Concepts · Spain

VeriFactu and Ley Crea y Crece: Two Rules, One Invoice

Spain is regulating the same invoice twice: once where it is produced, and once where it travels to the customer and gets paid. What each rule requires, how they differ, where they meet, and what the alignment to October 2028 announced on 5 October 2026 means for your plans.

Concepts  ·  October 2026  ·  For CFOs, heads of tax and IT leads with Spanish entities

Download the Full Dossier (PDF, EN) Talk to us about Spain

Oct 2028

VeriFactu: announced new date for all pending obligations (not yet in the BOE)

6 Oct 2027

B2B e-invoicing: companies with turnover above €8M

6 Oct 2028

B2B e-invoicing: all other businesses and professionals

€50,000

VeriFactu fine per year for using non-compliant invoicing software

01 · The idea

One Invoice, Two Rules

VeriFactu controls how an invoice is produced and recorded. Ley Crea y Crece controls how it travels between businesses and when it is paid. One is an anti-fraud rule aimed at the invoicing software; the other is an e-invoicing and late-payment rule aimed at the exchange. For most Spanish SMEs both will land on the same invoice and, since 5 October 2026, very likely in the same month.

VeriFactu
ControlsThe integrity of the invoicing system

Every invoice issued with software creates a tamper-evident record, chained to the previous one and, in VERI*FACTU mode, sent automatically to the Tax Agency (AEAT). Every invoice carries a QR code the customer can check. It answers: was this invoice really issued, and has anyone altered it since?

Ley Crea y Crece
ControlsStructured exchange and payment behaviour

Businesses must issue, send and receive structured e-invoices with each other, through the AEAT public solution or private platforms, and report rejections and the date of full payment. It answers: did the invoice reach the customer in a usable format, and when was it paid?

What changed on 5 October 2026

Order HAC/1028/2026 was published in the BOE and started the B2B e-invoicing clock (in force 6 October 2026). The same day the Ministry of Finance announced that the pending VeriFactu obligations would move to October 2028 “to align them with e-invoicing”, and that a later reform will seek convergence of scope and technical aspects between the two, with ViDA digital reporting in mind. The technical guarantees VeriFactu requires stay substantially the same.

A note on the dates

The VeriFactu postponement to October 2028 is announced, but not yet published in the BOE. Until it is, the legal dates remain 1 January 2027 (corporate taxpayers) and 1 July 2027 (others).

Does it apply to me? The short answer

ProfileVeriFactuB2B e-invoicing
Company in SII with turnover above €8MExempt: SII filers are outFrom 6 Oct 2027
Company in SII, turnover €6M–€8MExemptFrom 6 Oct 2028
SME or self-employed, not in SII, using softwareApplies (Oct 2028 announced)From 6 Oct 2028
Retailer selling only to consumersApplies if not in SIIConsumer sales are out of scope
Basque Country or NavarreOwn regimes (TicketBAI / Navarre)Own provisions in RD 238/2026: confirm

Assessed per legal entity (NIF), not per group. Details and exceptions are in section 07.

02 · The origins

Two Laws, Two Purposes

The two rules are often discussed as if they were one “e-invoicing reform”. They are not. They come from different laws, answer to different ministries and were written to solve different problems.

VeriFactu: born from the anti-fraud law

Ley 11/2021, the anti-fraud law, amended the General Tax Law (art. 29.2.j) to require that invoicing software guarantees the integrity, conservation, accessibility, legibility, traceability and inalterability of records, and banned “dual-use” software able to hide or alter sales. It was developed by RD 1007/2023, the regulation on invoicing systems (RRSIF), and Orden HAC/1177/2024, the technical specifications. RD 254/2025 and RDL 15/2025 moved the dates; the decree-law was validated by Parliament on 11 December 2025.

  • Owner: the Ministry of Finance and the AEAT.
  • Target: sales suppression and undeclared turnover, especially in cash-intensive sectors.

Crea y Crece: born from the business-growth law

Ley 18/2022 (“Crea y Crece”, on company creation and growth) amended Ley 56/2007, art. 2 bis: all businesses and professionals must issue, send and receive electronic invoices in their commercial relations, and the status of each invoice, including payment, must be traceable. It was developed by RD 238/2026 (BOE 31 March 2026) and Order HAC/1028/2026 (BOE 5 October 2026), which set the operating rules of the public solution and started the transition periods.

