Validation artifacts
Versions, sources, and checksums of the validation artifacts used by the Beliq e-invoice engine.
Beliq validates every generated and uploaded e-invoice against official standards artifacts. This page lists the versions currently used in production. The same Italy FatturaPA XSD bundle applies to POST /v1/generate (standard: "fatturapa") and to POST /v1/validate when FatturaPA invoice XML is detected — POST /v1/parse accepts UBL 2.1 and CII only (FatturaPA and SDI messaggio inputs are validated, not parsed). Italy SDI file messaggio XML (MessaggiTypes) uses a separate vendored XSD graph and is validated only on POST /v1/validate when format=sdi_messaggio is set or when a known messaggio root is auto-detected — it is not FatturaPA invoice validation.
For the machine-readable version of this inventory, call GET /v1/rulesets: the same pinned versions and artifact hashes, keyless and with no quota cost.
Current versions
| Artifact | Version | Release date | Official source |
|---|---|---|---|
| EN 16931 CII Schematron | 1.3.16 | 2026-04-04 | ConnectingEurope/eInvoicing-EN16931 |
| EN 16931 UBL Schematron | 1.3.16 | 2026-04-04 | ConnectingEurope/eInvoicing-EN16931 |
| XRechnung Schematron | 2.6.0 | 2026-08-31 | itplr-kosit/xrechnung-schematron |
| Peppol BIS Billing 3.0 Schematron (UBL) | 3.0.21 | 2026-05-20 | OpenPEPPOL/peppol-bis-invoice-3 @ 780387ca — OpenPEPPOL publishes Billing validation artefacts on release branches and cuts no tag, so the pin is a commit. Mandatory on the Peppol network since 2026-08-17. |
| Factur-X 1.09.2 / CII D22B Schematron + per-profile XSDs (all 5 profiles: MINIMUM, BASIC_WL, BASIC, EN16931, EXTENDED) | 1.09.2 | 2026-09-04 | FNFE-MPE / FeRD joint pack — primary for BASIC_WL / EN16931 / EXTENDED; Mustangproject (Apache-2.0) secondary for MINIMUM and BASIC (FNFE-MPE-recommended downstream consumer; pinned to tag core-2.26.0). |
| France BR-FR-CTC Flux 2 Schematron (CII + UBL) | 1.4.0.04 | 2026-09-04 | FNFE-MPE on behalf of DGFiP / AIFE |
| France EXTENDED-CTC-FR Schematron (CII + UBL) | 1.4.0.04 | 2026-09-04 | FNFE-MPE on behalf of DGFiP / AIFE |
| Italy FatturaPA XSD (ordinaria/PA VFPR/VFPA 1.2.3 + semplificata VFSM 1.0.2, runtime bundle) | 1.4-runtime-2026-05-01 | — | fatturapa.gov.it — formato / XSD v1.4 |
| Italy SDI MessaggiTypes XSD (file messaggio v1.1) | 1.1.0-pinned-2026-05-02 | — | fatturapa.gov.it — Messaggi v1.1 + xmldsig companion. Runtime: POST /v1/validate with format=sdi_messaggio or auto-detect on known messaggio roots — XSD only, not FatturaPA invoice validation. |
| Italy SDI transport — SOAP / spec URL bundle (reference URLs only, not vendored) | sdi-interchange-1.8.4-urls-2026-04-28 | — | DocumentazioneSDI + Specifiche tecniche v1.8.4 PDF + WSDL/XSD export tree. Reference only — SDI submission, signing, and operator interchange are not implemented in Beliq (italy_sdi_transport is blocked); transmission belongs to your SDI intermediary. |
| Spain Facturae XSD (3.2.2 runtime bundle) | 3.2.2-research-2026-05-24 | 2017-06-06 | facturae.gob.es — formato (MINECO unified spec). Runtime: XSD-only on POST /v1/generate (standard: "facturae") and POST /v1/validate (format=facturae or auto-detect). |
