VeriFactu and Ley Crea y Crece: Two Rules, One Invoice
Spain is regulating the same invoice twice: once where it is produced, and once where it travels to the customer and gets paid. What each rule requires, how they differ, where they meet, and what the alignment to October 2028 announced on 5 October 2026 means for your plans.
Concepts · October 2026 · For CFOs, heads of tax and IT leads with Spanish entities
Oct 2028
VeriFactu: announced new date for all pending obligations (not yet in the BOE)
6 Oct 2027
B2B e-invoicing: companies with turnover above €8M
6 Oct 2028
B2B e-invoicing: all other businesses and professionals
€50,000
VeriFactu fine per year for using non-compliant invoicing software
One Invoice, Two Rules
VeriFactu controls how an invoice is produced and recorded. Ley Crea y Crece controls how it travels between businesses and when it is paid. One is an anti-fraud rule aimed at the invoicing software; the other is an e-invoicing and late-payment rule aimed at the exchange. For most Spanish SMEs both will land on the same invoice and, since 5 October 2026, very likely in the same month.
Every invoice issued with software creates a tamper-evident record, chained to the previous one and, in VERI*FACTU mode, sent automatically to the Tax Agency (AEAT). Every invoice carries a QR code the customer can check. It answers: was this invoice really issued, and has anyone altered it since?
Businesses must issue, send and receive structured e-invoices with each other, through the AEAT public solution or private platforms, and report rejections and the date of full payment. It answers: did the invoice reach the customer in a usable format, and when was it paid?
What changed on 5 October 2026
Order HAC/1028/2026 was published in the BOE and started the B2B e-invoicing clock (in force 6 October 2026). The same day the Ministry of Finance announced that the pending VeriFactu obligations would move to October 2028 “to align them with e-invoicing”, and that a later reform will seek convergence of scope and technical aspects between the two, with ViDA digital reporting in mind. The technical guarantees VeriFactu requires stay substantially the same.
A note on the dates
The VeriFactu postponement to October 2028 is announced, but not yet published in the BOE. Until it is, the legal dates remain 1 January 2027 (corporate taxpayers) and 1 July 2027 (others).
Does it apply to me? The short answer
| Profile | VeriFactu | B2B e-invoicing |
|---|---|---|
| Company in SII with turnover above €8M | Exempt: SII filers are out | From 6 Oct 2027 |
| Company in SII, turnover €6M–€8M | Exempt | From 6 Oct 2028 |
| SME or self-employed, not in SII, using software | Applies (Oct 2028 announced) | From 6 Oct 2028 |
| Retailer selling only to consumers | Applies if not in SII | Consumer sales are out of scope |
| Basque Country or Navarre | Own regimes (TicketBAI / Navarre) | Own provisions in RD 238/2026: confirm |
Assessed per legal entity (NIF), not per group. Details and exceptions are in section 07.
Two Laws, Two Purposes
The two rules are often discussed as if they were one “e-invoicing reform”. They are not. They come from different laws, answer to different ministries and were written to solve different problems.
VeriFactu: born from the anti-fraud law
Ley 11/2021, the anti-fraud law, amended the General Tax Law (art. 29.2.j) to require that invoicing software guarantees the integrity, conservation, accessibility, legibility, traceability and inalterability of records, and banned “dual-use” software able to hide or alter sales. It was developed by RD 1007/2023, the regulation on invoicing systems (RRSIF), and Orden HAC/1177/2024, the technical specifications. RD 254/2025 and RDL 15/2025 moved the dates; the decree-law was validated by Parliament on 11 December 2025.
- Owner: the Ministry of Finance and the AEAT.
- Target: sales suppression and undeclared turnover, especially in cash-intensive sectors.
Crea y Crece: born from the business-growth law
Ley 18/2022 (“Crea y Crece”, on company creation and growth) amended Ley 56/2007, art. 2 bis: all businesses and professionals must issue, send and receive electronic invoices in their commercial relations, and the status of each invoice, including payment, must be traceable. It was developed by RD 238/2026 (BOE 31 March 2026) and Order HAC/1028/2026 (BOE 5 October 2026), which set the operating rules of the public solution and started the transition periods.
- Owner: economic and digital-transformation policy; the AEAT runs the public solution (SPFE).
- Target: late payment between businesses, and SME digitalisation.
