Toonbank
What leaves support, what driver and firmware level the lanes are on, and which fiscal rule lands next. We keep this board for our own POS estate and publish it because most of it is just as true for anyone else running tills.
Dated across the estate
Checked at source 14 Sep 2026
Windows LTSC runway
Microsoft LifecycleSeptember servicing, all three Windows 10 LTSC channels
| Channel | Update | Build |
|---|---|---|
| LTSC 2021 / 21H2 | KB5122878 | 19044.7725 |
| 22H2 (non LTSC) | KB5122878 | 19045.7725 |
| LTSC 2019 / 1809 | KB5122876 | 17763.9245 |
| LTSC 2016 / 1607 | KB5123099 | 14393.9512 |
- Released
- 8 Sep 2026, still current five days on. No out of band release, including for the RDS issue below.
- Next
- Patch Tuesday 13 Oct 2026, the same week LTSC 2016 expires.
Open known issues
Checked at source 15 Sep 2026 at 16:07
OPOS and UPOS driver levels
23 confirmed| Package | Version | Released | Age | Note |
|---|---|---|---|---|
| Epson | ||||
| OPOS ADK | 3.00E R27 | 26 Jun 2025 | 15 mo | Compliant with the Radio Equipment Directive. |
| JavaPOS ADK (Windows) | 1.14.38W | 26 Jun 2025 | 15 mo | Same RED release train as OPOS R27. Epson prints the level as Ver.1.14.38W and the ADK is Windows only, despite what this row used to claim: the Linux ADK is a separate download and is not tracked here. |
| OPOS ADK for .NET | 1.14.37 | 20 Feb 2025 | 19 mo | Signed binaries for Windows 11 Smart App Control. A matching 1.14.38 probably shipped in Jun 2025 but its note could not be surfaced, so this is the last confirmed level. |
| Advanced Printer Driver 6 | 6.10 | 25 Jun 2025 | 15 mo | Versioned per printer model, not globally. 6.10 is the TM-T88VII build; TM-m30III sits at 6.07R1. |
| TM Virtual Port Driver | 8.70c | 22 Aug 2024 | 25 mo | Now a user mode driver, renamed from TMCOMUSB. Separate 8.70b line for TM-S. |
| Zebra | ||||
| Scanner SDK for Windows | 3.07.0009 | 1 Apr 2026 | 5 mo | Installs CoreScanner. Bluetooth pairing fix, Han Xin and Grid Matrix support. Roughly quarterly cadence. |
| OPOS driver, scanner+scale | 3.07.0009 | 1 Apr 2026 | 5 mo | Not independently versioned: it ships inside the SDK InstallShield, so it carries the SDK version. OPOS CCO is at 1.14.1. |
| 123Scan | 6.01.0001 | 1 Apr 2026 | 5 mo | New Staging File Wizard combines firmware and config into one file, useful for rollout tooling. |
| JavaPOS driver (Windows) | 3.07.0008 | 1 Jan 2026 | 8 mo | The documented level, and it lags. The SDK 3.07.0009 notes claim JPOS changes, so the installed binaries are almost certainly 3.07.0009. Expect a false mismatch when the two pages are compared. |
| Datalogic | ||||
| OPOS drivers | 1.14.211 | 19 Jul 2024 | 26 mo | Confirmed twice, on the download portal and the developer docs site. |
| JavaPOS drivers | 1.14.093 | 14 Jul 2026 | 2 mo | Portal entry of 14 Jul 2026, read from the live page. The developer docs at datalogic.github.io lag the portal, so the dated portal entry wins and the disagreement is noted rather than resolved silently. |
| USB-COM driver | 7.1.5 | 17 Jun 2026 | 3 mo | Certified for Windows 10 and 11, MSI only now that the EXE wrapper is dropped. A legacy 6.3.2 branch from 2018 is still listed for pre Windows 10 images. |
| Aladdin configuration | 3.3.1.8 | 26 Nov 2025 | 10 mo | 64 bit, Windows 8 through 11. |
| DLRMUS | 1.0.28 | 1 Jun 2026 | 3 mo | Remote management suite that updates scanner and scale firmware with no OPOS dependency. Listed here because it is the likeliest public route to Magellan firmware levels, through the model list it bundles. |
| Newland | ||||
| OPOS driver | v120 | 9 Feb 2026 | 7 mo | Newland publishes no version string for this download, so the level is the token in the filename, recorded verbatim rather than reformatted. |
| JavaPOS driver | v1141 | 9 Feb 2026 | 7 mo | Filename token again. Very probably 1.14.1, matching the JavaPOS spec level, but Newland does not print it that way and the digit grouping is not published. |
| UFCOM virtual COM driver | 186 | 9 Feb 2026 | 7 mo | Filename token. The USB virtual COM driver, equivalent to Datalogic USB-COM. |
| EasySet configuration tool | 2.03.006 | 2 Sep 2026 | 0 mo | Version taken from the link label, which Newland does print for this one. |
| Nset configuration tool | 3.01.001 | 12 Mar 2026 | 6 mo | Version taken from the link label. |
| HP | ||||
| Line Display T-Series OPOS | 7.0.3.2 | 4 Jan 2023 | 44 mo | sp144415. The only current generation HP OPOS package: covers Engage Go, One, Flex Pro and Essential on Win10/11 and IoT Enterprise. |
| Cash Drawer Port OPOS | 2.2.2.2 G | 25 Apr 2019 | 89 mo | sp95904. Ageing |
| Receipt Printer OPOS | 1.14.1.12 G | 5 Mar 2018 | 102 mo | sp85623. Ageing |
| USB Cash Drawer OPOS | 1.13.5 | 20 May 2016 | 124 mo | sp75252. Ageing |
Checked at source 15 Sep 2026 at 16:07
Device firmware
8 unverified| Device | Level | Scanner build | Released | What it changes |
|---|---|---|---|---|
| Epson | ||||
| TM-T88VII | 63.08 | – | 23 Jun 2025 | Thai font redesign for Font A/B and Special Font A/B. No bug fixes, no security content. |
| TM-T88VI | 40.61 | – | 24 Sep 2025 | Thai font redesign. Worth knowing: the prior 40.60 added automatic CA signed certificate updates, and enabling that stops the printer entering power saving mode. A separate low speed model line sits at 43.58A. |
| TM-m30III | 13.19 | – | 24 Feb 2026 | Fixes a failure in network communication even with the Wi-Fi LED lit. |
