Mandatory e-invoicing : real time tax control now has a name
Why this reform is landing now, who it really targets, and what nobody is saying
Sorting truth from fiction before going any further
The subject is polluted. On one side, a smooth official narrative that presents e-invoicing as a painless modernization, almost a gift to businesses. On the other, a haze of posts and threads that see in OpenPeppol a global cartel steering, from Brussels, the mass surveillance of French tradespeople.
Let’s settle what’s false first, so that we can then talk about what’s true.
No, OpenPeppol is not a “private-law monopoly created by the European Commission.” It’s a Belgian nonprofit, born of a European research project launched in 2008, that publishes specifications for exchange formats, exactly as the IETF publishes RFCs for the internet. Its governance is private and international, which is a fair concern when a technical standard becomes mandatory under French law without thorough parliamentary debate. But its foreign members (including those outside the EU) do not “control” your data, for the same reason that China’s seat at the ISO doesn’t give it access to your screw-thread standards.
No, the reform does not impose a “mandatory digital identity” in the biometric or civic sense of the term.
No, a company cannot be “thrown out of the lobby” and stripped of its right to invoice. Companies are not members of OpenPeppol: the platforms are. You choose a certified platform; you join nothing.
These exaggerations are counterproductive. They let the administration dismiss the entire critique without answering the legitimate points. And legitimate points do exist.
Once these exaggerations are set aside, what remains is a reform that raises real questions: about the concentration of economic flows, about data sovereignty, and about the asymmetry of its effects depending on the size and mobility of those involved.
What the reform really is
VAT fraud in France represents an estimated shortfall of somewhere between €10 and €20 billion a year, depending on the methodology. The DGFiP (France’s tax authority) leans toward the low end (€6 to €10 billion using a top-down method), the national statistics institute INSEE toward the high end (€20 to €25 billion), and in 2025 the Court of Auditors lamented the absence of a robust, up-to-date estimate. The exact figure hardly matters. The real question, absent from the official press releases, is a simple one: if this shortfall has been known for years and is relatively stable, why the urgency in 2026?
The answer comes down to three texts. EU Directive 2014/55 mandates e-invoicing for public procurement. Ordinance 2021-1190 extends the obligation to private B2B. The September 2024 decree sets the final timeline, which has to be read carefully, because each deadline covers a different scope:
- September 1, 2026: the obligation to receive electronic invoices for all businesses, including very small businesses and micro-enterprises. At the same time, the obligation to issue electronic invoices and to transmit e-reporting for large and mid-sized companies (ETI). B2C e-reporting (flow summaries) also begins on this date for all taxable entities.
- September 1, 2027: the obligation to issue electronic invoices for SMEs, very small businesses, and micro-enterprises.
The asymmetry is worth emphasizing: the smallest businesses will have to receive, process, and report their B2C flows starting in 2026, a full year before they are even required to issue. Large companies, meanwhile, will get an entire year’s head start to break in their systems before their very small suppliers are forced to follow.
What was originally pitched as administrative simplification has gradually revealed itself for what it really is: a tool for real-time tax control.
The technical term is e-reporting. In practice, it isn’t merely about sending your client an invoice in digital form. It’s about reporting the details of every B2B transaction to the French tax authority, the DGFiP, in near real time. For B2C flows (retail sales, bakeries, shops), what gets transmitted is a summary of the flows (the equivalent of an end-of-day register total, the “Z report”): amounts and VAT by period and by category, not the identity of each customer or the contents of each basket. The State sees the overall financial flow, not yet the itemized, named receipt. The distinction matters: let’s not leave it to the conspiracy theorists to distort.
I’ve already detailed the concrete implications for online merchants in an article devoted to WooCommerce, PrestaShop, and Shopify stores: if you sell online, your current invoicing workflows are not compliant with the new framework. This is not a concern for large accounts alone.
The technical architecture: the private tollbooths on the tax highway
Three players structure this system, and confusing them is the source of every misinterpretation.
The PPF, or Public Invoicing Portal, is the central state hub, the heir to Chorus Pro (already in use for invoices to public administrations). It’s the node toward which everything converges and from which the DGFiP draws in the flows. Its role is sovereign, its funding public.
The PA, or Approved Platforms (formerly called PDP, Partner Dematerialization Platforms, a label still in common use but officially replaced as of July 2025), are another matter. These are private operators, certified by the DGFiP, that serve as mandatory intermediaries for all B2B exchanges. Think of them as the tollbooths on a highway: you don’t get to choose whether to use them, only which one. Their certification guarantees their tax compliance. It guarantees little else. This is exactly the pattern I described in connection with fiber optics and its seven invisible subcontractors: behind the promise of a simple service lies a chain of private players you never chose.