The legal history, side by side
| When | VeriFactu | Ley Crea y Crece |
|---|---|---|
| Jul 2021 | Ley 11/2021 (anti-fraud law) | — |
| Sep 2022 | — | Ley 18/2022 amends Ley 56/2007 |
| Dec 2023 | RD 1007/2023: invoicing-systems regulation | — |
| Oct 2024 | Orden HAC/1177/2024: technical specifications | — |
| Apr 2025 | RD 254/2025: user dates moved to 2026 | — |
| 29 Jul 2025 | Software producers must offer adapted systems | — |
| Dec 2025 | RDL 15/2025: 1 Jan 2027 (corporate taxpayers), 1 Jul 2027 (others) | — |
| 31 Mar 2026 | — | RD 238/2026: the B2B regulation |
| 5 Oct 2026 | Postponement to Oct 2028 announced (press note) | Order HAC/1028/2026 published; in force 6 Oct |
Why the different purposes matter
A different purpose means different scope, a different authority and different penalties. VeriFactu cares about every invoice a system produces, including tickets to consumers. Crea y Crece cares only about invoices between businesses, and about whether they are paid on time.
They will converge, not merge
The Ministry now wants “maximum convergence” between the two, but nothing announced so far removes either obligation. Plan for two sets of requirements served by one design.
VeriFactu in Brief
Rules for the software that issues invoices. VeriFactu does not change what an invoice looks like or how it reaches the customer. It changes what the system must do every time it issues one.
The six guarantees every invoicing system must provide
- Integrity
- Conservation
- Accessibility
- Legibility
- Traceability
- Inalterability
How it works: a chain of invoice records
For every invoice the system creates an invoice record (and an annulment record when one is cancelled). Each record carries the fingerprint (hash) of the previous one, so a deleted or edited invoice breaks the chain. In VERI*FACTU mode the records reach the AEAT automatically.
Any hash values used as examples are illustrative.
Two ways to comply
| Aspect | VERI*FACTU mode | Non-VERI*FACTU mode |
|---|---|---|
| Records | Sent to the AEAT automatically as invoices are issued | Kept by the taxpayer, electronically signed |
| Event log | Not required | Required |
| On the invoice | QR plus the “VERI*FACTU” legend | QR |
| On request | — | Records delivered to the AEAT when asked |
The QR code
The QR lets the customer check the invoice at the AEAT’s website. On paper and PDF invoices it is printed; for structured e-invoices the specifications ask for the QR’s URL to be included as a field in the file (Orden HAC/1177/2024, art. 20, as reported by practitioners).
Who is in, who is out
- In: corporate taxpayers, self-employed with business income, non-residents with a permanent establishment, when they issue invoices with software.
- In: every invoice that software issues, whether B2B, B2C or simplified (tickets).
- Out: taxpayers in the SII.
- Out: the Basque Country and Navarre (own regimes, e.g. TicketBAI).
- Out: invoicing by hand, without a computerised system.
What an invoice record contains
- Issuer NIF, invoice series and number, issue date
- Invoice type (full, simplified, corrective) and description
- Recipient, where there is one
- VAT breakdown and invoice total
- Hash of the previous record, timestamp and system identification
What VeriFactu does not change
- The invoice format: paper and PDF remain valid
- How the invoice reaches the customer
- The VAT return or the SII
- Anything about payment
Software producers
Since 29 July 2025, producers must offer adapted systems with a responsible declaration of compliance. Ask your vendor, or your SAP partner, for it.
Penalties (art. 201 bis General Tax Law)
€50,000 per year for users of non-compliant systems; €150,000 per year for each type of non-compliant system a producer sells.
Ley Crea y Crece in Brief
Rules for the invoice exchanged between businesses. Crea y Crece changes the invoice itself, which must be structured data and not a PDF, and makes the customer part of the process: receiving, rejecting and reporting when it paid.
Supplier
Issues a structured e-invoice (EN 16931: UBL, CII, EDIFACT or Facturae).
SPFE or private platforms
The AEAT’s public solution, or interoperable private platforms that also send a true copy to the SPFE.
Customer
Receives the e-invoice and reports rejection and the date of full payment.
Private platforms must be free to interconnect with each other and meet the requirements of RD 238/2026 (ISO 27001, AS2/AS4, eIDAS, all four syntaxes, continuity). Customer consent is no longer needed to send an e-invoice.
Statuses and payments
- Mandatory: rejection, the date of full payment, the due date
- Voluntary: collection, non-payment
- Presumed acceptance if the customer does not reject
- Reported within four calendar days, excluding weekends and national holidays
- Payment is reported whichever route the invoice took
One unique identifier
Each invoice is identified by the issuer’s NIF + series and number + issue date.
Scope
- In: all businesses and professionals, as issuers and as recipients, when the customer is a business established in Spain.
- Out: sales to consumers; simplified invoices unless a full invoice is requested.
- Out: electricity and gas market operators; IATA clearing houses.