| Zebra | ||||
| MP7000 | PAADGS00-006-R05 | CAADGS00-006-R05 | 5 Mar 2026 | Release 43, from the 2026-Q1 note. End of sale was 15 Sep 2025; service and support run to 15 Dec 2030. Expect firmware releases to taper. |
| MP7200 | PAAFES00-005-R01 | CAAFES00-005-R01 | 21 May 2026 | Release 17, from the 2026-Q2 note. Colour camera bug fix. |
| DS9908 | PAAECS00-007-R00 | CAAECS00-007-R00 | 8 Jun 2026 | Release 23, from the 2026-Q2 note. Adds support for Digimarc Gift Card. |
| DS8108 | PAACZS00-013-R01 | CAACZS00-013-R01 | 10 Apr 2026 | Release 37, from the 2026-Q2 note. Adds Selectable Label Identifier in the Symbologies setting, so a symbology ID can be remapped before transmission to the host, and UDI label parsing for GS1 fields 715 and 716. |
| DS8178 | PAACXS00-013-R01 | CAACXS00-013-R01 | 10 Apr 2026 | Release 48, from the 2026-Q2 note. Same two changes as the DS8108. Cradle firmware is a separate component at CAACYS00-012-R01. |
| DS2208 | PAADES00-009-R00 | CAADES00-009-R00 | 11 Jun 2026 | Release 20, from the 2026-Q2 note. Resolves a rare condition where the previously scanned barcode was sent instead of the current one. |
| DS2278 | PAADFS00-008-R00 | – | 20 Nov 2025 | From the 2025-Q4 note, which lists a plug-in build for this model and no separate scanner component. Shared with the CR2278 cradle. |
| DS4608 | PAAEIS00-004-R00 | CAAEIS00-004-R00 | 23 Jul 2025 | Release 17, from the 2025-Q3 note. |
| LI4278 | PAABIS00-005-R02 | – | 7 Nov 2025 | From the 2025-Q4 note, which lists a plug-in build for this model and no separate scanner component. Shared with the STB4278 cradle. |
| DS9808 | Not verified | – | – | Not mentioned in any of the last eight Evolution Update notes, so no level is claimed here. A note only appears when firmware moves, which means either this model has not moved in two years or it is no longer covered. 123Scan would settle it. |
| ZD421 / ZD621 Link-OS | Not verified | – | – | Printer firmware, which the scanner Evolution notes do not cover. Link-OS 7.2 is the newest release note that exists in search indexes, but the document itself does not serve, so the per printer V9x build number is unknown. |
| Datalogic | ||||
| Magellan 9400i | Not verified | – | – | Re-checked on the open web on 13 Sep 2026 rather than assumed, after the same assumption about Zebra turned out to be wrong. Still not published: the fixed retail product pages carry no firmware, the download portal has no firmware category for this line, and its only firmware images are for Windows Mobile, CE and Android handhelds. |
| Magellan 9800i | Not verified | – | – | As above. Before any partner login is considered, the realistic route is DLRMUS, a free public download whose changelog refers to a bundled model list. A stored portal credential would be the most valuable thing on the collector host, and automating a partner login risks a suspended account rather than a failed script. |
| Opticon | ||||
| NLV-1001 | RBCV0155 | – | – | Published openly on the Opticon downloads page, one server rendered table per family, no login. Opticon prints no release date beside the code, so none is claimed here. The collector tracks all 37 current models; these are the lane relevant ones and the list is a starting point to trim. |
| NLV-4001 | TC27J05 | – | – | From the same open downloads table. |
| NLV-5201 | BD52J09 | – | – | From the same open downloads table. |
| MDI-4700 | BJ01J07 | – | – | From the same open downloads table. |
| MDI-5350 | BK01J01 | – | – | From the same open downloads table. |
| F-70 | TC03J10 | – | – | From the same open downloads table. |
| OPR-2001Z | TM07J09 | – | – | From the same open downloads table. |
| OPR-3201Z | TM07J09 | – | – | From the same open downloads table. |
| OPI-3601 | BA01J39 | – | – | From the same open downloads table. |
| Honeywell | ||||
| Genesis XP 7680g, Stratos, Solaris | Not verified | – | – | Checked on 13 Sep 2026. Honeywell publishes no scanner firmware or software version on the open web: the product pages carry none at all, and every download route ends at hsmftp.honeywell.com, which requires a sign in. This one needs an account before it can be collected. |
| OPOS and JavaPOS suites | Not verified | – | – | Same gate. Version numbers surface only inside support knowledge articles, which are prose rather than a catalogue, so nothing here is machine readable yet. No collector was written rather than one that could only ever emit empty rows. |
| HP | ||||
| Engage One Pro, BIOS S30 | 2.27.00 | – | 19 Aug 2026 | Security HP rates this release Critical. It addresses CVE-2026-20708, CVE-2026-20715 and CVE-2026-20734, and fixes the on-screen keyboard going missing after Secure Boot is switched on, which a touchscreen lane can depend on. Listed for Windows 10 IoT Enterprise 2021 LTSC. HP SoftPaq sp174265, effective 19 Aug 2026. Patch priority. |
| Engage One Pro G2, BIOS W30 | 2.07.00 | – | 19 Aug 2026 | Security The BIOS for the 15.6, 19.5 and 23.8 inch G2 systems, HP platform 8D09. HP rates this release Critical: the same three CVEs as the S30 release (CVE-2026-20708, CVE-2026-20715 and CVE-2026-20734) and the same on-screen keyboard fix after Secure Boot is switched on. Listed for Windows 10 IoT Enterprise 2021 LTSC. HP SoftPaq sp174264, effective 19 Aug 2026. Patch priority. |
| Engage One Pro G2, driver pack | 1.00 Rev A | – | 9 Dec 2024 | Windows 11 x64 pack covering the 15.6, 19.5 and 23.8 inch G2 systems, 22H2 through 24H2. |