OpenPeppol is the body that publishes the technical specifications for the exchange formats (UBL, CII, Factur-X). It’s a standardization layer, the way HTML is a standardization layer for the web. Its governance is private and international, which, it bears repeating, becomes politically problematic when this piece of technical machinery becomes a legal obligation without explicit democratic debate.
The resulting architecture is easy to grasp: every French B2B invoice will now pass through a certified private third party (the PA) and be reported in real time to the administration (via the PPF). The siphoning of economic flows is total, structural, and irreversible.
Why now: the real question
James C. Scott, the American political scientist, developed in Seeing Like a State (1998) a concept that illuminates this reform better than any technocratic commentary: state legibility. A state intervenes effectively only on what it can read, measure, and trace. The history of modern states is the history of the gradual reduction of the illegible: land registries, censuses, the standardization of surnames, social-security numbers. The mandatory accounting crystallization of every commercial transaction is the latest chapter in this long saga.
But why is this chapter being written now?
What has changed over the past decade is mobility. The wealthiest 10% of taxpayers account for roughly 70% of income tax in France. And a growing share of them has realized it can legally settle elsewhere (Lisbon, Dubai, the Canary Islands) without severing every economic tie to France. Tax optimization is no longer reserved for multinationals; it has become available to skilled freelancers, mobile professionals, and digital entrepreneurs. Gabriel Zucman has documented this mechanism of legal avoidance in detail in his work on the hidden wealth of nations.
The mechanism that kicks in is therefore accounting-driven, not ideological: fewer mobile taxpayers captured, sustained pressure on the sedentary ones, and a need for unprecedented granularity of control over those who stay. This isn’t a conspiracy. It’s an administrative rationality perfectly consistent with itself, and that is precisely what should worry us.
The “Scottian paradox” is that this digital enclosure of the territory accelerates the very thing it’s trying to offset. The tighter the system closes around the sedentary, the more it pushes the next ones to leave. The spiral feeds itself. I analyzed a local version of this same mechanism in connection with the French administrative mille-feuille: decisions made far from citizens, with no direct mandate, whose consequences always fall on the same people.
Who pays, and who slips through the cracks
The reform strikes those whose entire economic activity is domestic, visible, traceable: tradespeople, sole proprietors, very small businesses, small shopkeepers, professionals with a local clientele. They are the ones who will pay the subscriptions to the Approved Platforms, train their staff, and upgrade their software. The URSSAF, the agency that collects social-security contributions, already drops a cash-flow guillotine on them every third quarter with its brutal recalculations. E-invoicing piles a layer of fixed cost onto businesses whose margins don’t always absorb it.
It does not strike the optimized structures: foreign holding companies, non-residents, firms operating from other European jurisdictions. By design, those flows fall outside the reform’s perimeter.
The digital divide is a real and underestimated risk. A 58-year-old rural craftsman still writing invoices on carbon-copy pads will receive no structural support whatsoever. The legal obligation comes with no credible sector-wide training plan.
This asymmetry is nothing new. It fits into what I described in connection with the France of estates and fiscal racketeering: a system that bears down on the visible and spares the mobile, structurally and deliberately.
The case of the regulated professions: where the conflict turns constitutional
This is where the reform raises the most serious questions, and the least discussed.
The professional confidentiality of lawyers, doctors, and accountants is not a contractual convenience. It’s a constitutional guarantee, protected by centuries of case law, because it underpins the effective freedom to access justice and health care.
Yet the reform requires that every B2B invoice pass through a PA: a private commercial operator, subject to its own terms and conditions, its own security incidents, its own shareholders.
The question isn’t whether the content of a legal consultation will be read by the platform. It won’t. The question is one of metadata. The mere knowledge that a struggling company billed 50 hours to a lawyer specializing in restructuring, on a specific date, for a specific amount, is major strategic intelligence. It reveals the existence of a pre-litigation proceeding, the likely nature of a financial difficulty, perhaps the identity of a creditor. Confidentiality isn’t only about the text of an invoice: it’s about the very existence of the flow.
The current texts don’t clearly answer this question. Have the professional bodies obtained enforceable contractual guarantees on this point? On what legal basis? The answer, if it exists, isn’t public.
This is not an isolated case. I raised similar questions about the European digital identity: promises of security are worth only as much as the contractual guarantees on metadata, not just on content.
