The Elo Cloud family
Guide

ZATCA Phase 2 E-Invoicing for Hotels in Saudi Arabia: Complete Compliance Guide 2026

EEloPMS Team··5 min read
ZATCA Phase 2 E-Invoicing for Hotels in Saudi Arabia: Complete Compliance Guide 2026

Saudi Arabia's e-invoicing system is being extended to smaller businesses in waves, and independent and boutique hotels are among the businesses being brought in. Check the current notifications on ZATCA's website, or ask your tax adviser, for what applies to your hotel and when.

ZATCA Phase 2 e-invoicing requires Saudi hotels to submit invoices to the Fatoora portal in real-time UBL 2.1 XML format with cryptographic stamps (PIH invoice hash).

This guide walks hotel operators through every technical requirement — from UBL 2.1 XML invoice structure to cryptographic stamp automation — with step-by-step setup instructions and common mistake avoidance strategies. Whether you manage a 30-room boutique hotel in Jeddah or a 200-room resort in Riyadh, you'll understand exactly what ZATCA Phase 2 demands and how modern hotel PMS platforms automate the entire e-invoicing workflow.

What Is ZATCA Phase 2 E-Invoicing? (Waves Explained)

ZATCA (Zakat, Tax and Customs Authority) is Saudi Arabia's tax regulator. The authority introduced e-invoicing in two phases:

Phase 1 (December 2021): Generation phase. Hotels began issuing e-invoices with QR codes on guest receipts. Basic compliance — the invoice needed a digital format and QR verification, but no real-time government submission required.

Phase 2 (started January 2023, rolling out in waves): Integration phase. Hotels in scope submit invoices to the Fatoora portal in real-time, using standardized UBL 2.1 XML format with cryptographic stamps and immutable audit trails.

ZATCA Phase 2 requires every invoice to carry three cryptographic elements: a unique UUID identifier, a hash of the invoice content (tamper detection), and a PIH (Previous Invoice Hash) that chains the current invoice to the one before it. This creates an unbreakable audit trail — if you edit invoice #100 post-submission, the PIH of invoice #101 breaks, and ZATCA's system immediately flags the violation.

The Wave Structure: When Do Hotels Need to Comply?

ZATCA brings businesses into Phase 2 in waves based on annual turnover, starting with the largest and moving down to smaller businesses. Each business is notified of its own integration date. If you received a ZATCA notification letter or see your assigned wave in the Fatoora portal dashboard, that is the date to plan around.

Why ZATCA Phase 2 Matters for Saudi Hotel Operators

ZATCA Phase 2 is not just a tax compliance checkbox — it fundamentally reshapes hotel financial operations:

Real-time tax transparency. The government tracks all sales and VAT collection the moment a guest checks out. No month-end reconciliation delays, no manual VAT filing errors.

Audit protection. An immutable digital trail means fewer manual audits. ZATCA knows your revenue in real time, so routine inspections decrease. VAT refund approvals process faster when your digital records match government data perfectly.

Guest trust. International travelers expect legitimate businesses to provide scannable QR code invoices. A missing or invalid QR signals an unregistered operation — damaging to boutique hotels competing with international chains.

Vision 2030 alignment. Saudi Arabia's digital economy mandate prioritizes tech-forward businesses.

Operational efficiency. No more end-of-month VAT nightmares. EloPMS's ZATCA integration auto-generates reports, calculates VAT across multi-currency bookings, and handles OTA commission VAT automatically.

ZATCA Phase 2 Compliance Requirements for Hotels: A Checklist

A hotel in scope needs these 12 technical and operational pieces in place:

