CESOP reporting compared: national channels in the EU
CESOP reporting is one EU dataset delivered through seven different national doors. The content of the quarterly file is fixed by Council Directive (EU) 2020/284 and the Commission’s XML schema, and every tax administration forwards the data to the same central database. But the channel, the identity you need to reach it, the packaging, the size limits and the receipts are national. A payment firm passported into several Member States owes one file per Member State, and each is filed under different rules. This hub compares the national routes in Germany, Spain, France, Ireland, Italy, Luxembourg and the Netherlands, and links to the detailed guide for each.
1. What is the same everywhere
The substance comes from the VAT Directive as amended by Directive (EU) 2020/284, and the central system from Regulation (EU) 2020/283 amending Regulation (EU) No 904/2010. Every national law we cover applies from 1 January 2024 and repeats the same core:
- Trigger: more than 25 cross-border payments to the same payee in a calendar quarter, counted per Member State and per payee identifier, or per payee when the provider knows that one payee holds several identifiers.
- Who reports: the payee’s provider when it is in a Member State. The payer’s provider records and reports only when no payee-side provider is in a Member State, but those payments still count towards the threshold.
- Where: the home Member State, plus every host Member State in which the provider offers payment services outside its home state.
- When: by the end of the month after the quarter, so 30 April, 31 July, 31 October and 31 January.
- Retention: electronic records for three calendar years from the end of the year of the payment.
- Messages: CESOP100 (new data), CESOP101 (correction) and CESOP102 (no data), each with a MessageRefId that may never be reused.
If your data model and the per-payee count are right once, they are right for every country. The national differences sit almost entirely in the transmission layer.
2. The national channels side by side
| Country | Tax authority and legal hook | Channel | Access for a non-resident provider |
|---|---|---|---|
| Germany | BZSt; § 22g UStG | DIP (Digitaler Posteingang) in the BZSt online portal: automated XML exchange or manual upload | BZSt registration form, then BZSt number, secret and certificate (ELSTER certificate for German taxpayers) |
| Spain | AEAT; Modelo 379 | AEAT sede electrónica; XML web service, procedure GI51 | Electronic access to the AEAT sede |
| France | DGFiP; art. 286 sexies CGI | Espace professionnel on impots.gouv.fr, service “Paiements transfrontaliers – CESOP”, deposit through PASSTRANS | IDSP substitute identifier from the DINR (form EE0, registry extract, translated articles, mandate) |
| Ireland | Revenue; Part 9A VAT Consolidation Act 2010 | ROS, “Complete a Form Online”, reporting obligation CESOP | Non-Resident Registration app, manual review, Tax Reference Number, then ROS certificate |
| Italy | Agenzia delle Entrate; arts 40-bis to 40-sexies DPR 633/1972 | SID, by PEC or an FTP exchange node, using the SID Gestione Flussi CESOP module | REI enrolment (financial-investigations section), Entratel or Fisconline, then SID |
| Luxembourg | AED; VAT law of 12 February 1979 as amended in July 2023 | Certified CESOP business eSpace on MyGuichet.lu, upload procedure per file; API pre-fill available | eIDAS identity from another EU or EEA country, plus certification with a signed mandate and a recent RCS extract |
| Netherlands | Belastingdienst | Digipoort File Exchange FTP, machine to machine only | PKIoverheid certificate, which needs a Dutch KvK registration; otherwise a fiscal representative or service provider |
Each identity step involves a human review or a third party: the DINR issues the IDSP, Revenue’s CESOP team approves non-resident registrations in date order, the AED certifies the eSpace, and a trust service provider issues the PKIoverheid certificate. Schedule them before the data work, not after it.
3. Packaging and size limits
| Country | What you send | Size rule | Test route |
|---|---|---|---|
| Germany | Plain XML | Manual upload up to 200 MB | Customer test environment, files up to 10 MB; EU validation module available |
| France | XML (UTF-8, no BOM), zipped without password, then GnuPG-encrypted with the DGFiP key; fixed file name | Over 135,000 ReportedTransaction elements rejected; deposits over 200 MB rejected unread | Own pre-deposit checks: the EU module does not flag a BOM or the transaction cap |
| Ireland | Plain XML, no meta file | 1 GB uncompressed per file, one file per upload | Three-layer validation on every live file |
| Italy | Data file plus separate signature, both produced by the CESOP module (compressed, encrypted, signed) | 20 MB by PEC, 100 MB by FTP node | Client-side checks in the module before sending |
| Luxembourg | XML or a DEFLATE zip with one XML, no password | 80 MB per file; unzipped file under 900 MB | Commission validation module before upload |
| Netherlands | Data file plus metafile over FTP | Per Belastingdienst specifications | Validation Test Service (via ODB registration) and Digipoort test scenarios |
The practical consequence is that “the CESOP file” is really several exports. A large quarter may need splitting by transaction count for France, by compressed size for Luxembourg, and by transport limit for Italy. Build the splitting rules into the export job, keyed by destination country, and name every part with the Commission convention (PMT-quarter-year-country-PSPId-part-total).
4. Receipts and rejections
Every channel returns two layers of result: a national check, then the Commission’s verdict. The labels differ:
- Ireland: pre-validation on screen, national result in the ROS inbox (normally within 12 minutes), then fully accepted, partially rejected or fully rejected from CESOP. Revenue adds rule 99999 against corrections sent before the original is processed.
