comply with the required specifications is punished with a fixed fine of 50,000 euros for each tax year. The manufacture, production and marketing of such systems is punished with 150,000 euros for each year in which sales were made and for each type of software concerned.
The practical consequence for a small business is easy to summarise: it is responsible for having compliant software, even if someone else wrote it. It is advisable to request in writing from the supplier the compliance declaration required by the regulation and keep it, as it is the document that proves due diligence in the event of an audit.