  1. E-invoicing solution onboarded to Fatoora — a PMS or middleware that completes ZATCA's onboarding checks and holds a valid cryptographic stamp identifier (CSID)
  2. Fatoora portal integration — Real-time invoice submission API connectivity
  3. UBL 2.1 XML invoice format — Standardized e-invoice structure (NOT PDF-only)
  4. Cryptographic stamp generation — PIH (Previous Invoice Hash), invoice UUID, cryptographic signature
  5. QR code embedding — TLV-encoded QR on guest receipts with seller name, VAT number, timestamp, total, VAT amount
  6. Simplified vs Standard tax invoices — B2C guests receive simplified receipts with QR; B2B corporate bookings require standard invoices with full buyer details
  7. VAT calculation automation — 15% VAT on room + F&B, with exemptions for foreign diplomats and GCC nationals
  8. Multi-currency handling — Booking engine USD/EUR sales converted to SAR for ZATCA reporting
  9. Audit trail integrity — No invoice deletion or editing post-submission; immutable ledger
  10. Clearance vs Reporting invoices — B2B standard invoices require real-time Fatoora approval (clearance mode); B2C simplified invoices batch-submit within 24 hours (reporting mode)
  11. Error handling + resubmission — Automated retry mechanism for ZATCA rejection codes
  12. Compliance reporting dashboard — Real-time submission status, error log, Fatoora portal sync visibility

How EloPMS Automates ZATCA Phase 2 E-Invoicing for Hotels

EloPMS connects to ZATCA's Fatoora platform natively from the hotel accounting module and generates ZATCA Phase 2 e-invoices — no third-party middleware required. The workflow is transparent to front desk staff:

Real-time invoice flow: Guest checks out → folio finalized → UBL 2.1 XML auto-generated → cryptographic stamp applied → Fatoora portal submission → QR code printed on receipt. Total time: under 3 seconds.

Simplified vs Standard invoice auto-detection. The system reads guest type at checkout. Individual walk-in = simplified QR receipt (code 388, reporting mode). Corporate booking with captured VAT ID = standard clearance invoice (code 381, real-time approval required).

Multi-currency conversion. Your booking engine sells rooms in USD or EUR. At checkout, EloPMS auto-converts the transaction to SAR at the Saudi Central Bank rate, calculates 15% VAT, and submits the SAR-denominated invoice to Fatoora.

Channel manager integration. OTA bookings from Booking.com or Expedia sync via the channel manager. Commission amounts auto-calculate, VAT applies, and the ZATCA invoice issues at guest checkout — all without manual intervention.

Cryptographic stamp automation. PIH calculation, UUID generation, and invoice hash creation happen transparently. The system maintains the invoice chain automatically. If a hash mismatch occurs (indicating tampering), the compliance dashboard alerts the front desk immediately.

Error handling. If Fatoora rejects an invoice (wrong VAT ID format, missing buyer details), the system queues it for resubmission and alerts the front desk with the specific ZATCA error code. Staff corrects the issue (e.g., captures the guest's VAT registration number), and the invoice auto-resubmits.

Step-by-Step: Setting Up ZATCA Phase 2 E-Invoicing in Your Hotel PMS

Follow these steps ahead of your hotel's integration date:

1. Register hotel with ZATCA

Obtain your VAT registration number and onboard to the Fatoora portal. ZATCA will assign your wave and provide API credentials.

2. Obtain ZATCA compliance certificate

Onboard your PMS through the Fatoora portal: ZATCA issues the compliance certificate (CSID) that your PMS uses to sign invoices. Your PMS vendor (EloPMS, for example) supports this onboarding step. Each solution is checked during onboarding against ZATCA's technical requirements.

3. Configure PMS tax settings

Set VAT rate to 15% standard. Add exemption rules for GCC nationals and foreign diplomats. Define tax categories for room revenue, F&B sales, and miscellaneous charges.

4. Connect booking engine + channel manager to PMS

Multi-currency sales from your direct booking engine and OTA channels must flow into a unified ledger. EloPMS consolidates all revenue sources automatically.

5. Enable ZATCA API integration

Enter your Fatoora API credentials in the EloPMS accounting module. The system auto-connects and validates the connection with a test ping.

6. Test invoice generation

Run a sample B2C transaction (walk-in guest, cash payment). Verify the printed receipt includes a scannable QR code. Run a sample B2B transaction (corporate booking with VAT ID). Confirm Fatoora clearance approval arrives before checkout completes.

7. Train staff on VAT ID capture

Front desk teams must ask corporate guests for their VAT registration number. Without it, the system cannot generate a standard invoice, and clearance fails. Add this to your check-in script.

8. Go live + monitor

Switch to production mode. Review the compliance dashboard daily for the first two weeks. Check submission status, error rates, and Fatoora sync timing.