| Slovenia e-SLOG XSD (2.0 runtime bundle, INVOIC v200 + xmldsig companion) | 2.0-08-2020 | 2020-08 | epos.si (GZS/ePOS invoice package). Runtime: XSD-only on POST /v1/generate (standard: "eslog", invoices + credit notes) and POST /v1/validate (format=eslog or auto-detect on the urn:eslog:2.00 root). |
| Romania RO_CIUS Schematron (XSLT pair: EN 16931 CIUS-RO + RO e-Factura operational/VAT) | 1.0.9 | 2024-06-05 | Helger phive-rules-cius-ro 4.5.6 (Maven Central, Apache-2.0; vendors ANAF’s authoritative XSLT). Runtime: fired on UBL invoices carrying the CIUS-RO CustomizationID (urn:efactura.mfinante.ro:CIUS-RO:1.0.1 current or RO_CIUS:1.0.0.2021 legacy). The CIUS-RO XSLT bakes in EN 16931 + Peppol BIS rules; both XSLTs fire sequentially. See Romania format reference. |
| Netherlands NLCIUS Schematron (SI-UBL 2.0; single XSLT covering Invoice + CreditNote) | 2.0.3.13 | 2026-05-21 | NPa peppolautoriteit-nl/validation 2026-05-21 (Nederlandse Peppol Autoriteit; MIT-licensed; STPE / Stichting Simplerinvoicing copyright; no Helger wrapper). Runtime: fired on UBL invoices carrying the NLCIUS CustomizationID prefix urn:cen.eu:en16931:2017#compliant#urn:fdc:nen.nl:nlcius:v1.0 (matched starts-with). The NPa-compiled XSLT bakes in EN 16931 + Peppol BIS rules; failures carry BR-NL-* rule IDs. See Netherlands NLCIUS format reference. |
| CII XSD (D16B) | D16B | 2016 | UN/CEFACT (vendored via the EN 16931 reference repository) |
| CII XSD (D22B, used by Factur-X 1.09.2 / ZUGFeRD 2.x) | D22B | 2023-06-23 | UN/CEFACT |
| UBL 2.1 XSD | 2.1 | 2013-11-04 | OASIS |
| Mustang CLI (ZUGFeRD/Factur-X) | 2.26.0 | 2026-08-25 | mustangproject.org |
| Saxon HE (XSLT processor) | 12.10 | 2026-07-16 | saxonica.com |
| VeraPDF (PDF/A validator) | 1.30.2 | 2026-06-08 | verapdf.org |
| SchXslt2 (Schematron transpiler — vendor-time only, not runtime) | 1.10.3 | 2025-09 | Codeberg — SchXslt/schxslt2 |
Cross-validation tooling
These artifacts are not used to validate customer traffic; they are used internally to cross-check the T3 spec-derived fixtures we ship are validated against an independent reference implementation.
| Artifact | Version | Release date | Official source |
|---|---|---|---|
| KoSIT validator (standalone JAR) | 1.6.3 | 2026-08-20 | itplr-kosit/validator |
| KoSIT XRechnung scenario configuration | 2026-08-31 (compatible with XRechnung 3.0.x) | 2026-08-31 | itplr-kosit/validator-configuration-xrechnung |
| KoSIT Peppol BIS scenario configuration | 3.0.21 | 2026-08-05 | itplr-kosit/validator-configuration-bis |
| AGID FEL — Fattura Elettronica compilation software XSD bundle | 2.1.4 | 2025-04-01 | Agenzia delle Entrate — Software di compilazione |
KoSIT xml-mutate (T2 fixture-generation tooling — not a validator) |
0.6 | 2026-02-13 | projekte.kosit.org — xml-mutate |
Licences and attribution
Beliq runs these artifacts as their publishers released them. Every pack, schema
and JAR listed above is vendored byte-for-byte from the upstream release: no rule
is added, no assertion is edited and nothing is recompiled. The one exception is
the Peppol BIS Billing Schematron, whose XSLT is transpiled from the upstream
.sch with SchXslt2 because OpenPEPPOL
ships no compiled form; the rules themselves are untouched.
This section is the attribution those licences ask for.