  • Owner: economic and digital-transformation policy; the AEAT runs the public solution (SPFE).
  • Target: late payment between businesses, and SME digitalisation.

The legal history, side by side

WhenVeriFactuLey Crea y Crece
Jul 2021Ley 11/2021 (anti-fraud law)—
Sep 2022—Ley 18/2022 amends Ley 56/2007
Dec 2023RD 1007/2023: invoicing-systems regulation—
Oct 2024Orden HAC/1177/2024: technical specifications—
Apr 2025RD 254/2025: user dates moved to 2026—
29 Jul 2025Software producers must offer adapted systems—
Dec 2025RDL 15/2025: 1 Jan 2027 (corporate taxpayers), 1 Jul 2027 (others)—
31 Mar 2026—RD 238/2026: the B2B regulation
5 Oct 2026Postponement to Oct 2028 announced (press note)Order HAC/1028/2026 published; in force 6 Oct

Why the different purposes matter

A different purpose means different scope, a different authority and different penalties. VeriFactu cares about every invoice a system produces, including tickets to consumers. Crea y Crece cares only about invoices between businesses, and about whether they are paid on time.

They will converge, not merge

The Ministry now wants “maximum convergence” between the two, but nothing announced so far removes either obligation. Plan for two sets of requirements served by one design.

03 · VeriFactu

VeriFactu in Brief

Rules for the software that issues invoices. VeriFactu does not change what an invoice looks like or how it reaches the customer. It changes what the system must do every time it issues one.

The six guarantees every invoicing system must provide

  • Integrity
  • Conservation
  • Accessibility
  • Legibility
  • Traceability
  • Inalterability

How it works: a chain of invoice records

For every invoice the system creates an invoice record (and an annulment record when one is cancelled). Each record carries the fingerprint (hash) of the previous one, so a deleted or edited invoice breaks the chain. In VERI*FACTU mode the records reach the AEAT automatically.

Any hash values used as examples are illustrative.

Two ways to comply

AspectVERI*FACTU modeNon-VERI*FACTU mode
RecordsSent to the AEAT automatically as invoices are issuedKept by the taxpayer, electronically signed
Event logNot requiredRequired
On the invoiceQR plus the “VERI*FACTU” legendQR
On request—Records delivered to the AEAT when asked

The QR code

The QR lets the customer check the invoice at the AEAT’s website. On paper and PDF invoices it is printed; for structured e-invoices the specifications ask for the QR’s URL to be included as a field in the file (Orden HAC/1177/2024, art. 20, as reported by practitioners).

Who is in, who is out

  • In: corporate taxpayers, self-employed with business income, non-residents with a permanent establishment, when they issue invoices with software.
  • In: every invoice that software issues, whether B2B, B2C or simplified (tickets).
  • Out: taxpayers in the SII.
  • Out: the Basque Country and Navarre (own regimes, e.g. TicketBAI).
  • Out: invoicing by hand, without a computerised system.

What an invoice record contains

  • Issuer NIF, invoice series and number, issue date
  • Invoice type (full, simplified, corrective) and description
  • Recipient, where there is one
  • VAT breakdown and invoice total
  • Hash of the previous record, timestamp and system identification

What VeriFactu does not change

  • The invoice format: paper and PDF remain valid
  • How the invoice reaches the customer
  • The VAT return or the SII
  • Anything about payment

Software producers

Since 29 July 2025, producers must offer adapted systems with a responsible declaration of compliance. Ask your vendor, or your SAP partner, for it.

Penalties (art. 201 bis General Tax Law)

€50,000 per year for users of non-compliant systems; €150,000 per year for each type of non-compliant system a producer sells.

04 · Crea y Crece

Ley Crea y Crece in Brief

Rules for the invoice exchanged between businesses. Crea y Crece changes the invoice itself, which must be structured data and not a PDF, and makes the customer part of the process: receiving, rejecting and reporting when it paid.

Step 1

Supplier

Issues a structured e-invoice (EN 16931: UBL, CII, EDIFACT or Facturae).

Step 2

SPFE or private platforms

The AEAT’s public solution, or interoperable private platforms that also send a true copy to the SPFE.

Step 3

Customer

Receives the e-invoice and reports rejection and the date of full payment.

Private platforms must be free to interconnect with each other and meet the requirements of RD 238/2026 (ISO 27001, AS2/AS4, eIDAS, all four syntaxes, continuity). Customer consent is no longer needed to send an e-invoice.