- Italy: an intake receipt with a protocol number (usually within five days), then ACCEPTED, PARTIALLY REJECTED or FULLY REJECTED.
- France: MS1 from the DGFiP within 24 to 72 hours, then MS2 from the Commission; status messages stay in PASSTRANS for 45 days. A file with a BOM fails with French code 500901.
- Luxembourg: AED “FULL REJECTION” means the message is void and never reached CESOP; send a new CESOP100. The Commission result arrives as the IE3V01 message in the eSpace.
- Netherlands: a processing report through Digipoort, VALIDATED or FULLY_REJECTED, with partial states defined in the specifications.
The national rejection matters for reference reuse. In Italy and Luxembourg, a file rejected at national intake never reached CESOP; Italy says its identifiers may then be reused, and Luxembourg treats the message as void. A Commission-level rejection burns the identifiers everywhere.
5. Nil reports and penalties
No country in this group makes a nil report a statutory duty, but most invite one. The BZSt recommends an empty report to avoid reminders; the Agenzia delle Entrate recommends CESOP102 as a first compliance check; Revenue says a nil return reduces the chance of a compliance check and offers a button for it. France rejects a whole CESOP102 file that contains ReportedPayee blocks (code 40040).
Penalty amounts are national. Germany is explicit: § 26a UStG makes late, wrong or incomplete transmission, a missed one-month correction or early destruction of records an administrative offence, with fines of up to EUR 5,000 each. Germany also requires corrections within one month of discovering an error (§ 22g(5) UStG). For the other countries, check the national penalty provisions directly before you quote a figure internally.
6. Worked example: building a filing map for a passported EMI
Facts: An e-money institution authorised in Luxembourg serves merchants in Luxembourg, France, Ireland and Italy under the freedom to provide services. It has no French SIREN, no Irish tax number and no Italian presence.
What the rule says: Luxembourg is the home Member State; France, Ireland and Italy are host Member States. Four files are due each quarter, each covering only that country’s services.
What the practitioner does: Opens four workstreams on day one: AED eSpace certification (mandate and RCS extract); the EE0 pack to the DINR for an IDSP; the NRR registration with Revenue; and REI enrolment, Entratel and SID for Italy. Data work runs in parallel, with one payee model and four export profiles.
Outcome: The identity steps, not the XML, set the go-live date. Starting them together turns four sequential delays into one.
7. Worked example: one big quarter, three split rules
Facts: The same institution’s Q4 holds 400,000 reportable transactions for French payees, a 1.4 GB Luxembourg XML and 150 MB of Italian data.
What the rule says: France caps each file at 135,000 ReportedTransaction elements; Luxembourg takes 80 MB per file and under 900 MB unzipped; Italy takes 20 MB by PEC or 100 MB by FTP node.
What the practitioner does: Splits France into three files by transaction count, numbered 1-1, 2-2 and 3-3 as the DGFiP prefers. Splits Luxembourg into parts whose zips stay under 80 MB, one upload procedure each. Moves Italy to an FTP exchange node, or splits it under the PEC limit.
Outcome: Each country’s files pass on the first send because the split logic sits in code, not in an analyst’s late-January spreadsheet.
8. Worked example: one error, four corrections
Facts: After the Q3 deadline, the institution finds that refunds were not flagged in any of its four files.
What the rule says: Each administration needs its own CESOP101, with a new MessageRefId and the original in CorrMessageRefId. Ireland refuses the correction until the original is processed by CESOP; Italy accepts corrective files after the deadline but wants them promptly.
What the practitioner does: Confirms each original has a final Commission status, then sends four corrections through four channels and archives each receipt against the quarter.
Outcome: One data defect produces four filings and eight receipts. A single correction register across countries prevents identifier reuse.
FAQ
Does one CESOP file cover all EU countries?
No. A provider files in its home Member State and in each host Member State where it provides payment services, each through that country’s channel.
Is the CESOP deadline the same everywhere?
Yes, the end of the month after the quarter: 30 April, 31 July, 31 October and 31 January.
Which country is hardest for a foreign provider to reach?
The Netherlands, because Digipoort needs a PKIoverheid certificate that a firm without a KvK registration cannot buy directly. France, Ireland and Luxembourg also need an identity step with a manual review.
Can the same XML be sent everywhere?
The schema is the same, but the population differs per country, and so do encoding, packaging and size rules. Plan one export profile per country.
Do all countries accept a nil report?
All the countries covered here accept or invite one, though none makes it a statutory duty. Check the format rules: France rejects a nil message that contains payee blocks.
How long must CESOP records be kept?
Three calendar years from the end of the year of the payment, in electronic form, under each national transposition.
What to do, today
- Head of regulatory reporting: list your home and host Member States and the channel, identity and owner for each.
- Passported firms: start every non-resident identity step (IDSP, NRR, eSpace certification, PKIoverheid route, REI) at once.
- Data team: add per-country export profiles covering encoding, compression, encryption, naming and split rules.
- Operations: keep one MessageRefId and DocRefId register across all countries, with each receipt filed against it.
- Compliance: file nil reports where invited, and record each country’s penalty provision from the national text.
Related: What is CESOP reporting? · Building the CESOP file · CESOP XML schema mapping · Reporting channels compared


