本站热词:
上海城市精神: 海纳百川 追求卓越 开明睿智 大气谦和

Guidelines for Natural System Connection for Self-use of Shanghai Municipal Tax Service of State Taxation Administration (2025 Edition)

发布时间:2025-02-12 09:53
字号:[ ] [ ] [ ]
打印本页

  Chapter I Overview

  1. Concepts

  (1) Natural System

  The Natural System (meaning proprietary information system) is a tax service featuring embedded rules and interoperable data the tax authorities provide for enterprises meeting certain conditions through the direct connection between the tax authorities' information systems and enterprises' proprietary information systems.

  (2) Natural System Platform

  The Natural System Platform is a digital platform created by the State Taxation Administration based on the principles of rule-based openness and standard uniformity. It is directly connected to enterprises' proprietary information systems. The platform provides enterprises with functions such as application for connection, subscription of capabilities, testing and verification, rule application, and authorization management.

  (3) Directly-Connected Platforms

  Directly-connected platforms refer to enterprises' proprietary information systems that have been directly connected to the Natural System Platform, embedded with tax and fee business rules, and transformed.

  (4) Natural System Connection for Self-use

  The Natural System Connection for Self-use ("NSCS") refers to the model where applicants, through Directly-connected platforms, provide tax-related services such as the use of fully digitalized electronic invoices and tax declaration for themselves and their subordinates. Subordinates typically include enterprises' members, branches, equity-controlled entities.

  (5) Applicants

  Applicants refer to the enterprises that apply for connection to the Natural System Platform. Generally, they are the headquarters of enterprise groups, the head offices of parent companies and actual controlling entities with equity control relationships. If there is no subordinate, an applicant refers to the enterprise itself.

  (6) Directly-Connected Entities

  Directly-connected entities refer to domestic entities that own or control directly-connected platforms and possess independent legal person status. Directly-connected entities can be applicants themselves or subordinates designated by applicants. Where a directly-connected entity is a subordinate designated by the applicant, an application for connection can be filed directly upon authorization by the applicant.

  (7) User Entities

  User entities refer to entities that use fully digitalized electronic invoices, tax declaration and other tax-related services via directly-connected platforms upon registration by directly-connected entities. User entities are generally subordinates under the applicants, including enterprises' members, branches, equity-controlled entities (if there is no subordinate entity, a user entity refers to the enterprise itself).

  Chapter II Responsibilities of NSCS Entities

  1. Responsibilities of Directly-Connected Entities

  (1) Directly-connected entities are responsible for connecting directly-connected platforms to the Natural System Platform, notifying user entities to connect to directly-connected platforms, and maintaining their relationships in a timely manner. They shall ensure that themselves and user entities meet the connection requirements and provide relevant operational support such as reporting changes, updating versions, suspending or terminating services. When user entities utilize the functions of the Natural System, they shall promptly provide services such as problem solutions and operation guidance. If it is found that user entities do not meet the connection conditions, the provision of tax-related services should be immediately halted. When directly-connected entities are no longer related to user entities, the connection with them should be terminated.

  (2) Directly-connected entities shall provide tax data concerning themselves and user entities as required by tax authorities, including but not limited to information regarding the operators' identities, operating revenue, logistics and cash flows of user entities.

  (3) Directly-connected entities shall implement the cybersecurity classified protection system, assume responsibility for securing directly-connected platforms, and ensure their safe and stable operation in accordance with relevant laws and regulations, including the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, and the Personal Information Protection Law of the People's Republic of China.

  (4) Directly-connected entities shall provide services for using fully digitalized electronic invoices in accordance with the Measures for the Administrative Measures for Invoices of the People's Republic of China and its implementation rules and relevant normative documents of the STA.

  (5) Directly-connected entities shall report to the tax authorities all of their significant changes and those in user entities, in a bid to ensure the authenticity of the submitted information or materials.

  (6) Directly-connected entities shall regulate the daily tax-related activities of user entities, ensure that the original data sources for invoice issuance can be traced, and carry out tax-related risk prevention and control as required by the tax authorities. In the event of any abnormalities in invoice issuance or usage by user entities, directly-connected entities shall report them to the tax authorities promptly and cooperate with the tax authorities to prevent risks.

  2. Responsibilities of User Entities

  (1) User entities shall be responsible for the authenticity of their business operations. They should handle tax-related matters such as the use of fully digitalized electronic invoices and tax declaration in accordance with laws and regulations.

  (2) As required by the tax authorities, user entities shall cooperate with directly-connected entities to upload tax data through directly-connected platforms, including but not limited to information regarding their operators' identities, operating revenue, logistics and cash flows.

