Skip to Content

Portugal QES PDF Sign

208.95 208.95

Instant digital delivery after payment confirmation.
License: OPL-1, every download is watermarked.
Terms and Conditions

Portugal QES on PDF Invoices

Qualified electronic signatures & CIUS-PT — ready for the 1 January 2027 mandate

From 1 January 2027 a PDF invoice is a legally valid electronic invoice in Portugal only when it carries a Qualified Electronic Signature (QES). This module prepares your customer-invoice PDFs for qualified signing — and, as the mandate allows, issues the structured CIUS-PT (EN 16931) document instead. The qualified key stays in your Trust Service Provider's QSCD: bring-your-own-key, signed remotely, never bundled.

What it does

PAdES signature preparation

Appends a PDF incremental-update revision with an ETSI.CAdES.detached signature dictionary, a fixed /ByteRange and a reserved /Contents placeholder. Computes the ByteRange digest and the CAdES signedAttributes (content-type, message-digest and the ETSI signing-certificate-v2 attribute) with a dependency-light DER encoder.

BYOK remote qualified signing

A Cloud Signature Consortium (CSC v2) client calls credentials/info and signatures/signHash on your qualified TSP with your own access token and credential. Only the document digest is sent; the returned signature is wrapped into a detached CAdES SignedData and embedded into the PDF.

CIUS-PT structured invoice

EN 16931 UBL 2.1 Invoice / CreditNote with the Portuguese customization id and the Peppol billing profile — the structured alternative the 2027 rule accepts alongside QES-on-PDF.

ATCUD + AT QR code

Builds the <validation-code>-<sequence> ATCUD and the AT QR string (fields A..R) with the per-region VAT band breakdown, rendered to a PNG for the printed invoice.

Real NIF / NIPC validation

The published Autoridade Tributária mod-11 check-digit algorithm on company and partner, with holder-class detection (natural person / NIPC / public entity / sole trader).

Validation profile & onboarding

A Portuguese rule set layered on the shared engine's EN 16931 core (seller/buyer NIF, EUR, tax region, ATCUD, VAT category), plus a guided onboarding wizard, a signing-connection model, an optional batch cron and full transport logging.

How signing works

  1. Prepare — the invoice PDF is rendered and a PAdES revision is appended with a placeholder and a stable ByteRange.
  2. Digest — the ByteRange is hashed and the CAdES signed attributes are assembled; the digest to sign is stored.
  3. Sign (BYOK) — your qualified TSP signs the digest in its QSCD and returns the signature value.
  4. Embed — the signature is wrapped into a CAdES SignedData and written into the reserved hole, yielding the final signed PDF.

Compatibility & disclosure

Compatible with Odoo 18 and Odoo 19 (Community). Built on the shared e-Invoice Core Engine; no engine functionality is duplicated.

Disclosure: this module transmits only document digests to the qualified TSP signing endpoint you configure. Your access token, credential and any PIN/SAD are stored solely on your own database and are never sent anywhere else.

Screenshots

Portugal Invoice Cius Pt Iss

Portugal Invoice Cius Pt Iss

Generated Cius Pt Structured

Generated Cius Pt Structured

Update date: 2026-07-02