| Artifact | Licence | Rights holder and source |
|---|---|---|
| EN 16931 CII Schematron, EN 16931 UBL Schematron | EUPL-1.2 | The EN 16931 validation artefacts, published by the European Commission’s ConnectingEurope/eInvoicing-EN16931 project. Vendored verbatim from the tagged release; the EUPL notice travels inside every .sch file and the compiled XSLT. |
| XRechnung Schematron, XRechnung severity overrides | Apache-2.0 | KoSIT (Koordinierungsstelle für IT-Standards), itplr-kosit/xrechnung-schematron and itplr-kosit/validator-configuration-xrechnung. |
| Peppol BIS Billing 3.0 Schematron | None published | OpenPEPPOL AISBL, OpenPEPPOL/peppol-bis-invoice-3. The repository attaches no licence file and the Schematron carries no notice; the artefacts are a specification deliverable, published for implementers under the OpenPEPPOL IPR policy. |
| Factur-X Schematron and profile XSDs | FNFE-MPE / FeRD terms (free use, redistribution permitted for implementation) | FNFE-MPE and FeRD. The MINIMUM and BASIC profiles are taken from Mustangproject (Apache-2.0), which republishes the same files. |
| France BR-FR-CTC and EXTENDED-CTC-FR Schematron | FNFE-MPE / DGFiP publication | FNFE-MPE on behalf of DGFiP / AIFE. |
| AFNOR XP Z12-012 (the norm the France packs implement) | AFNOR, all rights reserved; published for free download | AFNOR, distributed by FNFE-MPE. |
| Romania CIUS-RO Schematron | Apache-2.0 (the packaging) | ANAF (Ministerul Finanțelor) artefacts, packaged by Philip Helger’s phive-rules. |
| Netherlands NLCIUS Schematron | MIT | Copyright (c) 2017 Stichting Simplerinvoicing, now the Nederlandse Peppol Autoriteit. |
| CII XSD (D16B and D22B) | UN/CEFACT copyright notice | UN/CEFACT. Copying and distribution are permitted without restriction provided the copyright notice travels with every copy, which is why the schemas are vendored unmodified. |
| UBL 2.1 XSD | OASIS IPR Policy (RF on Limited Terms) | Copyright (c) OASIS Open 2013. All Rights Reserved. |
| Italy FatturaPA and SDI MessaggiTypes XSD | No licence attached | Agenzia delle Entrate / Sistema di Interscambio, fatturapa.gov.it. |
| Spain Facturae XSD | No licence attached | MINECO, facturae.gob.es. |
| Slovenia e-SLOG XSD | GZS / ePOS published terms (free use for electronic commerce; the schemas may not be altered) | Gospodarska zbornica Slovenije, epos.si. |
| Poland KSeF FA(2) and FA(3) XSD | No licence attached | Ministerstwo Finansów, via the Centralne Repozytorium Wzorów. |
| Saxon HE | MPL-2.0 | Saxonica. Run as a separate process; the commercial PE and EE editions are not used. |
| Mustang CLI | Apache-2.0 | Mustangproject. Run as a separate process. |
| veraPDF | GPL-3.0-or-later or MPL-2.0 | veraPDF consortium. Run as a separate process invoked by the engine, never linked into Beliq’s own code. |
| sRGB ICC profile | ICC, freely redistributable | International Color Consortium, IEC 61966-2.1 (black-scaled). |
| SchXslt2 (build-time transpiler, not runtime) | MIT | SchXslt. |
The EUPL is worth singling out, because it is the one licence here whose terms reach a hosted service rather than only a shipped download. Running the EN 16931 Schematron behind an API counts as providing access to its functionality, so the licence applies to Beliq even though customers never receive the files. What it asks in return is this notice and the link above. It would ask for more only if Beliq modified the rules, which it does not: a test in the engine fails the build if either pack stops carrying the notice it was published with.
Validation pipeline
Every invoice goes through a validation pipeline before a result is returned.
For UBL 2.1 and CII instances in the EN 16931 family, the chain is:
Input → XSD Schema → EN 16931 Schematron → CIUS Schematron → Result
For Italy FatturaPA XML (FatturaElettronica / FatturaElettronicaSemplificata in the
Italian namespaces) and Spain Facturae XML (Facturae 3.2.2 in the MINECO namespace), the
engine runs W3C XSD validation only against the authority schema graph pinned in the engine
(no EN 16931 Schematron layer; responses omit schematronVersion and carry country-specific
metadata instead).
- XSD schema validation checks XML structure (UBL 2.1, CII D16B/D22B, Factur-X profile subset, FatturaPA XSD, or Facturae XSD)
- EN 16931 Schematron checks core business rules (not run for FatturaPA or Facturae)
- CIUS Schematron checks country- or network-specific rules when the document declares a recognised customization:
- XRechnung (KoSIT) — when the
CustomizationIDmatches an XRechnung URN - Peppol BIS Billing 3.0 (OpenPeppol) — when the
CustomizationIDmatchesurn:cen.eu:en16931:2017#compliant#urn:fdc:peppol.eu:2017:poacc:billing:3.0. UBL only — Peppol Network only transports UBL, so Peppol rules are not applied to CII payloads even if they happen to carry the URN. - Factur-X / ZUGFeRD (FNFE-MPE / FeRD) — when the
CustomizationIDcarries afactur-x.eufragment, which the MINIMUM, BASIC_WL, BASIC and EXTENDED profiles do. The Factur-X EN 16931 profile’s URN is the bareurn:cen.eu:en16931:2017, indistinguishable from a plain EN 16931 CII document, so it is covered by step 2 alone.
