HMRC's consultation on mandatory software standards for Electronic Point of Sale (EPOS) and Mobile Point of Sale (MPOS) systems remains open for responses until 18 August 2026. The target is Electronic Sales Suppression (ESS), also called till fraud: manipulating digital sales records to hide or reduce reported turnover. HMRC names Austria, Germany, and Norway directly as the international models behind its proposals, and the consultation asks EPOS/MPOS vendors by name for input.
TL;DR
- HMRC's consultation on mandatory software standards for EPOS/MPOS systems, aimed at preventing Electronic Sales Suppression (ESS), is open for responses until 18 August 2026.
- The proposed package centers on an unalterable SAF-T transaction log, encrypted receipt chaining, an EPOS/MPOS registration or certification scheme, and penalties for manufacturers whose systems get used for ESS.
- HMRC explicitly cites Austria, Germany, and Norway as the international approaches it consulted before drafting these proposals.
- HMRC's own data shows the small business tax gap reached £28 billion in 2023 to 2024, with deliberate evasion accounting for £5.2 billion of that.
- This is a consultation, not legislation. No implementation timeline has been set.
- fiskaly already runs certified cloud infrastructure built on the same three national models HMRC is using as its reference points.
What just happened
HMRC's Electronic Sales Suppression consultation is an eight-week public consultation, seeking views on mandatory software standards for EPOS and MPOS systems.
It builds directly on earlier groundwork: a 2018 Call for Evidence, which drew 11 responses from till system creators, suppliers, and trade bodies and fed into HMRC's 'Prevent, Promote, Respond' compliance strategy, and the Finance Act 2022 (Schedule 14), which made possessing, making, supplying, or promoting ESS tools a specific offence for the first time, alongside expanded information-gathering powers under Finance Act 2008, Schedule 36. Autumn Budget 2025 then flagged further high-street fraud measures.
Sixteen of the 37 OECD countries already mandate EPOS use for tax compliance, and five of those also require automated transmission of sales data straight to the tax authority. That context matters given how fast the UK's own payment mix has shifted: the British Retail Consortium's 2024 Payments Survey found cash usage fell from 53% of retail payments in 2013 to a low of 15% in 2021, recovering slightly to 20% by 2023, while debit card use rose from 32% to 62% over the same period.
A 2016 HMRC report into one specific form of ESS put the associated tax loss at £100 million, and a broader 2019 estimate put VAT losses from suppression above £450 million a year. The National Audit Office reported in 2024 that ESS compliance yield rose from £17 million in 2022 to 2023 to £98 million in 2023 to 2024, as HMRC's casework expanded from 253 to 1,275 cases.
In the 2023 to 2024 tax year, the small business tax gap grew to £28 billion, 60% of the UK's overall £46.8 billion tax gap, with the deliberate evasion component alone reaching £5.2 billion. That sits against total HMRC revenue of £858.9 billion in 2024 to 2025, the funding base for public services the consultation says these measures are designed to protect. HMRC is addressing this specifically to EPOS/MPOS developers, providers, and resellers, alongside retail and hospitality businesses and tax professionals.
One HMRC case shows what this looks like in practice: investigators traced software that let a linked mobile app remotely delete sales from an EPOS database without leaving a trace in the audit trail. Fourteen businesses known to be using that software were pursued for tax on suppressed sales, two of them through criminal prosecution, recovering £1.3 million in tax.
What's actually being proposed
The consultation lays out six measures that would work together, not as standalone options.
-
An unalterable transaction log in the OECD's SAF-T (Standard Audit File for Tax) format, with every transaction and adjustment cryptographically chained.
-
A registration or certification scheme for EPOS/MPOS systems sold, transferred, or used in the UK, with three variants under consideration: manufacturer self-certification, supplier registration at point of sale, or user registration on purchase.
-
Mandatory information on receipts and system reports, most likely delivered as a scannable QR code that both auditors and consumers can use to verify the cryptographic chain; the consultation separately asks whether mandatory receipting should apply to every transaction or only above a minimum threshold, floating £35 as an example.
-
Faster, lower-intensity compliance checks: an officer scans the QR code, verifies the chain and summary values, and can close a check in roughly 30 minutes rather than the months a traditional enquiry takes.
-
A general duty on suppliers to protect their systems' integrity against ESS tampering.
-
Penalties for manufacturers and suppliers who fail to meet that duty, with a route to avoid sanctions if a vulnerability is disclosed to HMRC and fixed.
HMRC's stated preference is for standards that existing systems can meet through a software update rather than hardware replacement, rolled out in phases rather than all at once. No implementation timeline has been decided; that depends on what this consultation surfaces.
Where the blueprint comes from: Austria, Germany, and Norway
HMRC's proposals are modeled directly on systems already operating in Austria, Germany, and Norway, the three countries the consultation names by name in its Annex B.
- Austria requires individually recorded (not batched) cash sales, mandatory receipt issuance, and cryptographically chained transactions and till reports that an auditor verifies by scanning a QR code.
- Germany requires certified Technical Certification Devices, legally defined transaction contents, a mandatory digital signature on every transaction (including voided or "no sale" transactions, which still must generate a receipt), and a penalty regime for manufacturers who fail to protect their systems, the closest existing analogue to HMRC's proposed manufacturer-penalty measure.
- Norway requires SAF-T as standard, registers and audits EPOS systems with the tax authority (Skatteetaten) at setup, requires suppliers to obtain a product declaration before a system can legally be sold, and publishes a public database of certified systems.
The consultation also mentions the Netherlands' voluntary Q-mark scheme and the more punitive, downstream-enforcement approach used in Australia and New Zealand, but its own conclusion favors the Austria, Germany, and Norway model: mandatory, upstream, software-based standards rather than penalties applied after the fact. HMRC's stakeholder list (Annex A) also includes Greece's Independent Authority for Public Revenue among the tax authorities consulted, though Greece's approach isn't detailed as a reference model the way Austria, Germany, and Norway's are.