Statuses and payments

  • Mandatory: rejection, the date of full payment, the due date
  • Voluntary: collection, non-payment
  • Presumed acceptance if the customer does not reject
  • Reported within four calendar days, excluding weekends and national holidays
  • Payment is reported whichever route the invoice took

One unique identifier

Each invoice is identified by the issuer’s NIF + series and number + issue date.

Scope

  • In: all businesses and professionals, as issuers and as recipients, when the customer is a business established in Spain.
  • Out: sales to consumers; simplified invoices unless a full invoice is requested.
  • Out: electricity and gas market operators; IATA clearing houses.
  • Special: the Basque Country and Navarre (own provisions).

Dates set by Order HAC/1028/2026

DateWhat applies
6 Oct 2026Order in force; the transition periods start
By Aug 2027The SPFE must be available at least two months before the first effective date
6 Oct 2027Businesses with turnover above €8M; for 12 months they also send a PDF unless the customer accepts the e-invoice alone
6 Oct 2028All other businesses and professionals
6 Oct 2029Status reporting becomes mandatory for individuals and income-attribution entities up to €8M

Penalties: lighter and less clear than VeriFactu’s

Ley 56/2007, art. 2 bis.9, provides a warning or a fine of up to €10,000, imposed by the Secretary of State for Digitalisation and AI. Its wording targets failing to offer e-invoicing or access to past invoices; how it applies to B2B breaches is debated, and neither RD 238/2026 nor the order adds a specific regime. The commercial consequence, customers who cannot process your invoice, will be felt first.

05 · Side by side

Side by Side: The Differences, Row by Row

The two rules share an authority and an invoice identity, but they answer different questions. This table sets them face to face.

The differences, row by row

AspectVeriFactuLey Crea y Crece
Core questionWas the invoice really issued, and is it unaltered?Did the structured invoice reach the customer, and when was it paid?
Policy goalFight sales suppression and tax fraudFight late payment; digitalise business-to-business trade
Legal basisLey 11/2021 · General Tax Law art. 29.2.j · RD 1007/2023 · Orden HAC/1177/2024 · RDL 15/2025Ley 18/2022 · Ley 56/2007 art. 2 bis · RD 238/2026 · Orden HAC/1028/2026
What is regulatedThe invoicing software and the records it producesThe invoice: its format, its exchange and its statuses
Who is obligedTaxpayers who issue invoices with softwareAll businesses and professionals in B2B relations, as issuer and recipient
TransactionsEvery invoice the system issues: B2B, B2C, simplifiedB2B only, customer established in Spain
Main exclusionsSII filers · Basque Country and Navarre · manual invoicingConsumers · simplified invoices · energy market operators, IATA clearing
Invoice formatUnchanged (paper, PDF or e-invoice), plus a QRStructured e-invoice (EN 16931: UBL, CII, EDIFACT, Facturae); PDF only during the transition
Data the AEAT getsAn invoice record (header, tax breakdown, hash), automatically in VERI*FACTU modeThe e-invoice through the SPFE, or a true copy from private platforms, plus statuses
Customer’s rolePassive: may check the QRActive: must receive, and report rejection and payment date
Payment dataNoYes: date of full payment within four days
Moment of truthWhen the invoice is issuedWhen it is exchanged, and again when it is paid
DatesLegal today: 1 Jan 2027 / 1 Jul 2027 · Announced: Oct 2028 for all6 Oct 2027 (> €8M) · 6 Oct 2028 (rest) · 6 Oct 2029 (status reporting for individuals)
Penalties€50,000/yr users · €150,000/yr per system for producersWarning or up to €10,000; application to B2B breaches debated
SII filersExemptFully in scope
VendorsResponsible declaration since 29 Jul 2025Private platforms must meet RD 238/2026 requirements

Swipe to see the whole table →

The same authority

Both send invoice data to the AEAT’s systems: records in one case, e-invoices or copies in the other.

The same invoice

Both identify an invoice by issuer NIF, series and number, and issue date.

The same direction

Both move Spain towards near-real-time, structured invoice data, the destination of the EU’s ViDA package from 2030.

06 · Where they meet

Where They Intersect: One Billing Event, Two Obligations

For a company subject to both, a single invoice triggers two flows that start at the same moment, in the same system, and end at the same authority. The invoicing system, whether ERP or billing software, is the “SIF” in VeriFactu terms.

