# Sales Tax Exemption Certificate: A Guide for SaaS

> What a sales tax exemption certificate is, when a B2B SaaS buyer can claim one, how to validate and store it, and what happens in an audit if you cannot.
- **Author**: Deepak Jangir
- **Published**: 2026-08-07
- **Category**: Compliance, SaaS
- **URL**: https://dodopayments.com/blogs/sales-tax-exemption-certificate

---

A procurement contact replies to your invoice with a PDF and one line: "We are exempt, please reissue without tax." The PDF is a sales tax exemption certificate. Whether you can act on it, and what happens if you act on a bad one, is entirely your problem rather than theirs.

A sales tax exemption certificate is a document a buyer provides to a seller to claim that a purchase is not subject to sales tax. Accepting a valid one in good faith shifts the liability for that uncollected tax from the seller to the buyer. Accepting an invalid one leaves the liability exactly where it started, with you.

That asymmetry is the entire subject. The certificate is not paperwork, it is the evidence that protects you in an audit years later.

## When a SaaS Buyer Can Actually Claim Exemption

Not every buyer who asks is entitled. Exemptions fall into a small number of categories, and only some apply to software.

| Exemption type | Basis of the claim | Applies to SaaS? |
| --- | --- | --- |
| Resale | Buyer will resell the product rather than consume it | Yes, for genuine resellers and some agencies |
| Entity-based | Buyer is a government body, school, or qualifying nonprofit | Often, but varies by state |
| Use-based | The specific use is exempt, such as manufacturing or R&D | Sometimes, narrowly defined |
| Direct pay permit | Buyer is authorised to self-assess and remit directly | Yes, where the state issues them |
| Product-based | The product category itself is not taxable in that state | Not a certificate matter, see below |

The last row causes the most confusion. In several US states, SaaS is simply not a taxable product, and in others it is taxable only in specific configurations. That is not an exemption and it does not need a certificate. It is a taxability determination you make from the state's rules and the nature of the product.

The practical consequence is that a buyer in a state where SaaS is untaxed may send you a certificate you do not need, while a buyer in a state where SaaS is fully taxable may claim resale status they are not entitled to. Our guide to [sales tax on digital goods by state](https://dodopayments.com/blogs/sales-tax-digital-goods-by-state) covers the taxability map, and [US sales tax for SaaS](https://dodopayments.com/blogs/us-sales-tax-saas) covers the underlying framework.

Exemption only becomes relevant once you have an obligation to collect in that state at all, which depends on nexus. [Sales tax nexus and when to collect](https://dodopayments.com/blogs/sales-tax-nexus-saas-when-to-collect) covers the thresholds, and [states with no sales tax](https://dodopayments.com/blogs/states-with-no-sales-tax-saas-sellers) covers where the question never arises.

## What Makes a Certificate Valid

A certificate that is missing required fields is not a weak certificate. In most states it is no certificate, and the good faith protection does not attach.

Check every one of these before you stop charging tax:

- **Buyer's legal name and address**, matching the entity on the invoice rather than a trading name.
- **Seller's name**, which should be your legal selling entity. A certificate made out to a different company is not yours to rely on.
- **A permit or registration number** where the state requires one, in the correct format for that state.
- **The reason for exemption**, stated specifically rather than as a generic tick.
- **A description of the property or service** covered, which must plausibly cover what you actually sell.
- **Signature and date**, from someone with authority.
- **The correct state form**, or a multistate form the state actually accepts.

Two structural points matter as much as the fields.

A resale claim has to be plausible. If a buyer claims they are purchasing your product for resale, and your product is an internal analytics tool they are obviously consuming themselves, the certificate does not protect you. Good faith means the claim is credible on its face, not that you collected a document.

Multistate forms are convenient but not universal. Several states do not accept them, or accept them only for certain exemption types. Treat a multistate form as a starting point to verify, not as automatic coverage.

## Validation, Storage, and Expiry

This is where the operational failures happen, and where audits find money.

**Validate before you stop charging.** Where a state provides a verification lookup for permit numbers, use it. A number that does not resolve is a number that will not resolve in an audit either.

**Store the certificate itself, not a note that one exists.** In an audit, a line in your billing system saying "exempt" is worth nothing. You need the document, linked to the customer and to the specific transactions it covers.

**Track expiry.** Some certificates are single-purchase. Some are blanket certificates covering ongoing sales. Some expire on a fixed schedule and some remain valid while the relationship is continuous. A blanket certificate from four years ago for a customer whose business has changed is a weak position.

**Re-verify on change.** If the buyer's entity name changes, they restructure, or they start buying a materially different product, the existing certificate may no longer describe the transaction.

**Keep them for the audit window.** Retention needs to outlast the state's lookback period, which is commonly several years and longer where no return was filed.

A workable process for a small team:

1. Refuse to zero-rate an invoice until the certificate is received and checked against the list above.
2. Verify the permit number where a lookup exists.
3. Attach the document to the customer record with the states and date range it covers.
4. Set a review date, and re-request on expiry or on any change of entity or product.
5. Reconcile monthly: every exempt sale should map to a stored certificate.

Our [accounts receivable guide](https://dodopayments.com/blogs/accounts-receivable-saas-guide) covers where this sits in the billing cycle, and [automated invoices for SaaS](https://dodopayments.com/blogs/automated-invoices-saas) covers getting the tax treatment onto the document correctly.

## What Happens in an Audit

An auditor selects exempt transactions and asks for the supporting certificate. For every transaction where the certificate is missing, incomplete, or implausible, the assessment is the tax you did not collect, plus interest, plus penalties.

