Verifactu checklist: what to ask your software vendor

·

Article 8 of Spanish Royal Decree 1007/2023 does not ask you to «be adapted»: it asks for nine specific, verifiable things. Here they are turned into questions you can put to your vendor today, with the answer you should get. The deadlines in force are 1 January 2027 for corporate income tax payers and 1 July 2027 for everyone else.

Almost every invoicing software vendor has already sent an email saying they «comply with Verifactu». That claim is hard to check unless you know exactly what the rule demands — and that is the problem: most companies have no way to tell a real adaptation from a marketing label.

The good news is that article 8 of Royal Decree 1007/2023 is unusually specific. It does not talk about «adapting»: it lists verifiable requirements. This article turns them into nine questions you can ask in writing, together with the answer you should receive.

First: are you covered?

Article 3 sets the scope. It covers taxpayers who use invoicing software — «even if they only use it for part of their activity», says the text, which rules out the «we invoice almost everything by hand» excuse:

The Regulation also applies to the producers and distributors of those systems, as regards their production and marketing activity. In other words: your vendor is covered too, not just you.

The deadlines, which most outdated material still places in 2025

After the amendment introduced by Royal Decree-law 15/2025, of 2 December, the fourth final provision of RD 1007/2023 sets two dates:

WhoWhatWhen
Obliged parties under article 3.1.a) — corporate income tax payersSystems adaptedBefore 1 January 2027
All other obliged parties under article 3.1Systems operationalBefore 1 July 2027

This is worth being clear about, because much of what is published still refers to 2025 or 2026. If a vendor pushes a date earlier than 2027, they are either out of date or using urgency as a sales argument.

The nine questions

1. Does the system detect and warn if a record is altered?

Article 8.2.a) requires integrity and immutability «so that, once generated and recorded, they cannot be altered without the system detecting it and issuing a warning». Note the double verb: detect and warn. A system that merely prevents editing does not comply: it must be able to flag the attempt.

The rule also defines what counts as alteration: hiding or deleting a record, modifying it in whole or in part, and also adding simulated or false records. All three.

2. Are records chained so the trail can be followed from the first one?

Paragraph 2.b) requires records to be «chained so that their trail can be verified following their creation sequence from the first to the last». Concrete question: can I request a full chain verification today and get a result?

3. Is there any function that allows operations to be hidden?

The same paragraph is blunt: «Any functionality or mechanism that allows the trail of operations to be altered or hidden constitutes a breach of this requirement». This points straight at the «delete invoice» or «training mode» features many legacy programs carry. Ask whether they exist and what happened to them.

4. Does every record carry the exact time it was recorded?

From 2.b): «All recorded data must be correctly dated, indicating the moment the record is made». Note the nuance: the moment of recording, not the invoice date. They are different things and often confused.

5. Can I export all records to a readable external file?

Paragraph 2.c) requires «a procedure for downloading, dumping and securely archiving the invoicing records», exportable «to external storage in a readable electronic format». This is the question that most unsettles vendors who lock customers in: if you cannot get your records out, you do not comply.

6. Are they kept for the period set by the General Tax Law?

The same paragraph refers to Law 58/2003. The practical question: what happens to my records if I stop paying the licence? If the answer is that they are lost, there is a compliance problem, not just a commercial one.

7. Is there an event log, and can I consult it myself?

Article 8.3 requires an event log capturing interactions and occurrences automatically «at the moment they occur», which «must be consultable from the system itself». It is not enough for it to exist on the vendor's server: you must be able to see it.

8. Is tax-relevant access separated from confidential data?

Article 8.4 requires that access to tax-relevant information be «duly dissociated» from access to any confidential non-financial information, so the tax authority can consult its part without entering the rest. Almost nobody checks this requirement, and it has data protection implications.

9. Does submission to the tax authority meet all eight adverbs?

Article 8.1 requires the capacity to submit records «in a continuous, secure, correct, complete, automatic, consecutive, instantaneous and reliable manner». Eight cumulative conditions. The most demanding in practice is automatic: if someone has to press a button every day, it is not.

What to do with the answers

Ask for all nine in writing. A vendor who complies answers without difficulty and usually has the documentation ready; one who replies with commercial generalities is telling you something without saying it.

If you want a quick first check before that conversation, we have published a SII vs Verifactu comparison that places your case in a few minutes. And if what you need is to understand the rule as a whole before going into technical detail, the Verifactu guide with deadlines and scope covers the general framework.

One last thing worth separating: Verifactu is not B2B electronic invoicing. They are two different obligations, with different rules and different calendars — and the B2B one is not even settled yet. We explain it in the guide to B2B e-invoicing dates.

Sources