France · PA outage, continuity and recovery

Build a fallback plan for a France e-invoicing platform outage

Plan for a French approved-platform outage: preserve evidence, keep business moving, prevent duplicates and regularise safely.

Quick verdict:
  • Map the failed link and quarantine only the affected population.
  • Unresolved acceptance state creates the sharpest duplicate exposure.
  • Start one identifier-led ledger before authorising any replay.
Last checked: 14 August 2026Based on official sourcesClear summaryBusiness guidance, not legal advice
Official sources prioritized
Last-checked dates visible
Free checker, no signup required

What you need to know

Guide

1. Scope the outage in the first 15 minutes

Start with classification, not repeated resubmission. Determine whether the fault sits with your plateforme agréée (PA), the recipient’s PA, your ERP, API or connector, the annuaire routing data, the network, or another technical provider. Check whether the impact affects all traffic, one legal entity, one customer, one format such as Factur-X, UBL or CII, or one direction only. Record the first observed time, last known successful exchange, affected environments and exact error text. DGFiP’s practical guide says a temporary outage should not stop economic activity and asks businesses to identify the responsible link. It does not create a universal 15-minute legal threshold; that window is a recommended operational target for gaining control. Keep proven-good flows running, but stop speculative retries wherever the submission state is uncertain. Name an incident lead and open one shared record before teams begin separate workarounds.

Guide

2. Freeze evidence and create one incident ledger

Official guidance emphasises retaining errors, PA notices, support tickets, timestamps and exchanges. Capture them before logs rotate or screens change. Use one incident ledger covering every affected invoice or message: legal entity, customer or supplier, invoice number, invoice date, amount, VAT amount, ERP document ID, PA message ID, correlation ID, format, direction, attempted time, last confirmed status and current owner. Store the original payload and checksum where your controls permit, plus API responses and screenshots with reliable timestamps. Never rewrite an original merely to make a retry easier. The ledger should distinguish not sent, confirmed received, rejected, and unknown—not collapse them into “failed.” Link every alternative copy, later electronic transmission, credit or other regularisation to the same business operation. This evidence supports reconciliation, customer communication and a documented explanation of reasonable corrective action.

Guide

3. Decide whether continuity treatment is justified

Separate three populations: unaffected flows that can continue normally, blocked flows with a confirmed failure, and uncertain flows whose acceptance state is unknown. For each blocked invoice, assess whether delaying visibility would materially disrupt delivery, collections, contractual administration or cash flow; whether the recipient can identify an alternative copy safely; and whether AR can prevent payment and posting twice. DGFiP allows an alternative channel to bring the same invoice to the customer’s attention when electronic issue is temporarily impossible and continuity requires it. That is not a declaration that an emailed PDF is generally compliant. Recommended control: require approval from the incident lead and AR owner, document the business reason, and exclude uncertain submissions until their state has been checked. A provider failure does not pause compliance duties: continue unaffected processing, isolate the exception population and plan prompt electronic transmission or appropriate regularisation after recovery.

Guide

4. Use an alternative channel without creating a second invoice

Send a representation of the same invoice and operation—not a newly numbered substitute. Mark the communication clearly as a temporary continuity copy, quote the original invoice number and date, identify the outage incident, and ask the recipient not to pay or post a second version if an electronic copy later arrives. Do not describe the channel itself as the statutory e-invoice route. Record the recipient, channel, dispatch time and delivery evidence in the incident ledger. Add a payment hold or duplicate-warning flag in AR and tell customer service which wording to use. After recovery, issuers already in scope should transmit the same invoice electronically or apply an appropriate regularisation promptly, then reconcile acknowledgements, accounting entries, payment and reporting. The exact instrument depends on the facts and professional advice; there is no universal correction document for every outage. Remove the warning only after one receivable, one posting and one reporting outcome are confirmed.

Guide

5. Recover the outbound queue in a controlled sequence

Treat an unknown submission state as the highest duplicate risk. Before retrying, query the PA using the original invoice number, message ID, correlation ID or API status endpoint and request written confirmation if the interface cannot resolve it. Recommended engineering controls include a stable idempotency key tied to the legal entity and invoice, immutable payload hashes, deduplication at the connector, and a replay queue that requires approval for unknown items. These are controls, not DGFiP-mandated retry rules. Recover in batches: first validate connectivity with a non-ambiguous test or agreed low-risk item; then release confirmed-not-sent invoices; next handle explicit rejections according to their real status; and resolve unknowns individually before replay. Pause if acknowledgements diverge from the ledger. Reconcile PA, ERP and bank/payment views after each batch, and preserve both the original and recovery message identifiers. Never let a generic scheduler blindly resend the entire backlog.

Guide

6. Maintain inbound and AP continuity

When the PA or connector is unavailable, AP should keep procurement and operations moving without pretending that an invoice or status was received electronically. Record expected invoices from purchase orders, supplier notices and delivery evidence in a temporary exception queue, but do not manufacture a receipt timestamp, PA acknowledgement or lifecycle status. Ask suppliers to reference their original invoice number in any continuity copy and explain that it will be matched against the later electronic flow. Apply duplicate controls across supplier, invoice number, date, amount, VAT and purchase order; route close matches to review. Protect payment deadlines through controlled accrual or approval processes where appropriate, while keeping the temporary record distinct from the definitive invoice posting. Once service returns, import or receive the authentic electronic messages, match them to the exception queue, resolve differences, and release only one payable. Document who approved any payment made before normal receipt.