| Engage Go, Engage One Essential | Not verified | – | – | The S30 SoftPaq explicitly excludes the Essential variant, and no Engage Go BIOS release note surfaced. The driver listings for these models are client side rendered, so they cannot be read without a browser. |
| Value Receipt Printer | Not verified | – | – | Dedicated support pages exist but return no driver rows. The C-Series receipt printer driver (A776, A798, A799, H300) is confirmed at 1.08 Rev B, 11 Feb 2020. |
Checked at source 14 Sep 2026
Peripheral advisories
Open, and structural
Quiet
Checked at source 15 Sep 2026 at 16:07
CVE register
5 exploitedThe register
| CVE | Lands on | What it gives | State | Fix |
|---|---|---|---|---|
| Act now: exploited, or no fix exists | ||||
| CVE-2026-84869 | ConnectWise ScreenConnect client, every version before 26.6.5 | Files can be transferred to and executed on the Host client system through an active remote session, without authorisation or Host confirmation. The server is not the affected component, the client is, so the exposure runs from a session back toward the machine running support, not only outward to the endpoint. | Exploited KEV 14 Sep 9.9 | ScreenConnect 26.6.5. Published 8 Sep 2026, added to the exploited catalogue 11 Sep with a three day due date. |
| CVE-2026-85880 | Windows ALPC, LTSC 2016, 2019 and 2021 | Heap overflow in the Advanced Local Procedure Call subsystem. Local escalation to SYSTEM, which is the second stage after any foothold on a till. | Exploited KEV 22 Sep 7.8 | September cumulative update |
| CVE-2026-23767 | Every networked Epson TM printer | ESC/POS over TCP 9100 requires no authentication. Anyone with a network path can print, reconfigure, brick the device, or read everything it prints. | No fix ever 9.8 | Segmentation and IP filtering only. JPCERT records that the specification will not be revised. |
| CVE-2025-35970 | Epson TM Web Config, confirmed on TM-T88VI, TM-m50II, TM-H6000V | The initial admin password is the device serial number, and the serial is readable over SNMP with no authentication. | Chain start 8.7 | No firmware fix. Change the password, disable SNMP where unused. Trivial to exploit and trivial to close. |
| CVE-2025-66635 | 35 Epson TM models | Command execution from a Web Config screen. Needs the admin password, which the row above hands over. Treat the pair as one attack path, not two findings. | Chained 8.6 | Fixed firmware available for current generation models |
| CVE-2026-19908<br>CVE-2026-19909<br>CVE-2026-19910<br>CVE-2026-19911 | PAX Q80 payment terminals, firmware 2.6.33.6690R | Unauthenticated root on an adjacent network, and an installer signature verification bypass that defeats the exact control meant to stop unauthorised code reaching a PIN entry device. | No fix 7.1 to 7.5 | None available. Disclosure ran ahead of a fix, and no fixed firmware is expected before April 2027. The only stated mitigation is to restrict interaction with the device. |
| CVE-2025-59287 | WSUS, where the server role is enabled | Unauthenticated remote code execution as SYSTEM through unsafe deserialisation. Does not affect Windows 10 clients, but a compromised WSUS is a direct path to every lane it serves. | Exploited KEV 9.8 | The out of band update of 23 Oct 2025. The 14 Oct patch was incomplete, so confirm which one the server took. |
| CVE-2026-47301 | Microsoft Configuration Manager site server | A four stage chain taking any authenticated domain user to SYSTEM on the site server. Public proof of concept exists. | Public PoC Partly unpatched | Partial fix 14 Jul 2026. The remaining links wait for ConfigMgr 2609 in October 2026. |
| Reaches a lane, and a fix exists | ||||
| CVE-2026-68839 | Windows USB Mass Storage Class Driver, all three builds | Remote code execution. The single most lane specific bug in the September release. | 9.8 | September cumulative update |
| CVE-2026-69768 | Windows RNDIS, all three builds | Remote code execution over USB attached networking, reachable by plugging in a device that presents as a USB network adapter. | 9.8 | September cumulative update |
| CVE-2026-69769 | Windows HTTP Print Provider, all three builds | Remote code execution. One of 11 print spooler and print provider issues this month, none of them exploited. | 9.8 | September cumulative update |
| CVE-2026-69525 | Remote Desktop Services, all three builds | Remote code execution. Matters only where a lane accepts inbound RDP for support access. | Test first 9.8 | September cumulative update, but Microsoft opened a known issue on 11 Sep 2026 for RDS becoming unstable after that same update, with LTSC 2016, 2019 and 21H2 on the affected list. Pilot before a fleet rollout. |
| CVE-2026-69731 | Windows HID Class Driver, all three builds | Local escalation. Relevant because a lane has keyboards, scanners and card readers presenting as HID devices. | 7.8 | September cumulative update |
| CVE-2026-69458 | BitLocker, all three builds | Elevation of privilege. A second BitLocker issue, CVE-2026-69449, allows remote code execution at 6.7. | 8.0 | September cumulative update |
| CVE-2022-36133 | Epson TM-C3500 and TM-C7500 colour label printers | Web Config authentication bypass with no credentials required. | 9.1 | Firmware update through the Epson business portal |