- XRechnung (KoSIT) — when the
For PDF output (ZUGFeRD/Factur-X), additional steps also run:
- Mustang CLI embeds validated XML into a PDF/A-3 document
- VeraPDF validates the resulting PDF against PDF/A-3b
API response metadata
Validation responses include the artifact versions used:
| Response field / header | Example value | Description |
|---|---|---|
validationResult.schematronVersion |
"1.3.16" |
EN 16931 Schematron version (omitted when validating Italy FatturaPA or Spain Facturae XSD-only) |
validationResult.ciusVersion |
"XRechnung-2.6.0" or "PeppolBIS-Billing-3.0.21" |
CIUS-specific Schematron version (when detected) |
validationResult.peppolVersion |
"PeppolBIS-Billing-3.0.21" |
Peppol BIS Billing 3.0 CIUS version. Only present when the document was detected as Peppol; mirrors ciusVersion for Peppol-specific consumers (e.g. Access Point integrations). |
validationResult.italyFatturapaXsdBundle |
(bundle label string) | Human-readable label of the authority XSD graph used for FatturaPA (XSD-only). |
validationResult.italyFatturapaRuntimeVersion |
e.g. 1.4-runtime-2026-05-01 |
Runtime bundle pin (XSD-only invoices). |
validationResult.italySdiMessaggiXsdBundle |
(bundle label string) | Human-readable label of the SDI MessaggiTypes XSD graph (XSD-only). Present only when format=sdi_messaggio was used or auto-detected. |
validationResult.italySdiMessaggiXsdVersion |
e.g. 1.1.0-pinned-2026-05-02 |
SDI MessaggiTypes XSD pin. |
validationResult.spainFacturaeXsdBundle |
(bundle label string) | Human-readable label of the authority XSD graph used for Spain Facturae (XSD-only). |
validationResult.spainFacturaeRuntimeVersion |
e.g. 3.2.2-research-2026-05-24 |
Runtime bundle pin (XSD-only invoices). |
validationResult.sloveniaEslogXsdBundle |
(bundle label string) | Human-readable label of the authority XSD used for Slovenia e-SLOG (XSD-only). |
validationResult.sloveniaEslogRuntimeVersion |
e.g. 2.0-08-2020 |
Runtime bundle pin (XSD-only; invoices and credit notes). |
validationResult.romaniaRoCiusVersion |
e.g. 1.0.9 |
Romania CIUS-RO Schematron version pin. Populated when profileDetected === "romania-ro-cius". |
validationResult.netherlandsNlciusVersion |
e.g. 2.0.3.13 |
Netherlands NLCIUS (SI-UBL 2.0) Schematron version pin. Populated when profileDetected === "netherlands-nlcius"; mirrors ciusVersion. |
x-schematron-version header |
1.3.16 |
Same as schematronVersion, also exposed as a response header on generate/validate |
These fields show which rule versions were applied to your invoice. Validation responses also carry sha256 (the exact bytes validated) and rulesetSha256 + rulesetArtifacts (the rule artifacts that judged them, hashed); see Verify a hash to reproduce both and cross-check the ruleset against the public catalog.
Business rule reference
EN 16931 and related standards use rule IDs with these prefixes:
| Prefix | Source | Example |
|---|---|---|
BR-* |
EN 16931 core rules | BR-01: An Invoice shall have a Specification identifier |
BR-CL-* |
EN 16931 code list rules | BR-CL-01: Currency code must be valid ISO 4217 |
BR-CO-* |
EN 16931 calculation rules | BR-CO-10: Sum of line net amounts must equal invoice net amount |
BR-DE-* |
XRechnung (Germany) | BR-DE-15: Buyer reference is required |
PEPPOL-EN16931-R* |
Peppol BIS 3.0 cross-border | PEPPOL-EN16931-R003: Buyer reference or order reference is required |
PEPPOL-COMMON-R* |
Peppol BIS 3.0 common | PEPPOL-COMMON-R040: Country-specific rule set must be applied |
FX-SCH-* |
Factur-X 1.09.2 profile Schematron (FNFE-MPE / FeRD) | FX-SCH-A-000015: Profile-specific assertion (Factur-X reports the EN 16931 rule code in the message body) |
BR-FR-CTC-* |
France BR-FR-CTC Flux 2 overlay (DGFiP / FNFE-MPE) | BR-FR-CTC-01: SIREN or SIRET must be present on French parties |
EXT-FR-* |
France EXTENDED-CTC-FR overlay | EXT-FR-FE-163: EXTENDED-CTC-FR-specific structural assertion |
*_NOT_ENFORCED |
Beliq advisory, not an official rule ID | EN16931_BR_CO_25_NOT_ENFORCED: a rule in the standard’s text that no artifact which ran enforces (see below) |
Official rule references:
Rules a pinned artifact does not enforce
A standard’s text and the Schematron published for it are two different things, and they do not always agree. A rule can sit in the normative text while the published artifact omits it, which means an invoice can pass one validator and be rejected by another that implements the text more fully.
