A stocktake of the machine-readable Jahresrechnung in Switzerland · 255 public documents, every statement with its source and its date

Two standards, 26 cantons · Part 3 of 14

3 · Three gates, not one

The short version of the bottleneck in circulation goes: a contract is missing. That is correct, and it is the smaller half. Anyone who reads the Swissdec Transmitter specification of 06.03.2026 («Technische Spezifikation eBILANZ · Version 20260306 · Anforderungen Transmitter») (Technical specification eBILANZ · Version 20260306 · Transmitter requirements) together with the 35 XML schemas shipped with it, the one WSDL file and the eleven SOAP examples finds not one admission condition but three — contractual, certificate-based, identity-based. They are independent of one another, each is documented separately, and each would have to fall separately. The third sits furthest from tax law: the identity of a Swiss company on the national transmission network is proven through its insurer.

Gate 1 — the contract

Directly below the communication matrix (Table 2.1, Part 2) sits a note. In the debate it is regularly quoted half. In full it reads:

«Aus vertragsrechtlichen und statuarischen Gründen seitens Swissdec können aktuell nur kantonseigene Deklarationslösungen die E-Bilanz via Distributor elektronisch empfangen. Für die Anbindung von privaten Deklarationslösungen an den Distributor müssen zuerst die vertraglichen Grundlagen geschaffen werden.» (for reasons of contract law and of Swissdec's own statutes, currently only the cantons' own Deklarationslösungen can receive the E-Bilanz electronically via the Distributor; for private Deklarationslösungen to be connected to the Distributor, the contractual basis has to be created first)

— Swissdec, Technische Spezifikation eBILANZ, edition 06.03.2026, ch. 2, note directly below Table 2.1 (statuarischen sic)

Three observations that only the full text yields.

First: «seitens Swissdec». (on Swissdec's side) The half-sentence names who carries the barrier. It is not a federal rule, not one of the Schweizerische Steuerkonferenz (the Swiss Tax Conference), not one of a canton. It is the contractual and statutory position of the association that runs the network — described by that association itself. Anyone who wants to see the barrier fall knows which table to sit down at.

Second: the two readings. Sentence 1 speaks of receiving — «können aktuell nur kantonseigene Deklarationslösungen die E-Bilanz via Distributor elektronisch empfangen» (currently only the cantons' own Deklarationslösungen can receive the E-Bilanz electronically via the Distributor). Read narrowly, it governs who may be the addressee of a DeclareRawBalanceSheet, that is, the target side of the XBRL track. Sentence 2 generalises: it speaks of «der Anbindung von privaten Deklarationslösungen an den Distributor» (the connection of private Deklarationslösungen to the Distributor) as such, without a direction. The two sentences do not say the same thing. That ambiguity belongs in the open rather than resolved in one direction or the other — because the same matrix the note sits under already carries a numbered row DISTRRIBUTOR[2] (sic, three Rs) for the route Private Deklarationslösung → SwissdecAdapter, Teil 7, DeclareBalanceSheet, eCH-0276. And the process description in §2.2 lists the «Private Deklarationslösung Transmitter» as the third of three participating systems. The architecture knows this actor. It is suspended, not excluded.

Third: «zuerst». (first) The word presupposes a «dann» (then). It points forward; it does not close. A sentence meant to exclude a category permanently would manage without that adverb. This is neither a commitment nor a deadline — but it is the difference between a wall and a door without a key.

A margin note on diligence: we cite this passage structurally, not by page number. Our own extraction places it between page mark 6 and the heading §2.1; an earlier note of our own says «§2, S. 6» (§2, p. 6). Where we cannot evidence the page with certainty, we do not name it.

