Skip to main content

Compliance with the requirements

This chapter follows the Tax Administration's L-PFR self-assessment questionnaire (sections 10 to 18) and, for every requirement, says how the device meets it and where this manual describes it.

10. Operating functions​

RequirementHow the device meets itDetails
P1The device signs receipts without an internet connection. Signing uses only the card and the device's memory.Audit
P2Every receipt is signed by the secure element. Receipt amounts and counters are kept on the card.Card and PIN
P3For the token to access the TaxCore services, the device identifies itself with the certificate from the secure element's PKI applet.Internet audit
P4The token is used in every call to the TaxCore web services.Internet audit
P5The device runs all TaxCore commands, over the internet and from a USB drive.Local audit
P6The device's memory holds about 180,000 receipts (about 1 GB) while it works without the internet.Audit
P7Sending data and signing receipts run at the same time, independently of each other.Audit
P8 to P13The TIN, UID, taxpayer, point of sale name, address and municipality are read from the secure element and shown in the device window.Device window
P14The top of the device window shows whether the device works and can sign receipts.Device window
P15Receipts and audit data are stored on the computer's disk and are kept without power.Installation
P16Tax is calculated per item, from the amount and tax label the ESIR sends.Connecting the ESIR
P17Tax rates arrive by the Tax Rates command, automatically over the internet or from a USB drive, with the date and time they apply from.Card and PIN
P18Audit packages are deleted only after a proof of audit and are never replaced with new ones.Audit
P19A proof of audit is handed to the secure element as soon as it is received.Internet audit
P20An audit does not slow down issuing receipts.Audit
P21Memory is freed only when a proof of audit arrives.Audit
P22After a card change, the old card's data is still sent over the internet and written to a USB drive.Card and PIN
P23Audit data is formatted according to the technical guide.Local audit
P24Commands are run in the order they are received.Local audit
P25The device uses the computer's internet connection, wired or wireless (WiFi).Installation

11. Real-time clock​

RequirementHow the device meets itDetails
GeneralReceipt date and time are in ISO 8601 format. The device checks the time against an NTP server once a day, at the latest every 48 hours.Clock and time
P1The device corrects the receipt time by the measured offset, so the receipt time stays within the allowed drift.Clock and time
P2The time server address arrives by command and can be changed.Clock and time
P3Alternative for a software L-PFR: a receipt never carries a time earlier than the previous receipt (code 6002).Clock and time

12. Error reports​

RequirementHow the device meets itDetails
P1The device records every error of the technical guide in the error log.Error log
P2Entries are chronological, with date, hour and minute in local time.Error log
P3The log is exported with the Izvezi greške (Export errors) button to a USB drive, as a text file.Error log
P4The log keeps the entries of the last 90 days.Error log
P5The log is a separate database, apart from the memory holding the receipts.Error log

13. Audit​

RequirementHow the device meets itDetails
P1The device supports internet and local audit.Audit
P2Audit packages are encrypted with AES-256, with the key the technical guide prescribes.Audit
P3The same data format is used for both kinds of audit.Audit
P4When an audit is required, the Get Status answer carries auditRequired, and the device window shows Vreme je za iščitavanje (Time for an audit).Device window
P5Communication with TaxCore follows the technical guide.Internet audit
P6The commands file is named after the secure element's UID, for example XB9LDN7F.commands.Local audit
P7Audit data is written to the memory before the ESIR receives the answer with the signed receipt.Audit

14. Local audit​

RequirementHow the device meets itDetails
P1The device writes the data to a USB drive automatically when the drive is inserted, or on request with the Lokalno iščitavanje (Local audit) button.Local audit
P2Data is written to a folder named after the UID, in an Audit subfolder. Folders are created if they do not exist.Local audit
P3The folder holds ARP.bin, {UID}.arp and the packages {UID}-{UID}-{sequence number}.json.Local audit
P4The device window shows when the transfer to the USB drive started and when it finished.Local audit
P5The device reads and runs the end-of-audit command from the USB drive.Local audit

15. Internet audit​

RequirementHow the device meets itDetails
P1Internet audit follows the technical guide.Internet audit
P2Packages not sent before go first, oldest first.Internet audit
P3Packages are sent continuously while there are packages and internet, checked every minute.Internet audit
P4Packages are kept until a proof of audit arrives.Internet audit
P5The proof of audit request is sent periodically, at most every 10 minutes, which is longer than the required 5 minutes.Internet audit

16. Audit package storage and receipt processing​

RequirementHow the device meets itDetails
P1The device receives and processes the receipt request from the ESIR.Connecting the ESIR
P2The request structure is verified; an invalid request is refused with a code from the technical guide.Error codes
P3Tax is calculated with the tax rates currently in force.Connecting the ESIR
P4Amounts are rounded to four decimals, half up.Connecting the ESIR
P5Data for signing is sent to the card with the current date and time and the PIN, according to ISO/IEC 7816-4.Card and PIN
P6The device receives the receipt signed by the card.Card and PIN
P7The device creates the receipt journal and the verification URL.Connecting the ESIR
P8The ESIR receives the signed receipt in the answer to its request.Connecting the ESIR
P9Errors are returned with codes from the technical guide, for example 1300 when the card is not in the reader.Error codes

17. Digital certificates​

RequirementHow the device meets itDetails
P1Audit data is sent for every receipt type: normal sale, advance, copy, training and proforma.Audit
P2Every receipt gets a unique URL for the QR code.Connecting the ESIR
P3The card's signature on the receipt allows the receipt's integrity and authenticity to be verified.Card and PIN

18. Forbidden functions​

RequirementHow the device meets itDetails
P1On an error the device returns only an error code from the technical guide or a manufacturer code defined in this manual (6001 to 6013).Error codes
P2A request with a tax label that does not exist, is not active, or was not active on the date of the referenced document is refused with code 2310.Error codes
P3The communication protocol parameters cannot be changed.Connecting the ESIR
P4The PIN is kept only in working memory. After a device restart the PIN is entered again.Card and PIN
P5Without a secure element in the reader the device signs no receipt and returns code 1300.Card and PIN