fiskaly.

9 min read

UK's Electronic Sales Suppression Consultation: What EPOS/MPOS Vendors Should Know

An overview of HMRC's 2026 consultation on till fraud software standards for EPOS/MPOS systems, and the Austria, Germany, and Norway blueprint it draws from.

A modern point-of-sale terminal printing a receipt at a retail checkout

HMRC's consultation on mandatory software standards for Electronic Point of Sale (EPOS) and Mobile Point of Sale (MPOS) systems remains open for responses until 18 August 2026. The target is Electronic Sales Suppression (ESS), also called till fraud: manipulating digital sales records to hide or reduce reported turnover. HMRC names Austria, Germany, and Norway directly as the international models behind its proposals, and the consultation asks EPOS/MPOS vendors by name for input.

TL;DR

  • HMRC's consultation on mandatory software standards for EPOS/MPOS systems, aimed at preventing Electronic Sales Suppression (ESS), is open for responses until 18 August 2026.
  • The proposed package centers on an unalterable SAF-T transaction log, encrypted receipt chaining, an EPOS/MPOS registration or certification scheme, and penalties for manufacturers whose systems get used for ESS.
  • HMRC explicitly cites Austria, Germany, and Norway as the international approaches it consulted before drafting these proposals.
  • HMRC's own data shows the small business tax gap reached £28 billion in 2023 to 2024, with deliberate evasion accounting for £5.2 billion of that.
  • This is a consultation, not legislation. No implementation timeline has been set.
  • fiskaly already runs certified cloud infrastructure built on the same three national models HMRC is using as its reference points.

What just happened

HMRC's Electronic Sales Suppression consultation is an eight-week public consultation, seeking views on mandatory software standards for EPOS and MPOS systems.

It builds directly on earlier groundwork: a 2018 Call for Evidence, which drew 11 responses from till system creators, suppliers, and trade bodies and fed into HMRC's 'Prevent, Promote, Respond' compliance strategy, and the Finance Act 2022 (Schedule 14), which made possessing, making, supplying, or promoting ESS tools a specific offence for the first time, alongside expanded information-gathering powers under Finance Act 2008, Schedule 36. Autumn Budget 2025 then flagged further high-street fraud measures.

Sixteen of the 37 OECD countries already mandate EPOS use for tax compliance, and five of those also require automated transmission of sales data straight to the tax authority. That context matters given how fast the UK's own payment mix has shifted: the British Retail Consortium's 2024 Payments Survey found cash usage fell from 53% of retail payments in 2013 to a low of 15% in 2021, recovering slightly to 20% by 2023, while debit card use rose from 32% to 62% over the same period.

A 2016 HMRC report into one specific form of ESS put the associated tax loss at £100 million, and a broader 2019 estimate put VAT losses from suppression above £450 million a year. The National Audit Office reported in 2024 that ESS compliance yield rose from £17 million in 2022 to 2023 to £98 million in 2023 to 2024, as HMRC's casework expanded from 253 to 1,275 cases.

In the 2023 to 2024 tax year, the small business tax gap grew to £28 billion, 60% of the UK's overall £46.8 billion tax gap, with the deliberate evasion component alone reaching £5.2 billion. That sits against total HMRC revenue of £858.9 billion in 2024 to 2025, the funding base for public services the consultation says these measures are designed to protect. HMRC is addressing this specifically to EPOS/MPOS developers, providers, and resellers, alongside retail and hospitality businesses and tax professionals.

One HMRC case shows what this looks like in practice: investigators traced software that let a linked mobile app remotely delete sales from an EPOS database without leaving a trace in the audit trail. Fourteen businesses known to be using that software were pursued for tax on suppressed sales, two of them through criminal prosecution, recovering £1.3 million in tax.

What's actually being proposed

The consultation lays out six measures that would work together, not as standalone options.

  1. An unalterable transaction log in the OECD's SAF-T (Standard Audit File for Tax) format, with every transaction and adjustment cryptographically chained.

  2. A registration or certification scheme for EPOS/MPOS systems sold, transferred, or used in the UK, with three variants under consideration: manufacturer self-certification, supplier registration at point of sale, or user registration on purchase.

  3. Mandatory information on receipts and system reports, most likely delivered as a scannable QR code that both auditors and consumers can use to verify the cryptographic chain; the consultation separately asks whether mandatory receipting should apply to every transaction or only above a minimum threshold, floating £35 as an example.

  4. Faster, lower-intensity compliance checks: an officer scans the QR code, verifies the chain and summary values, and can close a check in roughly 30 minutes rather than the months a traditional enquiry takes.

  5. A general duty on suppliers to protect their systems' integrity against ESS tampering.

  6. Penalties for manufacturers and suppliers who fail to meet that duty, with a route to avoid sanctions if a vulnerability is disclosed to HMRC and fixed.

HMRC's stated preference is for standards that existing systems can meet through a software update rather than hardware replacement, rolled out in phases rather than all at once. No implementation timeline has been decided; that depends on what this consultation surfaces.

Where the blueprint comes from: Austria, Germany, and Norway

HMRC's proposals are modeled directly on systems already operating in Austria, Germany, and Norway, the three countries the consultation names by name in its Annex B.