Guide

7. Preserve e-reporting data and regularise later

A PA transmits and receives e-invoices and sends invoice, transaction and payment data. An outage can therefore affect more than the invoice document. Preserve the underlying transaction, VAT, payment-status and e-reporting data at source, including period, event time, currency, customer category and links to the relevant invoice or operation. Maintain a separate backlog with record counts and control totals so missing data is visible. Do not invent a statutory outage deadline, grace period or replacement reason code. When the service is restored, compare what the ERP intended to send with what the PA confirms it accepted, then transmit or regularise the missing information through the supported process. Reconcile counts, taxable bases, VAT, gross amounts and payment data before closing the incident. This guide provides practical information, not legal, tax or accounting advice; obtain professional advice where treatment depends on the transaction. Alternative delivery does not remove the later electronic or reporting work.

Guide

8. Manage the PA and vendors through evidence and acceptance

Set a practical RACI: the incident commander coordinates; IT owns connectivity and logs; AR and AP own invoice populations; tax owns interpretation and reporting; treasury monitors cash impact; the PA or connector vendor diagnoses its service. Escalate with incident ID, scope, first failure, sample identifiers, redacted payload evidence and business impact—not vague “system down” messages. DGFiP says isolated incidents need not each be reported to the administration; address them first with the PA, provider or client and retain evidence. During start-up, sanctions are not immediate or automatic for genuine documented difficulties followed by corrective action, but this is not a mandate suspension. Recovery acceptance should prove send, receive, acknowledgement, status retrieval, reporting and reconciliation. When buying or renewing service, treat uptime targets, support hours, evidence exports, status visibility, idempotency, backlog handling, disaster recovery and exit assistance as contractual questions, not statutory guarantees. Approved PAs have passed regulatory, technical and interoperability tests, but your operating model still needs resilience.

Guide

9. Work an example, measure recovery and test again within seven days

Example: a connector times out after sending 240 AR invoices; 180 have PA acknowledgements, 35 are confirmed unsent and 25 are unknown. Keep the 180 untouched, queue the 35 for controlled release, and investigate the 25 by identifier before any retry. If five urgent confirmed-unsent invoices threaten collections, send continuity copies with duplicate warnings and ledger links, then transmit the same invoices electronically after recovery. Track affected documents, value at risk, oldest blocked age, unknown-state count, alternative copies, duplicate alerts, confirmed recoveries, unmatched AP items and unreconciled reporting totals. Common mistakes are mass replay, renumbering copies, erasing errors, treating email as the permanent route, inventing receipt statuses and closing on “service available” alone. Within seven days, run a tabletop and technical recovery test: recreate the queue, export evidence, approve one fallback, restore in stages, reconcile invoice/payment/reporting totals, review vendor response, update contacts and assign every corrective action an owner and due date.

Checklist

Name the incident lead and classify the failing component.

Open one ledger before retries or workaround activity begins.

Preserve payloads, identifiers, errors, notices and timestamps.

Separate unaffected, confirmed-blocked and unknown-state flows.

Approve alternative delivery only for a documented continuity need.

Link every continuity copy to the original invoice and operation.

Place duplicate-payment, posting and reporting controls immediately.

Resolve unknown submissions before releasing the recovery queue.

Reconcile ERP, PA, AP/AR, reporting and payment control totals.

Test recovery, record lessons and close corrective actions.

FAQ

What if my French e-invoicing platform is down?

Classify the failing link, preserve evidence and continue unaffected flows. Isolate confirmed-blocked and unknown items, contact the PA or provider, and use controlled continuity treatment only where electronic issue is temporarily impossible and business or cash-flow needs justify it.

Can I email a PDF during a PA outage?

Official guidance permits an alternative channel to bring the same invoice to the customer’s attention when continuity requires it. That does not make emailed PDF a generally compliant substitute. Link the copy to the original and complete electronic transmission or appropriate regularisation after recovery.

Should I retry an invoice with an unknown submission state?

Not blindly. First query the PA using invoice and message identifiers, compare acknowledgements and seek support confirmation if needed. A retry without resolving uncertainty can create duplicate delivery, posting, payment or reporting.

What evidence should we keep?

Keep errors, PA notices, tickets, timestamps, exchanges, payload or checksum evidence, invoice and message identifiers, affected scope, decisions, approvals, alternative dispatch proof, recovery acknowledgements and reconciliation results. Retain them under your normal security and record-management controls.

How do we regularise after PA downtime?

For issuers already in scope, send the same invoice electronically or use the appropriate regularisation promptly after recovery. Then reconcile invoice status, accounting, payment and reporting. The correct method depends on the facts; no single correction instrument fits every incident.

Does a platform failure pause the French mandate?

No. DGFiP frames documented start-up difficulties and corrective action pragmatically, but this is not a delay or suspension. Reception applies from 1 September 2026; issue obligations start then for large and mid-sized enterprises and on 1 September 2027 for SMEs and microbusinesses.

Must every isolated incident be reported to DGFiP?

The practical guide says isolated incidents do not each need reporting to the administration. Work first with the PA, technical provider or client, follow resolution and retain evidence. Seek advice if an incident creates a separate legal or tax reporting concern.

What should an outage acceptance test cover?

Prove outbound and inbound exchange, acknowledgements, status retrieval, queue replay, duplicate prevention, e-reporting or payment-data handling, and end-to-end reconciliation. Acceptance should rely on matched identifiers and control totals, not merely a green vendor status page.

Key regulations, formats and terms

FranceFrench tax administrationDGFiPimpots.gouv.frapproved platformplateforme agrééePDPFactur-XUBLCIISIRENVATe-reportingSMEmicro-enterpriseaccounting softwareEuropean CommissioneInvoicingEN 16931Directive 2014/55/EUstructured electronic invoiceVAT automationcross-border tradeFrance approved-platform outage fallback and recovery plan

France — Country hub

Continue reading

Official sources

We prioritize official government and EU sources where available and keep last-checked dates visible for mandate-sensitive pages.