fiskaly.

4 min read

French fiscalization explained: the four ISCA obligations

The four ISCA obligations — inalterability, security, conservation, archiving — explained in plain terms for POS vendors selling in France.

A baker using a point-of-sale system in a French bakery

The four ISCA obligations of French fiscalization, in plain terms

Since January 1, 2018, article 286-I-3° bis of the French General Tax Code (Code général des impôts, CGI) has required any VAT-liable business that records consumer payments through a point-of-sale system to use software meeting four conditions: inalterability, security, conservation, and archiving. Together, these four conditions are known as the ISCA obligations. This guide explains, in plain terms, what each one means for a cash-register or POS software vendor.

What the law says

The obligation was created by article 88 of the 2016 Finance Act and has applied since January 1, 2018. Its purpose is to fight VAT fraud by making so-called permissive software impossible, meaning software able to delete or alter recorded payments after the fact. It targets VAT-liable businesses in any sector whose system records customer payments "extra-comptablement", that is, capturing the payment in the till / POS system itself, separate from the accounting entries. This is what defines a système de caisse for the tax authority, and it applies whatever the payment method (cash, card, transfer) and whether the system is on-premise or online. Compliance of the cash register system can be proven in two ways: a certificate issued by an accredited body (LNE or InfoCert), or an individual attestation from the software publisher, matching a template set by the tax authority. The law concerns whether your system is compliant, not whether you must use one: if you use a till, it has to be compliant.

I — Inalterability

The software must record all payment data without any possibility of altering it. A cancellation or a correction is still allowed commercially, but it must itself be recorded and remain immediately identifiable. Nothing can be deleted or rewritten silently.

S — Security

The software must secure the original data, the modification data, and the data used to produce supporting documents, so that everything can be restored in its original recorded state. In practice, this relies on signing and cryptographic chaining of records.

C — Conservation

The software must calculate and record cumulative and summary data — daily, monthly, and annual closings — that are complete and tamper-proof. These frozen totals are what let the tax authority reconcile declared turnover.

A — Archiving

The software must archive recorded data on a chosen frequency (annual at most, or per financial year), to freeze the data and give it a certain date. The archive must remain accessible and usable in the event of an audit.

ObligationWhat the system must guarantee
InalterabilityNo payment record can be modified without a trace
SecurityOriginal and modification data protected and restorable as recorded
ConservationDaily, monthly, and annual closings, frozen and complete
ArchivingPeriodic archiving that gives recorded data a certain date

Two ways to prove compliance (overview)

ISCA describes what the system must guarantee, not how to prove it. For proof, two routes coexist: certification by an accredited body (LNE or InfoCert), and the publisher's individual attestation, reinstated by the 2026 Finance Act. Both are recognized equally by the tax authority. We cover that choice in dedicated articles.

Not to be confused with e-invoicing

The ISCA obligations belong to the anti-fraud regime for cash-register software. They are separate from the rollout of e-invoicing, even though both topics move on similar timelines. These are two distinct obligations driven by two different mandates: ISCA secures how customer payments are recorded at source in the till, while e-invoicing governs how invoices are issued, transmitted and reported between businesses.

Next steps

fiskaly SIGN FR provides the technical foundation — signing, cryptographic chaining, tamper-proof journaling, and archiving — that ISCA compliance rests on, whether you choose accredited certification or the publisher's individual attestation. Test the API for free, with no commitment, or talk to our team to scope your French compliance. Last updated: September 2026. This article is general guidance, not legal or tax advice. Confirm the applicable scope and requirements against the French tax authority's current guidance (BOFiP, bofip.impots.gouv.fr) and the text of article 286-I-3° bis of the CGI on Légifrance.

Frequently asked questions

Since January 1, 2018, under article 286-I-3° bis of the CGI, created by the 2016 Finance Act.

VAT-liable businesses in every sector that record payments from private customers through a POS system. Purely B2B activities and the VAT-exemption scheme (franchise en base) are excluded.

No. ISCA refers to the four technical requirements you must meet. Accredited certification and the publisher attestation are two ways to prove you meet them.

Interested? Request a first meeting

  • We're here to help with any questions and find the perfect solution.
  • Over 1,900 customers trust our fiscalization solutions. We've got you covered!

Optional

Optional