This article concerns a French regulatory obligation. Since 1 January 2018, any business subject to French VAT that records payments through point-of-sale software must use software certified as meeting requirements for tamper-proofing, security, retention and archiving. The certificate of conformity issued by the vendor is the visible condition. What it does not cover is often discovered too late.
The LNE standard certifies the software — not the company's operational set-up
The LNE — France's national metrology and testing laboratory — is the accredited body whose standard is today the most widely used technical reference on the French market. That standard applies to the software itself, for one precise version, certified at the vendor's request. It covers neither the configuration of the system in the company's production environment, nor the interfaces with other systems.
The vendor's certification is a necessary condition — it is not a sufficient one. That is the distinction organisations underestimate most often.
ISCA: four technical criteria that determine compliance
- Tamper-proofing: recorded data cannot be modified or deleted without leaving a trail. Any correction must appear as a visible, timestamped counter-entry.
- Security: the software must guarantee data integrity against any alteration, accidental or intentional — generally through hashing or cryptographic chaining of the records.
- Retention: transaction data must be kept for at least six years, in conditions that guarantee it remains legible and intact.
- Archiving: the software must produce periodic closes — daily, monthly, annual — archived in a format that can be used during a tax inspection.
ERP integrations, customisations, archiving: three risk areas
Certification covers one precise version of the software. Any major update may call for fresh certification: checking that the version running in production is indeed the certified one is an elementary control, and few organisations carry it out regularly.
In architectures where the point-of-sale software is interfaced with an ERP, the data exchange flows can affect the tamper-proofing of the records. An analysis of the flows is needed to make sure no modification happens downstream of the certified recording. In the same way, any customisation — however minor — has to be assessed for its impact on the ISCA mechanisms.
Effective archiving across six years is often handled insufficiently in multi-till or multi-site environments. An operational archiving policy — verified backups, media management, a tested restore procedure — is a prerequisite, not an option.
During an inspection, the fine is fixed and renewable
The French tax authorities may ask for the vendor's certificate of conformity, the closing journals and the transaction archives in a legible format. Having no certification, or being unable to produce the archives, exposes the business to a fixed fine of €7,500 per non-compliant piece of software, renewable if the situation persists.
Compliance plays out over time: ERP migrations, changes of supplier, application updates, architecture changes. A periodic review of operational compliance — distinct from the vendor's certification — is a practice that organisations handling significant transaction volumes have every reason to put in place.

