Electronic invoice in Malta
The Definitive Guide to Malta’s E-Invoicing Landscape: Navigating the voluntary Peppol B2G model, EN 16931 compliance, and future-proofing your operations for the 2030 ViDA horizon.
Malta has no mandatory e-invoicing for suppliers in B2G, domestic B2B or B2C. The only obligation is on the receiving side: contracting authorities must accept and process structured invoices conforming to EN 16931 where the invoice relates to procurement above the applicable EU threshold. A supplier is not obliged to send one.
The existing state infrastructure is built on Peppol and the decentralised four-corner model. It is not a clearance system: no invoice goes to the Malta Tax and Customs Administration (MTCA) for prior approval, registration or a tax identifier, and there is no VAT real-time reporting or other national CTC mechanism. What Malta does have that many EU countries do not is a fiscal receipt regime for consumer sales, which sits alongside all of this.
Malta transposed the procurement directive and has announced nothing since. The one date that matters is European.
Directive 2014/55/EU was transposed through two separate instruments — one for central administration and one for local councils, which are governed by their own financial rules.
The receiver-side obligation took effect for central government.
Malta used the additional year the directive allowed for regional, local and other sub-central authorities. See B2G.
Structured e-invoicing becomes the mandatory and default method for the covered cross-border B2B transactions. See ViDA and 2030.
National domestic real-time reporting systems, where they exist, must be aligned with the EU model and standards. For Malta this is a harmonisation milestone rather than an announced domestic mandate.
MTCA is examining B2B, B2G and B2C e-invoicing together, and in June 2025 completed an EU-funded project aimed at preparing Malta for the 2030 ViDA requirements. But no bill, technical specification, phased rollout or turnover threshold has been published for a national mandate. ViDA already permits member states to introduce domestic mandatory e-invoicing under defined conditions — Malta has not done so, and no date exists.
Contracting authorities must accept and process compliant EN 16931 invoices where the invoice relates to a contract above the EU public procurement thresholds. Economic operators may still invoice by any other agreed means, because no supplier-side mandate was introduced.
The government put the receiving side out to tender and awarded the public contract for Peppol networking and e-invoicing services to Pagero. Peppol is the standardised interoperable channel chosen for central administration, public entities, regional authorities and local councils.
The absence of national accreditation does not mean a provider can automatically invoice every public body. Before sending you still need to check the specific recipient's Peppol participant ID, its registered document types, any mandatory buyer references, the purchase order or contract reference, and the authority's own internal procurement requirements.
No law requires structured e-invoices to be issued or received between Maltese businesses, or between a business and a consumer. E-invoicing remains voluntary and rests on agreement between the parties. The ordinary Malta VAT Act rules apply — and they turn on registration type, which is the part most often missed.
For consumer sales the principal tax document remains the fiscal receipt, which may be produced by an approved fiscal cash register, on an official manual fiscal receipt book, by a computer, electronic or POS system pre-approved by MTCA and carrying an EXO number, or in defined cases by another MTCA-approved document.
This is a separate fiscal receipt regime — not structured EN 16931 e-invoicing, and not real-time CTC. A POS integration project in Malta is a fiscal receipt project, not an e-invoicing one.
The B2G infrastructure is the standard Peppol four-corner arrangement — supplier, supplier's Access Point, buyer's Access Point, contracting authority — with routing through Peppol SML and SMP and documents moving between certified service providers.
The European Commission's phrase "no centralised platform" means there is no single national clearance or CTC platform. There is a Peppol service, provided by a state-selected service provider, for receiving public-sector invoices. Both are true: a reception service for public bodies is not a tax clearance system.
There is no mandatory VAT real-time reporting. MTCA is running a technical, legal and operational assessment of a future system, so none of the design questions is settled — not the corner model, not the tax authority API, not the transmission deadlines, acknowledgement and rejection messages, invoice status reporting, an intermediary accreditation scheme, or the national reporting dataset. ViDA requires digital reporting but does not oblige Malta to adopt clearance; service providers, direct transmission or a state portal are all open options.
Malta has adopted EN 16931 in full for B2G. The practical profile is Peppol BIS Billing 3.0, the Peppol CIUS, with UBL 2.1 Invoice and Credit Note as the operational syntax. There is no Maltese national CIUS and no national extensions.
On CII. EU law recognises two EN 16931 syntax families — UN/CEFACT Cross Industry Invoice XML (CII 16B) and UBL Invoice and Credit Note under UBL 2.1 — so CII is a valid European syntax. But the official Maltese material for actual B2G exchange emphasises Peppol BIS Billing 3.0 and UBL. Do not assume any CII file can be sent to a given public recipient without first checking its Peppol capability and registered document types.
A plain PDF, a scanned invoice or a PDF emailed to the buyer is not a structured e-invoice under Directive 2014/55/EU and does not satisfy the EN 16931 requirement for B2G.
In domestic B2B, where no mandate applies, a PDF may continue to be used as an ordinary invoice document provided it meets the general VAT Act requirements and the parties accept it. What it cannot be called is an EN 16931 e-invoice, and it is not automatically fit for Peppol exchange.
The country-specific Peppol Electronic Address Scheme is 9943 — Malta VAT number, giving a participant ID of the form 9943:.
A recurring configuration error worth naming: 9930 is the German VAT number scheme and does not apply to a Maltese VAT ID. Getting this wrong produces a participant that cannot be found.
Other global identifier schemes such as GLN may be used in Peppol where the receiver's registration supports them, but the official EAS list provides 9943 specifically for the Maltese VAT number. No separate confirmed national EAS for the Malta Business Registry number was found in the documentation reviewed.
