Hardware vs. Cloud Fiscalization: A Country-by-Country Overview
A USB stick fails in a till in Munich. A smartcard expires in a bar in Vienna. A registratore telematico needs its 2-year Verificazione Periodica in Milan. A kontrollenhet reaches the end of its certified life in a café in Stockholm.
Four countries, four fiscalization mandates, and the same underlying question every POS vendor eventually hits: does compliance live in a physical box screwed to the till, or in an API call? Germany's KassenSichV, Austria's RKSV, Italy's corrispettivi telematici rules, and Sweden's kassaregister law each started with a hardware requirement, and all four now recognize a cloud alternative under that same law. This guide lines up what "hardware" and "cloud" actually mean in each market, since the mechanism differs country by country rather than being the same regulation copy-pasted four times.
Key takeaways
Every market's cloud alternative answers to the same underlying compliance regime as its hardware option — except Austria, which certifies neither — and cloud isn't automatically cheaper, more reliable, or further along everywhere.
- Germany's TSS (called a TSE, Technische Sicherheitseinrichtung, in the regulation) can be a physical USB/SD module or a BSI-certified cloud TSS. Both variants must be certified — TSE and TSS are the same thing. fiskaly's current cloud TSS certificate runs through 2033, but that date belongs to fiskaly's own certificate, not to every vendor's or to any future recertification.
- Austria's RKSV has no government certification scheme at all, for hardware or cloud. Compliance rests on a qualified certificate from a Trust Service Provider under eIDAS (such as A-Trust, PrimeSign, or GlobalTrust) plus the POS provider's own declaration of conformity — and registering the signature unit with FinanzOnline stays the merchant's own legal responsibility either way.
- Italy's certified cloud path, SIGN IT full, isn't homologated yet. fiskaly is part of the Agenzia delle Entrate's pilot group working toward that under Legislative Decree 1/2024, Article 24; first homologations are expected by the end of 2026 or in early 2027. In the meantime, SIGN IT lite runs on the AdE's own Documento Commerciale Online portal, live since 2016.
- Sweden's cloud option predates fiskaly's entry into the market by four years. SKVFS 2020:9 legalized cloud-based control systems (kontrollsystem) on January 1, 2021; fiskaly's 2025 acquisition of InfraSec Sweden AB folded an already-established cloud infrastructure into SIGN SE, rather than creating the category.
- The genuinely strong cloud arguments are scalability and, looking ahead, patchability — not "hardware fails and cloud doesn't." Cloud services have outages too; the real difference is maintenance overhead and how fast a fix reaches every till at once.
How does Germany's TSE work in hardware form, and what does cloud replace?
Germany's KassenSichV (Kassensicherungsverordnung) requires every electronic cash register to run a Technical Security System (TSS) — called a TSE in the regulation itself — that signs each transaction and stores it tamper-proof. fiskaly's KassenSichV and TSE guide covers the wider set of obligations this creates; this section focuses on the hardware-versus-cloud choice inside it.
A hardware TSS ships as a USB stick, SD card, or embedded module from BSI-accredited vendors, chiefly Swissbit, whose modules are also sold under the Epson and Diebold Nixdorf brands. Every TSS — hardware or cloud — has to be certified by the BSI (Bundesamt für Sicherheit in der Informationstechnik), and that certification runs on two separate clocks that are easy to conflate: the hardware platform itself is certified for 5 years, and the TSS signing key carries its own, separate 8-year validity limit. Once either one expires, the device can no longer legally sign transactions, which is what actually forces a hardware swap — there's no separate per-unit BSI renewal fee involved.
A cloud TSS doesn't depend on a local hardware platform, so it avoids that specific swap — but its signing key still carries the same 8-year limit unless it's recertified. The certified component behind fiskaly's SIGN DE is the fiskaly sign Cloud-TSE; SIGN DE itself is a product that incorporates that certified TSS, not a TSS or a certified component in its own right, and fiskaly's current certificate for it runs through 2033. Removing the hardware doesn't remove all maintenance overhead, either — cloud services can have outages of their own, and any TSS fleet, hardware or cloud, still needs its signing-key renewal tracked. See fiskaly's guide on what happens when a hardware TSS certificate quietly expires for what that looks like in practice.
What changed with Austria's move from A-Trust smartcards to cloud RKSV?
Austria's RKSV (Registrierkassensicherheitsverordnung) requires a signature creation unit (Signaturerstellungseinheit) to sign every receipt before it prints, plus a data capture log — the DEP per § 7 RKSV — and registration with FinanzOnline (FON). fiskaly's overview of the RKSV covers the full set of requirements this creates.
Most businesses that went live when RKSV took effect on April 1, 2017, integrated a hardware-bound signature device, typically an A-Trust smartcard. Those cards carry a qualified certificate with a fixed expiry, and Austria's 2017-era installed base is now reaching that renewal window.
A cloud-based setup, such as fiskaly SIGN AT, replaces the smartcard with an API integration that produces the same DEP capture per § 7 RKSV. What doesn't change is who's responsible for the paperwork: registering the cash register and signature unit with FinanzOnline, and reporting when a signature unit goes offline for an extended period, both stay the taxpayer's own legal obligation — the signature unit itself only supplies the cryptographic serial numbers and public keys the merchant needs to file. And unlike the other three markets in this guide, no government body certifies the signature unit at all in Austria: compliance instead rests on a qualified certificate issued by a Trust Service Provider under eIDAS (A-Trust, PrimeSign, GlobalTrust), with the POS provider filing its own declaration of conformity rather than obtaining a state certification.
Where does Italy's fiscalization software path stand today?
