eliDocs
Compliance

Validation artifacts

Versions, sources, and checksums of the validation artifacts used by the Beliq e-invoice engine.

Beliq validates every generated and uploaded e-invoice against official standards artifacts. This page lists the versions currently used in production. The same Italy FatturaPA XSD bundle applies to POST /v1/generate (standard: "fatturapa") and to POST /v1/validate when FatturaPA invoice XML is detected — POST /v1/parse accepts UBL 2.1 and CII only (FatturaPA and SDI messaggio inputs are validated, not parsed). Italy SDI file messaggio XML (MessaggiTypes) uses a separate vendored XSD graph and is validated only on POST /v1/validate when format=sdi_messaggio is set or when a known messaggio root is auto-detected — it is not FatturaPA invoice validation.

For the machine-readable version of this inventory, call GET /v1/rulesets: the same pinned versions and artifact hashes, keyless and with no quota cost.

Current versions

Current versions

Artifact Version Release date Official source
EN 16931 CII Schematron 1.3.16 2026-04-04 ConnectingEurope/eInvoicing-EN16931
EN 16931 UBL Schematron 1.3.16 2026-04-04 ConnectingEurope/eInvoicing-EN16931
XRechnung Schematron 2.6.0 2026-08-31 itplr-kosit/xrechnung-schematron
Peppol BIS Billing 3.0 Schematron (UBL) 3.0.21 2026-05-20 OpenPEPPOL/peppol-bis-invoice-3 @ 780387ca — OpenPEPPOL publishes Billing validation artefacts on release branches and cuts no tag, so the pin is a commit. Mandatory on the Peppol network since 2026-08-17.
Factur-X 1.09.2 / CII D22B Schematron + per-profile XSDs (all 5 profiles: MINIMUM, BASIC_WL, BASIC, EN16931, EXTENDED) 1.09.2 2026-09-04 FNFE-MPE / FeRD joint pack — primary for BASIC_WL / EN16931 / EXTENDED; Mustangproject (Apache-2.0) secondary for MINIMUM and BASIC (FNFE-MPE-recommended downstream consumer; pinned to tag core-2.26.0).
France BR-FR-CTC Flux 2 Schematron (CII + UBL) 1.4.0.04 2026-09-04 FNFE-MPE on behalf of DGFiP / AIFE
France EXTENDED-CTC-FR Schematron (CII + UBL) 1.4.0.04 2026-09-04 FNFE-MPE on behalf of DGFiP / AIFE
Italy FatturaPA XSD (ordinaria/PA VFPR/VFPA 1.2.3 + semplificata VFSM 1.0.2, runtime bundle) 1.4-runtime-2026-05-01 fatturapa.gov.it — formato / XSD v1.4
Italy SDI MessaggiTypes XSD (file messaggio v1.1) 1.1.0-pinned-2026-05-02 fatturapa.gov.it — Messaggi v1.1 + xmldsig companion. Runtime: POST /v1/validate with format=sdi_messaggio or auto-detect on known messaggio roots — XSD only, not FatturaPA invoice validation.
Italy SDI transport — SOAP / spec URL bundle (reference URLs only, not vendored) sdi-interchange-1.8.4-urls-2026-04-28 DocumentazioneSDI + Specifiche tecniche v1.8.4 PDF + WSDL/XSD export tree. Reference only — SDI submission, signing, and operator interchange are not implemented in Beliq (italy_sdi_transport is blocked); transmission belongs to your SDI intermediary.
Spain Facturae XSD (3.2.2 runtime bundle) 3.2.2-research-2026-05-24 2017-06-06 facturae.gob.es — formato (MINECO unified spec). Runtime: XSD-only on POST /v1/generate (standard: "facturae") and POST /v1/validate (format=facturae or auto-detect).
Slovenia e-SLOG XSD (2.0 runtime bundle, INVOIC v200 + xmldsig companion) 2.0-08-2020 2020-08 epos.si (GZS/ePOS invoice package). Runtime: XSD-only on POST /v1/generate (standard: "eslog", invoices + credit notes) and POST /v1/validate (format=eslog or auto-detect on the urn:eslog:2.00 root).
Romania RO_CIUS Schematron (XSLT pair: EN 16931 CIUS-RO + RO e-Factura operational/VAT) 1.0.9 2024-06-05 Helger phive-rules-cius-ro 4.5.6 (Maven Central, Apache-2.0; vendors ANAF’s authoritative XSLT). Runtime: fired on UBL invoices carrying the CIUS-RO CustomizationID (urn:efactura.mfinante.ro:CIUS-RO:1.0.1 current or RO_CIUS:1.0.0.2021 legacy). The CIUS-RO XSLT bakes in EN 16931 + Peppol BIS rules; both XSLTs fire sequentially. See Romania format reference.
Netherlands NLCIUS Schematron (SI-UBL 2.0; single XSLT covering Invoice + CreditNote) 2.0.3.13 2026-05-21 NPa peppolautoriteit-nl/validation 2026-05-21 (Nederlandse Peppol Autoriteit; MIT-licensed; STPE / Stichting Simplerinvoicing copyright; no Helger wrapper). Runtime: fired on UBL invoices carrying the NLCIUS CustomizationID prefix urn:cen.eu:en16931:2017#compliant#urn:fdc:nen.nl:nlcius:v1.0 (matched starts-with). The NPa-compiled XSLT bakes in EN 16931 + Peppol BIS rules; failures carry BR-NL-* rule IDs. See Netherlands NLCIUS format reference.
CII XSD (D16B) D16B 2016 UN/CEFACT (vendored via the EN 16931 reference repository)
CII XSD (D22B, used by Factur-X 1.09.2 / ZUGFeRD 2.x) D22B 2023-06-23 UN/CEFACT
UBL 2.1 XSD 2.1 2013-11-04 OASIS
Mustang CLI (ZUGFeRD/Factur-X) 2.26.0 2026-08-25 mustangproject.org
Saxon HE (XSLT processor) 12.10 2026-07-16 saxonica.com
VeraPDF (PDF/A validator) 1.30.2 2026-06-08 verapdf.org
SchXslt2 (Schematron transpiler — vendor-time only, not runtime) 1.10.3 2025-09 Codeberg — SchXslt/schxslt2