The real technical risks
The PPF as a single point of failure. By concentrating the siphoning of economic flows into one central hub, the reform creates a Single Point of Failure for the French economy. A major outage, a successful cyberattack, a data corruption, and a significant share of the country’s economy can no longer invoice legally. The French State has already shown it can lose 1.2 million banking records over a single stolen password. Trust in the resilience of public digital infrastructure is not a given.
A widened attack surface. Concentrating flows into a small number of nodes (the PPF plus a few dominant PAs) creates prime targets for malicious actors, whether state-backed or criminal. The question isn’t whether an attempt will be made, but when, and with what consequences.
Concentration in the Approved Platform market. In early 2026 the DGFiP published a list of more than a hundred approved PAs, so the starting point looks open and competitive. But this initial profusion won’t last: in any market with network effects, consolidation is mechanical. Within three to five years, a handful of dominant players will capture most of the flows. They will become critical infrastructure in fact, without the legal status of critical infrastructure. What happens if one of them is bought out by a foreign fund? Raises its prices by 300%? Shuts down?
Vendor lock-in and the archival black hole. A very small business that picks a PA today is committing for far longer than two years. The legal retention period for tax archives is ten years. What export formats are guaranteed? What are the migration costs? And above all: if a PA goes bankrupt three years after you sign up, who recovers your certified archives? Who guarantees their evidentiary value over the seven years that remain of the legally required retention period? The current texts don’t answer this question. It’s a legal void the drafters seem either not to have seen or to have carefully avoided.
Data sovereignty. DGFiP certification guarantees a PA’s tax compliance. It guarantees neither sovereign hosting, nor the absence of subcontracting to non-European actors, nor GDPR protections beyond the legal minimum. It’s the same question I raised about the US Cloud Act and sovereign AI: a national certification isn’t enough to guarantee that your data stays out of reach of a foreign subpoena. Reading your PA’s contracts with a specialized lawyer isn’t paranoia: it’s due diligence.
The real cost for very small businesses. A subscription to the Approved Platform, an upgrade of the invoicing software, training time, and possibly beefed-up accounting support: the burden is real and recurring, for businesses whose margins are not always so. The reform mechanically creates a new captive market for software vendors and service providers, exactly like the subscriptions forced into cars or the paid upgrades of Adobe Creative Cloud: opting out of paying simply isn’t on the table.
What you should do: be an actor rather than a subject
The reform is inescapable. The dates are set, the texts are published, the first audits will come. There’s no point burning energy contesting it: it’s been in the regulatory pipeline since 2021, and no political force has seriously challenged it. The only variable you still have any grip on is your degree of preparation and clear-sightedness.
But preparation does not mean silent capitulation.
This system was designed for the sedentary. It rests on the assumption that you have nowhere to go, that you’ll shoulder the burden without flinching, that you’ll sign with the first PA that comes along because you don’t have time to read the terms of service. That assumption is exactly what has to be refused: not by boycotting a legal obligation, but by choosing demandingly rather than submitting by default.
Check right now whether your invoicing software supports the Factur-X and UBL formats. Don’t take the vendor’s word at face value: ask for a technical demonstration with a real flow. If you use Odoo, I’ve documented how to deploy it and connect it to your banking and e-commerce flows. It’s one of the few solutions that natively covers the entire chain.
Choose your Approved Platform on criteria that go beyond price. Financial soundness, sovereign hosting, subcontracting policy, portability and termination terms. Ask the question outright: “If I want to leave in three years, how do I recover my ten years of archives in a standard, enforceable format?” If the answer is fuzzy, walk away.
Plan for incoming flows. As of September 1, 2026, every business without exception will have to be able to receive electronic invoices. Your large-company suppliers will switch over on that date, whether you’re ready or not.
Question your accountant. Are they ready themselves? Have they chosen and tested a PA? If the answer is vague, that’s a signal: not about the reform, about them.
For the regulated professions, put the question explicitly to your professional body: what metadata-confidentiality guarantees have been negotiated with the DGFiP? Get the answer in writing. If Signal remains the only tool that truly guarantees the confidentiality of communications, it’s precisely because no metadata is exposed to third parties, a standard the Approved Platforms come nowhere close to meeting.
The reform is technically coherent, administratively rational, and politically deliberate in its asymmetry, even if no one at Bercy, the finance ministry, will ever have the nerve to put it that way. It was built to close the gate on those who stay, while those who can leave keep leaving. This isn’t a conspiracy. It’s worse: it’s a deliberate, documented choice, perfectly rational from the standpoint of those who made it.
The only dignified response is to refuse to make their job easy.