9. Monthly ZATCA portal reconciliation

Cross-check Fatoora portal records against EloPMS reports. Discrepancies indicate missed submissions or rejected invoices that need resubmission.

ZATCA Phase 2 Wave Structure: How Hotels Are Brought In

ZATCA rolled out Phase 2 in waves to avoid overwhelming the Fatoora portal. Here's where most hotels fit:

How to check your wave: ZATCA sent notification letters to VAT-registered businesses. You can also log into the Fatoora portal — your assigned wave and integration date appear on the dashboard home screen.

Rollout Plan for Hotels Joining a Wave

Preparation: Onboard PMS to Fatoora portal, test invoices in sandbox mode, train front desk and accounting teams.

Parallel run: Submit invoices to Fatoora but monitor errors closely. Keep legacy invoicing active as backup.

Cutover: All invoices go through Fatoora before guest checkout. Legacy invoicing disabled.

ZATCA Simplified vs Standard Tax Invoices: What's the Difference?

ZATCA defines two invoice types. Your PMS must detect which type to issue based on the guest's profile:

Simplified Tax Invoice (B2C)

For: Individual guests (walk-ins, tourists, personal bookings)

Format: QR code receipt with TLV-encoded data (seller name, VAT number, timestamp, total, VAT amount)

Submission mode: Reporting. Batch-submit to Fatoora within 24 hours.

Invoice code: 388 (subtype 02)

Example: Hotel guest checks out, pays by card, receives printed receipt with QR code. The invoice reports to Fatoora overnight in a batch file.

Standard Tax Invoice (B2B)

For: Corporate guests with VAT registration number

Format: UBL 2.1 XML with full buyer details (VAT ID, legal name, address, line-item breakdown)

Submission mode: Clearance. Real-time Fatoora approval REQUIRED before invoice finalizes.

Invoice code: 381 (subtype 01)

Example: Corporate booking. Front desk captures buyer VAT ID at check-in. At checkout, the system sends invoice to Fatoora for clearance, waits for approval (typically 2-5 seconds), then completes checkout and prints the approved invoice.

Comparison Table: Simplified vs Standard

Feature Simplified Invoice (B2C) Standard Invoice (B2B)
Recipient Individuals (walk-ins, tourists) Companies with VAT registration
Format QR code receipt UBL 2.1 XML
Submission Mode Reporting (24h batch) Clearance (real-time approval)
Guest Data Required Name only Name + VAT ID + address
Fatoora Approval Not required REQUIRED before checkout
Invoice Code 388 381
Use Case Leisure traveler pays cash Corporate booking, buyer provides VAT ID

Understanding UBL 2.1 XML Format: ZATCA's E-Invoice Standard

UBL 2.1 (Universal Business Language) is an ISO/IEC 19845 international standard for structured e-invoices. ZATCA chose UBL 2.1 for international interoperability and tax audit clarity.

Hotel-specific UBL fields include:

Invoice header: UUID (unique invoice ID), issue date, invoice type code (388 simplified or 381 standard)

Seller details: VAT number, legal name, address, commercial registration

Buyer details: VAT ID (if B2B), name

Line items: Room nights (quantity, unit price, subtotal), F&B charges, VAT per line

Tax totals: Total taxable amount, VAT 15%, grand total

Cryptographic stamp: PIH (previous invoice hash), current invoice hash, signature

EloPMS auto-generates UBL 2.1 XML in the background. Hoteliers never see the XML — the system handles formatting, validation, and Fatoora submission transparently. The front desk simply processes checkout as usual.

ZATCA Cryptographic Stamps: PIH, UUID, and Invoice Hash Explained

A cryptographic stamp is a digital signature that ensures invoice integrity. If anyone tampers with the invoice post-submission, the hash changes, and ZATCA detects it immediately.

Three components secure every invoice:

1. UUID (Universally Unique Identifier)

Each invoice receives a unique ID that is never reused. Format: 550e8400-e29b-41d4-a716-446655440000.

2. PIH (Previous Invoice Hash)

A SHA-256 cryptographic hash of the previous invoice in the sequence. This creates an immutable chain — if invoice #100 is edited, the PIH of invoice #101 breaks, alerting ZATCA to tampering.