One billing event, two lanes

StepVeriFactu lane: the recordCrea y Crece lane: the invoice
1Invoice record created at issuanceStructured file in EN 16931
2Hash of the previous record addedSPFE, or private platform + true copy
3QR on the invoice; URL field in e-invoicesAccepts or rejects
4Record sent (VERI*FACTU mode) or kept, signedPayment date reported within four days

Eight points where they meet

Where they meetWhat happensWhat to design
1 · The documentThe invoice VeriFactu records is the invoice Crea y Crece exchangesGenerate both from one billing event; never re-key
2 · The identityIssuer NIF + series and number + date identify the invoice in bothOne numbering logic; platforms must not renumber
3 · The QRStructured e-invoices carry the VeriFactu QR as a URL field rather than an imageMap the field in your B2B format
4 · CorrectionsA B2B rejection is a status. In VeriFactu, correcting means a corrective invoice or an annulment recordOne correction process that feeds both
5 · The authorityThe AEAT receives VeriFactu records and B2B copies and statuses, and SII records from larger companiesReconcile before the AEAT does
6 · The softwareThe same system must produce records and structured invoicesChoose once; check the vendor’s declaration and platform credentials
7 · The calendarOctober 2028 for most SMEs, on both, if the announcement is confirmedOne programme, one go-live
8 · The futureThe Ministry plans convergence of scope and technical aspects, with ViDA in mindAvoid one-off builds that convergence will undo

Swipe to see the whole table →

Complying with one does not satisfy the other

A VeriFactu record is not an e-invoice, and an e-invoice sent through a platform does not create the hash-chained record. Both obligations stand on their own.

Where they do not meet

Consumer sales and tickets are VeriFactu only. Payment reporting is Crea y Crece only. SII companies meet only the B2B side.

07 · Who, what and when

Who Must Do What, and When

The answer depends on SII, turnover and territory. One fact sorts most companies: SII is mandatory above roughly €6M of annual turnover, and SII filers are exempt from VeriFactu. In practice, almost every company in the first B2B wave (above €8M) is already in SII, so VeriFactu and B2B land together mainly on the second wave, in October 2028.

Profile by profile

ProfileVeriFactuB2B e-invoicingWatch
SII filer, turnover above €8MExempt6 Oct 2027; PDF alongside for 12 months unless the customer accepts the e-invoice aloneInbound: suppliers’ invoices will carry VeriFactu data
SII filer, €6M–€8MExempt6 Oct 2028Same as above
Not in SII, invoices with softwareOct 2028 announced (legal today: 1 Jan / 1 Jul 2027)6 Oct 2028One project for both
Joins SII voluntarilyExempt while in SII6 Oct 2028Leaving SII is only possible in November
Self-employed invoicing by handOut while invoicing by hand6 Oct 2028Structured e-invoices need software, and VeriFactu follows
B2C retailerApplies if not in SIIConsumer sales outB2B purchases still arrive as e-invoices
Basque Country / NavarreOwn regimes (TicketBAI in all three Basque provinces)Own provisions: confirmForal treatment still unsettled

Swipe to see the whole table →

VAT-group members and companies in the monthly refund register (REDEME) are also in SII. Each NIF is assessed on its own: groups usually mix profiles.

The combined calendar

29 Jul 2025

VeriFactu

Software producers must offer adapted software.

31 Mar 2026

B2B e-invoicing

RD 238/2026.

5 Oct 2026

VeriFactu

Postponement to October 2028 announced.

6 Oct 2026

B2B e-invoicing

Order in force.

1 Jan 2027

VeriFactu: legal until the BOE changes it

Corporate taxpayers.

1 Jul 2027

VeriFactu: legal until the BOE changes it

Others.

By Aug 2027

B2B e-invoicing

SPFE live.

6 Oct 2027

B2B e-invoicing

Turnover above €8M.

31 Dec 2027

SAP

SAP ERP 6.0 mainstream maintenance ends.

Oct 2028

VeriFactu: announced

All pending obligations.

6 Oct 2028

B2B e-invoicing

All others.

6 Oct 2029

B2B e-invoicing

Status reporting for individuals.

1 Jul 2030

EU

ViDA digital reporting.