  (3) If the relevant transactions do not rely on channels such as apps or WeChat official accounts, user entities shall not, under the pretext of the tax-related services provided via directly-connected platforms, require transaction counterparties to download their apps or follow their WeChat official accounts.

  3. Others

  Directly-connected entities and user entities shall offer various methods for delivering fully digitalized electronic invoices, such as QR codes, emails, downloads and printouts. If the invoice recipient is an individual (i.e., the invoice title is an "individual" or an individual's name), priority should be given to providing delivery methods such as QR code download and free invoice printing. Email shall not be designated as the sole delivery method.

  Chapter III Connection of NSCS Entities

  1. Connection of Directly-Connected Entities

  (1) Connection Conditions

  Directly-connected entities connecting to the Natural System Platform shall meet the following basic conditions:

  (a) A directly-connected entity and its registered user entities shall achieve a combined revenue of more than 50 million yuan in the previous year;

  (b) For the 12 months prior to the application for connection, a directly-connected entity and its registered user entities shall issue and receive no less than 10,000 invoices in total, or the cumulative invoicing amount shall be no less than 100 million yuan;

  (c) The tax credit rating for the previous year was either A or B;

  (d) No major tax violations or significant tax-related public opinion events happened in the past three years;

  (e) Directly-connected entities shall possess professional capabilities in informatization, service, operation and maintenance, as well as security, and have software copyrights, usage rights or relevant authorizations for their proprietary information systems that are intended to be connected to the Natural System Platform.

  If players in industries related to people's livelihood such as hospitals, education, water, gas, heating and electricity, and public transportation, as well as large state-owned enterprises, public institutions, and industry associations apply for connecting to the Natural System Platform, the connection conditions will be adjusted based on specific circumstances.

  (2) Connection Process

  (a) Application for Connection

  (i) Applications for connection submitted by directly-connected entities Directly-connected entities that meet the connection conditions can submit their application materials to their competent tax authorities (If a directly-connected entity is a subordinate of the applicant, an authorization letter from the applicant should be provided).

  (ii) Acceptance and confirmation by tax authorities Upon accepting the applications, the competent tax authorities shall review the application materials and submit them to the tax authorities at the provincial level or above once the applications are approved. Upon confirmation by the provincial tax authorities, official connection can be initiated.

  (iii) Cybersecurity connection strategy activated by tax authorities After the provincial tax authorities confirm the connection of directly-connected entities, applications shall be filed for activating the taxation cybersecurity connection strategy for directly-connected entities' proprietary information systems. Following activation, directly-connected entities can connect to the Natural System Platform and carry out joint debugging and simulation tests.

  (b) Embedding of Natural System Rules

  (i) Capability subscription Directly-connected entities subscribe to Natural System Capabilities released by the tax authorities via the Natural System Platform.

  (ii) System transformation Directly-connected entities complete the transformation of their proprietary information systems and the embedding of the Natural System Rules. They provide tax-related services to user entities in accordance with the rules.

  (iii) Capability testing following the transformation of their proprietary information systems, directly-connected entities carry out joint debugging and simulation tests on the testing center of the Natural System Platform. After they pass such tests, the Natural System Platform will generate corresponding test reports.

  (iv) Capability activation Directly-connected entities submit the capability test reports to tax authorities and have them confirmed, after which the corresponding Natural System Capabilities will be activated. Directly-connected entities can independently set the validity periods of the enabled capabilities. Upon expiration, they need to re-subscribe these capabilities, re-submit the capability test reports, and have it confirmed by tax authorities before reactivation.

  (v) Capability authorization Directly-connected entities can authorize user entities to utilize the relevant capabilities based on the industries where they operate business and their qualifications.

  (3) Submission of Connection Materials

  Eligible directly-connected entities apply to the competent tax authorities for connection to the Natural System Platform. They need to submit the following materials:

  (a) NSCS Direct Connection (Change) Information Form (attached: list of user entities);

  (b) NSCS Commitment Letter;

  (c) Proofs of software copyrights, usage rights or related authorizations;

  (d) NSCS Project Report, including business description, technology description, and tax risk prevention and control plan;

  (i) Business description should contain the business scope, business model, tax-related business, business volume, data flow and operating instructions regarding directly-connected entities applying for NSCS connection, as well as transformation and deployment methods of their proprietary information systems, such as concrete information of a third-party company (if any) that participates in or undertakes technological transformation and authorization for transformation;

  (ii) Technology description should cover the network environment, security plan, hardware environment, system design, and technical implementation method of directly-connected platforms, wherein the security plan should satisfy the requirements of the cybersecurity classified protection system set out in the Cybersecurity Law of the People's Republic of China;

  (iii) Tax risk prevention and control plan should include tax risk prevention and control requirements, risk prevention and control indicators, risk response measures, and daily monitoring.