- Special: the Basque Country and Navarre (own provisions).
Dates set by Order HAC/1028/2026
| Date | What applies |
|---|---|
| 6 Oct 2026 | Order in force; the transition periods start |
| By Aug 2027 | The SPFE must be available at least two months before the first effective date |
| 6 Oct 2027 | Businesses with turnover above €8M; for 12 months they also send a PDF unless the customer accepts the e-invoice alone |
| 6 Oct 2028 | All other businesses and professionals |
| 6 Oct 2029 | Status reporting becomes mandatory for individuals and income-attribution entities up to €8M |
Penalties: lighter and less clear than VeriFactu’s
Ley 56/2007, art. 2 bis.9, provides a warning or a fine of up to €10,000, imposed by the Secretary of State for Digitalisation and AI. Its wording targets failing to offer e-invoicing or access to past invoices; how it applies to B2B breaches is debated, and neither RD 238/2026 nor the order adds a specific regime. The commercial consequence, customers who cannot process your invoice, will be felt first.
Side by Side: The Differences, Row by Row
The two rules share an authority and an invoice identity, but they answer different questions. This table sets them face to face.
The differences, row by row
| Aspect | VeriFactu | Ley Crea y Crece |
|---|---|---|
| Core question | Was the invoice really issued, and is it unaltered? | Did the structured invoice reach the customer, and when was it paid? |
| Policy goal | Fight sales suppression and tax fraud | Fight late payment; digitalise business-to-business trade |
| Legal basis | Ley 11/2021 · General Tax Law art. 29.2.j · RD 1007/2023 · Orden HAC/1177/2024 · RDL 15/2025 | Ley 18/2022 · Ley 56/2007 art. 2 bis · RD 238/2026 · Orden HAC/1028/2026 |
| What is regulated | The invoicing software and the records it produces | The invoice: its format, its exchange and its statuses |
| Who is obliged | Taxpayers who issue invoices with software | All businesses and professionals in B2B relations, as issuer and recipient |
| Transactions | Every invoice the system issues: B2B, B2C, simplified | B2B only, customer established in Spain |
| Main exclusions | SII filers · Basque Country and Navarre · manual invoicing | Consumers · simplified invoices · energy market operators, IATA clearing |
| Invoice format | Unchanged (paper, PDF or e-invoice), plus a QR | Structured e-invoice (EN 16931: UBL, CII, EDIFACT, Facturae); PDF only during the transition |
| Data the AEAT gets | An invoice record (header, tax breakdown, hash), automatically in VERI*FACTU mode | The e-invoice through the SPFE, or a true copy from private platforms, plus statuses |
| Customer’s role | Passive: may check the QR | Active: must receive, and report rejection and payment date |
| Payment data | No | Yes: date of full payment within four days |
| Moment of truth | When the invoice is issued | When it is exchanged, and again when it is paid |
| Dates | Legal today: 1 Jan 2027 / 1 Jul 2027 · Announced: Oct 2028 for all | 6 Oct 2027 (> €8M) · 6 Oct 2028 (rest) · 6 Oct 2029 (status reporting for individuals) |
| Penalties | €50,000/yr users · €150,000/yr per system for producers | Warning or up to €10,000; application to B2B breaches debated |
| SII filers | Exempt | Fully in scope |
| Vendors | Responsible declaration since 29 Jul 2025 | Private platforms must meet RD 238/2026 requirements |
Swipe to see the whole table →
The same authority
Both send invoice data to the AEAT’s systems: records in one case, e-invoices or copies in the other.
The same invoice
Both identify an invoice by issuer NIF, series and number, and issue date.
The same direction
Both move Spain towards near-real-time, structured invoice data, the destination of the EU’s ViDA package from 2030.
Where They Intersect: One Billing Event, Two Obligations
For a company subject to both, a single invoice triggers two flows that start at the same moment, in the same system, and end at the same authority. The invoicing system, whether ERP or billing software, is the “SIF” in VeriFactu terms.