| CVE-2025-32008<br>CVE-2025-20080<br>CVE-2025-27708 | HP Engage One Pro, through Intel AMT and CSME firmware | Two network denial of service issues and one local read. Inert unless Intel AMT or Standard Manageability is provisioned, which on a typical store lane it is not. | 5.6 to 8.7 | HP bulletin HPSBHF04088, released 10 Feb 2026 and at Rev. 5 as of 3 Sep 2026. Minimum BIOS 02.25.00 (SoftPaq SP170192) for the HP Engage One Pro AIO System, but 02.05.00 (SP170191) for the Engage One Pro 15.6, 19.5 and 23.8 G2 AiO systems, so the fix level depends on which generation a lane carries. Read from HP 14 Sep 2026. |
| Management plane and POS software | ||||
| CVE-2026-86218 | N-able N-central before 2026.3.1.14 | Static code injection giving pre-authentication remote code execution on the management server. A change made there propagates to every system the platform manages, which is the whole point of the tool and the whole problem with the bug. | Exploited KEV 9.8 v3.1, 10.0 v4.0 | N-central 2026.3.1.14, shipped as 2026.3 Hotfix 4. KEV due date was 11 Sep 2026 and has passed. |
| CVE-2026-3564 | ConnectWise ScreenConnect before 26.1 | Per instance machine keys stored in server config could be extracted and reused to authenticate sessions. | Priority 1 9.0 | ScreenConnect 26.1 |
| CVE-2024-1708<br>CVE-2024-1709 | ConnectWise ScreenConnect before 23.9.8 | Path traversal and authentication bypass. Chained and used to deploy Medusa ransomware in April 2026, which is why the older of the two was added to the exploited catalogue two years after disclosure. | Exploited KEV 8.4 and 10.0 | ScreenConnect 23.9.8 |
| CVE-2026-60167<br>CVE-2026-60168<br>CVE-2026-60169<br>CVE-2026-60170 | Oracle Hospitality Simphony 19.8 to 19.10, component POS | Unauthenticated takeover of the application, access to the kiosk administrator console, NTLM hash coercion through the printing handler, and an arbitrary file write to the host. | 7.5 to 8.1 | July 2026 Critical Patch Update |
| CVE-2025-36537 | TeamViewer with Remote Management, before 15.67 | A local unprivileged user deletes arbitrary files as SYSTEM through MSI rollback. Only systems with Backup, Monitoring or Patch Management enabled. | 7.0 | 15.67, or 15.64.5 on the older branch |
| Historic, conditional, or superseded | ||||
| CVE-2014-7888 to<br>CVE-2014-7898 | HP OPOS drivers before 1.13.003 | Ten CVEs, remote code execution through the OPOS ActiveX controls. Covers displays, receipt and MICR printers, cash drawers, MSRs, keyboards and scanners. | Fixed 2015 | OPOS driver 1.13.003, SoftPaq SP70564. One inventory query settles this permanently. |
| CVE-2015-1495<br>CVE-2015-1496 | Motorola Scanner SDK, the CoreScanner ancestor | A remote buffer overflow and a local escalation through weak file permissions on CoreScanner.exe. | Superseded | The Zebra 3.x SDK line. Only relevant where legacy Motorola branded middleware survives. |
| CVE-2023-4957 | Zebra ZT410 and GK420d printers | Authentication bypass from the adjacent network when protected mode is off. | Discontinued hardware | Link-OS 6.0 protected mode. Both models went end of sale in 2020 and 2022 and support ended in 2025, so this reads as a lifecycle finding more than a vulnerability. |
| CVE-2017-6443 | Epson Web Config across 40 or so TM models | Cross site scripting. Needs an administrator to follow a crafted link. | Fixed firmware | Firmware versions 1.02 to 4.44 depending on model |
| CVE-2021-43333 | Datalogic DXU on rugged mobile computers | The DXU service requires no authentication to read or change configuration. In store relevant for DL-Axist and Skorpio handhelds, not for fixed lane scanners. | Config 6.5 | No fixed version published. Disable DXU. Off by default on current Skorpio X5. |
September 2026 Patch Tuesday, by type
The cluster that is specific to a till
This is the attack surface a checkout lane has and an office desktop does not: a physically reachable machine in a public space with live USB ports and a scanner, a scale, a card reader and a cash drawer hanging off them. Patching is the fix, but USB device installation policy, allowlisting by hardware ID, is the control that holds between patch cycles.
Dated, and not a CVE
Worth sitting with: lanes are the least physically secure domain joined machines in the estate, standing in a public space, and the deployment tool routinely hands them credentials that work fleet wide.
Where this register is blind
Payment terminal firmware largely sits outside the CVE system. It is patched through PCI PTS certified channels instead, so the public record structurally understates the category. A sweep across the major terminal lines for 2024 to 2026 returns almost nothing, and that is a property of the disclosure route rather than a clean bill of health.
A maintained advisory feed does not exist for every line on this board. For most of the peripheral lines here there is no security feed to subscribe to, and one publishes BIOS CVEs inside per package release notes rather than on a product security page. Where that is the case NVD and CISA ICS have to be watched directly, and a bulletin page with nothing recent on it cannot be read as an absence of issues.
Retail POS software is thinly covered. A sweep across the major retail POS suites returns no 2025 or 2026 CVEs at all, and several carry a single record going back a decade. Given how much of this software runs on a lane, that is far likelier to describe how little of it is researched than how few bugs it holds.