Beliq runs the pinned artifact and nothing else: that is what makes rulesetSha256
meaningful, and valid is decided by those artifacts alone. But staying silent about a
known divergence is not neutral either, so where all four of the following hold, Beliq
reports the violation as an advisory (severity: "info" in warnings, never affecting
valid, see Advisory findings):
- The obligation is in a normative text and citable by clause.
- No artifact that judged the document enforces it.
- At least one named independent implementation does enforce it, so the advisory describes a real risk of downstream rejection rather than a Beliq opinion.
- The absence upstream is disputed or unexplained, rather than a decision Beliq agrees with. A rule the standards body deliberately dropped for reasons Beliq accepts gets documented, not advised on.
BR-CO-25 (payment due date or payment terms)
“In case the Amount due for payment (BT-115) is positive, either the Payment due date (BT-9) or the Payment terms (BT-20) shall be present.” EN 16931-1:2017+A1:2019 § 6.13.7.
The rule was removed from the EN 16931 Schematron in release 1.3.16 (April 2026). CEN’s
technical committee had agreed in 2020 to drop it, on the grounds that it mis-fires where
payment terms are agreed outside the invoice and is illogical for credit notes. That
removal is now contested: in July 2026 a committee member argued on the upstream tracker
that BR-CO-25 is a rule of EN 16931, was not withdrawn in the 2026 revision, and should
be restored to both the UBL and CII bindings. The question is open
(issue #500,
#511).
While it is open, these validators still enforce it, and an invoice Beliq calls valid can be rejected by one of them:
- the Mustangproject Factur-X BASIC, BASIC-WL, EN 16931 and EXTENDED packs,
- the FNFE-MPE France EXTENDED-CTC-FR overlay,
- the Romanian RO-CIUS overlay.
So documents Beliq judges with the Factur-X packs, the French EXTENDED overlay or the
Romanian overlay have the rule applied as an ordinary error. Documents judged by the
EN 16931, XRechnung, Peppol BIS or NLCIUS artifacts do not, and those are the ones that
draw the advisory. If a future EN 16931 release restores the rule, the advisory retires
itself: the artifact enforces it, so the finding arrives as an error from the artifact
and Beliq stops adding anything of its own.
BR-CO-27 (“either the IBAN or a Proprietary ID (BT-84) shall be used”) gets no
advisory, for a different reason: there is nothing unenforced to advise on. The same
committee member confirmed it is not an EN 16931 rule and belongs in the CII syntax
layer, which is where the obligation now lives. The EN 16931 CII artifact carries it as
CII-SR-470 and applies it as a fatal error, so every CII document Beliq validates
against an EN 16931 or XRechnung CII profile already has it checked. In UBL the question
does not arise: UBL carries the payment account identifier in a single field, so there is
no IBAN-versus-proprietary choice to make, and the presence of BT-84 itself is covered by
BR-50 and BR-61.
One difference is worth knowing if you pin an older ruleset. The Factur-X 1.08 edition,
selectable until it is retired on 16 May 2027, states the rule as exactly one of the
two, and rejects a document that carries both an IBAN and a proprietary identifier on a
credit-transfer payment means. CII-SR-470 requires at least one and accepts both. The
current rulesets follow CII-SR-470.
Update policy
Beliq does not auto-update validation artifacts. Version updates are reviewed and tested before rollout. For how versions are classified (safe vs breaking), announced, and how to pin a channel per request or org-wide, see Ruleset versioning.
Nightly content-SHA drift detection
Beyond reviewing official release announcements, the engine runs a nightly content-SHA check against every pinned artefact. If an authority re-publishes an artefact without bumping its version tag (a real failure mode for FNFE-MPE Factur-X bundles and the AdE FEL XsdProject.jar), the workflow opens a tracking issue on the engine repository within 24 hours.
- Cadence: every day at 04:00 UTC.
- Workflow:
.github/workflows/check-artifact-updates.yml, Layer 3 (the Python moduletools/sha_drift). - Coverage: every SHA-pinned artefact in the engine’s
third-party/versions.json. The set is enumerated from the file rather than listed by hand, and a handful of pins are skipped by construction because they have no upstream to re-fetch (a file byte-identical to a sibling in the same bundle, or a profile the authority has retired from its own site). The engine’s enumeration-coverage test fails loud if a SHA is added without a paired URL and without being declared skipped, so a new artefact cannot silently fall out of the nightly check. - Signal-only: the workflow never auto-bumps anything. Each detected drift creates an issue for human review; vendor / re-pin happens explicitly via
scripts/upgrade-artifact.sh. - Status visibility: drift status is visible in the engine’s GitHub Actions run logs and as tracking issues on the engine repository.
XRechnung release cycle
KoSIT does not publish XRechnung on a fixed calendar, and there are two kinds of release with different timing.