One billing event, two lanes
| Step | VeriFactu lane: the record | Crea y Crece lane: the invoice |
|---|---|---|
| 1 | Invoice record created at issuance | Structured file in EN 16931 |
| 2 | Hash of the previous record added | SPFE, or private platform + true copy |
| 3 | QR on the invoice; URL field in e-invoices | Accepts or rejects |
| 4 | Record sent (VERI*FACTU mode) or kept, signed | Payment date reported within four days |
Eight points where they meet
| Where they meet | What happens | What to design |
|---|---|---|
| 1 · The document | The invoice VeriFactu records is the invoice Crea y Crece exchanges | Generate both from one billing event; never re-key |
| 2 · The identity | Issuer NIF + series and number + date identify the invoice in both | One numbering logic; platforms must not renumber |
| 3 · The QR | Structured e-invoices carry the VeriFactu QR as a URL field rather than an image | Map the field in your B2B format |
| 4 · Corrections | A B2B rejection is a status. In VeriFactu, correcting means a corrective invoice or an annulment record | One correction process that feeds both |
| 5 · The authority | The AEAT receives VeriFactu records and B2B copies and statuses, and SII records from larger companies | Reconcile before the AEAT does |
| 6 · The software | The same system must produce records and structured invoices | Choose once; check the vendor’s declaration and platform credentials |
| 7 · The calendar | October 2028 for most SMEs, on both, if the announcement is confirmed | One programme, one go-live |
| 8 · The future | The Ministry plans convergence of scope and technical aspects, with ViDA in mind | Avoid one-off builds that convergence will undo |
Swipe to see the whole table →
Complying with one does not satisfy the other
A VeriFactu record is not an e-invoice, and an e-invoice sent through a platform does not create the hash-chained record. Both obligations stand on their own.
Where they do not meet
Consumer sales and tickets are VeriFactu only. Payment reporting is Crea y Crece only. SII companies meet only the B2B side.
Who Must Do What, and When
The answer depends on SII, turnover and territory. One fact sorts most companies: SII is mandatory above roughly €6M of annual turnover, and SII filers are exempt from VeriFactu. In practice, almost every company in the first B2B wave (above €8M) is already in SII, so VeriFactu and B2B land together mainly on the second wave, in October 2028.
Profile by profile
| Profile | VeriFactu | B2B e-invoicing | Watch |
|---|---|---|---|
| SII filer, turnover above €8M | Exempt | 6 Oct 2027; PDF alongside for 12 months unless the customer accepts the e-invoice alone | Inbound: suppliers’ invoices will carry VeriFactu data |
| SII filer, €6M–€8M | Exempt | 6 Oct 2028 | Same as above |
| Not in SII, invoices with software | Oct 2028 announced (legal today: 1 Jan / 1 Jul 2027) | 6 Oct 2028 | One project for both |
| Joins SII voluntarily | Exempt while in SII | 6 Oct 2028 | Leaving SII is only possible in November |
| Self-employed invoicing by hand | Out while invoicing by hand | 6 Oct 2028 | Structured e-invoices need software, and VeriFactu follows |
| B2C retailer | Applies if not in SII | Consumer sales out | B2B purchases still arrive as e-invoices |
| Basque Country / Navarre | Own regimes (TicketBAI in all three Basque provinces) | Own provisions: confirm | Foral treatment still unsettled |
Swipe to see the whole table →
VAT-group members and companies in the monthly refund register (REDEME) are also in SII. Each NIF is assessed on its own: groups usually mix profiles.
The combined calendar
VeriFactu
Software producers must offer adapted software.
B2B e-invoicing
RD 238/2026.
VeriFactu
Postponement to October 2028 announced.
B2B e-invoicing
Order in force.
VeriFactu: legal until the BOE changes it
Corporate taxpayers.
VeriFactu: legal until the BOE changes it
Others.
B2B e-invoicing
SPFE live.
B2B e-invoicing
Turnover above €8M.
SAP
SAP ERP 6.0 mainstream maintenance ends.
VeriFactu: announced
All pending obligations.
B2B e-invoicing
All others.
B2B e-invoicing
Status reporting for individuals.
EU
ViDA digital reporting.
The SII decision
A company below €6M can join the SII voluntarily (form 036) and so fall outside VeriFactu. The price: submitting invoice records, issued and received, within four days, and you can only leave in November, for the following year. For mid-sized companies with good data this can be the simpler route; for others VeriFactu is lighter. It is a real, dated decision worth taking before 2028.
What It Means for SAP Users
Company code by company code. Most large SAP users in Spain file under SII, so VeriFactu can look irrelevant. It rarely is: smaller subsidiaries, suppliers’ invoices and the B2B obligation all reach the same SAP system.
VeriFactu in SAP
SAP Document and Reporting Compliance (DRC) offers a VERI*FACTU scenario for Spain, creating and submitting the records as electronic documents (SAP Help; SAP knowledge base article 3609812 collects the FAQ). It matters for company codes not in SII.
- Check which company codes are outside SII.
- Check whether invoices are also issued outside SAP (POS, portals, other tools), since every issuing system must comply.
B2B e-invoicing in SAP
DRC handles the outbound structured invoice and the inbound flow; SAP has indicated it will cover Crea y Crece in DRC. Confirm the release and SAP Notes once the SPFE specifications are final.