Checked and not applicable here
| CVE | Why it does not apply |
|---|---|
| CVE-2026-81963 | The other September zero day, in the Windows Update stack, and also exploited. It lists only Windows 11 and Server 2025 as affected. It does not reach a Windows 10 LTSC lane. |
| CVE-2026-42016<br>CVE-2026-42018<br>CVE-2026-67277<br>CVE-2026-86060<br>CVE-2026-19490<br>CVE-2026-20079<br>CVE-2026-85706<br>CVE-2026-75650 | The rest of the exploited catalogue additions in the week to 11 Sep 2026: JFrog Artifactory, MikroTik RouterOS, Citrix NetScaler, Cisco Firewall Management Center, GitLab and Adobe Commerce. All are real and several are network edge or build chain issues worth someone's attention, but none is a lane, a peripheral, a payment terminal or the tooling that deploys to them. Listed here so the same week is not re-triaged next run. |
| CVE-2026-73542 | Epson retained revoked root certificates. The affected list runs to 266 models, all inkjet, laser, scanner and large format. No TM series, no UB interface boards. |
| CVE-2025-64310 | Epson, no rate limiting on authentication. Projector products only. |
| CVE-2025-42598 | Epson Windows driver local escalation in non English environments. Epson's affected list names the Universal Printer Driver and consumer lines; no POS driver is listed, though absence from a list is not the same as confirmed unaffected. |
| CVE-2019-13526 | Datalogic AV7000. An industrial conveyor and parcel scanner, not a lane scanner. |
| CVE-2026-58315<br>CVE-2024-47295<br>CVE-2023-23572 | Epson Web Config issues whose affected model tables cover consumer and office print lines only. No POS models listed. |
Checked at source 14 Sep 2026
GS1 Sunrise 2027
Scanner and hostWhat it actually says, and where it does not agree with itself
What the scanner has to do
- Decode all three retail 2D types: GS1 DataMatrix, QR Code carrying a GS1 Digital Link URI, and Data Matrix carrying a Digital Link URI.
- Handle normal and reversed reflectance.
- Decode in under 300 ms on a bioptic, under 500 ms on presentation and activated handheld.
- Support scanning modes 1, 2 and 3.
- Let the retailer configure which data is transmitted.
What the POS host has to do
- Parse both GS1 element string syntax and GS1 Digital Link URI syntax.
- Accept a 14 digit GTIN (09506000134352, not only 9506000134352) and store it normalised.
- Identify the right item when linear and 2D sit on the same pack, with one beep, not two.
- Process optional AIs: expiry 17, batch or lot 10, serial 21, weight.
- Act on them: expiry stop sale, batch recall blocking, date driven markdown.
- Persist everything received for backend use.
Fleet position
| Question | Answer | Detail |
|---|---|---|
| Imager or laser | Hard line | 2D at POS needs an image based scanner. No firmware rescues a laser, there is no image to process. Any remaining laser lane is a replacement, not an upgrade. Audit this first, it is the only part with a capex tail. |
| Zebra MP7000 | Capable | Multiple CMOS array imager. Decodes Aztec, DataMatrix, MicroPDF417, MicroQR, PDF417, QR and Han Xin, with integrated Digimarc support. Digital Link arrived by firmware, not hardware: reseller documentation puts MP7000 in an April 2025 wave across 16 Zebra models, configured through 123Scan with the mode set in the Symbologies tab, mode 2 recommended. That firmware claim comes from reseller documentation and was not confirmed against the vendor's own release notes. Remember the MP7000 is end of sale since 15 Sep 2025. |
| Datalogic Magellan 9400i | Capable | Digital imagers in all planes, reads 1D, 2D and Digimarc. The product sits under a vendor path named /retail-gs1-digital-link/, but the page does not state Digital Link parsing specifics or an upgrade path, so treat the positioning as a signal rather than a conformance statement. |
| Datalogic Magellan 9800i | Not verified | Same product family and same Digital Link URL path, but the symbology list and Digital Link statement were not retrieved. Capability by family inference is not asserted here. |
| Is imager enough | No | GS1's own guideline warns that "not all imaging scanners will be capable of the Ambition 2027 goal". The bar is the full criteria above, including reversed reflectance and the latency budget. A scanner that decodes a QR code on the bench can still miss 300 ms at lane speed. Per model conformance is worth getting from Zebra and Datalogic in writing. |
The one thing worth doing this quarter
Normative documents, and their current versions
| Document | Version | Date |
|---|---|---|
| POS Host and Backend Systems Playbook | 1.0.1 | May 2026 |
| Creation and Printing Playbook | 1.0.1 | Jun 2026 |
| 2D at Retail POS Implementation Guideline | 1.1.0 | Dec 2025 |
| Solution provider 2D readiness criteria | 1.0.0 | Apr 2025 |
| 2D Barcodes in Retail test suite | 1.1 | Feb 2025 |
Checked at source 14 Sep 2026
Fiscalisation
61 marketsHow much of this reaches the till
Benelux and the neighbours
Rest of Europe
| Market | Reaches | Regime | What the till has to do | Next |
|---|---|---|---|---|
| Italy | Certified till | RT | Certified registratore telematico transmitting daily takings. Since 1 Jan 2026 payment terminals must be logically linked to the RT, registered through Fatture e Corrispettivi. Penalties 1,000 to 4,000 euro for a missing link. The instant receipt lottery still has not launched; the weekly one runs normally. | rolling |
| Spain | Certified till | VeriFactu | Chained, hash linked, signed invoice records with a QR on every invoice, either streamed to AEAT or stored tamper evidently, from software carrying a producer declaration. Delayed a second time by Real Decreto-ley 15/2025 of 2 Dec 2025, a royal decree-law rather than a royal decree, which is what to search for in the BOE. TicketBAI is separate and is mandatory across the three Basque provinces. Navarra does not use TicketBAI: it has its own regime, branded NaTicket, whose technical specification is not final and which is not yet in force. Read 14 Sep 2026. | 1 Jan 2027 |