Cross-validation tooling

These artifacts are not used to validate customer traffic; they are used internally to cross-check the T3 spec-derived fixtures we ship are validated against an independent reference implementation.

Artifact Version Release date Official source
KoSIT validator (standalone JAR) 1.6.3 2026-08-20 itplr-kosit/validator
KoSIT XRechnung scenario configuration 2026-08-31 (compatible with XRechnung 3.0.x) 2026-08-31 itplr-kosit/validator-configuration-xrechnung
KoSIT Peppol BIS scenario configuration 3.0.21 2026-08-05 itplr-kosit/validator-configuration-bis
AGID FEL — Fattura Elettronica compilation software XSD bundle 2.1.4 2025-04-01 Agenzia delle Entrate — Software di compilazione
KoSIT xml-mutate (T2 fixture-generation tooling — not a validator) 0.6 2026-02-13 projekte.kosit.org — xml-mutate
Licences and attribution

Licences and attribution

Beliq runs these artifacts as their publishers released them. Every pack, schema and JAR listed above is vendored byte-for-byte from the upstream release: no rule is added, no assertion is edited and nothing is recompiled. The one exception is the Peppol BIS Billing Schematron, whose XSLT is transpiled from the upstream .sch with SchXslt2 because OpenPEPPOL ships no compiled form; the rules themselves are untouched.

This section is the attribution those licences ask for.