- Normative releases carry the specification, the syntax binding and a bundle together, and take effect on a date KoSIT sets per release. The last two landed on the 1 February / 1 August rhythm: 3.0.0 was published 2023-07-31 for 2023-08-01, 3.0.1 was published 2023-11-15 for 2024-02-01. The gap between publication and validity is set release by release, not by a rule. KoSIT states the 3.0 line stays in force until at least 2027-07-31.
- Bugfix bundles inside a line land whenever they are ready and are valid from their own publication date, with no transition window. The 3.0.2 line has taken several since 2024-07-02, which is why the release date beside the XRechnung Schematron pin in Current versions is also the date that bundle became the one to validate against.
The authority publishes no grace period for a superseded bundle, so the buffer is Beliq’s rather than KoSIT’s: the outgoing ruleset stays selectable on the previous channel for at least 6 months, until the retirement date its changelog row names (see Ruleset versioning). When KoSIT ships a bundle that is valid the day it lands, what compresses is the announcement window, not the pin.
Two version numbers travel together here: the bundle and the specification are XRechnung 3.0.2, and the Schematron pack that judges against them is 2.6.0. The XRechnung format reference says which one each response field reports.
Version changelog
| Date | Artifact | Old version | New version | Notes |
|---|---|---|---|---|
| 2026-04-04 | EN 16931 Schematron | — | 1.3.16 | Initial version |
| 2026-01-31 | XRechnung Schematron | — | 2.5.0 | Initial version |
| 2026-02-04 | Mustang CLI | — | 2.22.0 | Initial version |
| 2026-04 | Peppol BIS Billing 3.0 Schematron | — | 3.0.20 | Initial version. Compiled from upstream .sch sources at vendor time using SchXslt2. |
| 2026-04 | Factur-X / D22B Schematron + XSDs | — | 1.08 | Initial version. Vendored from FNFE-MPE / FeRD public ZIP. Covers BASIC_WL, EN16931 and EXTENDED profiles directly. |
| 2026-04-24 | Factur-X 1.08 — MINIMUM and BASIC profiles | — | 1.08 | Vendored from Mustangproject core-2.22.0 (Apache-2.0) as the FNFE-MPE-recommended downstream consumer. All five Factur-X 1.08 profiles (MINIMUM, BASIC_WL, BASIC, EN16931, EXTENDED) are now supported. |
| 2026-04 | France BR-FR-CTC Flux 2 + EXTENDED-CTC-FR Schematron | — | 1.3.0 | Initial version. Vendored from the FNFE-MPE 2026-02-16 publication. |
| 2026-04-25 | KoSIT Peppol BIS scenario configuration | — | 3.0.20 | Cross-validation only. Added alongside the KoSIT validator JAR. |
| 2026-09-17 | KoSIT Peppol BIS scenario configuration | 3.0.20 | 3.0.21 | Cross-validation only. Re-aligns the reference implementation with the 3.0.21 runtime ruleset, so a differential run compares like with like. The bundled XSLT is not byte-identical to the runtime one because KoSIT and Beliq transpile the same Schematron with different compilers; the rule content agrees, including all 82 electronic-address scheme codes. |
| 2026-09-03 | Peppol BIS Billing 3.0 Schematron | 3.0.20 | 3.0.21 | Breaking, and already mandatory on the network since 2026-08-17, so it took effect on merge with no notice period. Six rules go warning to fatal (PEPPOL-COMMON-R052/R053 in both syntaxes, DK-R-003/DK-R-017 in UBL) and the electronic-address codelist behind the fatal PEPPOL-EN16931-CL008 drops 14 schemes. 3.0.20 stays pinnable until 2027-03-03. |
| 2026-09-17 | Peppol BIS Billing 3.0 unit-test corpus | 3.0.20 corpus (58 testSets / 227 cases) | 3.0.21 corpus (62 testSets / 335 cases) | No runtime artifact version change: the ruleset has been 3.0.21 since 2026-09-03 and only the corpus that proves its verdicts moved, re-vendored from the same pinned commit. Four rules 3.0.21 adds gain their negative fixtures (PEPPOL-COMMON-R054, R055, R056-1, R057) and seven existing files are brought current, including PEPPOL-COMMON-R052/R053, whose fixtures still asserted the pre-3.0.21 warning severity. |