Gate 2 — certification

The second gate is not in the prose, it is in the interface description. schema/BalanceSheetDeclarationService.wsdl (SHA-256 3ca8a5806b283649b154bb79008fb4bbc6e7ed2f8ca811ce18a0e88af7175879) defines seven operations. Six of them carry a word-identical wsdl:documentation:

This operation must be signed by: ERP Certificate

The ones affected are DeclareRawBalanceSheet, SynchronizeDeclareRawBalanceSheet, DeclareBalanceSheet, GetStatusFromDeclareBalanceSheet, SynchronizeDeclareBalanceSheet and CheckInteroperability. The seventh, Ping, carries:

This operation must be signed by: None

That matches §8.15 of the guidelines: «Ausser dem Erreichbarkeitstest muss jede Übermittlung signiert und verschlüsselt werden.» (apart from the reachability test, every transmission must be signed and encrypted). Everything that carries data needs a certificate; the bare knock-on-the-door call does not.

On the name of this certificate: the published interface holds no authorisation class of its own for a Deklarationslösung. Even the two operations that per Table 2.1 are called exclusively by Deklarationslösungen — the cantons' own and private ones alike — require an «ERP Certificate», that is, the authorisation of the actor on the other track. That is first of all an observation about wording, not about intent. But it has a practical edge: a provider wanting to go through the certification process today would find no credential in the interface cut for them.

How this credential appears in the message is stated by Table 4.2 and 8.3 respectively, UserAgentType, verbatim:

Certificate — «Zertifikatsnummer, xxxx.yy wie auf dem physischen Zertifikat abgebildet» (certificate number, xxxx.yy as shown on the physical certificate)

Producer — «Name des Softwareherstellers» (name of the software manufacturer)

And §8.1.1.1 follows up — the passage is marked in the original with a bold warning word: «Der UserAgent muss im Anschluss an die abgeschlossene Swissdec-Zertifizierung aktualisiert werden und muss sämtliche Informationen zum ERP-System (und nicht zum Endbenutzer) enthalten.» (the UserAgent must be updated once Swissdec certification is complete and must contain all information on the ERP system, and not on the end user).

That makes the finding precise: every message on this line carries the name of the software manufacturer and a physical certificate number. Functionally that is an admission register per manufacturer, kept at the interface itself. We write this sentence from a house that holds exactly such a thing: a German manufacturer ID that travels with every filing we transmit, and through which the tax administration counts each month how many real payload blocks we have submitted. A manufacturer register is a long-established instrument, and it carries a price worth knowing before paying it: whoever is not in it does not exist on the line.

How early the programme stands shows in the examples shipped. All eleven SOAP samples in the package carry <ep:Producer>Swissdec</ep:Producer>, <ep:StandardVersion>0.0</ep:StandardVersion> and <ep:Certificate>n/a</ep:Certificate>. The certification level for eBILANZ 1.0 is not yet numbered in the artefacts shipped.

Gate 3 — SUA, and what a company is recognised by

The third gate concerns not the software but the filing company. Annex C describes the «Swissdec Unternehmens-Authentifizierung» (SUA) (Swissdec company authentication). C.1, verbatim:

«Grundlage einer SUA Registrierung ist eine bestehende Geschäftsbeziehung des Unternehmens zu einer Versicherung, welche Identität des Unternehmens bereits geprüft hat. Auf diese überprüfte Identität stützt sich Swissdec für die Identifikation des Unternehmens. Der Distributor prüft während der Registrierung die Angaben zum Unternehmen sowie die bestehende Vertragsbeziehung beim Versicherer.» (the basis of an SUA registration is an existing business relationship between the company and an insurer that has already verified the company's identity; Swissdec relies on that verified identity to identify the company; during registration the Distributor checks the company details and the existing contractual relationship held at the insurer)

The mandatory fields, likewise verbatim from the table: company name «Identisch mit Angaben aus dem UID-Register» (identical with the details from the UID register); UID number identical with the UID register and with the details held at the insurer; «Bestehende Vertragsverbindung (Vertragsnummer und Kundenummer)» (existing contractual connection — contract number and customer number) — identical with the details held at the insurer.

For representation, C.2.1.1 applies:

«Als Sicherheitsmassnahme muss der identische Stellvertreter beim Versicherer auch hinterlegt sein, was der Distributor im Rahmen der Registrierung überprüft.» (as a security measure, the identical representative must also be on file at the insurer, which the Distributor checks as part of registration)

We set this sentence down flat and we source it. A Treuhandgesellschaft that wants to register for a client along this route has to be on file with the client's insurer. What follows from that for a Treuhandgesellschaft registering for several clients is not in the documents; C.2.1.1 governs the individual representative.