Artifact Licence Rights holder and source
EN 16931 CII Schematron, EN 16931 UBL Schematron EUPL-1.2 The EN 16931 validation artefacts, published by the European Commission’s ConnectingEurope/eInvoicing-EN16931 project. Vendored verbatim from the tagged release; the EUPL notice travels inside every .sch file and the compiled XSLT.
XRechnung Schematron, XRechnung severity overrides Apache-2.0 KoSIT (Koordinierungsstelle für IT-Standards), itplr-kosit/xrechnung-schematron and itplr-kosit/validator-configuration-xrechnung.
Peppol BIS Billing 3.0 Schematron None published OpenPEPPOL AISBL, OpenPEPPOL/peppol-bis-invoice-3. The repository attaches no licence file and the Schematron carries no notice; the artefacts are a specification deliverable, published for implementers under the OpenPEPPOL IPR policy.
Factur-X Schematron and profile XSDs FNFE-MPE / FeRD terms (free use, redistribution permitted for implementation) FNFE-MPE and FeRD. The MINIMUM and BASIC profiles are taken from Mustangproject (Apache-2.0), which republishes the same files.
France BR-FR-CTC and EXTENDED-CTC-FR Schematron FNFE-MPE / DGFiP publication FNFE-MPE on behalf of DGFiP / AIFE.
AFNOR XP Z12-012 (the norm the France packs implement) AFNOR, all rights reserved; published for free download AFNOR, distributed by FNFE-MPE.
Romania CIUS-RO Schematron Apache-2.0 (the packaging) ANAF (Ministerul Finanțelor) artefacts, packaged by Philip Helger’s phive-rules.
Netherlands NLCIUS Schematron MIT Copyright (c) 2017 Stichting Simplerinvoicing, now the Nederlandse Peppol Autoriteit.
CII XSD (D16B and D22B) UN/CEFACT copyright notice UN/CEFACT. Copying and distribution are permitted without restriction provided the copyright notice travels with every copy, which is why the schemas are vendored unmodified.
UBL 2.1 XSD OASIS IPR Policy (RF on Limited Terms) Copyright (c) OASIS Open 2013. All Rights Reserved.
Italy FatturaPA and SDI MessaggiTypes XSD No licence attached Agenzia delle Entrate / Sistema di Interscambio, fatturapa.gov.it.
Spain Facturae XSD No licence attached MINECO, facturae.gob.es.
Slovenia e-SLOG XSD GZS / ePOS published terms (free use for electronic commerce; the schemas may not be altered) Gospodarska zbornica Slovenije, epos.si.
Poland KSeF FA(2) and FA(3) XSD No licence attached Ministerstwo Finansów, via the Centralne Repozytorium Wzorów.
Saxon HE MPL-2.0 Saxonica. Run as a separate process; the commercial PE and EE editions are not used.
Mustang CLI Apache-2.0 Mustangproject. Run as a separate process.
veraPDF GPL-3.0-or-later or MPL-2.0 veraPDF consortium. Run as a separate process invoked by the engine, never linked into Beliq’s own code.
sRGB ICC profile ICC, freely redistributable International Color Consortium, IEC 61966-2.1 (black-scaled).
SchXslt2 (build-time transpiler, not runtime) MIT SchXslt.

The EUPL is worth singling out, because it is the one licence here whose terms reach a hosted service rather than only a shipped download. Running the EN 16931 Schematron behind an API counts as providing access to its functionality, so the licence applies to Beliq even though customers never receive the files. What it asks in return is this notice and the link above. It would ask for more only if Beliq modified the rules, which it does not: a test in the engine fails the build if either pack stops carrying the notice it was published with.

Validation pipeline

Validation pipeline

Every invoice goes through a validation pipeline before a result is returned.

For UBL 2.1 and CII instances in the EN 16931 family, the chain is:

Input → XSD Schema → EN 16931 Schematron → CIUS Schematron → Result

For Italy FatturaPA XML (FatturaElettronica / FatturaElettronicaSemplificata in the Italian namespaces) and Spain Facturae XML (Facturae 3.2.2 in the MINECO namespace), the engine runs W3C XSD validation only against the authority schema graph pinned in the engine (no EN 16931 Schematron layer; responses omit schematronVersion and carry country-specific metadata instead).

  1. XSD schema validation checks XML structure (UBL 2.1, CII D16B/D22B, Factur-X profile subset, FatturaPA XSD, or Facturae XSD)
  2. EN 16931 Schematron checks core business rules (not run for FatturaPA or Facturae)
  3. CIUS Schematron checks country- or network-specific rules when the document declares a recognised customization:
    • XRechnung (KoSIT) — when the CustomizationID matches an XRechnung URN
    • Peppol BIS Billing 3.0 (OpenPeppol) — when the CustomizationID matches urn:cen.eu:en16931:2017#compliant#urn:fdc:peppol.eu:2017:poacc:billing:3.0. UBL only — Peppol Network only transports UBL, so Peppol rules are not applied to CII payloads even if they happen to carry the URN.
    • Factur-X / ZUGFeRD (FNFE-MPE / FeRD) — when the CustomizationID carries a factur-x.eu fragment, which the MINIMUM, BASIC_WL, BASIC and EXTENDED profiles do. The Factur-X EN 16931 profile’s URN is the bare urn:cen.eu:en16931:2017, indistinguishable from a plain EN 16931 CII document, so it is covered by step 2 alone.