  • Austria requires individually recorded (not batched) cash sales, mandatory receipt issuance, and cryptographically chained transactions and till reports that an auditor verifies by scanning a QR code.
  • Germany requires certified Technical Certification Devices, legally defined transaction contents, a mandatory digital signature on every transaction (including voided or "no sale" transactions, which still must generate a receipt), and a penalty regime for manufacturers who fail to protect their systems, the closest existing analogue to HMRC's proposed manufacturer-penalty measure.
  • Norway requires SAF-T as standard, registers and audits EPOS systems with the tax authority (Skatteetaten) at setup, requires suppliers to obtain a product declaration before a system can legally be sold, and publishes a public database of certified systems.

The consultation also mentions the Netherlands' voluntary Q-mark scheme and the more punitive, downstream-enforcement approach used in Australia and New Zealand, but its own conclusion favors the Austria, Germany, and Norway model: mandatory, upstream, software-based standards rather than penalties applied after the fact. HMRC's stakeholder list (Annex A) also includes Greece's Independent Authority for Public Revenue among the tax authorities consulted, though Greece's approach isn't detailed as a reference model the way Austria, Germany, and Norway's are.

Where the blueprint comes from: Austria, Germany, and Norway

RequirementAustriaGermanyNorway
Individual transaction recordingMandatory – every cash transaction recorded individually and sequentiallyMandatory – every transaction recorded individually, including cancellations/voidsMandatory – every sale recorded individually in the electronic journal
Signature / chaining modelDigitally signed receipt chain using a signature/seal creation unit and cryptographic chaining between receiptsCertified Technical Security System (TSE) with secure storage, digital signatures and transaction loggingNo mandatory receipt signing or cryptographic receipt chaining. Security relies on protected electronic journals and audit trails rather than signed receipts.
Data format standardProprietary RKSV data structureDSFinV-K standard export formatSAF-T Cash Register export required for inspections.
System registration or certificationSecurity device/certificate registered with the tax authority; no approval of POS software itselfTSE components must be certified by the German Federal Office for Information Security (BSI). POS systems themselves are not certified.Cash register systems must be registered with the Norwegian Tax Administration (Skatteetaten), and suppliers must submit a product declaration before marketing the system.
Public list of compliant systemsNot includedNot includedIncludedpublic register of declared cash register systems.
Manufacturer/supplier penalty regimePartly includedobligations primarily fall on taxpayers rather than software suppliers.Includedmanufacturers and suppliers have statutory obligations relating to compliant TSE integration and documentation.Includedsuppliers can face enforcement action if they market systems that do not comply with the Cash Register Systems Act.

HMRC isn't proposing anything Austria, Germany, and Norway haven't already run in production for years. The main open question for the UK is which specific combination of these features it adopts, and how.

Who this affects

The consultation is aimed at three groups: EPOS/MPOS developers and suppliers, the retail and hospitality businesses that use their systems, and tax professionals who advise them.

The UK has an estimated 547,000 retail and wholesale businesses, per the Department for Business and Trade's 2025 population estimates, concentrated in the small retail, takeaway, and hospitality sectors where HMRC says ESS is most prevalent. Question 13 of the consultation asks respondents directly about experience with standards "in other jurisdictions, such as, but not limited to, Austria, Germany, or Norway".

Key takeaways

  • This is a consultation, not law. Responses are due 18 August 2026, and no implementation timeline has been set.
  • The international models HMRC consulted. Austria, Germany, and Norway each run some combination of encrypted chaining, mandatory certification, and SAF-T today, and HMRC names all three directly.
  • Manufacturers are in scope, not just merchants. The proposed supplier-penalty regime mirrors Germany's existing rules for Technical Security Device manufacturers.
  • The preferred path is software, not hardware. HMRC wants standards that are deliverable via an update to existing systems wherever possible.
  • fiskaly already operates this exact model across the three countries HMRC is using as its reference points.

Whether HMRC's proposals become UK law in this form is still an open question, but the direction of the reference models is consistent: cryptographically verifiable, SAF-T-based, cloud-deliverable compliance, not hardware mandates or after-the-fact penalties.

Frequently asked questions

18 August 2026, eight weeks after it opened on 23 June 2026.

HMRC's stated preference is for standards that existing systems can meet through a software update, though it acknowledges the final approach and timeline haven't been decided.

Standard Audit File for Tax, an OECD-defined international data standard, first published in 2005 and updated to version 2 in 2010, for exchanging accounting data with a tax authority or auditor. The consultation proposes it as the mandatory transaction-log format for UK EPOS/MPOS systems.

Both. The consultation proposes recording all transactions regardless of payment method.

Yes. Norway certifies and publicly lists compliant EPOS systems, Germany requires certified Technical Certification Devices, and Austria mandates chained, digitally signed receipts, three models the consultation cites directly as precedent.

Sixteen of the 37 OECD countries already require mandatory EPOS use for tax compliance purposes, and five of those also require automated transmission of that sales data directly to the tax authority.

EPOS/MPOS developers, providers, and resellers, retail and hospitality businesses, tax professionals, and industry bodies, and HMRC accepts partial responses focused on the sections most relevant to the respondent.

For more information on the country-by-country fiscalisation picture across the EU, see fiskaly's fiscalisation overview. For the e-invoicing side of that same infrastructure, guide to Europe's e-invoicing mandates shows more details about today's landscape.

Last updated: August 2026. This article is general guidance, not legal advice. Confirm scope and requirements against HMRC's current consultation documents and any resulting legislation.