| 2026-09-18 | Peppol BIS Billing 3.0 example invoices | 3.0.20 examples (9) | 3.0.21 examples (10) | No runtime artifact version change. The positive corpus is re-vendored from the same pinned commit as the ruleset and the unit-test corpus. 3.0.21 adds base-example_profile02.xml, an invoice that asks the buyer for an invoice response (ProfileID urn:peppol:bis:billing_with_response); Beliq and the KoSIT 3.0.21 reference configuration both accept it. The other three changed files differ only in a comment. |
| 2026-09-05 | KoSIT validator + KoSIT XRechnung scenario configuration | 1.6.2 / 2026-01-31 | 1.6.3 / 2026-08-31 | Cross-validation only. The 2026-08-31 configuration adopts CEN Schematron 1.3.16, so it no longer carries BR-CO-25 and is no longer among the validators listed above that enforce it. The runtime severity-override table regenerated from the same release is a separate bump, in force since 2026-09-09 and recorded in the row below. |
| 2026-09-09 | XRechnung Schematron + KoSIT severity-override table | 2.5.0 / 2026-01-31 | 2.6.0 / 2026-08-31 | Breaking, and it took effect on merge with no notice period: no organisation had a member who is not a test account, so waiting would have protected nobody while 2.5.0 kept rejecting conforming documents. BR-TMP-2 goes warning to fatal in both syntaxes (BT-124 must be an absolute URL) and CII-SR-465/CII-SR-466 go warning to error on CII (a contact must not carry both a person name and a department name). Going the other way, PEPPOL-EN16931-R008 no longer rejects an empty cac:OrderReference/cbc:ID. Both stay pinnable as previous until 2027-06-11. |
| 2026-09-10 | Factur-X Schematron + France BR-FR-CTC Flux 2 + France EXTENDED-CTC-FR | 1.08 / 1.3.1 | 1.09.2 / 1.4.0.03 | Breaking, announced 2026-08-20 for 2026-11-20 and brought forward: no organisation had a member who is not a test account, so the notice period protected nobody. The Flux 2 pack raises 141 CII and 145 UBL asserts from warning to fatal with no rule-id change, so a France CTC document carrying any BR-FR-* finding is now invalid rather than valid-with-warnings. Four of the five Factur-X profiles gain asserts; BR-CO-25 leaves BASIC, BASIC_WL and EN16931 and is served as an advisory there. The packs emit upstream rule ids beside the generated FX-SCH-A ones. 1.08 and 1.3.1 stay pinnable as previous until 2027-05-16. |
| 2026-09-15 | France BR-FR-CTC Flux 2 + France EXTENDED-CTC-FR (Factur-X pack re-pinned, spec unchanged) | 1.4.0.03 | 1.4.0.04 | Took effect on merge. The FNFE pack moved; the Factur-X specification did not, so facturx_schematron stays 1.09.2 and only its archive pin changed (the 2026-09-04 archive ships its Factur-X tree as Factur-X_1.09.2.fixFR04). Nothing measured newly fails: four of the five vendored packs keep their assert id set and flag histogram exactly, and every predicate change is a false-positive fix. The nine BR-FXEXT-*-01 rules had a DETAIL-only scope that never applied because the predicate addressed a sibling as a child, so invoices with GROUP lines were judged as if every line were a DETAIL line; several monetary comparisons moved from number() to xs:decimal(); BR-FR-CO-07 now tolerates more than one payment due date; and BR-FR-20/BT-21 accepts B2CINT as a BAR note value. On EXTENDED-CTC-FR CII, CII-SR-069 and CII-SR-072 are replaced by CII-FREXT-SR-069 / -072, which test <= 1 where the base rules test = 1 — matching what both rules’ own text always said. 1.4.0.03 is not retained: previous stays 1.3.1 until 2027-05-16. |
| 2026-10-05 | EN 16931 syntax schemas: CII D16B, CII D22B, UBL 2.1 and the Factur-X profile XSDs | not in rulesetSha256 |
in rulesetSha256 |
No schema version moves and no verdict changes. The schema a document was checked against is now a rulesetArtifacts row and part of rulesetSha256, so the fingerprint of every EN 16931 result changed once, and a document the schema rejects now carries both fields. Announced on the public changelog on 2026-09-20. FatturaPA, Facturae and e-SLOG fingerprints did not change: their root XSD was already recorded. |
| 2026-04-28 | AGID FEL XSD bundle | — | 2.1.4 | Cross-validation only. Added to back T3 negatives for italy_fatturapa_ordinaria. |
| 2026-05-01 | Italy FatturaPA runtime XSD bundle | — | 1.4-runtime-2026-05-01 | Runtime XSD validation on POST /v1/generate and POST /v1/validate for FatturaPA FPR12 / FPA12 / FSM10. |