For PDF output (ZUGFeRD/Factur-X), additional steps also run:

  1. Mustang CLI embeds validated XML into a PDF/A-3 document
  2. VeraPDF validates the resulting PDF against PDF/A-3b
API response metadata

API response metadata

Validation responses include the artifact versions used:

Response field / header Example value Description
validationResult.schematronVersion "1.3.16" EN 16931 Schematron version (omitted when validating Italy FatturaPA or Spain Facturae XSD-only)
validationResult.ciusVersion "XRechnung-2.6.0" or "PeppolBIS-Billing-3.0.21" CIUS-specific Schematron version (when detected)
validationResult.peppolVersion "PeppolBIS-Billing-3.0.21" Peppol BIS Billing 3.0 CIUS version. Only present when the document was detected as Peppol; mirrors ciusVersion for Peppol-specific consumers (e.g. Access Point integrations).
validationResult.italyFatturapaXsdBundle (bundle label string) Human-readable label of the authority XSD graph used for FatturaPA (XSD-only).
validationResult.italyFatturapaRuntimeVersion e.g. 1.4-runtime-2026-05-01 Runtime bundle pin (XSD-only invoices).
validationResult.italySdiMessaggiXsdBundle (bundle label string) Human-readable label of the SDI MessaggiTypes XSD graph (XSD-only). Present only when format=sdi_messaggio was used or auto-detected.
validationResult.italySdiMessaggiXsdVersion e.g. 1.1.0-pinned-2026-05-02 SDI MessaggiTypes XSD pin.
validationResult.spainFacturaeXsdBundle (bundle label string) Human-readable label of the authority XSD graph used for Spain Facturae (XSD-only).
validationResult.spainFacturaeRuntimeVersion e.g. 3.2.2-research-2026-05-24 Runtime bundle pin (XSD-only invoices).
validationResult.sloveniaEslogXsdBundle (bundle label string) Human-readable label of the authority XSD used for Slovenia e-SLOG (XSD-only).
validationResult.sloveniaEslogRuntimeVersion e.g. 2.0-08-2020 Runtime bundle pin (XSD-only; invoices and credit notes).
validationResult.romaniaRoCiusVersion e.g. 1.0.9 Romania CIUS-RO Schematron version pin. Populated when profileDetected === "romania-ro-cius".
validationResult.netherlandsNlciusVersion e.g. 2.0.3.13 Netherlands NLCIUS (SI-UBL 2.0) Schematron version pin. Populated when profileDetected === "netherlands-nlcius"; mirrors ciusVersion.
x-schematron-version header 1.3.16 Same as schematronVersion, also exposed as a response header on generate/validate

These fields show which rule versions were applied to your invoice. Validation responses also carry sha256 (the exact bytes validated) and rulesetSha256 + rulesetArtifacts (the rule artifacts that judged them, hashed); see Verify a hash to reproduce both and cross-check the ruleset against the public catalog.

Business rule reference

Business rule reference

EN 16931 and related standards use rule IDs with these prefixes:

Prefix Source Example
BR-* EN 16931 core rules BR-01: An Invoice shall have a Specification identifier
BR-CL-* EN 16931 code list rules BR-CL-01: Currency code must be valid ISO 4217
BR-CO-* EN 16931 calculation rules BR-CO-10: Sum of line net amounts must equal invoice net amount
BR-DE-* XRechnung (Germany) BR-DE-15: Buyer reference is required
PEPPOL-EN16931-R* Peppol BIS 3.0 cross-border PEPPOL-EN16931-R003: Buyer reference or order reference is required
PEPPOL-COMMON-R* Peppol BIS 3.0 common PEPPOL-COMMON-R040: Country-specific rule set must be applied
FX-SCH-* Factur-X 1.09.2 profile Schematron (FNFE-MPE / FeRD) FX-SCH-A-000015: Profile-specific assertion (Factur-X reports the EN 16931 rule code in the message body)
BR-FR-CTC-* France BR-FR-CTC Flux 2 overlay (DGFiP / FNFE-MPE) BR-FR-CTC-01: SIREN or SIRET must be present on French parties
EXT-FR-* France EXTENDED-CTC-FR overlay EXT-FR-FE-163: EXTENDED-CTC-FR-specific structural assertion
*_NOT_ENFORCED Beliq advisory, not an official rule ID EN16931_BR_CO_25_NOT_ENFORCED: a rule in the standard’s text that no artifact which ran enforces (see below)

Official rule references:

Rules a pinned artifact does not enforce

Rules a pinned artifact does not enforce

A standard’s text and the Schematron published for it are two different things, and they do not always agree. A rule can sit in the normative text while the published artifact omits it, which means an invoice can pass one validator and be rejected by another that implements the text more fully.