  (e) Registration Form for Network Addresses of Directly-Connected Platforms;

  (f) Certificate for Dedicated Use of Fixed IP Addresses;

  (g) List of abnormalities required to be rectified during the previous withdrawal of directly-connected entities ordered by the tax authorities and their directly-connected platforms, the corresponding reports on the rectification efforts, and explanation of the guarantee mechanism for preventing the recurrence of any abnormalities;

  (h) Other materials.

  2. Connection of User Entities

  (1) Connection Conditions

  User entities connecting to the Natural System Platform shall meet the following basic conditions:

  (a) User entities shall be subordinates of applicants, including enterprises' members, branches, equity-controlled entities;

  (b) The tax credit rating of a user entity should, in principle, be A, B or M (except for those that are not involved in the tax credit rating evaluation, such as non-independent accounting branches);

  (c) There were no major tax violations identified by the tax authorities within the past three years;

  (e) Others.

  (2) Connection Process

  Upon receipt of notices from directly-connected entities via the Natural System Platform, user entities shall confirm this on the platform, fill in the competent tax authorities, the relationships with applicants and other information, and file applications to the competent tax authorities for use. User entities can be connected to the platform upon acceptance and confirmation by the competent tax authorities.

  (3) Submission of Connection Materials

  (a) Relevant materials that can prove their relationships with applicants;

  (b) Others required by the tax authorities.

  Chapter IV Services and Supervision

  1. Service Content

  (1) Directly-connected entities can obtain documents, operating instructions, version upgrade notices and more regarding the Natural System released by the tax authorities through the Natural System Platform.

  (2) Directly-connected entities can gain technical support by consulting, via Natural System-related promotion, operation and maintenance service channels established by the competent tax authorities, on problems encountered during system transformation and joint debugging and simulation tests, and on technical problems concerning the Natural System Platform during operations.

  (3) Directly-connected entities and user entities can consult and obtain information about the Natural System through local taxpayer-tax authority interaction platforms, the 12366 hotline, and tax service venues.

  2. Daily Supervision

  (1) Change in Basic Information

  Changes in the basic information of directly-connected entities and IP addresses of directly-connected platforms shall be promptly reported to the competent tax authorities.

  (2) Data Submission

  Directly-connected entities shall, in accordance with the requirements of the tax authorities, promptly submit tax data regarding themselves and user entities through the Natural System Platform, tax service venues and other channels.

  (3) Operation Monitoring

  The Natural System Platform sets monitoring indicators to monitor and issue a warning on connection conditions, risk points, operational stability of directly-connected platforms, among others. Additionally, it will directly push the warning information to directly-connected entities, user entities and the corresponding competent tax authorities via the Natural System Platform, electronic tax service bureaux, taxpayer-tax authority interaction platforms and other channels. Directly-connected entities shall embed the monitoring indicators provided by the Natural System Platform into directly-connected platforms, so as to assist the tax authorities in conducting tax-related risk monitoring.

  3. Handling of Abnormalities

  (1) Handling of Abnormalities in Directly-Connected Entities

  (a) In any of the following circumstances, the competent tax authorities shall give directly-connected entities a reminder:

  (i) Failure to carry out system upgrades in accordance with the requirements for direct connection to the Natural System, in a timely manner or in compliance with laws and regulations;

  (ii) Inconsistency between the Natural System Capabilities granted and the industries where user entities operate business and their qualifications;

  (iii) Unstable operation or system failure of directly-connected entities, affecting the use of the Natural System Capabilities;

  (iv) Failure to report tax data regarding directly-connected entities or user entities as required by the tax authorities or to update important registration information in a timely manner;

  (b) In any of the following circumstances, the competent tax authorities shall order directly-connected entities to make corrections within a specified time limit:

  (i) Failure to implement the tax risk prevention and control measures or embed the risk prevention and control rules as required by the tax authorities;

  (ii) Occurrence of cybersecurity attacks on the tax authorities due to the reasons of directly-connected entities or directly-connected platforms, resulting in losses or adverse impacts.

  If tax-related illegal activities such as fictitious invoice issuance and false tax declaration conducted by directly-connected entities in collaboration with user entities via the Natural System and attacks on the tax authorities' information systems through directly-connected platforms lead to serious adverse consequences, the tax-related services function of directly-connected platforms can be suspended upon confirmation by the provincial tax authorities.

  (2) Handling of Abnormalities in User Entities

  (a) In any of the following circumstances that cause complaints among consumers, the competent tax authorities shall order user entities to make corrections within a specified time limit. If user entities fail to make corrections within a specified time limit, the competent tax authorities may terminate their connection to the Natural System.

