VeriFactu: Do You Really Need an Electronic Signature?
VeriFactu: Do You Really Need an Electronic Signature?
The short answer: it depends on your software's modeSince Spain's anti-fraud law (Ley Antifraude) and the VeriFactu regulation entered the scene, one...
The short answer: it depends on your software's mode
Since Spain's anti-fraud law (Ley Antifraude) and the VeriFactu regulation entered the scene, one question keeps coming up in offices across Lleida, Barcelona and Tarragona: do I need an electronic signature to issue invoices? The honest technical answer is that there is no universal "yes". It hinges on two things: the technical mode your invoicing software uses, and the channel through which you deliver invoices to your clients.

Under Royal Decree 1007/2023, which governs invoicing software (Sistemas Informáticos de Facturación, or SIF), there are two compliance routes. Each one carries different signature obligations, and confusing them is the most common source of unnecessary panic among autónomos, SMEs and gestorías.
Mode 1: VERI*FACTU — no per-record signature required
If your software operates in VERI*FACTU mode, it sends each invoicing record to the AEAT's electronic headquarters in a continuous, secure and near-instantaneous stream. That continuous submission is what guarantees the record's inalterability and authenticity. Because the tax authority receives the data in real time, it explicitly states in its official guidance that you do not need to electronically sign each individual invoicing record. Signing remains optional in this mode.
What you do need is to authenticate the sending connection itself using a qualified electronic certificate. That certificate can belong to the issuer, a legal representative, a social collaborator or the cloud service provider. In practice, this means the heavy lifting happens automatically behind the scenes — no manual signing ritual before every invoice.
Mode 2: non-verifiable systems — signature is mandatory
If your software stores records locally or does not submit them continuously to Hacienda, you are using a non-verifiable system. Here the regulation is strict: you must apply an advanced or qualified electronic signature to every invoicing record (both issuance and cancellation) and to the event log, using the XAdES Enveloped cryptographic standard.
This is where many businesses get caught out. A desktop tool that never talks to the AEAT may look cheaper, but it shifts a significant compliance burden onto your shoulders. For gestorías managing multiple clients, that burden multiplies quickly.
Clearing up the terminology
Part of the confusion stems from mixing up four related but distinct concepts:
- Electronic certificate: a digital document issued by a trusted certification authority (such as the FNMT) that proves the identity of a person or company and assigns them a cryptographic key pair.
- Electronic signature: the result of applying a cryptographic operation to data using a certificate's private key. It identifies the author and confirms the data has not changed since signing.
- Electronic seal: a variant intended for legal entities, designed to run unattended on servers and sign transactions automatically.
- Channel authentication: using a certificate to open an encrypted, identified connection with the AEAT when transmitting information — a different act from signing an individual record.
Signature levels under eIDAS
EU Regulation 910/2014 (eIDAS) defines three signature levels with different legal weight. A simple signature — ticking a box or entering a PIN without a qualified cryptographic basis — does not meet the requirements for tax records. An advanced signature is uniquely linked to the signer and allows reliable identification. A qualified signature adds a qualified certificate and a qualified creation device, giving it the strongest legal presumption.
For non-verifiable systems, the regulation demands at least an advanced signature. For channel authentication in VERI*FACTU mode, a qualified certificate is the norm.
What about B2B electronic invoicing?
Separately from VeriFactu, the B2B electronic invoicing framework (RD 238/2026) will push businesses toward structured invoice exchange. Here too, certificates and signatures play a role in ensuring authenticity and non-repudiation, but the obligations are tied to the invoicing format and the parties involved rather than to each VeriFactu record.
What to demand from your technology provider
When evaluating invoicing software, ask direct questions:
- Does it operate in VERI*FACTU mode with continuous AEAT submission?
- Which certificate does it use for channel authentication, and who owns it?
- If it is a non-verifiable system, how does it apply XAdES signatures to every record?
- How does it handle certificate renewal and revocation without interrupting invoicing?
- Does it keep an auditable event log, and is that log also protected?
A provider that answers these clearly is a provider that understands the regulation. One that dodges them is a risk.
The bottom line for Spanish businesses
If your cloud invoicing software is configured in VERI*FACTU mode, you are not legally required to manually sign each invoice. The continuous submission to the AEAT does the compliance work. If you use a non-verifiable system, signatures are mandatory and non-negotiable. Either way, a qualified certificate is needed somewhere in the chain — for authentication, for signatures, or for both.
At ALMC, we help autónomos, SMEs and gestorías across Catalonia implement VeriFactu-compliant invoicing without the guesswork: legal electronic invoicing, inalterable records and automatic submission to Hacienda. If you are unsure which mode your current setup uses, it is worth finding out before the next filing deadline.
Related
- VeriFactu AEAT: A Complete Guide for Spanish Businesses
- VeriFactu for Freelancers: Deadlines, Requirements and How to Prepare
- VeriFactu: Guide to Spain's Anti-Fraud Invoicing Law
- Automatización
Put these ideas into practice
Talk to ALMC about a solution for your business. Explore your options or contact our team.