Beliq runs the pinned artifact and nothing else: that is what makes rulesetSha256 meaningful, and valid is decided by those artifacts alone. But staying silent about a known divergence is not neutral either, so where all four of the following hold, Beliq reports the violation as an advisory (severity: "info" in warnings, never affecting valid, see Advisory findings):

  1. The obligation is in a normative text and citable by clause.
  2. No artifact that judged the document enforces it.
  3. At least one named independent implementation does enforce it, so the advisory describes a real risk of downstream rejection rather than a Beliq opinion.
  4. The absence upstream is disputed or unexplained, rather than a decision Beliq agrees with. A rule the standards body deliberately dropped for reasons Beliq accepts gets documented, not advised on.

BR-CO-25 (payment due date or payment terms)

“In case the Amount due for payment (BT-115) is positive, either the Payment due date (BT-9) or the Payment terms (BT-20) shall be present.” EN 16931-1:2017+A1:2019 § 6.13.7.

The rule was removed from the EN 16931 Schematron in release 1.3.16 (April 2026). CEN’s technical committee had agreed in 2020 to drop it, on the grounds that it mis-fires where payment terms are agreed outside the invoice and is illogical for credit notes. That removal is now contested: in July 2026 a committee member argued on the upstream tracker that BR-CO-25 is a rule of EN 16931, was not withdrawn in the 2026 revision, and should be restored to both the UBL and CII bindings. The question is open (issue #500, #511).

While it is open, these validators still enforce it, and an invoice Beliq calls valid can be rejected by one of them:

  • the Mustangproject Factur-X BASIC, BASIC-WL, EN 16931 and EXTENDED packs,
  • the FNFE-MPE France EXTENDED-CTC-FR overlay,
  • the Romanian RO-CIUS overlay.

So documents Beliq judges with the Factur-X packs, the French EXTENDED overlay or the Romanian overlay have the rule applied as an ordinary error. Documents judged by the EN 16931, XRechnung, Peppol BIS or NLCIUS artifacts do not, and those are the ones that draw the advisory. If a future EN 16931 release restores the rule, the advisory retires itself: the artifact enforces it, so the finding arrives as an error from the artifact and Beliq stops adding anything of its own.

BR-CO-27 (“either the IBAN or a Proprietary ID (BT-84) shall be used”) gets no advisory, for a different reason: there is nothing unenforced to advise on. The same committee member confirmed it is not an EN 16931 rule and belongs in the CII syntax layer, which is where the obligation now lives. The EN 16931 CII artifact carries it as CII-SR-470 and applies it as a fatal error, so every CII document Beliq validates against an EN 16931 or XRechnung CII profile already has it checked. In UBL the question does not arise: UBL carries the payment account identifier in a single field, so there is no IBAN-versus-proprietary choice to make, and the presence of BT-84 itself is covered by BR-50 and BR-61.

One difference is worth knowing if you pin an older ruleset. The Factur-X 1.08 edition, selectable until it is retired on 16 May 2027, states the rule as exactly one of the two, and rejects a document that carries both an IBAN and a proprietary identifier on a credit-transfer payment means. CII-SR-470 requires at least one and accepts both. The current rulesets follow CII-SR-470.

Update policy

Update policy

Beliq does not auto-update validation artifacts. Version updates are reviewed and tested before rollout. For how versions are classified (safe vs breaking), announced, and how to pin a channel per request or org-wide, see Ruleset versioning.

Nightly content-SHA drift detection

Nightly content-SHA drift detection

Beyond reviewing official release announcements, the engine runs a nightly content-SHA check against every pinned artefact. If an authority re-publishes an artefact without bumping its version tag (a real failure mode for FNFE-MPE Factur-X bundles and the AdE FEL XsdProject.jar), the workflow opens a tracking issue on the engine repository within 24 hours.

  • Cadence: every day at 04:00 UTC.
  • Workflow: .github/workflows/check-artifact-updates.yml, Layer 3 (the Python module tools/sha_drift).
  • Coverage: every SHA-pinned artefact in the engine’s third-party/versions.json. The set is enumerated from the file rather than listed by hand, and a handful of pins are skipped by construction because they have no upstream to re-fetch (a file byte-identical to a sibling in the same bundle, or a profile the authority has retired from its own site). The engine’s enumeration-coverage test fails loud if a SHA is added without a paired URL and without being declared skipped, so a new artefact cannot silently fall out of the nightly check.
  • Signal-only: the workflow never auto-bumps anything. Each detected drift creates an issue for human review; vendor / re-pin happens explicitly via scripts/upgrade-artifact.sh.
  • Status visibility: drift status is visible in the engine’s GitHub Actions run logs and as tracking issues on the engine repository.
XRechnung release cycle

XRechnung release cycle

KoSIT does not publish XRechnung on a fixed calendar, and there are two kinds of release with different timing.

