Qualified timestamp · GoBD immutability · Malta

Qualified timestamp as a building block for GoBD-compliant retention.

GoBD requires immutability — and it is technology-neutral about how you deliver it. A qualified electronic timestamp from an EU QTSP carries the statutory presumption of time accuracy and data integrity under eIDAS Art. 41(2). That is the load-bearing legal component. CodeB Sovereign Communications from Malta puts one on every signed invoice through three signing paths: API, personal European Digital Identity Wallet, or Business Wallet.

00 · Precise attribution

What CodeB delivers — and what it does not.

To avoid confusion: “revisionssicher” is not a statutory category. It is a professional term from Germany's VOI (Verband Organisations- und Informationssysteme, originally 10 principles) and IDW RS FAIT 3. It describes a whole system that satisfies the statutory framework: AO §146, §147; HGB §257; and the GoBD (BMF letter 28.11.2019 as amended by BMF letters of 11.03.2024 and 14.07.2025). A timestamp or a signature by itself is not a system and therefore does not make an archive “revisionssicher” on its own.

ComponentRoleWhat it delivers legally
Qualified RFC 3161 timestampCodeB provides as a proxy to the QTSPLoad-bearing legal component. eIDAS Art. 41(2) grants the statutory presumption of accuracy of the date and time and integrity of the data linked with it. Only a qualified timestamp from a LOTL-listed QTSP carries this presumption.
Advanced Electronic Signature (AdES) on a self-signed tenant CACodeB provides today by defaultTechnical tamper-evidence. eIDAS Art. 3(11): detects later changes. Because the issuing CA is Aloaha-controlled, signer authenticity is only as trusted as our CA — no third-party, QTSP-attested identity.
Qualified Electronic Signature (QES)Available optionally via the wallet paths; not the default on the API patheIDAS Art. 25(2): legal equivalence to a handwritten signature. For invoices under UStG §14(3), not required since 2011.
Procedural documentation + orderly filingYour responsibility, not oursGoBD Rn. 151–155 — without this documentation no archive is revisionssicher, regardless of the technology.
01 · Foundation

What does “GoBD-compliant” actually require?

Revisionssicherheit is not a German statute. It comes from VOI (Verband Organisations- und Informationssysteme) and today is captured in IDW RS FAIT 3. The statutorily relevant provisions are AO §146 (immutability), §147 (retention), HGB §257 and the GoBD (BMF letter 28.11.2019 as amended by BMF letters of 11.03.2024 and 14.07.2025). Five properties derive from GoBD:

PropertyMeaningClassically satisfied bySignature-based satisfied by
CompletenessAll retention-mandated invoices are recorded.Filing process + controlFiling process + control (unchanged)
CorrectnessBooking matches invoice.Internal control procedureInternal control procedure (unchanged)
TimelinessInvoice is recorded promptly.Filing processTimestamp records the signing moment
OrderInvoice is findable and machine-processable.Archive indexingIndexing + PDF/A-3 with structured XML payload
ImmutabilityInvoice cannot be altered undetectably after filing.WORM hardware, blockchain, or audit-monitored databaseCryptographic signature + qualified timestamp
01a · The load-bearing pillar

The qualified timestamp — and why it carries the legal weight.

The central legal building block of our offering is the qualified electronic timestamp under eIDAS Art. 42, issued by a Qualified Trust Service Provider (QTSP) on the EU List of Trusted Lists (LOTL). CodeB proxies the QTSP call, defaulting to Sectigo. The QTSP is the trust anchor — not CodeB.

eIDAS Art. 41(2) states: “A qualified electronic time stamp shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound.” This presumption is evidentiary in civil proceedings (analogous to §371a ZPO in Germany) and is accepted by tax auditors.

What about the signature in front of it? The AdES signature we ship by default uses an Aloaha-controlled CA certificate and therefore provides only tamper-evidence, not third-party-attested signer identity. For GoBD immutability that is enough, because the qualified timestamp attests the data's integrity. For formal signer attribution (e.g. in an authorship dispute), the stronger choice is a Qualified Electronic Signature (QES) with a qualified certificate — not, however, required for invoices by UStG §14(3).

02 · Three paths

Three signing paths at CodeB.

The right path depends on invoice volume and user profile. All three produce a PAdES-signed PDF with a qualified timestamp and long-term validation data (PAdES-B-LT), verifiable across the mandatory ten-year retention window.

GA

1. Sign via API

The Cloud Signature Consortium v2 endpoint /csc/v2/signatures/signHash signs a SHA-256 hash of an invoice with an OIDC-authenticated user certificate. Ideal for accounting software, ERP integrations and automated invoice output. Curl, Node.js, C#, PHP samples in the HOWTO.

HOWTO: sign via API →

Preview

2. Sign via personal EU Wallet

The invoice issuer scans a QR code, confirms in their European Digital Identity Wallet (EUDI wallet app on their phone), and receives back a signed PDF with PAdES signature. Ideal for freelancers, tradespeople and small self-employed issuers signing as natural persons.

HOWTO: sign via wallet →

Preview

3. Sign via Business Wallet

An authorised employee or an automated batch signs on behalf of the company through a Business Wallet instance under CSC v2 Remote Signature Service Protocol. With audit trail of who signed what when. Ideal for accounting teams handling several hundred invoices per month.

HOWTO: Business Wallet →

Preview paths are working; wallet integrations are in pilot with selected partners. The API path is production-available and documented at /csc-v2-api.

04 · Cost

Cost comparison: WORM appliance vs. signature-based archive.

An illustrative comparison for a mid-sized company with roughly 500 inbound and outbound invoices per month, ten-year retention:

Line itemWORM archive (classic)Signature-based (CodeB)
AcquisitionHardware WORM 5,000–15,000 EUR, or cloud archive setupOne-off software licence, or managed service
Running cost15–25% maintenance p.a., or monthly cloud subscription per userSignature volume ∼ cents per signature; qualified timestamp ∼ cents each
StorageProprietaryFile system, your choice of location, your backup
10-year migrationHardware refresh + data migration requiredPDF/A stays PDF/A; no migration needed
Vendor lock-inUsually strong: format, API, certificationOpen standards: PAdES, RFC 3161, CSC v2
Cloud sovereigntyOften US-cloud (CLOUD Act, Schrems II)On-premise or Malta-managed — EU law

Savings for an SME are typically in the four-digit range per year, plus a marked reduction in IT complexity. For smaller businesses under 100 invoices per month, the difference is even more pronounced.

05 · Why CodeB

Why CodeB from Malta.

Four points that German mid-market operators find here and rarely in US-hosted cloud-only offerings:

Make invoices immutable at a fraction of the WORM cost.

Try the signature API with a sample call, or request a Malta-managed offer.

HOWTO: API signing CSC v2 API reference
Related: Digital Signatures Cookbook · E-Invoicing SDK · CSC v2 API · TSA Server · OCSP Responder · EU ID Wallet Software Malta · Deutsch