3. Invoice Hash

A cryptographic hash of the current invoice content. Any post-submission edit changes the hash, triggering a mismatch alert.

Why it matters for hotels: Immutable audit trail eliminates manual record-keeping. When ZATCA audits your property, the cryptographic chain proves every invoice's authenticity automatically. No spreadsheets, no paper backups.

EloPMS automation: Cryptographic stamps auto-generate for every invoice. PIH chains maintain automatically. If a hash mismatch occurs (e.g., someone attempts manual invoice editing), the compliance dashboard flags the violation and blocks the transaction.

Common ZATCA Compliance Mistakes Hotels Make (And How to Avoid Them)

1. Missing VAT ID for corporate guests

Mistake: Front desk forgets to capture buyer VAT registration number during check-in. At checkout, the system tries to generate a standard invoice but fails clearance because buyer VAT ID is missing.

Impact: Guest checkout delayed. Frustrated corporate traveler. Possible no-show penalty from the booking company.

Fix: Train front desk staff to ask for VAT ID when a booking source is marked "corporate" or "company." Add a mandatory field in the PMS check-in screen for business guests.

2. Wrong invoice type

Mistake: B2C guest receives a standard invoice instead of simplified. Fatoora rejects because clearance mode was triggered unnecessarily.

Impact: Invoice rejection, delayed checkout, re-issuance required.

Fix: Let the PMS auto-detect invoice type. EloPMS reads guest profile (individual vs corporate) and selects simplified or standard automatically.

3. QR code printing errors

Mistake: Thermal printer settings misconfigured. QR code prints but is unreadable by smartphone scanners.

Impact: Guest complaints. ZATCA compliance technically met (QR present) but guest cannot verify invoice authenticity.

Fix: Test QR code scannability weekly. Use high-quality thermal paper. Configure printer DPI to 203 or higher.

4. Multi-currency conversion errors

Mistake: Booking engine USD sale NOT converted to SAR before submitting to Fatoora. Invoice shows USD amount. ZATCA rejects.

Impact: Invoice rejection, re-issuance required, delayed accounting close.

Fix: Configure PMS to auto-convert all non-SAR transactions to SAR at the Saudi Central Bank exchange rate before invoice generation. EloPMS handles this automatically.

5. Channel manager commission VAT

Mistake: OTA booking arrives via Booking.com. Hotel pays 18% commission. Accounting team forgets to apply VAT to the commission itself, underpaying tax.

Impact: Tax underpayment that surfaces during a ZATCA audit, with back-taxes owed.

Fix: Configure channel manager integration to auto-calculate VAT on OTA commissions. EloPMS applies VAT to commission amounts automatically.

6. Clearance timeout

Mistake: B2B standard invoice sent to Fatoora for approval. Fatoora portal experiences downtime. Checkout process stalls, guest waits.

Impact: Guest dissatisfaction, operational bottleneck.

Fix: Implement local queueing with auto-retry. EloPMS queues the invoice locally if Fatoora is unreachable, completes checkout, and auto-submits when the portal recovers.

7. Editing invoices post-submission

Mistake: Front desk discovers a pricing error after invoice clears Fatoora. Staff attempts to edit the invoice in the PMS. PIH chain breaks.

Impact: Audit trail violation. ZATCA detects hash mismatch. Compliance failure.

Fix: Train staff: invoices are immutable post-clearance. Corrections require a credit note (reverse the original) and a new invoice. EloPMS enforces this rule — editing locked invoices triggers a warning screen.

ZATCA vs FBR Compliance: What Multi-Country Hotel Groups Need to Know

If you operate properties in both Saudi Arabia and Pakistan, you face dual compliance mandates. Here's how ZATCA and FBR digital invoicing compare:

Similarities

Both require real-time e-invoicing, QR codes on receipts, audit trails, and POS integration.

Differences

Invoice format:

Submission mode:

Cryptographic requirements:

Tax rates:

Rollout:

EloPMS Advantage for Multi-Country Groups

EloPMS integrates natively with BOTH FBR digital invoicing and ZATCA's Fatoora platform. Hotel groups with properties in Lahore and Riyadh use one PMS for both countries' e-invoicing — no separate software stacks, no middleware integration costs.

