Compliance

Compliance & Certifications

WameedPOS meets every regulatory standard required to operate a retail business in Saudi Arabia — and goes beyond with international security certifications.

receipt_longZATCA Phase 2
credit_cardPCI-DSS L1
shieldSaudi PDPL
account_balanceSAMA Regulated
verified_userISO 27001 Aligned
inventory_2SASO Certified

Regulatory Frameworks

Detailed breakdown of every compliance standard WameedPOS meets, with specific implementation details.

receipt_long

ZATCA Phase 2 E-Invoicing

Fully Compliant

WameedPOS is fully certified for ZATCA Phase 2 (Integration Phase) compliance. Every invoice generated through our platform meets the mandatory requirements for electronic invoicing in Saudi Arabia.

  • check_circleReal-time XML invoice generation in UBL 2.1 format with all required fields
  • check_circleCryptographic stamping using ZATCA-issued digital certificates (CSID)
  • check_circleQR code generation embedding seller info, VAT number, invoice total, VAT amount, and cryptographic hash
  • check_circleAutomated submission to ZATCA Fatoora Portal via API for B2B (clearance) and B2C (reporting)
  • check_circleSupport for standard invoices, simplified invoices, debit notes, and credit notes
  • check_circleOffline invoice queuing with automatic submission when connectivity is restored
  • check_circleReal-time clearance status tracking and rejection handling
  • check_circleFull audit trail of all invoice submissions, responses, and corrections
credit_card

PCI-DSS Compliance

Level 1 Certified

WameedPOS adheres to the Payment Card Industry Data Security Standard (PCI-DSS) to ensure cardholder data is handled with the highest level of security.

  • check_circleEnd-to-end encryption (E2EE) for all card transactions from terminal to processor
  • check_circlePoint-to-point encryption (P2PE) certified payment terminals
  • check_circleZero storage of full card numbers, CVV codes, or magnetic stripe data
  • check_circleNetwork segmentation isolating payment processing from other system functions
  • check_circleRegular vulnerability scanning and quarterly ASV (Approved Scanning Vendor) assessments
  • check_circleAnnual penetration testing by independent PCI QSA (Qualified Security Assessor)
  • check_circleStrong access control with multi-factor authentication for payment system access
  • check_circleComprehensive logging and monitoring of all access to cardholder data environments
shield

Saudi PDPL Compliance

Compliant

We fully comply with the Saudi Personal Data Protection Law (PDPL), enacted by Royal Decree M/19 dated 9/2/1443H, ensuring that personal data is processed lawfully and transparently.

  • check_circleLawful basis established for all personal data processing activities
  • check_circleTransparent privacy notices provided to all data subjects at point of collection
  • check_circleData subject rights implemented: access, correction, deletion, portability, and objection
  • check_circleData Protection Impact Assessments (DPIA) conducted for high-risk processing
  • check_circleData breach notification procedures with 72-hour reporting to SDAIA
  • check_circleData residency maintained within Saudi Arabia for all primary data storage
  • check_circleData Processing Agreements (DPA) in place with all sub-processors
  • check_circleDesignated Data Protection Officer (DPO) responsible for PDPL compliance
account_balance

SAMA Regulations

Compliant

WameedPOS operates in alignment with Saudi Central Bank (SAMA) regulations governing electronic payments and financial technology services.

  • check_circleIntegration with SAMA-licensed payment service providers and acquirers
  • check_circleSupport for Mada debit network as the primary card payment rail
  • check_circleCompliance with SAMA Open Banking framework for authorized data sharing
  • check_circleSettlement and reconciliation processes aligned with SAMA clearing requirements
  • check_circleAnti-fraud measures following SAMA cybersecurity guidelines
  • check_circleTransaction monitoring and suspicious activity reporting capabilities
lock

Data Security Standards

Enterprise Grade

Our security architecture is built on industry best practices and undergoes continuous monitoring and improvement.

  • check_circleAES-256 encryption for all data at rest across databases and backups
  • check_circleTLS 1.3 encryption for all data in transit between client, server, and third parties
  • check_circleSOC 2 Type II aligned controls for security, availability, and confidentiality
  • check_circleISO 27001 aligned Information Security Management System (ISMS)
  • check_circleZero-trust architecture with least-privilege access controls
  • check_circleReal-time intrusion detection and prevention systems (IDS/IPS)
  • check_circleAutomated security patching and vulnerability management
  • check_circleEncrypted backups with geo-redundant disaster recovery (RPO < 1 hour, RTO < 4 hours)
inventory_2

Saudi Standards (SASO)

Compliant

WameedPOS hardware bundles and software comply with Saudi Standards, Metrology and Quality Organization (SASO) requirements.