Italy's Legislative Decree 127/2015 requires certified Registratore Telematico (RT) hardware to transmit corrispettivi telematici — the daily electronic transmission of sales receipts — to the Agenzia delle Entrate (AdE), a requirement in force since 2020.
RT devices need Verificazione Periodica, a mandatory technical inspection, every 2 years — a recurring cost and logistics problem for any chain running hundreds of locations. A software-only alternative has actually existed since 2016: the AdE's own Documento Commerciale Online web portal (Provvedimento 28/10/2016, § 1.11), which fiskaly offers today as SIGN IT lite. A fully certified path, SIGN IT full, is being built under Legislative Decree 1/2024, Article 24. fiskaly is part of the AdE's pilot group working toward it, but as of 2026 no software solution has been certified or homologated yet — certification (an authorized body such as CNR or PoliMi testing the solution) and homologation (the Commissione Misuratori Fiscali's own approval) are two separate steps, and neither has completed for any vendor. First homologations are expected by the end of 2026 or in early 2027. fiskaly's guide to Italy's 2026 certification requirements covers the process in more detail.
Since January 1, 2026, Italy's 2025 Budget Law (Law 207/2024, Article 1, paragraphs 74–77) also requires every fiscalization solution, hardware or cloud, to know the matricola of the POS it's connected to — in Italian usage, POS means the electronic payment terminal, not point-of-sale software — and to have declared that pairing to the AdE. That's a device-identification requirement, not a certification: there's no such thing as a "certified matricola," a matricola is simply the serial number or logical pairing on file, and the rule applies the same way whether the fiscal device behind it is hardware or cloud.
How does Sweden's kassaregister law treat hardware versus cloud control systems?
Sweden's Cash Register Act (SFS 2007:592, now part of the Tax Procedure Act, Skatteförfarandelag SFS 2011:1244) requires every business receiving cash payments to use a certified kassaregister paired with a control system that generates the 113-character avstämningskod (control code) attached to every receipt. That control system was historically a physical kontrollenhet, wired into the till and certified under SKVFS 2014:9.
Cloud-based control systems (kontrollsystem) have been legally permitted since January 1, 2021, under SKVFS 2020:9 — years before fiskaly entered the Swedish market. fiskaly's 2025 acquisition of InfraSec Sweden AB folded Sweden's already-established cloud compliance infrastructure into SIGN SE, a single API covering the mandatory four-tier VAT structure and the 13 required receipt fields under SKVFS 2021:17, without a physical kontrollenhet on site. Skatteverket (the Swedish Tax Agency) still requires the same three-step registration process and a 14-day notification window when a control system changes, whichever kind of control system it is. fiskaly's guide on what "certified" actually means for a Swedish cash register covers the accredited-body mechanics behind that certification.
What changes operationally when a business switches from hardware to cloud?
Hardware fiscalization ties compliance to a physical unit: something that needs maintenance, expires, or requires an on-site technician. Cloud fiscalization ties it to an API integration a vendor updates centrally. Not every hardware unit in a fleet actually fails, and a hardware fleet usually runs on one TSS version with one shared certificate expiry rather than hundreds of separate renewal dates — the same is true of a cloud TSS fleet, since it's just as version-dependent as the hardware it replaces.
The two advantages that hold up under scrutiny are scalability and, increasingly, patchability. Provisioning ten additional cloud TSS instances takes a minute or less, against ordering, shipping, and installing that many hardware modules. And looking ahead, a cloud TSS can be patched centrally against a newly discovered vulnerability — a growing concern as AI-assisted attacks become more frequent — where a hardware fleet needs a firmware update pushed, or in the worst case a physical swap, device by device. None of this makes cloud immune to disruption: cloud services have outages of their own, so the honest framing is reduced maintenance overhead and faster fixes, not a reliability guarantee hardware can't offer.
Comparison table: hardware vs. cloud fiscalization, by market
| Market | Regulation | Hardware component | Cloud alternative | Recurring hardware cost/risk |
|---|---|---|---|---|
| Germany | KassenSichV | USB/SD TSS (TSE) | BSI-certified cloud TSS (fiskaly sign Cloud-TSE, via SIGN DE) | 5-year hardware-platform certificate; 8-year signing-key expiry (applies to the cloud TSS too) |
| Austria | RKSV | A-Trust smartcard signature creation unit | Cloud signature creation unit (SIGN AT) — no government certification either way | Smartcard's qualified certificate expiry (QTSP-issued under eIDAS) |
| Italy | Legislative Decree 127/2015 | Registratore Telematico (RT) | AdE Documento Commerciale Online portal (SIGN IT lite, since 2016); SIGN IT full in AdE pilot, not yet homologated | Verificazione Periodica every 2 years |
| Sweden | SFS 2007:592 / SFS 2011:1244 | Kontrollenhet control unit | Cloud control system — kontrollsystem via SIGN SE — legal since SKVFS 2020:9 | Physical installation and per-till hardware; certified control systems, either kind, run up to 5 years with mandatory annual reassessment |
Bottom line
The hardware-versus-cloud choice is a certification question wearing a hardware costume: three of these four countries require the cloud path to answer to the same certifying authority as the hardware it replaces, and the fourth, Austria, doesn't certify either one. Cloud's real advantages are scalability and, over time, patchability — not immunity to outages, and not, in Germany's case, escaping a per-device fee that was never actually charged in the first place. Where a market's cloud option genuinely still lags — Italy's SIGN IT full homologation, pending as of 2026 — that's worth knowing before assuming every country's cloud path is equally mature. fiskaly SIGN covers Germany, Austria, Italy, and Sweden through one API for any business weighing the switch, with fiskaly SAFE handling the audit-ready archiving each country's tax authority expects behind it.