| Portugal | Certified till | ATCUD | AT certified software, ATCUD code and QR on every invoice, monthly SAF-T PT. From Jan 2027 a PDF invoice needs a qualified electronic signature to count as an e-invoice. | 1 Jan 2027 |
| Poland | Certified till | Kasy online + KSeF | Certified online cash registers streaming to the central repository, required by designated sectors rather than universally, plus structured e-invoicing through KSeF: large enterprises above PLN 200m turnover from 1 Feb 2026, other VAT payers from 1 Apr 2026. The duty to receive through KSeF applied to everyone from 1 Feb 2026. Micro entrepreneurs invoicing under PLN 10,000 gross a month were carved out and join on 1 Jan 2027, which is also when the transition reliefs end and sanctions begin. Ministerstwo Finansów, read 14 Sep 2026. | 1 Jan 2027 |
| Greece | Certified till | myDATA | Certified registers linked to AADE, QR on receipts, payment terminals interconnected with the register per A.1098/2022 and A.1155/2023. B2B e-invoicing is in its final phase. | 30 Sep 2026 |
| Austria | Certified till | RKSV | Signature creation device, AES-256 chained signatures, QR on the receipt, DEP export. Mandatory above 15,000 euro turnover with more than 7,500 in cash. No change pending. | none |
| Romania | Certified till | AMEF + RO e-Factura | Fiscal cash registers alongside B2B and B2C e-invoicing. From 1 Jan 2026 e-Factura scope extends to non resident VAT registered customers and the submission window relaxes from 5 calendar to 5 working days. The AMEF cash register regime is long established but was not re-verified for this board. | in force |
| Norway | Certified till | Kassasystemlova | The Nordic exception. The supplier files a product declaration with Skatteetaten and only declared systems may be used. Electronic journal, X and Z reports, no delete function, SAF-T Cash Register export with a digital signature. Skatteetaten publishes the list of declared systems. | none |
| Serbia | Certified till | E-fiskalizacija | ESIR sends each sale to a local or virtual PFR, which signs it with a cryptographic security element and transmits in real time, with an offline buffer. QR on the receipt, and both ESIR and PFR must be on the accredited list. From 1 Apr 2026 retail sales to corporate cardholders need an e-invoice issued after the fiscal receipt. | 1 Jan 2027 |
| Albania | Certified till | Fiskalizimi | No turnover threshold, it applies from the first sale. Certified software hashes each invoice (NSLF), signs with the taxpayer certificate, and the administration returns an NIVF; both print on the receipt. Cash points need registered devices, offline ceiling is 48 hours, a failed device must be replaced within 5 days. A generic ERP connector or Peppol access point is explicitly not sufficient. | in force |
| Ukraine | Certified till | RRO / PRRO | Hardware RRO or state certified software PRRO registered with the tax service, with cloud PRROs transmitting continuously. QR on the receipt for verification. Covers cash, card and payment service provider settlements; direct IBAN transfers are exempt. Fines are 100 percent of transaction value, then 150. | in force |
| Russia | Certified till | 54-FZ online kassa | The most invasive model on this page. Every till needs a replaceable cryptographic fiscal drive registered with the FNS plus a contract with an accredited OFD that relays every receipt. QR on the receipt, versioned FFD payload, 30,000 rouble fine per payment without one. VAT rose to 22 percent on 1 Jan 2026 and the inspection grace period has lapsed. | in force |
| Bosnia | Certified till | Fiscalisation Law | Entity level hardware fiscal registers today. A new state law enacted 12 Feb 2026 introduces an approved electronic fiscal system with certified devices and real time transmission, phased. | 2028 |
| Hungary | Real time | e-nyugta | Since 1 Sep 2026 around 270,000 taxpayers report aggregated daily receipt data to NAV within three calendar days, split by VAT rate, via cloud register, the KOBAK portal or M2M. Grace period to 31 Dec 2026, fines after. Hardware e-cash registers become mandatory 1 Jul 2028. | 1 Jan 2027 |
| Croatia | Real time | Fiskalizacija 2.0 | Mandatory B2B and B2G e-invoicing plus e-reporting between VAT registered taxpayers since 1 Jan 2026, with monthly e-reporting by the 20th. B2C is not in the e-invoicing mandate: consumer sales stay under receipt fiscalisation, and what changed on 1 Jan 2026 there is that fiscalisation now covers all payment methods rather than cash alone. Porezna uprava treats the two as separate procedures. From 1 Jan 2027 the duty to issue extends to taxpayers not registered for VAT, who until then need only be able to receive. Read 14 Sep 2026. | 1 Jan 2027 |
| Czechia | Real time | EET 2.0 | EET was abolished with effect from 1 Jan 2023, so nothing reaches the till today. Reintroduction as EET 2.0 was approved by the Chamber of Deputies on 15 Jul 2026, returned with amendments by the Senate on 19 Aug 2026, and finally adopted when the Chamber overrode the Senate on 9 Sep 2026. Covers payments involving in person contact: cash, card, QR and mobile. Paper receipts are not mandatory. Self employed people in the first flat tax bracket up to CZK 1m turnover can opt out entirely in exchange for a higher monthly prepayment. Ministerstvo financí and Finanční správa, read 14 Sep 2026. | Jan 2027 |
| United Kingdom | None | none | Nothing at the till. Making Tax Digital is digital record keeping and API filing by the business, not fiscalisation: no receipt format, no device certification, no transaction reporting. The announced B2B mandate is four corner Peppol with no real time feed to HMRC. | 1 Apr 2029 |
| Switzerland | None | none | Nothing at the till, explicitly unlike Germany. The obligation sits on the cash book: daily, chronological, unalterable entries, full books above CHF 500,000 turnover, ten year retention. | none |