The SII decision

A company below €6M can join the SII voluntarily (form 036) and so fall outside VeriFactu. The price: submitting invoice records, issued and received, within four days, and you can only leave in November, for the following year. For mid-sized companies with good data this can be the simpler route; for others VeriFactu is lighter. It is a real, dated decision worth taking before 2028.

08 · SAP

What It Means for SAP Users

Company code by company code. Most large SAP users in Spain file under SII, so VeriFactu can look irrelevant. It rarely is: smaller subsidiaries, suppliers’ invoices and the B2B obligation all reach the same SAP system.

VeriFactu in SAP

SAP Document and Reporting Compliance (DRC) offers a VERI*FACTU scenario for Spain, creating and submitting the records as electronic documents (SAP Help; SAP knowledge base article 3609812 collects the FAQ). It matters for company codes not in SII.

  • Check which company codes are outside SII.
  • Check whether invoices are also issued outside SAP (POS, portals, other tools), since every issuing system must comply.

B2B e-invoicing in SAP

DRC handles the outbound structured invoice and the inbound flow; SAP has indicated it will cover Crea y Crece in DRC. Confirm the release and SAP Notes once the SPFE specifications are final.

  • Decide the route: the SPFE directly or a private platform.
  • Decide where the full-payment date comes from (payment run, clearing, confirming, netting).
  • Review inbound processing for suppliers’ e-invoices.

Six design principles for one programme

PrincipleIn SAP terms
One billing event, two outputsThe billing document drives both the VeriFactu record and the structured e-invoice, with no parallel tools
One invoice identityNumber ranges, series and document dates designed once; no renumbering downstream
One correction processRejections, credit memos and cancellations mapped to both rules: corrective invoice and annulment record on one side, statuses on the other
Payment data from FIThe full-payment date comes from clearing in FI, not from a manual log. This is where most B2B projects underestimate effort
Clean master dataNIFs, addresses and tax codes valid for both validators
ReconciliationSII, VeriFactu and B2B data about the same invoice must agree: the AEAT can compare them

Invoices outside SAP

POS, portals or billing tools issue invoices too. Every issuing system must meet VeriFactu, and B2B invoices must go out structured.

Intercompany

Invoices between Spanish group companies are B2B: in scope for e-invoicing, and for VeriFactu where the issuer is not in SII.

Self-billing and third parties

When the customer or a provider issues the invoice for you, agree who generates the record and who sends the e-invoice.

Credit notes

Corrective invoices need their own record and their own e-invoice, linked to the original. Map them early.

The ERP clock comes first

Mainstream maintenance for SAP ERP 6.0 ends 31 December 2027, before both October 2028 dates. Legal updates after that require extended maintenance, available to 2030. For ECC users, the e-invoicing design and the S/4HANA plan are one decision.

Don’t stop the VeriFactu work

The October 2028 date is announced, not published. Keep the design moving, re-plan the go-live, and use the extra time to build VeriFactu and B2B as one project instead of two.

09 · How we help

How 30 Advisory Helps

One design for both rules, from Prepare to Run. One hour, no slides: we map your Spanish entities against both rules and tell you where to start.

Prepare

We map every Spanish NIF: SII or not, turnover band, territory, invoicing systems in use. You receive an entity map: who is in VeriFactu, which B2B wave.

Explore

One target design: billing event, numbering, corrections, payment data, route (SPFE or platform), and the SII decision where relevant. You receive the target design and roadmap.

Realize

SAP DRC configuration for VERI*FACTU and B2B, master-data fixes, end-to-end tests including rejections and payments. You receive a tested solution.

Deploy

Cutover, hypercare, cockpit routines for billing, AR, AP and tax. You go live with a buffer before the date.

Run

Regulatory watch: the BOE text of the postponement, the convergence reform, ViDA. Compliance becomes routine.

Six questions for your team

  • 1. Which of our Spanish entities are in SII, and which are not?
  • 2. Which systems issue invoices: only SAP, or also POS, portals or others?
  • 3. Does our software vendor have the VeriFactu responsible declaration?
  • 4. Will we use the SPFE or a private platform for B2B?
  • 5. Where will the full-payment date come from?
  • 6. Is our plan built on the legal VeriFactu dates or the announced one?

Our scope, honestly

We are SAP finance and compliance advisors, not a tax law firm. Tax positions stay with your tax advisers; we turn their decisions into a working process in SAP.

Book a free 60-minute diagnostic Download the Full Dossier (PDF, EN)