  • Normative releases carry the specification, the syntax binding and a bundle together, and take effect on a date KoSIT sets per release. The last two landed on the 1 February / 1 August rhythm: 3.0.0 was published 2023-07-31 for 2023-08-01, 3.0.1 was published 2023-11-15 for 2024-02-01. The gap between publication and validity is set release by release, not by a rule. KoSIT states the 3.0 line stays in force until at least 2027-07-31.
  • Bugfix bundles inside a line land whenever they are ready and are valid from their own publication date, with no transition window. The 3.0.2 line has taken several since 2024-07-02, which is why the release date beside the XRechnung Schematron pin in Current versions is also the date that bundle became the one to validate against.

The authority publishes no grace period for a superseded bundle, so the buffer is Beliq’s rather than KoSIT’s: the outgoing ruleset stays selectable on the previous channel for at least 6 months, until the retirement date its changelog row names (see Ruleset versioning). When KoSIT ships a bundle that is valid the day it lands, what compresses is the announcement window, not the pin.

Two version numbers travel together here: the bundle and the specification are XRechnung 3.0.2, and the Schematron pack that judges against them is 2.6.0. The XRechnung format reference says which one each response field reports.

Version changelog

Version changelog

Date Artifact Old version New version Notes
2026-04-04 EN 16931 Schematron 1.3.16 Initial version
2026-01-31 XRechnung Schematron 2.5.0 Initial version
2026-02-04 Mustang CLI 2.22.0 Initial version
2026-04 Peppol BIS Billing 3.0 Schematron 3.0.20 Initial version. Compiled from upstream .sch sources at vendor time using SchXslt2.
2026-04 Factur-X / D22B Schematron + XSDs 1.08 Initial version. Vendored from FNFE-MPE / FeRD public ZIP. Covers BASIC_WL, EN16931 and EXTENDED profiles directly.
2026-04-24 Factur-X 1.08 — MINIMUM and BASIC profiles 1.08 Vendored from Mustangproject core-2.22.0 (Apache-2.0) as the FNFE-MPE-recommended downstream consumer. All five Factur-X 1.08 profiles (MINIMUM, BASIC_WL, BASIC, EN16931, EXTENDED) are now supported.
2026-04 France BR-FR-CTC Flux 2 + EXTENDED-CTC-FR Schematron 1.3.0 Initial version. Vendored from the FNFE-MPE 2026-02-16 publication.
2026-04-25 KoSIT Peppol BIS scenario configuration 3.0.20 Cross-validation only. Added alongside the KoSIT validator JAR.
2026-09-17 KoSIT Peppol BIS scenario configuration 3.0.20 3.0.21 Cross-validation only. Re-aligns the reference implementation with the 3.0.21 runtime ruleset, so a differential run compares like with like. The bundled XSLT is not byte-identical to the runtime one because KoSIT and Beliq transpile the same Schematron with different compilers; the rule content agrees, including all 82 electronic-address scheme codes.
2026-09-03 Peppol BIS Billing 3.0 Schematron 3.0.20 3.0.21 Breaking, and already mandatory on the network since 2026-08-17, so it took effect on merge with no notice period. Six rules go warning to fatal (PEPPOL-COMMON-R052/R053 in both syntaxes, DK-R-003/DK-R-017 in UBL) and the electronic-address codelist behind the fatal PEPPOL-EN16931-CL008 drops 14 schemes. 3.0.20 stays pinnable until 2027-03-03.
2026-09-17 Peppol BIS Billing 3.0 unit-test corpus 3.0.20 corpus (58 testSets / 227 cases) 3.0.21 corpus (62 testSets / 335 cases) No runtime artifact version change: the ruleset has been 3.0.21 since 2026-09-03 and only the corpus that proves its verdicts moved, re-vendored from the same pinned commit. Four rules 3.0.21 adds gain their negative fixtures (PEPPOL-COMMON-R054, R055, R056-1, R057) and seven existing files are brought current, including PEPPOL-COMMON-R052/R053, whose fixtures still asserted the pre-3.0.21 warning severity.