  • check_circleHardware devices meet SASO electromagnetic compatibility (EMC) standards
  • check_circleBarcode and QR code generation follows GS1 Saudi Arabia standards
  • check_circleArabic language support across all interfaces, receipts, and reports
  • check_circleRight-to-left (RTL) layout support for Arabic-primary businesses
  • check_circleWeight and measurement units compliant with Saudi metrology standards
  • check_circleReceipt formatting meets Saudi consumer protection disclosure requirements

Audit-Ready by Design

WameedPOS is built from the ground up to make compliance effortless. Every feature is designed with auditability in mind.

history

Complete Audit Trail

Every transaction, modification, and access event is logged with timestamps, user IDs, and IP addresses. Audit logs are immutable and retained for 7 years.

download

Export-Ready Reports

Generate compliance reports in PDF, CSV, and XML formats. Pre-built templates for ZATCA audits, VAT returns, and financial reviews.

admin_panel_settings

Role-Based Access

Granular permission controls ensure employees only access data relevant to their role. Activity is logged per user for accountability.

notifications_active

Compliance Alerts

Automated alerts for certificate expiry, failed ZATCA submissions, data retention milestones, and security policy violations.

update

Automatic Updates

Regulatory changes are automatically reflected in the platform. When ZATCA updates requirements, WameedPOS adapts without manual intervention.

support_agent

Dedicated Compliance Support

Enterprise customers receive a dedicated compliance advisor to assist with audits, regulatory questions, and implementation guidance.

ZATCA Phase 2

E-Invoicing Compliance Made Simple

ZATCA Phase 2 (Integration Phase) requires all taxable businesses in Saudi Arabia to generate structured electronic invoices and transmit them to ZATCA's Fatoora platform in real-time. Non-compliance carries penalties starting from SAR 5,000 per violation.

WameedPOS handles the entire compliance workflow automatically — from invoice generation to ZATCA submission — so you can focus on running your business.

verifiedAutomatic UBL 2.1 XML generation for every transaction
verifiedReal-time API integration with ZATCA Fatoora Portal
verifiedDigital certificate management and automatic renewal
verifiedInvoice rejection handling with guided error resolution
verifiedMonthly compliance summary reports for your records

ZATCA Compliance Timeline

Phase 1Dec 4, 2021

Generation Phase — Electronic invoice generation required

Phase 2 — Wave 1Jan 1, 2023

Integration Phase — Businesses with revenue > SAR 3B

Phase 2 — Wave 2Jul 1, 2023

Businesses with revenue > SAR 500M

Phase 2 — Wave 3+2024 onwards

Progressively smaller businesses integrated

Compliance FAQs

Is WameedPOS approved by ZATCA for e-invoicing?

Yes. WameedPOS is a ZATCA-certified e-invoicing solution that meets all Phase 2 (Integration Phase) requirements. Our platform generates compliant XML invoices, applies cryptographic stamps, and submits to the Fatoora Portal via ZATCA's official API.

Does WameedPOS store credit card numbers?

No. We never store full card numbers, CVV codes, or PIN data. Card payments are processed through PCI-DSS certified payment terminals with end-to-end encryption. Only tokenized references and last-four digits are retained for transaction records.

Where is my data stored?

All primary data is stored on servers within the Kingdom of Saudi Arabia, in compliance with Saudi data residency requirements under the PDPL. Backups are maintained in geo-redundant Saudi-based data centers.

How does WameedPOS handle data breach incidents?

We have a comprehensive incident response plan that includes immediate containment, investigation, stakeholder notification within 72 hours (as required by PDPL), remediation, and post-incident review. Affected merchants are notified directly with specific guidance.

Can WameedPOS generate reports for ZATCA audits?

Yes. WameedPOS provides pre-built audit report templates that include all required fields for ZATCA inspections: invoice registers, clearance/reporting status logs, tax summaries, and cryptographic stamp verification records. Reports can be exported in PDF, CSV, and XML formats.

What happens if my internet goes down during a ZATCA submission?

WameedPOS has an offline-first architecture. Invoices are generated and stored locally, then queued for ZATCA submission. When connectivity is restored, all pending invoices are automatically submitted in chronological order. No data is lost.

Compliance Shouldn't Be Complicated

WameedPOS handles ZATCA, PCI-DSS, PDPL, and every other regulation so you can focus on growing your business.