- Wave 25, announced 24 July 2026, halves the integration threshold to SAR 187,500 of VAT-subject revenue (any year 2022–2025), with a Fatoora deadline of 1 February 2027. Wave 24 (SAR 375,000) passed its deadline on 30 June 2026.
- Zoho Books handles the mechanics: CSID onboarding, push to Fatoora with per-document status, locked invoices after sending, A3 PDFs with the cleared XML attached, and auto-push for recurring billing.
- Six things it does not do for you: Arabic master data, CSID renewal, push timing discipline, failed-push investigation, documents raised outside Zoho Books, and plan-level feature checks.
- If you are in Wave 25 and run Zoho Books, the critical path is your customer and item data — start there, not at the integration.
Wave 25 changed the question. On 24 July 2026, ZATCA published the criteria for the twenty-fifth integration wave: any taxpayer whose VAT-subject revenue exceeded SAR 187,500 in 2022, 2023, 2024 or 2025 must integrate with the Fatoora platform by 1 February 2027. That is half the Wave 24 threshold. For most small businesses in the Kingdom, integration is no longer an "if".
Many of those businesses run Zoho Books. So the practical question lands on our desk weekly: is Zoho Books enough for Phase 2, or do we need something more?
The short answer: Zoho Books is a Phase 2 compliant solution, and for a single-entity business invoicing from Zoho Books alone, it covers the core mandate. The longer answer is that "compliant solution" does not mean "compliance is handled". Several obligations remain yours. This note walks through both halves, based on Zoho's own Saudi Arabia documentation and ZATCA's published rules, verified on the date above. For the mandate itself, see our Saudi Arabia (ZATCA) compliance guide; for the ERP side, the Zoho integration page.
What Zoho Books handles
Fatoora integration and clearance
Zoho Books connects to the Fatoora platform through a Cryptographic Stamp Identifier (CSID). You generate a one-time password in the Fatoora portal, enter it in Zoho Books within one hour, and Zoho Books obtains the CSID. From then on, invoices, credit notes and debit notes can be pushed to Fatoora from inside the product. Each document carries a push status — Yet-to-be Pushed, Push Initiated, Pushed, or Failed — so you can see exactly what has cleared.
Document rules baked in
Phase 1 discipline carries through. Once an invoice is marked as sent, Zoho Books will not let you edit or delete it; corrections go through credit or debit notes, which is exactly what the regulation expects. Invoice PDFs export in the A3 format ZATCA specifies, with the cleared XML attached, and numbering is sequential.
Automation for recurring billing
Recurring invoices can be set to create, push and send automatically — or to land as drafts for a manual push. If an automatic push fails, Zoho Books surfaces the failure reason. Role permissions control which users can push transactions at all.
Where the limits are
1. Arabic master data is your job. Zoho Books will not generate a compliant e-invoice unless the customer name, billing address and item names are entered in Arabic. For standard (B2B) invoices, the buyer's full address details and identifiers are mandatory. None of this is transliterated for you. If your customer records were imported from a legacy system in English only, every one of them needs remediation before the first push succeeds. In our implementation experience this is the single largest piece of work in a Zoho Books Phase 2 project — not the integration itself. The pattern is the same one we documented in the rejection log as a master data audit.
2. The CSID lifecycle is manual. The onboarding OTP expires in one hour, and when a CSID expires or is revoked, pushes stop until someone renews it in the Fatoora portal and again in Zoho Books. There is no automatic renewal. If nobody owns this, you find out the CSID lapsed when invoices start failing — usually at month-end.
3. Push timing is still a human obligation. ZATCA's rule is precise: standard invoices must be cleared with Fatoora before they go to the customer; simplified invoices must be reported within 24 hours. Zoho Books gives you the button and the automation options, but nothing stops a user emailing a PDF before pushing, and drafts created under certain recurring-invoice preferences wait for a manual push. The timing discipline has to live in your process.
4. Failed pushes need investigation. A Failed status means someone must read the error, fix the underlying data — usually an address field, a missing identifier, or Arabic text — and retry. There is no queue that self-heals. High-volume businesses need a daily habit of reviewing push failures, or a monitoring layer that does it for them.
5. Zoho Books clears what lives in Zoho Books. The integration covers invoices, credit notes and debit notes raised in Zoho Books. If part of your revenue is billed elsewhere — a point-of-sale system, an e-commerce checkout, a project billing tool — those documents are outside this pipeline and need their own route to Fatoora. Multi-system businesses should map every document source before assuming they are covered.
6. Check your plan and edition. E-invoicing sits in Zoho Books' Saudi edition, and feature availability can vary by subscription plan. Before committing a rollout date, confirm with Zoho that your specific plan includes Phase 2 push — do not assume it from the marketing page.
"Compliant solution" does not mean "compliance is handled". The software clears the invoice; the data and the discipline are yours.
Abridged summary of the requirement, not the regulation text: Phase 2 requires invoices in UBL 2.1 XML with a cryptographic stamp, UUID and QR code, transmitted to Fatoora via API — clearance for standard invoices, reporting within 24 hours for simplified ones. Read ZATCA's detailed guidelines for the full text.
What this means if you are in Wave 25
The deadline is 1 February 2027. Working back from it, a realistic Zoho Books plan looks like this:
Now to October 2026: audit customer and item master data for Arabic completeness and mandatory fields; fix the gaps. This is the long pole.
November 2026: onboard the CSID, run test pushes, and give CSID renewal and failure monitoring a named owner.
December 2026 to January 2027: run live with daily failure review, well before the deadline. ZATCA has enforced penalties for non-compliance once waves go live, so a buffer matters.
If your invoicing spans more than one system, or the master data problem is large, that timeline stretches. Start from the data, not the deadline. The readiness assessment is the structured version of that first step — and our e-invoicing practice and data practice pick up where the software stops.
Regulatory positions on this page were verified against ZATCA's published announcements and Zoho's Saudi Arabia documentation on 10 August 2026. Waves and thresholds change — check ZATCA's primary documents before relying on any figure or deadline.