For structured B2G exchange, yes — Peppol is the channel the Maltese government chose. It is not mandatory for all Maltese B2B invoices, because no domestic B2B mandate exists.
No separate Malta Peppol Authority is designated in the official material. Malta is described as an OpenPeppol end-user member using the Peppol CIUS. In practice the certification of Access Points serving the Maltese market runs through OpenPeppol or another competent Peppol Authority — the Maltese provider PaperLess Innovation Ltd is certified under OpenPeppol, while the government's provider Pagero is certified under the Swedish authority NAPP.
No Maltese PASR of the kind published by France, Slovakia or Poland exists. That is why the market is open — and also why the governance rules that bind you are those of whichever Peppol Authority your own agreement sits under.
From 1 July 2030 the digital reporting requirements apply to relevant cross-border B2B transactions within the EU, and the structured e-invoice becomes the mandatory default method of documenting them. The expected coverage includes intra-Community supplies and acquisitions of goods, cross-border B2B services under reverse charge, and other transactions brought into the harmonised intra-EU DRR.
Peppol is the likeliest technological candidate given the existing infrastructure — but MTCA has not announced that ViDA reporting will be implemented through a Peppol five-corner model, so that architecture should not be treated as settled.
Nor does ViDA automatically introduce a general domestic B2B mandate in Malta. The state is free to introduce one separately, and ViDA already permits it under defined conditions — but no such decision or date has been published. And the cross-border DRR is aimed at intra-EU transactions, not at exports to third countries: for non-EU exports and supplies with a place of supply outside Malta, the ordinary VAT, customs and commercial documentation rules continue to apply.
No official requirement for additional Maltese accreditation was found — nothing comparable to the Slovak digitálny poštár, the French registered platform (PDP) or the provider certification schemes of the CTC countries. Malta has published no separate national security, interoperability or tax reporting requirements for Access Points.
A foreign Access Point can therefore onboard Maltese clients. The clearest evidence is that the Maltese government itself is served by a Swedish provider.
All of that describes the current voluntary Peppol/B2G regime. A future ViDA or CTC implementation could introduce separate intermediary registration, KYC, reporting liability, audit or security requirements — none of which has been published. This is the real regulatory risk in Malta: not today's requirements, but that MTCA is still designing tomorrow's.
Records, information, documents and accounts must be retained for at least six years from the end of the year to which they relate, or such other period as may be prescribed in special cases. Two extensions matter a great deal in practice and are frequently overlooked:
A twenty-six-year horizon for property-related input tax is longer than most archive platforms have existed. Any Maltese archive design should therefore classify documents by what the input tax relates to, not simply apply a flat six-year rule.
Because there is no clearance platform, nothing is stored on your behalf. Where an invoice was exchanged through Peppol, retaining the XML rather than only a rendered PDF is what preserves the structured evidence — and fiscal receipts fall under their own approval and record-keeping rules alongside.
Because there is no supplier-side mandate in B2G, domestic B2B or B2C, there is no specific penalty for failing to send a structured e-invoice. Stating one would be inventing it.
Ordinary VAT liability is unaffected, and in Malta it has a broader reach than in many EU states because of the fiscal receipt regime. Exposure remains for failing to issue a required tax invoice; failing to issue a fiscal receipt; misstating VAT; omitting mandatory invoice particulars; late declaration; and using an unapproved fiscal receipt or POS system. Those are VAT Act and fiscal receipt breaches, not e-invoicing breaches.
In B2G the risk is contractual. A contract or tender document may specify how the invoice is to be submitted, and not complying can affect acceptance and payment or amount to a breach of contract — but it is not the same as a statutory e-invoicing fine.
An electronic invoice is not the only lawful basis for deducting VAT. Among the other conditions, a taxable person must hold a valid tax invoice — but there is currently no requirement that it be a Peppol, EN 16931 or XML document. The right to deduct can therefore be supported by a valid tax invoice in any admissible form, on paper or electronically, including an ordinary electronic document that meets the VAT Act requirements.
After ViDA is implemented, a member state will be able in defined cases to make a compliant structured e-invoice a substantive condition of deduction for the transactions covered by mandatory e-invoicing. Malta has not yet adopted national rules imposing such a condition.
Malta needs no national module today. What it needs is a correctly configured Access Point and a plan for the requirements MTCA has not yet written:
9943 with the Malta VAT number — never 99309943:. A common configuration error is to use 9930, which is the German VAT number scheme and does not apply here; the result is a participant that cannot be found. Other global schemes such as GLN can be used where the receiver's registration supports them, but the official list provides 9943 specifically for the Maltese VAT number, and no separate confirmed national EAS for the Malta Business Registry number was found.Malta transposed the procurement directive in 2018 and stopped there. Public buyers must receive EN 16931 invoices above the EU thresholds; suppliers have never been required to send them; and domestic B2B and B2C remain voluntary, governed by the ordinary VAT Act and a fiscal receipt regime rather than by any e-invoicing rule. There is no clearance, no MTCA validation, no QR code and no real-time reporting.
Technically it is plain: Peppol BIS Billing 3.0 in UBL 2.1, no national CIUS, EAS 9943, and no Maltese accreditation, local entity, representative, e-ID, mailbox or local hosting requirement for a service provider.
The regulatory risk in Malta is not what exists — it is what does not yet. MTCA is still designing the future model, and until the law and technical specifications are published, nothing can be said with certainty about provider registration, reporting APIs, data residency, intermediary liability or service levels. Building now for EN 16931, ViDA reporting datasets and possible five-corner interoperability is the sensible hedge.