Most of the commentary on Oman's Decision No. 189/2026 has concentrated on the two dates it set. The provision worth more of an enterprise's attention added no date at all.

On 9 August 2026 the Oman Tax Authority issued Decision No. 189/2026, amending the Executive Regulations of the VAT Law made by Decision No. 53/2021 under Royal Decree 121/2020. The headline is a replaced Article 143 and two compliance dates read off a business's own turnover: 1 April 2027 where annual supplies exceed OMR 5 million, 1 October 2027 at or below. The four-phase Fawtara schedule the Authority still publishes on its FAQ no longer carries legal effect, and the roughly 100 companies in the first selected group now start in August 2026 ahead of any legal duty rather than under one. (As at the time of writing, the text of the decision had not appeared on the Authority's VAT law and regulations portal.)

Alongside the replaced articles, the decision adds three new ones. The third of them, Article 143bis1, places system security with the taxable person: protection against breach and unauthorised access, procedures for emergencies and technical failure, and data recovery mechanisms sufficient to keep the system running. Not with the accredited service provider. With the taxpayer.

The Assumption This Provision Breaks

Appointing an accredited service provider feels like transferring risk. The provider holds the accreditation, operates the connection, maintains the certification, and carries the technical relationship with the Authority. A finance leader who has just signed an ASP contract can be forgiven for concluding that the availability and integrity of the e-invoicing channel is now someone else's operational problem.

Article 143bis1 says otherwise, and it does so in a jurisdiction that has also built a centralised architecture — Oman operates a central SMP that providers connect through, and a taxpayer holds one provider at a time. The enterprise depends on infrastructure it does not run, while carrying a regulatory duty for the security and continuity of a system that spans its own ERP, its provider, and the Authority's platform.

That is not a contradiction. It is a specific allocation of responsibility, and it is the same allocation practitioners should expect to find, explicitly or implicitly, across PEPPOL-based regimes. The provider is accredited to perform a function. Accreditation is not indemnity.

What "Procedures for Emergencies and Technical Failure" Actually Requires

The obligation reads as boilerplate until it is decomposed. An enterprise asked to demonstrate it has procedures for technical failure has to answer questions that cut across three organisations.

When the provider is unavailable, what happens to the invoice? Not what happens to the transmission — what happens to the commercial document. Does the ERP hold it, queue it, or issue it in a form that does not meet the definition of a tax invoice? Once electronic issuance is the legal requirement, a PDF sent to a buyer during an outage is not a tax invoice. The commercial supply has occurred. The document obligation has not been met.

Who declares the emergency? An outage is discovered somewhere — a failed acknowledgement, a rejected batch, a monitoring alert in an IT function that does not know which failures carry tax consequences. The path from technical detection to a tax decision about whether to continue invoicing is a governance path, and it is usually undesigned. This is where the Compliance Project Handover Illusion™ shows up: the programme delivered a working connection and dissolved, leaving no one who owns the question of what to do when the connection stops working.

What is the recovery position? Data recovery mechanisms, in the language of the article, means the enterprise can reconstruct and re-transmit. That requires retaining the structured document — not the ERP record it was generated from, but the instrument as transmitted, in the form it was transmitted. An enterprise that keeps only its ERP data and relies on the provider's archive has outsourced its recovery capability to a party it can switch away from, and whose retention terms it may not have read against a statutory retention period.

The Penalty Position Is Not Yet the Reassuring Part

Oman has published no penalty schedule specific to e-invoicing, and Decision No. 189/2026 attaches no fines of its own. That absence is sometimes read as a soft-landing signal. It is better read as the general framework applying by default.

Under Article 100 of the VAT Law, deliberately refraining from issuing a tax invoice where required carries imprisonment of between two months and one year, a fine of between OMR 1,000 and OMR 10,000, or both — and the court may double the penalty where an offence recurs. The same article reaches deliberate failure to retain tax invoices and documents for the required period.

The operative word is deliberate, and it is precisely where the security and continuity obligation becomes material. An enterprise that suffered an outage, had documented procedures, followed them, recorded the decisions taken and remediated afterwards is describing an incident. An enterprise that continued issuing non-compliant documents for a sustained period with no procedure, no escalation, and no record is describing something a reviewer may characterise differently. The procedures required by Article 143bis1 are, among other things, the evidence that a failure was handled rather than tolerated.

There is also a relief mechanism worth knowing about. New Article 143bis2 allows the Chairman to exempt a taxable person from electronic issuance for a set period, on application with supporting documents and reasons the Authority accepts, conditional on the applicant continuing to file returns in the prescribed form and on time and to pay tax due on time. It is an application route with conditions attached, not a fallback that operates automatically when systems fail — which makes it something to understand in advance rather than reach for during an incident.

Do Not Plan Around Consumer Sales Arriving Later

One further point of scope, because it changes the size of the build. The replaced Article 143 covers supplies to persons not subject to tax, and the amended second paragraph of Article 146 puts simplified tax invoices on the same deadlines. Oman is not running consumer transactions as a later phase. A QR code is required on the human-readable invoice for those transactions, consolidated consumer invoices are not permitted, and reporting timing differs by transaction type — business-to-business tax data in real time, consumer transactions within 24 hours.

An enterprise scoping only its business-to-business flows on the assumption that retail follows in a later wave is scoping the wrong programme.

Why This Matters Outside Oman

For a group operating across the Gulf, the temptation after each regulatory change is to reopen the programme plan and resequence around the new dates. The more durable reading is that Article 143bis1 has made explicit something that is true wherever an enterprise transmits through an accredited intermediary: the duty to issue a compliant document, and to be able to prove it did, does not move to the provider.

That has a direct consequence for how ASP contracts are negotiated. The questions that follow from a taxpayer-held security duty are not the ones on a standard evaluation scorecard — availability commitments and what they are measured against, notification obligations and how fast, the enterprise's own access to transmitted documents independent of the provider relationship, retention terms tested against the statutory period, and what the enterprise receives on exit and in what format. Each of these is cheap to secure during selection and expensive to retrofit afterwards.

The UAE's own timeline continues to run alongside this, with the ASP appointment deadline of 30 October 2026 and go-live from January 2027. For groups in both jurisdictions, the contracts being signed in Oman and the UAE over the coming weeks are the instruments that will determine how a failure is handled two years from now. They are worth reading with the security obligation in view rather than the date.

Legislative references: Oman VAT Law (Royal Decree 121/2020); Executive Regulations (Decision No. 53/2021); Decision No. 189/2026 of 9 August 2026, as announced by the Oman Tax Authority. As at the time of writing the decision text had not been published on the Authority's portal, and the Authority's e-invoicing FAQ continued to carry the superseded four-phase schedule. Businesses should verify against the gazetted text and monitor further guidance.