- Decide the route: the SPFE directly or a private platform.
- Decide where the full-payment date comes from (payment run, clearing, confirming, netting).
- Review inbound processing for suppliers’ e-invoices.
Six design principles for one programme
| Principle | In SAP terms |
|---|---|
| One billing event, two outputs | The billing document drives both the VeriFactu record and the structured e-invoice, with no parallel tools |
| One invoice identity | Number ranges, series and document dates designed once; no renumbering downstream |
| One correction process | Rejections, credit memos and cancellations mapped to both rules: corrective invoice and annulment record on one side, statuses on the other |
| Payment data from FI | The full-payment date comes from clearing in FI, not from a manual log. This is where most B2B projects underestimate effort |
| Clean master data | NIFs, addresses and tax codes valid for both validators |
| Reconciliation | SII, VeriFactu and B2B data about the same invoice must agree: the AEAT can compare them |
Invoices outside SAP
POS, portals or billing tools issue invoices too. Every issuing system must meet VeriFactu, and B2B invoices must go out structured.
Intercompany
Invoices between Spanish group companies are B2B: in scope for e-invoicing, and for VeriFactu where the issuer is not in SII.
Self-billing and third parties
When the customer or a provider issues the invoice for you, agree who generates the record and who sends the e-invoice.
Credit notes
Corrective invoices need their own record and their own e-invoice, linked to the original. Map them early.
The ERP clock comes first
Mainstream maintenance for SAP ERP 6.0 ends 31 December 2027, before both October 2028 dates. Legal updates after that require extended maintenance, available to 2030. For ECC users, the e-invoicing design and the S/4HANA plan are one decision.
Don’t stop the VeriFactu work
The October 2028 date is announced, not published. Keep the design moving, re-plan the go-live, and use the extra time to build VeriFactu and B2B as one project instead of two.
How 30 Advisory Helps
One design for both rules, from Prepare to Run. One hour, no slides: we map your Spanish entities against both rules and tell you where to start.
Prepare
We map every Spanish NIF: SII or not, turnover band, territory, invoicing systems in use. You receive an entity map: who is in VeriFactu, which B2B wave.
Explore
One target design: billing event, numbering, corrections, payment data, route (SPFE or platform), and the SII decision where relevant. You receive the target design and roadmap.
Realize
SAP DRC configuration for VERI*FACTU and B2B, master-data fixes, end-to-end tests including rejections and payments. You receive a tested solution.
Deploy
Cutover, hypercare, cockpit routines for billing, AR, AP and tax. You go live with a buffer before the date.
Run
Regulatory watch: the BOE text of the postponement, the convergence reform, ViDA. Compliance becomes routine.
Six questions for your team
- 1. Which of our Spanish entities are in SII, and which are not?
- 2. Which systems issue invoices: only SAP, or also POS, portals or others?
- 3. Does our software vendor have the VeriFactu responsible declaration?
- 4. Will we use the SPFE or a private platform for B2B?
- 5. Where will the full-payment date come from?
- 6. Is our plan built on the legal VeriFactu dates or the announced one?
Our scope, honestly
We are SAP finance and compliance advisors, not a tax law firm. Tax positions stay with your tax advisers; we turn their decisions into a working process in SAP.
Sources: Ministerio de Hacienda, nota informativa on VeriFactu (5 October 2026); Infobae/Europa Press, elDerecho, SAPI and VeriBai on the announced postponement (5–6 October 2026); RDL 15/2025 (BOE 3 December 2025) and its validation (BOE 16 December 2025); RD 254/2025 (via Manubens); RD 1007/2023; Orden HAC/1177/2024 (QR in structured e-invoices, via Quaderno); art. 201 bis General Tax Law; Ley 18/2022; Ley 56/2007, art. 2 bis (BOE consolidated text); RD 238/2026 (BOE 31 March 2026); Order HAC/1028/2026 (BOE 5 October 2026); creaycrece.es on penalties; Sage, Davisa and Spun on how the two rules interact; SAP Help Portal and SAP KBA 3609812 on VERI*FACTU in DRC; 30 Advisory briefings on Spain (September–October 2026).
General information prepared by 30 Advisory on 7 October 2026 from public sources. It is not tax or legal advice. The VeriFactu postponement to October 2028 is announced, not yet published in the BOE; the legal dates remain 1 January 2027 and 1 July 2027 until it is. Thresholds, exclusions, foral provisions and SAP scope must be confirmed for each entity and software release. Hash values and examples are illustrative. SAP and SAP S/4HANA are trademarks of SAP SE; 30 Advisory is independent of SAP.