What VERI*FACTU is
Under the regulation approved by Royal Decree 1007/2023, invoicing software must generate, for every invoice, a tamper-evident registration record, chained to the previous one by a cryptographic hash, and must print a QR code on the invoice.
In VERI*FACTU mode those records are submitted to the tax agency continuously and automatically, at the moment of issue. In exchange, the system is exempt from electronically signing each record and from the retention requirements imposed on non-verifiable systems.
It is the simplest route to compliance. It is the one we implement.
The deadlines set by Royal Decree-Law 15/2025
- 29 July 2025 Invoicing software vendors and developers. Already passed: software on the market must comply with the regulation.
- 1 January 2027 Companies (SL, SA) and other corporate income tax payers.
- 1 July 2027 Self-employed workers and remaining obliged parties under personal income tax.
Dates per Royal Decree-Law 15/2025. This page is general information about the regulation, not tax advice — check your own situation with your adviser.
Where it applies
The regulation applies throughout Spanish territory, without prejudice to the foral tax regimes of concierto and convenio económico in force in the historical territories of the Basque Country and in the Chartered Community of Navarre.
What decides it is not where you invoice but where your tax domicile is. A tax domicile in common territory is in scope even if you sell in Bilbao. A tax domicile in the Basque Country or Navarre is outside this regulation, and we do not onboard those taxpayers: those territories regulate invoicing themselves, and it is their own foral tax authority to ask.
The Canary Islands, Ceuta and Melilla are in scope, with IGIC and IPSI standing in for VAT.
Royal Decree 1007/2023, article 1.3.
About certification
VerifactuCloud is not certified, approved or endorsed by the Spanish tax agency. The regulation provides for no prior approval: it is the software vendor who files a declaration of responsibility stating that their system complies. Ours is signed. Nobody can sell you an AEAT seal, because none exists. Be wary of anyone who tells you otherwise.
Frequently asked questions
Is VerifactuCloud approved by the AEAT?
No, and no provider is. The regulation provides for no prior approval: the vendor files a declaration of responsibility stating that their system complies.
Do I have to use VERI*FACTU?
You may opt for a non-verifiable system, but then you take on electronically signing every record plus additional retention requirements. VERI*FACTU is the simpler route, and it is the one we implement.
What happens if the connection to the AEAT drops?
The record is still generated and chained — that does not depend on AEAT. The submission stays queued. If AEAT rejects the record, it is resent automatically. If the connection itself fails, we do not resend blindly: AEAT may already hold it, and a duplicate in the ledger cannot be undone. That case is settled by asking AEAT what it has on file. The obligation is to submit, not to hit an exact instant.
What if I issue an invoice by mistake?
A cancellation record is submitted. Records are never deleted: they are cancelled, leaving a trace.
Does this work for self-employed workers?
Yes. Your deadline is 1 July 2027. You can connect your own system to our API, or use our invoicing application, which is what we invoice with ourselves.
Does it replace my invoicing software?
No. Today it connects to it: you keep issuing where you issue, and we handle the record and the submission.
Where is the data stored?
On our own hardware, in our office in Rojales (Alicante). The database is not with a cloud provider: the cluster is ours and will grow by adding nodes in the same place. Two things do leave. Backups are stored encrypted in Cloudflare R2 and kept for 90 days, with a Western Europe location hint — a placement preference, not a residency guarantee. And the verification email for partner accounts is sent through Scaleway (France), which receives the destination address and the text of the message, nothing else. In GDPR terms you are the controller of your data, we are the processor, and Cloudflare and Scaleway are sub-processors. What we have not settled is the retention period for each record. The huella chain is append-only by design, so deleting a link would break verification: we keep records for as long as the chain has to remain verifiable and for as long as tax rules require. The exact period is still pending legal review, and we will publish it here once it is set.
Let's talk
We are in production and taking on customers. Tell us what you invoice with, what volume you handle and how you want to integrate it, and we will tell you what fits and what does not. If you are integrating the API yourself, you can sign up directly in the partner dashboard.
- General, technical and integration enquiries hola@verifactucloud.com