  (i) Failure to offer various methods for delivering fully digitalized electronic invoices, such as QR codes, emails, downloads and printouts;

  (ii) Designation of emails as the sole delivery method or failure to make available QR code download and free invoice printing for individual consumers;

  (iii) Collection of additional information unrelated to transactions during invoice issuance;

  (iv) Requesting transaction counterparties to download their apps or follow their WeChat official accounts under the pretext of the tax-related services provided, although the relevant transactions do not rely on apps and WeChat official accounts.

  (b) Once user entities' original relationships are dissolved following their connection to the Natural System, the competent tax authorities may terminate such connection.

  Chapter V Network and Data Security

  1. Compliance and Security

  Directly-connected entities shall ensure cybersecurity level protection for directly-connected platforms in compliance with Cybersecurity Level Protection 2.0 standards (e.g. GB/T 22239-2019 Information Security Technology - Baseline for Classified Protection of Cybersecurity and GB/T 22240-2020 Information Security Technology - Classification Guide for Classified Protection of Cybersecurity). Directly-connected entities shall establish a responsibility system where a person with the ability to make independent decisions and maintaining a relatively stable state is appointed to ensure the cybersecurity of directly-connected platforms. Directly-connected entities shall formulate network and data security emergency plans and organize emergency drills on a regular basis.

  2. Cybersecurity

  For network boundaries of directly-connected platforms, a network intrusion prevention system should be established with security technologies that satisfy cybersecurity management requirements (e.g. firewalls and intrusion detection/defense), in order to prevent or limit network attacks launched from either the internal or external sides against directly-connected platforms, and ensure the security of network access and data circulation. Directly-connected platforms shall enhance host security protection, follow the principle of least privilege for the host, monitor and prevent intrusions into the host, and check and kill Trojan viruses on a regular basis. Directly-connected platforms shall standardize the conduct of security checks such as vulnerability scanning to prevent the diversion of scanning detection traffic to the tax authorities

  3. Application Security

  Directly-connected platforms shall provide a complete and unified security access mechanism to manage users' access rights securely. Directly-connected platforms shall record important behavior in systems and include date, time, initiator information, type, description and result concerning an event in audit records. They should ensure complete log records for all operations carried out by user entities. Such log records shall be retained for at least 6 months.

  4. Data Security

  (1) Clarifying Data Security Governance Framework

  Directly-connected entities should establish a data security responsibility system, designate a department to be responsible for data security work, clearly define the data security management responsibilities, and meet the requirements for data security protection and management.

  (2) Establishing Data Classification and Grading Standards

  Directly-connected entities should formulate a data classification and grading protection system, establish a data directory and classification and grading norms, dynamically manage and maintain the data directory, and adopt differentiated security protection measures.

  (3) Ensuring Data Transmission and Usage Security

  Directly-connected entities should establish a data security technology protection system, and clearly define data protection strategies and methods. During the transmission of sensitive data such as invoice data and personal information to the tax authorities' information systems, technical measures should be taken to ensure data security and prevent security issues such as data leakage, tampering, and loss.

  Directly-connected entities should not use, modify or delete user data without authorization of user entities. It is imperative to prevent security issues such as unauthorized collection, malicious tampering, information leakage, and illegal trading of sensitive data like invoice data and personal information.

  Chapter VI Exit from Natural System

  1. Exit of Directly-Connected Entities

  (1) Application for Exit from Natural System

  If directly-connected entities apply for exit from the Natural System, they must complete the service termination filing with the competent tax authorities prior to service termination. No new user entity may be added during the period from filing to exit from Natural System.

  Directly-connected entities that apply for exit shall not submit new applications within one year after exit.

  (2) Order from Tax Authorities for Exit from Natural System

  The tax authorities may order directly-connected entities to exit from the Natural System in the event that tax-related services on directly-connected platforms are suspended due to abnormalities set out in Chapter IV and directly-connected entities fail to rectify them within a specified time limit.

  Directly-connected entities that are ordered by the tax authorities to exit from the Natural System will be prohibited from reapplying for connection in the next three years.

  2. Exit of User Entities

  Where user entities apply for exit from the Natural System, their original relationships shall be dissolved via the Natural System Platform.

  Annexes:

  Annex 1. NSCS Direct Connection (Change) Information Form (attached: list of user entities)

  Annex 2. NSCS Commitment Letter

  Annex 3. Certificates of Software Copyrights and Rights to Use for Enterprises' Proprietary Information Systems

  Annex 4. NSCS Project Report

  Annex 5. Registration Form for Network Addresses of Directly-Connected Platforms

  Annex 6. Certificate for Dedicated Use of Fixed IP Addresses

【返回顶部】【打印本页】【关闭本页】

主办单位:国家税务总局上海市税务局

地址:上海市肇嘉浜路800号 电话:021-12366

网站标识码:bm29090019 沪ICP备19025643号-1 沪公网安备 31010402005587号