| 2026-05-02 | Italy SDI MessaggiTypes XSD | — | 1.1.0-pinned-2026-05-02 | XSD-only path on POST /v1/validate for SDI file messaggi (notifications / receipts). Not transport. |
| 2026-04-28 | Italy SDI transport URL bundle | — | sdi-interchange-1.8.4-urls-2026-04-28 | URL pointers only — no submission, signing, or operator integration is implemented. |
| 2026-05-23 | Nightly content-SHA drift detection | — | active | Re-fetches every SHA-pinned artefact nightly and opens tracking issues on detected drift. Internal — no customer-facing API change. |
| 2026-05-26 | Spain Facturae runtime XSD bundle | — | 3.2.2-research-2026-05-24 | Runtime XSD validation on POST /v1/generate (standard: "facturae") and POST /v1/validate for Facturae 3.2.2 — XSD-only, no EN 16931 Schematron (Facturae’s lineage is the MINECO spec, not CEN). |
| 2026-06-02 | Romania RO_CIUS Schematron (XSLT pair via the Helger phive-rules-cius-ro pack) | — | 1.0.9 | Runtime Schematron arm on POST /v1/validate for Romanian CIUS-RO UBL (current + legacy URN), plus POST /v1/generate with standard: "peppol-bis" + profile: "romania-ro-cius". Profile is provisional; promotion to supported waits on the remaining T3 negatives and phive cross-validation gate. ANAF SPV submission stays BYOC. |
| 2026-09-17 | Romania RO_CIUS Schematron (phive pack re-pinned, artefacts unchanged) | 4.4.1 | 4.5.6 | No rule change: phive-rules-cius-ro 4.5.6 still ships CIUS-RO 1.0.9 and the two vendored XSLTs are byte-identical across the pack bump, so validation behaviour does not move. The pin tracks a current Maven coordinate. |
| 2026-06-09 | Netherlands NLCIUS Schematron (SI-UBL 2.0 via NPa peppolautoriteit-nl/validation) | — | 2.0.3.13 | Runtime NLCIUS XSLT arm on POST /v1/validate for Dutch NLCIUS UBL (CustomizationID prefix urn:fdc:nen.nl:nlcius:v1.0, matched starts-with), plus POST /v1/generate with standard: "peppol-bis" + profile: "netherlands-nlcius". Single XSLT covers Invoice + CreditNote; failures carry BR-NL-*. Profile netherlands_peppol_nlcius promoted to supported. Digipoort / Logius B2G submission stays Peppol-AP-routed BYOC. |
| 2026-06-11 | Slovenia e-SLOG 2.0 runtime XSD bundle | — | 2.0-08-2020 | Runtime XSD validation on POST /v1/generate (standard: "eslog", invoices and credit notes) and POST /v1/validate for e-SLOG 2.0. XSD-only, no EN 16931 Schematron (GZS/ePOS publish no machine-readable business rules). UJP submission and e-route provider services stay BYOC. |
| 2026-06-18 | Mustang CLI | 2.22.0 | 2.24.0 | Hybrid PDF/A-3 assembly (--action combine). No API surface change. |
| 2026-06-18 | VeraPDF (PDF/A validator) | 1.28.2 | 1.30.2 | PDF/A-3b verification of the hybrid PDFs built by POST /v1/generate (output: "pdf"). No API surface change. |
| 2026-06-18 | France BR-FR-CTC Flux 2 + EXTENDED-CTC-FR Schematron | 1.3.0 | 1.3.1 | Re-vendored from the FNFE-MPE 2026-04-30 publication. |
| 2026-07-24 | Saxon HE (XSLT processor) | 12.9 | 12.10 | Schematron XSLT execution across every validation arm. No API surface change. |
| 2026-09-16 | Mustang CLI | 2.24.0 | 2.26.0 | Hybrid PDF/A-3 assembly (--action combine). Moves off the bundled veraPDF 1.26.5, which sits inside the affected range of CVE-2026-54079 and CVE-2026-54078; 2.26.0 bundles the patched 1.30.2. The same tag is the Factur-X MINIMUM / BASIC secondary source, and re-pinning it corrects two dangling schemaLocation hints in the vendored per-profile XSDs. No rule, flag or codelist moves, and no API surface change. |
| 2026-06-13 | Netherlands NLCIUS comprehensive corpus + Schematron-only harness | — | 2.0.3.13 (unchanged) | No runtime artifact version change (SI-UBL 2.0 v2.0.3.13, same SHA; SHA-drift unchanged). Test corpus grown 10 → 120 (the full NPa SI-UBL 2.0 authority testset) and asserted by a Schematron-only harness (every document outcome plus per-rule SVRL firing). A rule-coverage audit confirms a Tier-1 negative per critical rule family. Profile netherlands_peppol_nlcius promoted supported → fully-verified; two residuals documented (UBL-SR-09/15 upstream XSLT XPTY0004 crash, BR-NL-34 under the BR-NL-32 id). No API surface change. |