← Back to all articles
This article is not yet available in your language. Showing the English version.

Revisionssichere Archivierung under GoBD: requirements, retention periods, and the technology (2026)

SealDoc Team · · 6 min read

Revisionssichere Archivierung, audit-proof archiving, is the German standard for storing tax-relevant documents so they stay unchangeable, complete, traceable, and available for the entire retention period. It is not a product you buy or a single certificate you earn. It is a combination of technical and organisational measures, anchored in the GoBD. If you sell to or operate in Germany, here is what the GoBD actually requires, what the retention periods are in 2026 (they changed), and where technology fits.

What “revisionssicher” actually means

“Revisionssicher” is a practice term, not a law and not a single certification. The legal basis is the GoBD (Grundsaetze zur ordnungsmaessigen Fuehrung und Aufbewahrung von Buechern, Aufzeichnungen und Unterlagen in elektronischer Form sowie zum Datenzugriff), set out in the German Finance Ministry’s BMF letter of 28 November 2019. “Revisionssicher” describes storage that satisfies the GoBD so a tax auditor accepts it. No vendor can sell you the label; they can only sell you tools that help you meet the requirements.

The GoBD principles

The GoBD is built on a handful of principles. Your archiving has to satisfy all of them, not just immutability:

  • Nachvollziehbarkeit und Nachpruefbarkeit (traceability and verifiability): a knowledgeable third party must be able to understand your records within a reasonable time.
  • Vollstaendigkeit (completeness): every tax-relevant transaction is recorded, in full.
  • Richtigkeit (accuracy): the records reflect reality.
  • Zeitgerechte Buchungen und Aufzeichnungen (timeliness): transactions are captured promptly, not months later.
  • Ordnung (orderliness): filing is structured and unambiguous, so documents are quick to find during an audit.
  • Unveraenderbarkeit (immutability): once recorded or archived, documents must not be changed undetectably. If a change is needed, the original must stay identifiable alongside it.

Retention periods in 2026 (this changed)

This is the part where a lot of older guidance is now wrong. Germany shortened a key retention period.

  • Buchungsbelege (accounting vouchers, including invoices): 8 years. Reduced from 10 to 8 by the Fourth Bureaucracy Relief Act (Viertes Buerokratieentlastungsgesetz, BEG IV), effective 1 January 2025. Through a transitional rule it applies to all vouchers whose old 10-year period had not yet expired at the end of 2024, so it covers existing documents, not just new ones.
  • Handelsbuecher, Inventare, annual financial statements (Jahresabschluesse), management reports, opening balance sheets and the instructions needed to understand them: still 10 years.
  • Commercial and business letters (Handels- und Geschaeftsbriefe) and other tax-relevant documents: 6 years.
  • Exception (2025): banks (Kreditinstitute), insurers (Versicherungen), and securities institutions must keep Buchungsbelege for 10 years again, a reversal driven by Cum-Ex enforcement. For all other companies, 8 years stands.
  • Every period starts at the end of the calendar year in which the document was created or received.

Two caveats worth keeping in mind. These are minimums: an ongoing tax audit, civil-law limitation periods, or specific VAT records can require you to keep documents longer, so when in doubt, keep it. And a lot of guides still say “10 years for invoices.” For most companies that is now outdated; check the current wording of section 147 AO and section 257 HGB.

The part a tool cannot do for you: the Verfahrensdokumentation

The GoBD requires a written Verfahrensdokumentation: a description of how tax-relevant data and documents flow through your systems, from creation through indexing, processing, storage, retrieval and reproduction. The standard is concrete: a knowledgeable third party must be able to verify it within a reasonable time, and across the entire retention period you must be able to prove that the documented procedure matches the one actually in use, with a traceable change history.

It usually has four parts: a general description, user documentation (how staff actually operate the process), technical system documentation (hardware, software, versions, interfaces, formats), and operations documentation (access rights, change management, backup, IT security). Alongside it sits your internal control system (IKS): access and authorisation controls, functional separation, capture and reconciliation checks, all of them exercised and logged.

No archiving product writes this for you. It is your responsibility, and it is the piece most often missing.

The technology of immutability

The GoBD is technology-neutral. It does not mandate a specific product or method. Immutability can be achieved by hardware measures, software measures, or a combination, as long as changes are either prevented or made detectable. In practice, three mechanisms do the heavy lifting:

  • WORM storage (write once, read many): the archive prevents modification or deletion of a document before its retention period expires, whether through hardware WORM media or object-lock storage.
  • Cryptographic hash chains: each document gets a hash fingerprint, and linking those hashes makes any later change detectable down to a single byte.
  • Trusted timestamps (RFC 3161): a trusted third party attests when a document existed, so you can prove it has not changed since. If you want the mechanics, see our explainer on RFC 3161 timestamps.

Together these deliver the tamper-evidence that the Unveraenderbarkeit principle calls for.

Where SealDoc fits

SealDoc provides the technical building blocks for the immutability and tamper-evidence side of revisionssichere Archivierung. Documents are stored on WORM object storage with retention enforced, so they cannot be deleted before their period expires. Each document gets an RFC 3161 timestamp from a trusted, EU-based Time Stamping Authority (a qualified TSA is configurable on the Enterprise plan) and a SHA-384 hash chain, and everything can be exported as a court-ready Evidence Pack. It all runs in the EU with no US hyperscaler dependency, which matters when data sovereignty is part of the requirement.

What SealDoc does not do, and no tool does, is make you GoBD-compliant on its own. GoBD-compliance is broader than storage: it needs your Verfahrensdokumentation, your internal controls, and complete, timely capture across your whole process. SealDoc gives you the technical immutability and the proof; the process and its documentation stay with you. And SealDoc never claims more than it can prove: each guarantee in the Evidence Pack is asserted only when its backing proof is present. (Legal Hold, to freeze a document beyond its normal retention period, is coming soon.)

A short checklist for revisionssichere Archivierung

  1. Store tax-relevant documents so they cannot be changed undetectably (WORM plus hashes and timestamps).
  2. Capture completely and promptly.
  3. Keep them retrievable and machine-evaluable throughout the retention period.
  4. Apply the correct period: 8 years for invoices and vouchers (10 for banks and insurers), 10 for annual accounts, 6 for business letters.
  5. Write and maintain a Verfahrensdokumentation, and keep it matching your actual process.
  6. Run and log an internal control system.

Revisionssichere Archivierung is a combination of the right technology and the right documentation. Get the immutability and the proof right, keep the process documented, and the archive holds up when an auditor asks. See what SealDoc’s legal proof layer adds, or the German e-invoicing guide if you are also handling XRechnung and ZUGFeRD.


← Back to all articles