Pakistan-based groups expanding into Saudi Arabia (or vice versa) use the same system for both e-invoicing regimes. One training program, one vendor relationship, one consolidated multi-property dashboard.

ZATCA E-Invoicing Checklist for Hotels: Are You Ready?

Use this checklist to verify your readiness before your integration date:

Conclusion: Future-Proof Your Saudi Hotel with Native ZATCA E-Invoicing

ZATCA Phase 2 is reaching smaller businesses wave by wave. A hotel in scope needs full ZATCA Phase 2 integration — UBL 2.1 XML invoices, cryptographic stamps, Fatoora portal connectivity, and simplified vs standard invoice automation.

EloPMS's architecture handles the entire technical stack: multi-currency booking engine conversions, channel manager OTA integration, front desk VAT ID capture workflows, and real-time Fatoora clearance. No third-party middleware. No bolt-on integrations. ZATCA e-invoicing built into every module.

Vision 2030 rewards forward-thinking hoteliers. ZATCA compliance is your operational advantage — faster VAT refunds, fewer manual audits, guest trust through QR code verification, and seamless integration with international hotel management contracts.

See ZATCA Phase 2 automation in action. Book a demo or start your 14-day free trial today. Experience how EloPMS eliminates manual ZATCA filing and turns compliance into a competitive edge.

Explore EloPMS tax e-invoicing features for Saudi Arabia — including FBR (Pakistan) and MyInvois (Malaysia) for multi-country hotel groups.


Sources

TagsZATCA Phase 2 hotelZATCA e-invoicing hotelFatoora portal hotel PMS

Frequently asked questions

What is ZATCA Phase 2 e-invoicing for hotels?
ZATCA Phase 2 requires Saudi hotels to submit invoices to the Fatoora portal in real-time using UBL 2.1 XML format with cryptographic stamps. It includes simplified invoices for individual guests and standard invoices for corporate bookings.
How do I know when ZATCA Phase 2 applies to my hotel?
ZATCA brings businesses into Phase 2 in waves based on turnover and notifies each business of its integration date; your assigned wave also appears in the Fatoora portal. Check the current notifications on ZATCA's website, or ask your tax adviser, for what applies to your hotel and when.
What is a UBL 2.1 XML invoice?
UBL 2.1 is the international e-invoice standard (ISO/IEC 19845) adopted by ZATCA. It structures invoice data in XML format for government tax systems to read automatically.
What is the difference between simplified and standard tax invoices?
Simplified invoices (code 388) are for B2C guests, include QR codes, and batch-submit within 24 hours. Standard invoices (code 381) are for B2B corporate guests, require full buyer VAT details, and need real-time Fatoora clearance before checkout.
What is a cryptographic stamp (PIH)?
PIH (Previous Invoice Hash) is a SHA-256 hash of the previous invoice in the sequence. It creates an immutable audit trail — editing any past invoice breaks the chain and alerts ZATCA to tampering.
Can I use my existing PMS for ZATCA Phase 2?
Only if your PMS connects to ZATCA's Fatoora platform and generates Phase 2 e-invoices (UBL 2.1 XML with cryptographic stamps). Generic accounting software or legacy PMS platforms without Fatoora API connectivity will not meet Phase 2 requirements.
What happens during Fatoora portal downtime?
Modern PMS platforms like EloPMS queue invoices locally during Fatoora outages, complete guest checkout, and auto-sync when the portal recovers. Guests never experience delays.
Do OTA bookings (Booking.com, Expedia) require ZATCA invoices?
Yes. When a guest from Booking.com checks out, your PMS must generate a ZATCA Phase 2 e-invoice and submit it to Fatoora. The guest type (individual vs corporate) determines invoice type.
Can EloPMS handle ZATCA e-invoicing for hotel groups?
Yes. EloPMS multi-property consolidation provides centralized e-invoicing reporting across all properties. Head office views Fatoora submission status, error rates, and VAT totals for the entire portfolio in one dashboard.
Back to all articles

Run your whole hotel on one system

See how EloPMS unifies your front desk, outlets, bookings and accounts. Start free, or book a quick demo.

Start 15-Day Free TrialBook a demo