The access credentials do not arrive electronically. C.2.1:

«Zu diesem Zeitpunkt wird ein Brief an die beim Versicherer hinterlegten Adresse des Unternehmens gesendet. Dieser Brief enthält ein einmaliges Registrierungspasswort sowie das Sperrpasswort. Der physische Versand wird aus Sicherheitsgründen gemacht …» (at this point a letter is sent to the company address held at the insurer; this letter contains a one-time registration password as well as the blocking password; the physical dispatch is done for security reasons …)

(in the extracted text «Brief and die», sic)

The parameters, from Table C.3.1: security feature of the registration «Brief/ A+» (letter / A+), expressly as «Zweiter, nicht elektronsicher Kanal» (second, non-electronic channel) (sic); registration password at least 12 characters, valid 1 year; blocking password at least 12 characters, valid 5 years; renewal window 60 days before expiry; «3x (3 Jahre) Anzahl möglicher automatischer Erneuerungen» (3× — 3 years — number of possible automatic renewals) — after that, C.2.3: «Ist eine Zertifikat abgelaufen, kann die Erneuerung nicht mehr durchgeführt werden. In diesem Fall muss eine neue Registrierung durchgeführt werden.» (once a certificate has expired, renewal can no longer be carried out; in that case a new registration has to be made). The certificate itself is X.509v3 per RFC 5280, issuer CN = Verein Swissdec Issuing CA by DigiCert, subject CN = NTRCH-{UID}@swissdec.ch, O = {Name aus dem UID Register}, validity 1 year.

And then the observation that needs no verdict: a company without a swissdec-connected insurance relationship has no documented route in these papers. Not «einen schwierigen» (a difficult one). None described. Nowhere is this written as an exclusion — it follows from the registration knowing no second root.

Where the chassis comes from

That explains itself as soon as you count what this network is built on. The glossary in Annex B defines Domäne as: «Im Swissdec-Ökosystem bekannte Domänen sind; AHV, FAK, UVG, UVGZ, KTG, BVG, Lohnausweis, Quellensteuer, Grenzgänger und Statistik.» (the domains known in the Swissdec ecosystem are: AHV, FAK, UVG, UVGZ, KTG, BVG, Lohnausweis, Quellensteuer, Grenzgänger and statistics). The E-Bilanz is not in the list of known domains in its own specification. Institution there means: «Empfänger, der Daten erhält. Hier handelt es sich um Versicherungen, die den jeweiligen Domänen angehören.» (recipient that receives data; these are insurers belonging to the respective domains). Amounts are throughout of type ep SalaryAmountType — including the two operands and the results of the interoperability test. And §8.1.1.2, in a balance-sheet specification: «Es wird empfohlen, dass bei der Übermittlung grösserer Datenmengen (>2000 Personen) die Daten bereits vorher gefiltert werden.» (it is recommended that, when transmitting larger data volumes (>2000 persons), the data be filtered beforehand).

We quote that because the vocabulary shows where the network comes from. A network that has been distributing payroll data to insurers for years takes on a second freight, and the vocabulary is still the old one. That is exactly why identity is proven through the insurer: for the freight this chassis was built for, an insurance relationship is not a precondition but the business purpose.

The address, and the fourth gate

The endpoint is in the same WSDL, as what it is:

<soap:address location="https://distributor.swisscom.com/services/ebilanz/BalanceSheet/V1"/>

We name the URL and claim nothing about the arrangement behind it. We have never called this endpoint — not even Ping, the one operation that requires no certificate for it.

Three gates, then, and none of them technical: a contract that, per the body carrying it, is still to be created; a credential named after the actor on the other track; an identity that hangs on an insurance contract. For Zürich a fourth is added, sitting on an entirely different level and having nothing to do with the national network: a login that, per the canton, represents «immer eine natürliche Person» (always a natural person). It is called AGOV, and Part 5 resolves it.

All four are decisions. Decisions have authors, and authors can change them.