2026-09-18 Peppol BIS Billing 3.0 example invoices 3.0.20 examples (9) 3.0.21 examples (10) No runtime artifact version change. The positive corpus is re-vendored from the same pinned commit as the ruleset and the unit-test corpus. 3.0.21 adds base-example_profile02.xml, an invoice that asks the buyer for an invoice response (ProfileID urn:peppol:bis:billing_with_response); Beliq and the KoSIT 3.0.21 reference configuration both accept it. The other three changed files differ only in a comment.
2026-09-05 KoSIT validator + KoSIT XRechnung scenario configuration 1.6.2 / 2026-01-31 1.6.3 / 2026-08-31 Cross-validation only. The 2026-08-31 configuration adopts CEN Schematron 1.3.16, so it no longer carries BR-CO-25 and is no longer among the validators listed above that enforce it. The runtime severity-override table regenerated from the same release is a separate bump, in force since 2026-09-09 and recorded in the row below.
2026-09-09 XRechnung Schematron + KoSIT severity-override table 2.5.0 / 2026-01-31 2.6.0 / 2026-08-31 Breaking, and it took effect on merge with no notice period: no organisation had a member who is not a test account, so waiting would have protected nobody while 2.5.0 kept rejecting conforming documents. BR-TMP-2 goes warning to fatal in both syntaxes (BT-124 must be an absolute URL) and CII-SR-465/CII-SR-466 go warning to error on CII (a contact must not carry both a person name and a department name). Going the other way, PEPPOL-EN16931-R008 no longer rejects an empty cac:OrderReference/cbc:ID. Both stay pinnable as previous until 2027-06-11.
2026-09-10 Factur-X Schematron + France BR-FR-CTC Flux 2 + France EXTENDED-CTC-FR 1.08 / 1.3.1 1.09.2 / 1.4.0.03 Breaking, announced 2026-08-20 for 2026-11-20 and brought forward: no organisation had a member who is not a test account, so the notice period protected nobody. The Flux 2 pack raises 141 CII and 145 UBL asserts from warning to fatal with no rule-id change, so a France CTC document carrying any BR-FR-* finding is now invalid rather than valid-with-warnings. Four of the five Factur-X profiles gain asserts; BR-CO-25 leaves BASIC, BASIC_WL and EN16931 and is served as an advisory there. The packs emit upstream rule ids beside the generated FX-SCH-A ones. 1.08 and 1.3.1 stay pinnable as previous until 2027-05-16.
2026-09-15 France BR-FR-CTC Flux 2 + France EXTENDED-CTC-FR (Factur-X pack re-pinned, spec unchanged) 1.4.0.03 1.4.0.04 Took effect on merge. The FNFE pack moved; the Factur-X specification did not, so facturx_schematron stays 1.09.2 and only its archive pin changed (the 2026-09-04 archive ships its Factur-X tree as Factur-X_1.09.2.fixFR04). Nothing measured newly fails: four of the five vendored packs keep their assert id set and flag histogram exactly, and every predicate change is a false-positive fix. The nine BR-FXEXT-*-01 rules had a DETAIL-only scope that never applied because the predicate addressed a sibling as a child, so invoices with GROUP lines were judged as if every line were a DETAIL line; several monetary comparisons moved from number() to xs:decimal(); BR-FR-CO-07 now tolerates more than one payment due date; and BR-FR-20/BT-21 accepts B2CINT as a BAR note value. On EXTENDED-CTC-FR CII, CII-SR-069 and CII-SR-072 are replaced by CII-FREXT-SR-069 / -072, which test <= 1 where the base rules test = 1 — matching what both rules’ own text always said. 1.4.0.03 is not retained: previous stays 1.3.1 until 2027-05-16.
2026-10-05 EN 16931 syntax schemas: CII D16B, CII D22B, UBL 2.1 and the Factur-X profile XSDs not in rulesetSha256 in rulesetSha256 No schema version moves and no verdict changes. The schema a document was checked against is now a rulesetArtifacts row and part of rulesetSha256, so the fingerprint of every EN 16931 result changed once, and a document the schema rejects now carries both fields. Announced on the public changelog on 2026-09-20. FatturaPA, Facturae and e-SLOG fingerprints did not change: their root XSD was already recorded.
2026-04-28 AGID FEL XSD bundle 2.1.4 Cross-validation only. Added to back T3 negatives for italy_fatturapa_ordinaria.
2026-05-01 Italy FatturaPA runtime XSD bundle 1.4-runtime-2026-05-01 Runtime XSD validation on POST /v1/generate and POST /v1/validate for FatturaPA FPR12 / FPA12 / FSM10.