The part that surprises founders is who pays. You cannot generally go back to the customer for the tax after the fact as a practical matter, particularly if the relationship ended. So an assessment on uncollected tax comes out of your margin on a sale you already recognised. Our note on [revenue leakage](https://dodopayments.com/blogs/revenue-leakage-saas) covers how this class of problem compounds quietly.

Some states allow a post-audit window to obtain missing certificates. Relying on that is a poor plan: chasing signed documents from customers who churned two years ago has a low success rate.

```mermaid
flowchart TD
    A[B2B sale in a state where you have nexus] --> B{Is the product taxable in that state?}
    B -- No --> C[No tax, no certificate needed]
    B -- Yes --> D{Buyer claims exemption?}
    D -- No --> E[Charge and remit tax]
    D -- Yes --> F{Certificate complete and plausible?}
    F -- No --> E
    F -- Yes --> G[Zero-rate, store certificate, set review date]
    G --> H[Reconcile exempt sales to stored certificates monthly]
```

## Three Cases That Break the Simple Rule

The framework above handles most sales. These three come up often enough to plan for.

**The reseller who is also an end user.** An agency buys 20 seats of your product: 15 are resold to clients and 5 are used internally. A blanket resale certificate does not cover the 5 they consume. Strictly, tax is due on the portion used internally, and in many states the buyer is expected to self-assess use tax on it. Your exposure is limited if the certificate was valid and the claim plausible, but a certificate covering an obviously mixed purchase is worth a note in the file.

**The customer who becomes taxable mid-subscription.** Exemption status is not permanent. A nonprofit that loses its status, or a reseller whose permit lapses, changes the correct treatment from the next billing cycle. Annual subscriptions hide this well, because nobody revisits the tax decision between renewals. Re-verification belongs in the renewal path, not only at signup.

**Nexus arriving after the exemption was accepted.** You only need a certificate in states where you have an obligation to collect. Crossing an economic nexus threshold in a new state means transactions that were previously out of scope are now in scope, including those from existing exempt customers who never sent you a certificate because none was needed. Growing into a state retroactively creates a certificate collection exercise for the existing book, not just for new sales.

The common thread is that exemption is a property of a transaction at a point in time, not a permanent flag on a customer record. Billing systems tend to model it as the latter, which is why the reconciliation step matters.

## Where a Merchant of Record Changes the Obligation

Everything above assumes you are the seller of record and therefore the party responsible for determining taxability, collecting tax, validating exemption claims, and defending them in an audit.

Under a [merchant of record](https://dodopayments.com/blogs/what-is-a-merchant-of-record) model, the MoR is the legal seller on the transaction. It carries the registration, collection, filing, and remittance obligations for indirect taxes, and it holds the exposure that comes with them. That includes the sales tax determination on each transaction rather than only the arithmetic.

What this does and does not change:

- **It does change** who registers in each state, who files returns, who handles the exemption workflow on the transactions it processes, and who is assessed if a determination was wrong.
- **It does not change** your own income tax position, and it does not make an exemption claim valid that would otherwise be invalid.

On Dodo Payments, tax calculation, filing, and reporting across 190+ countries is included in the platform fee rather than charged as a percentage add-on. The [tax-inclusive pricing documentation](https://docs.dodopayments.com/features/tax-inclusive-pricing) covers how the determination is applied at checkout, the [B2B payments documentation](https://docs.dodopayments.com/features/b2b-payments) covers collecting business details at the point of sale, [invoice generation](https://docs.dodopayments.com/features/invoice-generation) covers getting the treatment onto the document, and the [merchant of record overview](https://docs.dodopayments.com/features/mor-introduction) covers who holds the liability. For the broader operating model, [how to automate global tax compliance](https://dodopayments.com/blogs/how-to-automate-global-tax-compliance-a-solopreneur-s-toolkit) covers the broader operating model. For businesses selling into both the US and Europe, [VAT versus sales tax](https://dodopayments.com/blogs/vat-vs-sales-tax-saas) explains why the exemption concept works so differently across the two systems.

## FAQ

### Does a customer telling me they are tax exempt let me stop charging tax?

No. You need the certificate itself, complete and plausible for what you sell, before you zero-rate an invoice. A verbal or emailed assertion provides no protection in an audit, and the liability for uncollected tax stays with you as the seller.

### How long do I need to keep exemption certificates?

At least as long as the state's audit lookback period, which is commonly several years and can be considerably longer where no return was filed. Store the document itself alongside the transactions it covers, not just a flag in your billing system.

### Are multistate exemption forms accepted everywhere?

No. Several states do not accept them at all, and others accept them only for particular exemption types. Treat a multistate form as a claim to verify against the specific state's rules rather than as blanket coverage.

### What if SaaS is not taxable in the customer's state?

Then no tax applies and no certificate is required. That is a taxability determination, not an exemption. Buyers sometimes send certificates in states where the product was never taxable, which is harmless but not something you need to rely on.

### Who is liable if an exemption certificate turns out to be invalid?

The seller, in most cases. Good faith acceptance of a valid, complete certificate shifts liability to the buyer, but an incomplete certificate or an implausible claim generally does not, leaving the uncollected tax, interest, and penalties with you.

## The Takeaway

Exemption certificates protect the seller, which is why the seller has to do the work. Establish taxability first, because a product that is not taxable in a state needs no certificate at all. Where a claim is genuine, collect a complete certificate before zero-rating anything, verify the permit number, store the document against the transactions it covers, and diary the expiry. The alternative is discovering in an audit that a folder of PDFs nobody checked is worth nothing.
---
- [More Compliance articles](https://dodopayments.com/blogs/category/compliance)
- [All articles](https://dodopayments.com/blogs)