
The 2026 finance law has reshuffled the deck on a point that many merchants have not yet integrated: the individual publisher’s certificate is reinstated. In practical terms, the NF525 certification is no longer the only path to compliance. The tax administration maintains the obligation to meet the four ISCA requirements (immutability, security, preservation, archiving), but it now accepts two proofs on the same level, without hierarchy: the certificate issued by an accredited body or the individual certificate from the software publisher.
Publisher’s certificate or NF525 certificate: technical implications for the merchant
The individual certificate reinstated on February 21, 2026, must follow the BOI-LETTRE-000242 model. It precisely identifies the software (name, version, license number), expressly refers to the four ISCA requirements, and bears the date and signature of the publisher. A merchant who holds this document is compliant, just like a peer equipped with software certified NF525 by LNE or INFOCERT.
Recommended read : Payment delays from Pôle emploi in 2026: pitfalls to avoid to claim your rights
The nuance lies elsewhere. In the event of a tax audit, the publisher’s certificate shifts the technical responsibility to the software provider. If the administration finds a flaw in the ISCA conditions, it is the publisher who must justify the compliance of their solution. We therefore recommend verifying the legal and technical robustness of the publisher before settling for a certificate: a financially fragile or unresponsive publisher regarding regulatory updates poses a direct risk to the merchant.
To understand the obligations related to the mandatory cash register in 2026 for merchants, it is essential to distinguish between software compliance and hardware compliance, two areas that the administration treats separately.
Related reading : Everything You Need to Know About Mandatory Motorcycle Equipment in Spain: What the Law Says
Card payments outside the cash register: the warning signal in a tax audit

Electronic payment terminals (TPE) are not subject to NF525 certification. This exemption creates a blind spot that the administration now actively exploits during accounting checks.
The mechanism is simple. The inspector compares the TPE transaction log (provided by the bank or payment service provider) with the tickets recorded in the cash register software. Any card payment not recorded in the cash register constitutes a major warning signal. Law firms specializing in tax law confirm that the administration can require payment contracts and cross-check these flows to detect revenue omissions.
The risk particularly concerns businesses that use a standalone TPE, not connected to the cash register software. This “off-chain” configuration is perfectly legal, but it imposes absolute rigor in the manual entry of transactions. In practice, we observe that this type of setup generates recurring discrepancies, even if unintentional.
- Ensure that each card transaction from the payment statement corresponds to a line in the cash journal
- Keep TPE contracts and monthly statements for the duration of the tax prescription
- Prefer a direct connection between the TPE and the cash register software to eliminate the risk of discrepancies
All-in-one software and the actual certification scope
Only the cash collection component of an ERP must be certified or attested. A business management software that integrates accounting, inventory, and cash register does not need a global certification. The obligation exclusively pertains to the module that records payments from individual customers.
This distinction has direct practical consequences. A merchant using an ERP whose cash module has a compliant publisher’s certificate is compliant, even if the other components of the software are not certified. Conversely, if the payment module is separate from the rest of the solution (third-party plugin, custom development), it is this specific module that must be subject to a certificate or attestation.
We recommend asking the publisher for a document that precisely identifies the scope covered by the certificate. A vague certificate that mentions the commercial name of the software without detailing the version of the cash module does not provide protection in the event of an audit.
Electronic invoicing and certified cash register: two distinct obligations to synchronize

The electronic invoicing reform will become operational on September 1, 2026, with the obligation to receive for all businesses. The mandatory issuance follows a staggered schedule. These two projects, certification of the cash register software and electronic invoicing, are legally separate but technically linked.
A cash register software compliant with ISCA requirements does not automatically generate electronic invoices in the required format (Factur-X, UBL, or CII). The merchant selling to professionals must ensure that their system can issue or receive invoices via a partner dematerialization platform (PDP) or the public invoicing portal.
- ISCA compliance covers sales to individuals recorded in the cash register
- Electronic invoicing concerns B2B transactions, with standardized formats
- A software can be NF525 certified for the cash register without managing electronic invoicing, and vice versa
- Anticipating the choice of a PDP compatible with the cash register software avoids double investment
The timeline requires addressing both topics in parallel, not one after the other. A merchant who postpones the issue of electronic invoicing to 2027 risks having to change solutions just after becoming compliant with the cash register.
Sanctions and control: what the €7,500 fine really covers
The fine provided for by the General Tax Code applies per non-compliant software or cash register system, not per establishment or per company. A merchant operating three points of sale with three non-compliant cash registers is exposed to three distinct fines.
Beyond the financial penalty, the lack of compliance undermines all VAT declarations. The administration can challenge the deductibility and proceed to reconstruct revenue based on monetary and banking flows. The cost of a reassessment far exceeds that of achieving compliance.
The issue of the cash register in 2026 is not limited to obtaining a compliance document. It is about securing the entire chain, from the payment terminal to the cash register software, including archiving and electronic invoicing. Merchants who treat these obligations as separate projects multiply the risks of inconsistency, exactly the type of flaw the administration looks for during an audit.