2026-05-02 Italy SDI MessaggiTypes XSD 1.1.0-pinned-2026-05-02 XSD-only path on POST /v1/validate for SDI file messaggi (notifications / receipts). Not transport.
2026-04-28 Italy SDI transport URL bundle sdi-interchange-1.8.4-urls-2026-04-28 URL pointers only — no submission, signing, or operator integration is implemented.
2026-05-23 Nightly content-SHA drift detection active Re-fetches every SHA-pinned artefact nightly and opens tracking issues on detected drift. Internal — no customer-facing API change.
2026-05-26 Spain Facturae runtime XSD bundle 3.2.2-research-2026-05-24 Runtime XSD validation on POST /v1/generate (standard: "facturae") and POST /v1/validate for Facturae 3.2.2 — XSD-only, no EN 16931 Schematron (Facturae’s lineage is the MINECO spec, not CEN).
2026-06-02 Romania RO_CIUS Schematron (XSLT pair via the Helger phive-rules-cius-ro pack) 1.0.9 Runtime Schematron arm on POST /v1/validate for Romanian CIUS-RO UBL (current + legacy URN), plus POST /v1/generate with standard: "peppol-bis" + profile: "romania-ro-cius". Profile is provisional; promotion to supported waits on the remaining T3 negatives and phive cross-validation gate. ANAF SPV submission stays BYOC.
2026-09-17 Romania RO_CIUS Schematron (phive pack re-pinned, artefacts unchanged) 4.4.1 4.5.6 No rule change: phive-rules-cius-ro 4.5.6 still ships CIUS-RO 1.0.9 and the two vendored XSLTs are byte-identical across the pack bump, so validation behaviour does not move. The pin tracks a current Maven coordinate.
2026-06-09 Netherlands NLCIUS Schematron (SI-UBL 2.0 via NPa peppolautoriteit-nl/validation) 2.0.3.13 Runtime NLCIUS XSLT arm on POST /v1/validate for Dutch NLCIUS UBL (CustomizationID prefix urn:fdc:nen.nl:nlcius:v1.0, matched starts-with), plus POST /v1/generate with standard: "peppol-bis" + profile: "netherlands-nlcius". Single XSLT covers Invoice + CreditNote; failures carry BR-NL-*. Profile netherlands_peppol_nlcius promoted to supported. Digipoort / Logius B2G submission stays Peppol-AP-routed BYOC.
2026-06-11 Slovenia e-SLOG 2.0 runtime XSD bundle 2.0-08-2020 Runtime XSD validation on POST /v1/generate (standard: "eslog", invoices and credit notes) and POST /v1/validate for e-SLOG 2.0. XSD-only, no EN 16931 Schematron (GZS/ePOS publish no machine-readable business rules). UJP submission and e-route provider services stay BYOC.
2026-06-18 Mustang CLI 2.22.0 2.24.0 Hybrid PDF/A-3 assembly (--action combine). No API surface change.
2026-06-18 VeraPDF (PDF/A validator) 1.28.2 1.30.2 PDF/A-3b verification of the hybrid PDFs built by POST /v1/generate (output: "pdf"). No API surface change.
2026-06-18 France BR-FR-CTC Flux 2 + EXTENDED-CTC-FR Schematron 1.3.0 1.3.1 Re-vendored from the FNFE-MPE 2026-04-30 publication.
2026-07-24 Saxon HE (XSLT processor) 12.9 12.10 Schematron XSLT execution across every validation arm. No API surface change.
2026-09-16 Mustang CLI 2.24.0 2.26.0 Hybrid PDF/A-3 assembly (--action combine). Moves off the bundled veraPDF 1.26.5, which sits inside the affected range of CVE-2026-54079 and CVE-2026-54078; 2.26.0 bundles the patched 1.30.2. The same tag is the Factur-X MINIMUM / BASIC secondary source, and re-pinning it corrects two dangling schemaLocation hints in the vendored per-profile XSDs. No rule, flag or codelist moves, and no API surface change.
2026-06-13 Netherlands NLCIUS comprehensive corpus + Schematron-only harness 2.0.3.13 (unchanged) No runtime artifact version change (SI-UBL 2.0 v2.0.3.13, same SHA; SHA-drift unchanged). Test corpus grown 10 → 120 (the full NPa SI-UBL 2.0 authority testset) and asserted by a Schematron-only harness (every document outcome plus per-rule SVRL firing). A rule-coverage audit confirms a Tier-1 negative per critical rule family. Profile netherlands_peppol_nlcius promoted supportedfully-verified; two residuals documented (UBL-SR-09/15 upstream XSLT XPTY0004 crash, BR-NL-34 under the BR-NL-32 id). No API surface change.