Beyond Europe
| Market | Reaches | Regime | What the till has to do | Next |
|---|---|---|---|---|
| Americas | ||||
| Brazil | Real time | NFC-e | Sign the XML with an ICP-Brasil certificate, get per sale authorisation from the state SEFAZ, print the DANFE with a QR derived from the state issued CSC, with offline contingency. Since 3 Aug 2026 every NFC-e must carry populated IBS and CBS fields or it is auto rejected. Sao Paulo retired SAT-CF-e on 31 Dec 2025 and moved retail to NFC-e. | 1 Dec 2026 |
| Mexico | Real time | CFDI 4.0 | Build the CFDI XML, sign with the CSD, have it stamped by an authorised PAC. Walk in customers get a simple ticket, consolidated into a factura global against the generic RFC. | none |
| Chile | Real time | Boleta Electronica | Signed XML DTE drawing folios from an authorised CAF range, reported to SII with a daily consumo de folios. Since 1 May 2025 in person B2C sales must hand over a printed representation. | none |
| Colombia | Real time | Documento equivalente POS | Signed XML pre-validated by DIAN before the receipt reaches the customer, which puts authority latency on the critical path. Paper contingency must be transmitted within 48 hours. Paper POS tickets are no longer valid. | in force |
| Argentina | Certified till | Controlador Fiscal | High volume retail and food service selling to final consumers must issue through an ARCA homologated fiscal controller storing fiscal data and filing periodic reports. Other taxpayers may use electronic invoicing instead. The current exemption boundary was not verified against a primary source. | in force |
| Peru | Real time | SEE boleta | Signed UBL boleta with QR at the till, transmitted to SUNAT in a resumen diario, same day or up to the seventh calendar day. | none |
| Uruguay | Real time | CFE e-Ticket | Obtain a CAE numbering range from DGI, issue the signed XML e-Ticket, transmit and retain five years. Universal for all VAT taxpayers since 1 Jan 2026. | complete |
| Costa Rica | Real time | Tiquete v4.4 | XML v4.4 with a 50 digit clave signed with the taxpayer key, pushed to the TRIBU-CR API. No fiscal validity until accepted, and no batch option. | none |
| Dominican Rep. | Real time | e-CF | DGII authorised invoicing system issuing signed XML e-CF; consumer sales use type 32. DGII validates and returns a tracking number. | 15 Nov 2026 |
| United States | None | none | No fiscalisation at all. No certified device, no fiscal memory, no clearance, no mandated receipt format. The receipt is a commercial document. The engineering effort is entirely rate and sourcing accuracy across roughly 13,000 jurisdictions, product taxability, exemption certificates, marketplace facilitator rules and economic nexus. A genuinely different model, not a gap. | none |
| Canada | None | none, except Quebec | Nothing federally. Quebec is the exception: restaurants, bars, caterers and paid passenger transport need a certified SEV transmitting to MEV-WEB and printing a QR plus transaction number. Quebec retail generally is not covered. | in force |
| Middle East | ||||
| Saudi Arabia | Real time | ZATCA Fatoora | Phase 2. B2C simplified invoices are cryptographically stamped locally, carry a TLV QR code on the receipt and are reported to ZATCA within 24 hours; B2B standard invoices are cleared before issue. UUIDs, hash chaining and anti tamper controls throughout. Wave 25 halved the threshold to SAR 187,500. | 1 Feb 2027 |
| Turkey | Certified till | YN OKC + e-Arsiv | Sales run on a GIB approved new generation cash register with secure fiscal memory, TSM connectivity and Z reports matched to GIB. From 2026 businesses in scope may not use standalone or mobile card terminals, payment must go through an EFT-POS enabled register. Above the threshold an e-Arsiv invoice replaces the receipt. | 1 Oct 2026 |
| United Arab Emirates | Invoice only | PINT AE | Peppol five corner exchange through an accredited service provider with a reporting leg to the FTA. Scope is B2B and B2G, so the retail till is not affected for ordinary consumer sales. | 1 Jan 2027 |
| Israel | Invoice only | Allocation number | Above the threshold, a tax invoice to a business customer claiming input VAT needs an allocation number from the tax authority API printed on it. Does not apply to private consumers, so an ordinary retail till is untouched. Threshold has fallen to NIS 5,000. | undated |
| Jordan | Real time | JoFotara | Every invoice including B2C is submitted for validation and the authority returns a QR that must appear on the document, so this one does reach the till. Four year tamper proof retention. | undated |
| Oman | Invoice only | Fawtara | PINT OM through an accredited service provider. Pilot only, and the timeline was pushed back in Aug 2026. Nothing at the till today. | 1 Apr 2027 |
| Qatar | Invoice only | GTA e-invoicing | Law and regulations approved 6 May 2026, pilot running. B2B is clearance, and B2C is planned as a live reporting model, so it will reach the till eventually. Specs still pending. | 1 Jan 2027 |
| Africa | ||||
| Egypt | Real time | ETA e-receipt | Each POS device is registered with the authority, holds a class 2 digital certificate and submits every receipt in real time over TLS; the authority returns a UUID and the receipt carries a QR. Still rolling out B2C by tax office rather than universally. | 31 Mar 2026 |
| Kenya | Real time | eTIMS | Every invoice including B2C is transmitted before issue and the authority returns a control unit invoice number, signature and QR that print on the receipt. Integration is via software control units, not certified hardware, so the burden is integration rather than certification. | in force |
| Ghana | Real time | E-VAT | Invoices and sales receipts go through a GRA certified invoicing system to the virtual sales data controller, which returns a clearance number, signature, QR and timestamp to embed on the document. Final rollout tranche not verified. | undated |
| Tanzania | Certified till | EFD / VFD | Fiscal receipt from an approved device for every sale: sequential numbering, SHA1 with RSA signature, receipt verification code and QR, daily Z report, real time submission with offline queueing. A proposed move to token based pre-clearance would turn an offline tolerant design into a blocking online dependency. | undated |
| Nigeria | Real time | EFS / MBS | Clearance style: transmit to the revenue service platform and receive an invoice reference number. Large taxpayers only; no published date for a retail or B2C phase. | not verified |
| Angola | Certified till | Facturacao electronica | Invoicing software must be certified or validated by the AGT, plus SAF-T (AO) and inventory file submission. In force since 1 Jan 2026 for large taxpayers and anyone invoicing above AOA 25m. Retail treatment is not explicit in the sources. | undated |
| Morocco | Invoice only | DGI e-invoicing | Clearance of XML on the DGI platform with ICE validation and a ten year archive. B2B and B2G only in this phase, B2C is explicitly deferred, so the till is out of scope for now. | 2027 |
| South Africa | None | consultation | Nothing required today. SARS published a VAT modernisation consultation paper in Aug 2026 proposing structured e-invoicing and near real time reporting, with phased adoption floated for around 2030. Nothing is mandatory and there is no binding commencement date. | 16 Oct 2026 |
| Asia Pacific | ||||
| Taiwan | Real time | eGUI | Heavy till involvement. Invoice numbers are allocated by the ministry, so the POS cannot generate its own and must manage number block inventory. Issue the eGUI, print a QR receipt or write to a carrier, upload MIG 4.0 XML. B2C credit notes upload within two days. | complete |
| South Korea | Real time | Cash Receipt | A genuine till obligation: capture a buyer identifier and get an approval number from the tax service. Designated sectors must issue automatically at KRW 100,000 and above whether or not the customer asks. Penalty is 20 percent for a mandatory sector failure. | none |
| Vietnam | Real time | Decree 70/2025 | The clearest recent case of an invoice regime pushed down into the cash register. Covered retail and hospitality sellers generate the e-invoice from the till per sale, transmit the same day and give the buyer a QR lookup. Deliberately exempt from the digital signature requirement. | in force |
| India | Invoice only | GST e-invoicing | B2B only: push JSON to an invoice registration portal and print the returned IRN and signed QR. Retail B2C sales need no IRN. Separate rule: above AATO 500 crore a dynamic QR carrying payment details goes on B2C invoices. B2C e-invoicing remains a voluntary pilot. | not dated |
| China | Invoice only | Fully digitalised e-fapiao | No Golden Tax hardware at the till any more. Fapiao are issued from the tax platform in XML and validated centrally, on customer request rather than automatically per sale. Ordinary retail receipts are not fiscalised. The new VAT Law made e-fapiao the sole legal invoice format on 1 Jan 2026. | end 2026 |
| Malaysia | Invoice only | MyInvois | Cleared e-invoices return a unique number and validation QR. Consumers who do not ask get a normal receipt covered by a consolidated periodic e-invoice, but from 1 Jan 2026 consolidation is prohibited above RM10,000, which is the rule that bites at a till. | in force |
| Philippines | Invoice only | EIS + ESRS | Covered taxpayers must issue system generated structured invoice data that a printout does not satisfy. POS and cash register users are explicitly in a later phase, contingent on the authority standing the system up. | 31 Dec 2026 |
| Indonesia | Invoice only | Coretax e-Faktur | Clearance covers B2B and B2G. A retail taxable business issues a simplified tax invoice, which may be an ordinary till slip, and may aggregate end consumer sales. No B2C or POS mandate. | none |
| Singapore | Invoice only | GST InvoiceNow | Structured invoice data to the tax authority through a Peppol access point. B2B and B2G, not a till obligation. | 1 Apr 2028 |
| Japan | None | Qualified Invoice | No device, no reporting. The receipt must carry the issuer registration number and tax split by 8 and 10 percent. Retail, restaurants and taxis may use the simplified qualified invoice, which is the format POS actually implements. Transitional input credit relief steps from 80 to 50 percent on 1 Oct 2026. | 1 Oct 2026 |
| Thailand | None | voluntary | Nothing mandatory at the till. Signed XML e-Tax Invoice and e-Receipt are optional, submitted by the 15th of the following month. No legislated mandate for 2026 or 2027. | none |
| Australia | None | none | Nothing at the till. No certified register, no fiscal memory, no reporting. Peppol is government supplier side only and the business eInvoicing right was never enacted as a B2B mandate. | none |
| New Zealand | None | none | Nothing at the till. Peppol obligations sit on government agencies and their large suppliers. | 1 Jan 2027 |
Estate calendar, next 24 months
Checked at source 13 Sep 2026
Field notes
23 notesThings that are not what they look like
Numbers worth distrusting
Rules with a sting in them
Quietly unfixable
Sources, and how to read this board
We read every version here from a vendor page or release note, and we publish this board because most of it is just as true for anyone else running tills. Where we cannot confirm a level at source we mark it Not verified rather than estimating it. Talk to us about a POS estate →
We publish this in good faith and check it at source, but vendor pages move and regulations change: we cannot warrant that everything here is complete or current, and Tillforge accepts no liability for decisions taken on the basis of this page. Anything acted on should first be confirmed with the vendor or the relevant authority. See our terms.